What is Data residency?
Data residency is the physical or geographic location where data is stored and processed. EU data residency is often offered as an answer to transfer restrictions, and it genuinely narrows the problem. It does not settle it — the controlling question is which law reaches the company holding the data, not only which country the disks are in.
Explanatory, not legal advice.
Residency, sovereignty, localisation
Three terms used interchangeably and worth separating:
- Residency — where the data sits.
- Sovereignty — whose laws it is subject to, which follows the operator as much as the location.
- Localisation — a legal requirement that it must not leave a territory.
The gap between the first two is the substance. A US-owned provider storing EU data in Frankfurt has EU residency; whether US legal process can reach that data is a sovereignty question, and it is the one Schrems II turned on.
What residency genuinely buys
- Latency, which is a real engineering benefit and unrelated to law.
- A narrower transfer surface, since fewer operations move data across borders.
- Contractual clarity about where processing happens, which your DPA and records of processing need anyway.
- Sector requirements, where health, finance or public-sector rules mandate a location outright.
The stronger position
Residency is a control over personal data. Where none is collected, there is no personal data whose location is regulated — and the answer does not change when the next transfer framework is challenged in court.
That is the position sonex takes, and it is worth being precise about what it does and does not claim: analytics data is hosted on infrastructure we operate, and it is your data, deletable per website or per account on request. What it is not is personal data about your visitors, because none is collected in the first place. If your organisation requires a specific storage region for its own policy reasons, that is a separate conversation from the legal one, and a fair thing to ask any vendor.