Every European business buying software eventually asks the residency question: where does this data actually live, and under whose law? The question is worth asking precisely, because the marketing answer — "EU hosting available!" — answers less than it appears to.
This guide is the precise version: what data residency actually is, what it is not, the questions that get a real answer out of a vendor, and the honest description of the one architecture that answers all of them by construction.
Residency, transfer, and jurisdiction are three different questions
Residency is geography: which datacenter, in which country, holds the bytes.
Transfer is movement: whether personal data leaves the EU/EEA in the course of processing — to a support engineer in another region, an analytics subprocessor, a backup replica. GDPR Chapter V governs this, and since the Court of Justice's Schrems II judgment (C-311/18, July 2020) struck down Privacy Shield, transfers to the US have run on standard contractual clauses and, more recently, the EU-US Data Privacy Framework — a regime that has been litigated twice already and may be again.
Jurisdiction is compulsion: whose courts can order the data handed over. This is the one EU hosting alone does not settle — under the US CLOUD Act (2018), a provider subject to US jurisdiction can be ordered to produce data it controls regardless of where the server stands. An EU datacenter owned by a US-headquartered vendor answers the residency question and leaves the jurisdiction question exactly where it was.
A vendor can truthfully advertise EU residency while the other two questions stay open. That is not an accusation of bad faith; it is a reason to ask all three questions separately.
The five questions that get real answers
Put these in writing, before the demo:
- "In which country is the production database for my tenant, and can I pin it?" Region pinning is a real feature some vendors sell; "our infrastructure is global" is an answer too.
- "Send me your current subprocessor list." Every GDPR-serious vendor maintains one. Count the entries outside the EEA, and note that the list can change after you sign — ask how you are notified.
- "Under which legal entity do I contract, and where is its parent incorporated?" This is the CLOUD Act question, asked politely.
- "What leaves the EU during support?" Screen-sharing sessions, support ticket attachments and debug dumps are transfers too.
- "What do I get on exit?" A full export in a documented format, and a stated deletion timeline for what remains — see what happens to your data when you cancel.
A vendor who answers all five crisply is a vendor you can work with. Several will answer none of them before a sales call — the same pattern as quote-gated pricing, applied to your data instead of your budget.
What self-hosting changes, stated exactly
A self-hosted application makes the first three questions disappear by construction:
- Residency: the data lives on hosting you chose. Pick a German, French or Dutch host and it is EU-resident because you put it there. For a concrete first-party number: Hetzner's own price API — machine-read on 10 August 2026 from behind its web-hosting and cloud pricing pages — lists web-hosting plans from €1.60 to €16.72 a month and entry cloud servers from €3.99 a month, German datacenters, VAT settled at checkout.
- Transfer: nothing moves unless you move it. There is no subprocessor list because there are no subprocessors — the list is your hosting company, full stop.
- Jurisdiction: your contract is with a host you selected, under the law you selected it in.
And here is what self-hosting does not change, stated just as exactly: GDPR governs processing, not just location. A self-hosted app with sloppy access control, no deletion process and no records of processing is non-compliant on an EU server. Residency is one article of the regulation; the other ninety-eight are still your job. Our own product FAQs say this in plain words — a tool helps you meet deadlines and keep records; whether your responses are legally sufficient remains your responsibility.
The compliance stack, priced both ways
The categories below are where residency questions bite hardest, because the data in them is personal by definition. In each, the rented incumbents and the owned alternative:
Data-subject requests (DSARs). Enzuzo's Starter carries 10 automated DSARs a month at $7 billed yearly, or $9 billed monthly — the $9 this guide previously quoted is the monthly-billed figure, not the cheapest published one (re-read 5 September 2026). Above it sit Growth at $22/$29, Pro at $59/$79 and Agency at $99, the last two with unlimited automated requests. And there is a free tier we had never recorded: $0 a month with three automated DSARs. For a small business receiving a handful of requests a year, that free tier is the honest first stop, and it competes with us. Osano still publishes no price at all — the page offers "Schedule a demo with one of our experts" and lists its modules by name (Cookie Consent, Subject Rights Management, Vendor Privacy Risk Management, Data Mapping, Assessments, and a Unified Consent & Preference Hub) without attaching a figure to any of them (read 5 September 2026). Privara is $79 once, self-hosted, and tracks every request against its statutory deadline. Note the second-order point: a DSAR portal itself holds personal data — running it on a third party adds a processor to your Article 30 record for the very tool you bought to manage GDPR.
