Tous les systèmes opérationnels · 40+ PoPsHébergement depuis 2010
INTERKVM HOST SRL·AS 25198
Accueil/Base de connaissances/EU data residency: where the bytes sit and who can reach them
Colocation 27 septembre 2026

EU data residency: where the bytes sit and who can reach them

Where the bytes physically sit is residency. Whose courts can compel their disclosure is sovereignty. What you owe the people the data describes follows you regardless. Conflating the three is how a compliance claim outruns the infrastructure behind it.

Publié
Lecture
6 min
Two-column comparison separating data residency, where the bytes physically sit, from data sovereignty, whose courts can compel disclosure.

EU data residency gets treated as a checkbox — pick a European city, tick the box, move on — and it is three separate questions wearing one name. Where the bytes physically sit is residency. Whose courts can compel someone to hand them over is sovereignty. What you owe the people the data describes is protection law, and that one follows you regardless of geography. Conflating them is how a company ends up with servers in Frankfurt, a compliance claim it cannot support, and backups quietly replicating somewhere else.

This is an engineering guide to where data actually goes, not legal advice. Your counsel decides what your obligations are; what follows helps you describe your infrastructure accurately enough for them to do that.

Residency, sovereignty and protection are not the same thing

Data residency is physical: which facility, in which country, holds the disks. It is the easiest of the three to verify and the least meaningful on its own.

Sovereignty is about legal reach. A provider incorporated in one jurisdiction can be subject to orders from that jurisdiction's courts about data it holds elsewhere. The United States CLOUD Act is the most-cited example: it reaches US-controlled providers regardless of where the storage physically is. So "our data is in Europe" and "only European law applies to our data" are different claims, and the second depends on who owns and operates the infrastructure, not on the address of the building.

Which law applies, and where?

Protection law is the obligation itself. Under Article 3 of the GDPR, the regulation applies to processing the personal data of people in the EU when you offer them goods or services or monitor their behaviour — whether or not you are established in the Union. Hosting in Frankfurt does not create compliance, and hosting in Virginia does not avoid the obligation. What location changes is whether you also need a legal basis for an international transfer.

For transfers out of the EEA, Chapter V requires one of: an adequacy decision for the destination country, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow derogation. Transfers to certified US organisations currently rely on the EU–US Data Privacy Framework, adopted by the Commission on 10 July 2023. The General Court dismissed an action to annul it on 3 September 2025, and as of September 2026 an appeal was pending before the Court of Justice — check the current status before relying on it. That history is worth knowing: the two previous frameworks were struck down, and an architecture that does not depend on the current one being upheld is the more durable one.

Where the data actually leaves

Residency almost never breaks at the primary server. It breaks at everything attached to it, and the list is longer than people expect:

Component What it holds Where it usually lives
Backups and replication A full copy of everything, nightly Wherever the target was provisioned — the most common leak by a wide margin
CDN edge caches Whatever is cacheable, including personal data in responses Every PoP the CDN serves from
Logging and monitoring IP addresses, user identifiers, sometimes payloads The vendor's region, plus its own sub-processors
Transactional email, support desks, error trackers Addresses, message content, session detail Each processor's own infrastructure
DNS and WAF Every query or request, including ones that never reach you The provider's global anycast footprint

Map these before arguing about the server's city. A data-flow diagram with a jurisdiction written beside every box is an afternoon's work and answers the question far better than a provider's marketing page.

What to ask a hosting provider

Five questions, all answerable in writing:

  1. Which legal entity contracts with me, and where is it incorporated? This sets whose courts can issue orders to the company holding your hardware.
  2. Exactly which facility will my server be in? City and building, not region. Ask for it in the order confirmation.
  3. Where do backups, snapshots and any replication go by default? Some providers replicate across regions unless told otherwise.
  4. Who can physically reach the machine, and under what process? Remote hands are a person with access to your hardware; the process around that access is part of your security model.
  5. Who are the sub-processors? Transit providers, DDoS scrubbing, out-of-band access, anything in the path.

On our side, the answers are: the contracting entity is INTERKVM HOST SRL, a Romanian company (VAT RO42390138) and therefore squarely inside EU jurisdiction; the facilities are named per location on our network page; twelve of the thirteen dedicated-server locations — Bucharest, Dublin, Milan, Vienna, Frankfurt, Amsterdam, Sofia, Madrid, Lisbon, Paris, Marseille and Warsaw — are in EU member states, with Ashburn the single non-EU option; all eight unmetered VPS regions are EU member states; and our storage nodes are in Bucharest and Frankfurt. Nothing replicates anywhere unless you configure it to. What we do with data in the course of running the business is in the privacy policy.

Architectures, ranked by how much control they give you

Managed platform in an EU region. Easy, and the weakest claim. You are relying on the operator's controls and inheriting their corporate jurisdiction along with their facility.

Dedicated server from an EU-incorporated provider. A single tenant on hardware in a named EU building, contracted with an EU entity. Strong on both residency and sovereignty, and you hold root.

Colocation. Your hardware, your disks, your keys, in an EU facility, with a documented access process. The strongest position available short of your own building — and where the financial case for it sits against renting is worked out in colocation vs dedicated servers. Our colocation footprint covers the European facilities.

Whichever you pick, encryption changes the risk shape. Full-disk encryption with keys you hold — LUKS opened at boot over out-of-band access, rather than a key file left on the machine — means physical access to the drive does not produce readable data. It does not remove your legal obligations, and it does not protect a running system, but it turns a stolen or seized disk into ciphertext, which is a meaningfully better outcome than the alternative.

A short, honest checklist

  • Name the facility and country for every copy of the data, including backups.
  • Write the contracting entity's jurisdiction next to each supplier in the path.
  • Decide whether your architecture survives a change in transfer law, rather than assuming today's framework is permanent.
  • Encrypt at rest with keys you control, and encrypt in transit between your own nodes.
  • Re-check yearly. Providers change sub-processors and add regions without telling you.

Frequently asked questions

Does EU data residency make me GDPR compliant?

No. Residency removes the need for a transfer mechanism under Chapter V. Everything else — lawful basis, minimisation, retention, subject rights, security — is unaffected by where the server is.

Is a European data centre owned by a non-EU company sufficient?

It satisfies residency. Whether it satisfies your sovereignty requirement depends on your risk assessment of the parent company's home jurisdiction, and that is a question for your counsel rather than for a spec sheet.

Where does the UK fit after Brexit?

As of September 2026 the UK holds an EU adequacy decision, so transfers to the UK are permitted without additional safeguards while it stands — it has been extended rather than granted open-endedly, so confirm the current expiry. It is a separate jurisdiction, so include it explicitly in your mapping rather than treating it as part of the EU.

Can I keep data in one specific country rather than the EU generally?

Yes — pick the location at order time and it stays there. Some sectors require a named country, which is why we quote the facility and not just the region.

How do I prove where my data is, to an auditor or a customer?

The order confirmation naming the facility, your own network and backup configuration, and a data-flow diagram covering every processor. If you need location details in a specific form for a customer questionnaire, ask us and we will provide them.

Tweaksv1
Theme