Data residency
GDPR, DPAs and keeping data in-region
What it is
Data residency means guaranteeing that a customer's data is stored and processed in a specific region, usually the EU. GDPR adds obligations on top: a data processing agreement, a published list of subprocessors, and handling requests to see or delete personal data. The hard part is that data rarely lives only in your main database. Logs, backups, analytics and support tools all hold copies.
European buyers often can't sign without a DPA, and some require EU hosting. A residency promise that turns out to be false is a breach of contract.
What it takes
About 4–8 engineer-weeks to build in-house.
Answer these first
- Legal: Do we offer a DPA today, and what does it already promise?
- Engineering: Where does customer data actually live, including logs, backups and analytics?
- Engineering: Does 'EU residency' mean the database, or everything?
- Security: How do we handle a deletion request from start to finish?
- Product: Which subprocessors would we have to disclose?
- Sales: Which deals need EU hosting, and which only need a DPA?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.