[email protected]Support 24/7 · Billing 09:00 – 00:00LinkedInXFacebook
NexonHost
Netherlands Dedicated ServersAmsterdam · Equinix AM6Germany Dedicated ServersFrankfurt · Equinix FR4Romania Dedicated ServersBucharest · VoxilityAustria Dedicated ServersVienna · Interxion VIEBulgaria Dedicated ServersSofia · TelepointFrance Dedicated ServersParis · Interxion PAR — Marseille · Digital Realty MRS3Ireland Dedicated ServersDublin · Equinix DB2Italy Dedicated ServersMilan · Irideos AvalonPoland Dedicated ServersWarsawSpain Dedicated ServersMadrid · Equinix MD2United States Dedicated ServersAshburn · Equinix DC
← All articles
BlogsSeptember 26, 2026

EU Data Residency: What It Buys You, and What It Does Not

EU Data Residency: What It Buys You, and What It Does Not

"Our data stays in the EU" is one of the most common sentences in European hosting procurement, and one of the least examined. EU data residency is a statement about geography. Compliance is a statement about law, contracts and process. They overlap, they are not the same thing, and confusing them produces both false comfort and needless cost.

Here is what the regulations actually say, what changed in 2025, and how to choose a location for reasons that survive scrutiny.

This is a description of the rules as published, not legal advice.

What the GDPR actually requires about location

The GDPR does not contain a general rule that personal data must be stored in the EU. What it contains is Chapter V, which restricts transfers of personal data to third countries and international organisations.

That distinction matters more than it sounds. The GDPR is concerned with data leaving the protection of the regulation, not with the postcode of a disk. A transfer to a third country is lawful where one of these applies:

  • An adequacy decision under Article 45 — the Commission has determined the destination provides an essentially equivalent level of protection.
  • Appropriate safeguards under Article 46 — standard contractual clauses, binding corporate rules and similar instruments.
  • A derogation under Article 49, for specific situations.

Keeping data on EU soil is the simplest way to avoid the question entirely. That is a legitimate reason to choose it. It is not the same as the law demanding it.

The adequacy list, as it stands

As of September 2026 the Commission recognises the following as providing adequate protection: Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, Uruguay, the European Patent Organisation, and the United States — the last limited to commercial organisations that participate in the EU-US Data Privacy Framework, adopted on 10 July 2023.

Two things follow. A transfer to Japan or the UK is not a compliance problem. And a transfer to a US provider is lawful only where that specific organisation is certified under the Data Privacy Framework — the adequacy is not country-wide.

Adequacy decisions are reviewed and can be withdrawn or annulled. Anything you build on one is built on something with a review cycle.

What the Data Act added in 2025

Regulation (EU) 2023/2854, the Data Act, has applied since 12 September 2025 and changes the conversation in two concrete ways.

Article 28 — contractual transparency on international access and transfer. Providers of data processing services must publish on their websites, and keep current, "the jurisdiction to which the ICT infrastructure deployed for data processing of their individual services is subject", plus a general description of the technical, organisational and contractual measures taken to prevent international governmental access to or transfer of non-personal data held in the Union where that would conflict with Union or Member State law. Those pages must be referenced in the contract.

This makes the residency question answerable rather than rhetorical. Ask where the infrastructure sits and which jurisdiction governs it, and the provider is obliged to have published the answer.

Articles 23 to 31 — switching. A maximum notice period of no more than two months, a mandatory maximum transitional period of 30 calendar days with assistance from the outgoing provider, at least 30 calendar days to retrieve data afterwards, and — under Article 29(1) — no switching charges at all from 12 January 2027. Until then only reduced charges, capped at the provider's directly incurred costs. The practical mechanics of using that window are in how to migrate a server without downtime.

What residency does not buy you

Three honest limits.

It does not make you compliant. A server in Frankfurt running an application with no lawful basis for processing, no retention policy and no record of processing activities is precisely as non-compliant as the same application in Ohio.

