"Our data stays in the EU" is one of the most common sentences in European hosting procurement, and one of the least examined. EU data residency is a statement about geography. Compliance is a statement about law, contracts and process. They overlap, they are not the same thing, and confusing them produces both false comfort and needless cost.
Here is what the regulations actually say, what changed in 2025, and how to choose a location for reasons that survive scrutiny.
This is a description of the rules as published, not legal advice.
What the GDPR actually requires about location
The GDPR does not contain a general rule that personal data must be stored in the EU. What it contains is Chapter V, which restricts transfers of personal data to third countries and international organisations.
That distinction matters more than it sounds. The GDPR is concerned with data leaving the protection of the regulation, not with the postcode of a disk. A transfer to a third country is lawful where one of these applies:
- An adequacy decision under Article 45 — the Commission has determined the destination provides an essentially equivalent level of protection.
- Appropriate safeguards under Article 46 — standard contractual clauses, binding corporate rules and similar instruments.
- A derogation under Article 49, for specific situations.
Keeping data on EU soil is the simplest way to avoid the question entirely. That is a legitimate reason to choose it. It is not the same as the law demanding it.
The adequacy list, as it stands
As of September 2026 the Commission recognises the following as providing adequate protection: Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, Uruguay, the European Patent Organisation, and the United States — the last limited to commercial organisations that participate in the EU-US Data Privacy Framework, adopted on 10 July 2023.
Two things follow. A transfer to Japan or the UK is not a compliance problem. And a transfer to a US provider is lawful only where that specific organisation is certified under the Data Privacy Framework — the adequacy is not country-wide.
Adequacy decisions are reviewed and can be withdrawn or annulled. Anything you build on one is built on something with a review cycle.
What the Data Act added in 2025
Regulation (EU) 2023/2854, the Data Act, has applied since 12 September 2025 and changes the conversation in two concrete ways.
Article 28 — contractual transparency on international access and transfer. Providers of data processing services must publish on their websites, and keep current, "the jurisdiction to which the ICT infrastructure deployed for data processing of their individual services is subject", plus a general description of the technical, organisational and contractual measures taken to prevent international governmental access to or transfer of non-personal data held in the Union where that would conflict with Union or Member State law. Those pages must be referenced in the contract.
This makes the residency question answerable rather than rhetorical. Ask where the infrastructure sits and which jurisdiction governs it, and the provider is obliged to have published the answer.
Articles 23 to 31 — switching. A maximum notice period of no more than two months, a mandatory maximum transitional period of 30 calendar days with assistance from the outgoing provider, at least 30 calendar days to retrieve data afterwards, and — under Article 29(1) — no switching charges at all from 12 January 2027. Until then only reduced charges, capped at the provider's directly incurred costs. The practical mechanics of using that window are in how to migrate a server without downtime.
What residency does not buy you
Three honest limits.
It does not make you compliant. A server in Frankfurt running an application with no lawful basis for processing, no retention policy and no record of processing activities is precisely as non-compliant as the same application in Ohio.
It does not place data beyond all foreign reach. Jurisdiction can follow the corporate parent, not only the hardware. A subsidiary of a non-EU group may face legal demands its EU-located servers do not insulate it from. This is why Article 28 asks about jurisdiction rather than location — and why the corporate structure of your provider is a question worth asking.
It does not by itself satisfy sector rules. Financial services, health and operators covered by NIS2 carry obligations that geography does not discharge. The hosting-provider side of NIS2 is covered in NIS2 hosting provider requirements.
Choosing a country for reasons that are real
Once residency inside the EU is settled, which country is a question of latency, language, jurisdiction and cost — not compliance. All eleven European locations below are in EU member states, so all keep data under the GDPR.
| Country | City | Facility | Typically chosen for |
|---|---|---|---|
| Netherlands | Amsterdam | Equinix AM6 | Interconnection density, Western European reach |
| Germany | Frankfurt | Equinix FR4 | Central Europe, DACH audiences |
| Romania | Bucharest | Voxility | Cost-efficient EU capacity |
| Austria | Vienna | Interxion VIE | DACH, CEE and the Balkans |
| Bulgaria | Sofia | Telepoint | Southeast Europe, Turkey |
| France | Paris | Interxion PAR | French audiences |
| France | Marseille | Digital Realty MRS3 | Africa, Middle East, Asia routes |
| Ireland | Dublin | Equinix DB2 | English-speaking common-law EU jurisdiction |
| Italy | Milan | Irideos Avalon | Italian and southern European traffic |
| Poland | Warsaw | — | Central and Eastern Europe |
| Spain | Madrid | Equinix MD2 | Iberia and Latin America routes |
Choosing between them on latency rather than folklore is worked through in choosing a European server location.
A twelfth location, Ashburn in Virginia, sits outside the EU. That is the point of it — US audiences — and data placed there is a Chapter V question, not an EU data residency one.
What to ask a provider
- Which legal entity am I contracting with, and where is it incorporated?
- In which facility, in which country, will my data physically sit?
- Which jurisdiction governs that infrastructure — your Article 28 disclosure?
- Are there sub-processors, and where are they?
- Where are backups stored, and where do support staff access systems from?
Question 5 catches more organisations than the first four combined. Data residency is frequently undone by a backup target or a support desk in a third country.
For the record: NexonHost SRL is a Romanian company, registered at the Romanian trade register under J02/594/2015 with VAT number RO34578646, operating from EU facilities in eleven member states. Dedicated servers and cloud hosting can be pinned to a named country at checkout, and if a specific facility matters contractually, ask before ordering.
Sources
- Regulation (EU) 2016/679 (GDPR), Chapter V, EUR-Lex. Articles 44–49 on transfers. Retrieved 21 September 2026.
- Adequacy decisions, European Commission. List current as of retrieval, 21 September 2026.
- Regulation (EU) 2023/2854 (Data Act), EUR-Lex. Articles 23–31, Article 50. Retrieved 21 September 2026.
- NexonHost locations and facilities. Retrieved 21 September 2026.




