EU Data Residency for Business Software — The Buyer's Guide
Where your business data physically lives, who can be compelled to hand it over, and what "EU hosting" does and does not buy you. The questions to ask any SaaS vendor, and the case where self-hosting answers all of them at once.
Every European business buying software eventually asks the residency question: where does this data actually live, and under whose law? The question is worth asking precisely, because the marketing answer — "EU hosting available!" — answers less than it appears to.
This guide is the precise version: what data residency actually is, what it is not, the questions that get a real answer out of a vendor, and the honest description of the one architecture that answers all of them by construction.
Residency, transfer, and jurisdiction are three different questions
Residency is geography: which datacenter, in which country, holds the bytes.
Transfer is movement: whether personal data leaves the EU/EEA in the course of processing — to a support engineer in another region, an analytics subprocessor, a backup replica. GDPR Chapter V governs this, and since the Court of Justice's Schrems II judgment (C-311/18, July 2020) struck down Privacy Shield, transfers to the US have run on standard contractual clauses and, more recently, the EU-US Data Privacy Framework — a regime that has been litigated twice already and may be again.
Jurisdiction is compulsion: whose courts can order the data handed over. This is the one EU hosting alone does not settle — under the US CLOUD Act (2018), a provider subject to US jurisdiction can be ordered to produce data it controls regardless of where the server stands. An EU datacenter owned by a US-headquartered vendor answers the residency question and leaves the jurisdiction question exactly where it was.
A vendor can truthfully advertise EU residency while the other two questions stay open. That is not an accusation of bad faith; it is a reason to ask all three questions separately.
The five questions that get real answers
Put these in writing, before the demo:
- "In which country is the production database for my tenant, and can I pin it?" Region pinning is a real feature some vendors sell; "our infrastructure is global" is an answer too.
- "Send me your current subprocessor list." Every GDPR-serious vendor maintains one. Count the entries outside the EEA, and note that the list can change after you sign — ask how you are notified.
- "Under which legal entity do I contract, and where is its parent incorporated?" This is the CLOUD Act question, asked politely.
- "What leaves the EU during support?" Screen-sharing sessions, support ticket attachments and debug dumps are transfers too.
- "What do I get on exit?" A full export in a documented format, and a stated deletion timeline for what remains — see what happens to your data when you cancel.
A vendor who answers all five crisply is a vendor you can work with. Several will answer none of them before a sales call — the same pattern as quote-gated pricing, applied to your data instead of your budget.
What self-hosting changes, stated exactly
A self-hosted application makes the first three questions disappear by construction:
- Residency: the data lives on hosting you chose. Pick a German, French or Dutch host and it is EU-resident because you put it there. For a concrete first-party number: Hetzner's own price API — machine-read from behind its pricing pages on 10 Aug 2026 — lists web-hosting plans from €1.60 to €16.72 a month and entry cloud servers from €3.99 a month, German datacenters, VAT settled at checkout.
- Transfer: nothing moves unless you move it. There is no subprocessor list because there are no subprocessors — the list is your hosting company, full stop.
- Jurisdiction: your contract is with a host you selected, under the law you selected it in.
And here is what self-hosting does not change, stated just as exactly: GDPR governs processing, not just location. A self-hosted app with sloppy access control, no deletion process and no records of processing is non-compliant on an EU server. Residency is one article of the regulation; the other ninety-eight are still your job. Our own product FAQs say this in plain words — a tool helps you meet deadlines and keep records; whether your responses are legally sufficient remains your responsibility.
The compliance stack, priced both ways
The categories below are where residency questions bite hardest, because the data in them is personal by definition. In each, the rented incumbents and the owned alternative:
Data-subject requests (DSARs). Enzuzo's Starter is $9/month including 10 DSARs a month (their pricing page, checked 2026-07-05); Osano publishes no price at all — "Schedule a demo" (checked 2026-07-05). Privara is $49 once, self-hosted, and tracks every request against its statutory deadline. Note the second-order point: a DSAR portal itself holds personal data — running it on a third party adds a processor to your Article 30 record for the very tool you bought to manage GDPR.
Whistleblowing channels. The EU Whistleblowing Directive requires organisations of 50+ staff to run a reporting channel with a 7-day acknowledgment and 3-month feedback clock. Whistlelink publishes €79/month for the 0–49 employee tier, billed annually (checked 2026-07-05); FaceUp is quote-gated (checked 2026-07-05). Confida is $119 once and tracks both statutory clocks — and for a channel whose entire value is that reporters trust it, "the reports never leave our server" is an argument you can make to your own staff.
Complaints registers. The incumbent category is quote-gated across the board (ProvePrivacy, the representative vendor we track, publishes no price — checked 2026-07-05). Complia is $69 once, with an acknowledgment timer and audit export.
Sharing secrets that must not persist. Onetime Secret's hosted Identity Plus tier is €35/month, with a free basic tier (checked 2026-07-05). Secreta is $44 once and zero-knowledge by design — the server cannot read what it stores, which is residency's logical endpoint.
The five compliance apps together are the Compliance Suite at $249 one-time. Against Whistlelink alone at €79/month, the whole suite pays for itself inside four months — and the comparison understates the case, because the suite's data never has a subprocessor list to audit.
Who should still rent
Honesty cuts both ways, so:
- If the vendor carries liability you cannot — some compliance products are priced partly as insurance, with counsel on staff — a subscription can be the right trade.
- If you have no one to apply updates and test backups, an EU-resident SaaS with a clean subprocessor list beats an unmaintained server anywhere. Read securing a self-hosted business app before deciding you are the exception.
- If your scale is genuinely enterprise, region-pinned enterprise SaaS with negotiated SCCs is a mature answer — you are the customer those contracts were written for.
The short version
Ask residency, transfer and jurisdiction as three separate questions. Get the subprocessor list in writing. Remember that an EU datacenter under a US parent settles only the first question. And know that the self-hosted answer settles all three by construction, for one-time prices and single-digit-euro monthly hosting — with the honest caveat that the rest of the regulation is still yours to keep.
Next steps
- The Compliance Suite — Privara, Confida, Complia, Packora and Nexura as one $249 purchase
- What "your data, your server" actually means — the general version of this article's argument
- Rent the hosting, own the software — the middle position, stated honestly
- The SaaS Price Observatory — every price above, quoted from the vendor's own page with the date read
Prices quoted from each vendor's own pricing page on the dates shown. Statutes and judgments named — GDPR Chapter V, the CLOUD Act (2018), Schrems II (C-311/18) — are cited for orientation, not as legal advice; your obligations depend on your situation and your counsel.