It does not place data beyond all foreign reach. Jurisdiction can follow the corporate parent, not only the hardware. A subsidiary of a non-EU group may face legal demands its EU-located servers do not insulate it from. This is why Article 28 asks about jurisdiction rather than location — and why the corporate structure of your provider is a question worth asking.

It does not by itself satisfy sector rules. Financial services, health and operators covered by NIS2 carry obligations that geography does not discharge. The hosting-provider side of NIS2 is covered in NIS2 hosting provider requirements.

Choosing a country for reasons that are real

Once residency inside the EU is settled, which country is a question of latency, language, jurisdiction and cost — not compliance. All eleven European locations below are in EU member states, so all keep data under the GDPR.

Country City Facility Typically chosen for
Netherlands Amsterdam Equinix AM6 Interconnection density, Western European reach
Germany Frankfurt Equinix FR4 Central Europe, DACH audiences
Romania Bucharest Voxility Cost-efficient EU capacity
Austria Vienna Interxion VIE DACH, CEE and the Balkans
Bulgaria Sofia Telepoint Southeast Europe, Turkey
France Paris Interxion PAR French audiences
France Marseille Digital Realty MRS3 Africa, Middle East, Asia routes
Ireland Dublin Equinix DB2 English-speaking common-law EU jurisdiction
Italy Milan Irideos Avalon Italian and southern European traffic
Poland Warsaw — Central and Eastern Europe
Spain Madrid Equinix MD2 Iberia and Latin America routes

Choosing between them on latency rather than folklore is worked through in choosing a European server location.

A twelfth location, Ashburn in Virginia, sits outside the EU. That is the point of it — US audiences — and data placed there is a Chapter V question, not an EU data residency one.

What to ask a provider

  1. Which legal entity am I contracting with, and where is it incorporated?
  2. In which facility, in which country, will my data physically sit?
  3. Which jurisdiction governs that infrastructure — your Article 28 disclosure?
  4. Are there sub-processors, and where are they?
  5. Where are backups stored, and where do support staff access systems from?

Question 5 catches more organisations than the first four combined. Data residency is frequently undone by a backup target or a support desk in a third country.

For the record: NexonHost SRL is a Romanian company, registered at the Romanian trade register under J02/594/2015 with VAT number RO34578646, operating from EU facilities in eleven member states. Dedicated servers and cloud hosting can be pinned to a named country at checkout, and if a specific facility matters contractually, ask before ordering.

Sources

Keep reading
How to Choose a Dedicated Server in Europe for High Traffic Workloads
April 27, 2026

How to Choose a Dedicated Server in Europe for High Traffic Workloads

Choosing a dedicated server in Europe for high-traffic workloads requires more than just specs—it’s about performance, network stability, and scalability. Learn how to evaluate bandwidth, hardware, and DDoS protection to handle peak traffic without downtime. Discover what actually matters before…

Read article →
Dedicated Server with DDoS Protection for Gaming Communities
April 23, 2026

Dedicated Server with DDoS Protection for Gaming Communities

Gaming communities demand ultra-low latency, high uptime, and protection against constant DDoS threats. A dedicated server with built-in DDoS protection ensures stable performance, uninterrupted gameplay, and a secure environment for players. It’s the foundation for scaling competitive gaming…

Read article →
What Is a DDoS Protection VPS and When Do You Actually Need It?
April 20, 2026

What Is a DDoS Protection VPS and When Do You Actually Need It?

A DDoS Protection VPS is designed to keep your server online during traffic-based attacks by filtering malicious requests before they reach your system. This guide explains how it works and when it becomes a necessity for businesses handling critical uptime, sensitive data, or high-traffic…

Read article →
Get in Touch

Together, Let’s Build a Faster, Safer Internet.

Build scalable infrastructure with NexonHost — high-performance dedicated servers, VPS hosting, cloud hosting, and DDoS protection across Europe.

Get Started →Contact Us
[email protected]Support 24/7 · Billing 09:00 – 00:00