How it plays out on a deal
Some clients must keep data in a specific jurisdiction because of law, regulation or internal policy. Public sector bodies, banks and companies with strict works councils are the usual cases. For them, residency is a pass or fail requirement.
Residency claims need care. Storage may sit in one region while support staff, backups or AI processing happen elsewhere. Ask for the full picture, including where backups live and which sub-processors can reach the data.
What to check in a review or demo
- 1Which regions are offered and whether the choice is per room or per account.
- 2Where backups, logs and any AI processing are located.
- 3Whether support staff in other countries can access room content.
Read alongside
- GDPRThe EU's privacy law since 2018.
- Data processing agreement (DPA)The contract annex in which the room vendor promises how it will treat personal information on your behalf: safeguards, who else it may use, cross-border moves and deletion at the end.
- Customer-managed keys (CMK)An option in which the client, not the provider, controls the encryption keys for its data, often through its own cloud key service.
- ISO 27001ISO/IEC 27001 sets out how an organization should run its security program as a managed cycle of risk assessment, controls and review.