Try the Privara demo ↗Live, on sample data, no sign-up.
Whistleblowing channels. Transposed across the EU, the Whistleblowing Directive makes organizations of 50+ workers run a reporting channel. We checked the clocks against the legislation itself rather than against our own summary of it (Directive (EU) 2019/1937 at EUR-Lex, read 5 September 2026). Article 9(1)(b) requires "acknowledgment of receipt of the report to the reporting person within seven days of that receipt", and Article 9(1)(f) sets the feedback period at three months. Seven days, not seven working days — the phrase "working days" appears nowhere in the Directive at all, so the clock runs on calendar days and is shorter than a reader might assume. The 50-worker threshold most people quote comes from Recital 48: "All enterprises having 50 or more workers should be subject to the obligation to establish internal reporting channels, irrespective of the nature of their activities, based on their obligation to collect VAT."
Whistlelink publishes a band ladder, re-read on 5 September 2026: €79/month for 0–49 employees, €99 for 50–149, €149 for 150–249, €199 for 250–499, €299 for 500–999, and "Contact us" above that, all inside what the page calls an annual subscription. Note which band this guide had been quoting. The €79 tier is the 0–49 band — the size of organization the Directive does not, as a general rule, oblige to run a channel at all. The rule has a real exception: Article 8(4) disapplies the fifty-worker threshold for entities covered by the Union acts in Parts I.B and II of the Annex, financial services among them, so a small firm in one of those sectors does carry the duty and the €79 band is properly its own. On headcount alone, though, the first band inside the Directive's 50-worker threshold is 50–149, at €99 a month, so the honest comparison for a business with a legal duty here is €1,188 a year, not €948. FaceUp remains quote-gated: *Starter and Professional both offer a "Get a Quote"* button and Enterprise a "Contact Sales" link, with no amount anywhere** (read 5 September 2026). Confida is $119 once and tracks both statutory clocks — and for a channel whose entire value is that reporters trust it, "the reports never leave our server" is an argument you can make to your own staff.
Complaints registers. The incumbent category is quote-gated across the board (ProvePrivacy, the representative vendor we track, publishes no price — read 3 September 2026). Complia is $79 once, with an acknowledgment timer and audit export.
Sharing secrets that must not persist. Onetime Secret publishes three tiers (re-read 5 September 2026): Basic at €0, described on the page as "Everything you need to share secrets securely, including your own custom domain, free.", Identity Plus at €35/month, and Team Plus at €125/month — the last of which this guide had not carried. Secreta is $79 once and zero-knowledge by design — the server cannot read what it stores, which is residency's logical endpoint.
The five compliance apps together are the Compliance Suite at $299 one-time. Against Whistlelink alone at €79/month, the whole suite pays for itself inside four months — and the comparison understates the case, because the suite's data never has a subprocessor list to audit.
Who should still rent
Honesty cuts both ways, so:
- If the vendor carries liability you cannot — some compliance products are priced partly as insurance, with counsel on staff — a subscription can be the right trade.
- If you have no one to apply updates and test backups, an EU-resident SaaS with a clean subprocessor list beats an unmaintained server anywhere. Read securing a self-hosted business app before deciding you are the exception.
- If your scale is genuinely enterprise, region-pinned enterprise SaaS with negotiated SCCs is a mature answer — you are the customer those contracts were written for.
The short version
Ask residency, transfer and jurisdiction as three separate questions. Get the subprocessor list in writing. Remember that an EU datacenter under a US parent settles only the first question. And know that the self-hosted answer settles all three by construction, for one-time prices and single-digit-euro monthly hosting — with the honest caveat that the rest of the regulation is still yours to keep.
Next steps
- The Compliance Suite — Privara, Confida, Complia, Packora and Cyresora as one $299 purchase
- A self-hosted DSAR portal and self-hosted whistleblowing software for the EU Directive — the two categories above, each at length
- What "your data, your server" actually means — the general version of this article's argument
- Rent the hosting, own the software — the middle position, stated honestly
- The SaaS Price Observatory — every price above, quoted from the vendor's own page with the date read
Prices quoted from each vendor's own pricing page on the dates shown. Statutes and judgments named — GDPR Chapter V, the CLOUD Act (2018), Schrems II (C-311/18) — are cited for orientation, not as legal advice; your obligations depend on your situation and your counsel.