Field note · Compliance
Data residency is not the same as compliance
Choosing an EU region does not make a deployment lawful under the GDPR, and keeping data in Hong Kong does not answer the PDPO. Residency answers one question — where the bytes sit. This note sets out the other questions it leaves open, with the text of each instrument behind them.
- Source
- Written by us. Method and judgement — no statement on this page rests on a fetched document.
- Evidence
- none on this page — it links to the pages that hold it
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01What residency actually answers
Data residency is a location fact: this storage bucket, this inference endpoint, this backup, in this region. It is worth having, it is checkable, and vendors increasingly publish it. It is also one input among several, and the smallest one.
The confusion is easy to make because residency is the only part of the question a procurement form can verify in an afternoon. Everything else needs the deployment to be described.
- ASSESSMENT
Mistral AI publishes a data-residency page describing where customer data is processed — an example of the class of vendor statement that residency questions can be answered from.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
We assess a published residency page as evidence of a location commitment and of nothing else: it does not describe the lawful basis, the retention period, the sub-processors, or who may read the data once it is there.
BasisRests on the vendor page cited above, read against the GDPR obligations quoted in the next section — each of which is about something other than location.
02What it leaves open under the GDPR
Four obligations sit alongside residency, and none of them is satisfied by a region setting. They are quoted below in the Regulation’s own words; the citation opens the fetched text.
- ASSESSMENT
The Regulation requires that processing be lawful only if and to the extent that at least one of the listed grounds applies — a question about purpose, not about place.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
Where processing is carried out on the controller’s behalf, the Regulation requires the controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
The Regulation requires that a processor not engage another processor without prior specific or general written authorisation of the controller — which makes the sub-processor list, and notice of changes to it, part of the deployment rather than of the vendor’s marketing.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
The Regulation requires personal data to be kept in a form permitting identification for no longer than is necessary for the purposes for which it is processed — an obligation about retention that a region setting does not touch.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the Regulation requires the controller to carry out an impact assessment before the processing begins.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
The Commission’s 2021 Decision states that the standard contractual clauses in its Annex are considered to provide appropriate safeguards within the meaning of Article 46(1) and (2)(c).
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
03The same mistake in Hong Kong, in reverse
Hong Kong deployments meet the mirror image of this error. Because the Ordinance’s cross-border transfer provision has not been brought into force, teams conclude that residency does not matter and that the Ordinance therefore does not constrain a hosted deployment. Both halves are wrong in different directions.
- ASSESSMENT
The Privacy Commissioner’s cross-border guidance states that section 33 is not yet effective.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
Data processors are not directly regulated under the PDPO, which places the obligation on the data user who engaged them rather than removing it.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
DPP4 requires data users to take all practicable steps to protect the personal data they hold against unauthorised or accidental access, processing, erasure, loss or use.
Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.
- ASSESSMENT
We assess the practical effect as the reverse of what teams expect: because the processor is not directly regulated and the transfer section is not in force, the whole weight of DPP4 falls on the organisation choosing the vendor.
BasisRests on the three PDPO and PCPD statements cited above, read together. It is an assessment of where responsibility lands, not a conclusion about any particular deployment.
04What to do instead
- RECOMMENDATION
We recommend describing the data flows before choosing a region: what leaves the network, to which processor, under what basis, retained for how long, and readable by whom.
BasisDepends on the brief carrying personal or confidential data. Rests on the five GDPR obligations quoted above, each of which asks about something other than location.
- RECOMMENDATION
We recommend treating "nothing leaves the network" as an architectural answer rather than a contractual one wherever the data is confidential and the workload fits on hardware you control.
BasisDepends on the brief’s confidentiality flags and on the deployment fitting a self-hosted or private-cloud class. Rests on the difference between the two kinds of guarantee: a contractual commitment is enforceable after the fact, an architectural one removes the flow.
- Write the flow diagram first. Every arrow that crosses the network boundary is a question to answer.
- For each arrow: which processor, under which agreement, retained for how long, and who is notified when the sub-processor list changes.
- Only then choose the region — and record it as one answer among the set, not as the answer.
05Related
Use cases
Stacks
Tools
Jurisdictions
Deployment reports
More field notes
Ask this as a question