Data residency
Where data sits, who can reach it, and why the server location alone does not answer the question.
The three questions
- 01
Where is the data stored?
Data centre location, including backups and failover sites.
- 02
Where is it processed?
Not identical to the storage location. Model inference may run elsewhere.
- 03
Who can access it?
Support, maintenance, sub-processors, and the provider's group structure.
What the contract must deliver
- Named storage and processing locations, not merely a region.
- A complete list of sub-processors with locations, with notice of changes.
- Rules on remote access: who, from where, on what conditions, logged.
- Exclusion of any use of inputs for training, technically evidenced.
- Procedure for third-country authority access requests.
- Deletion after the contract ends, with evidence.
Transfer bases
| Basis | When |
|---|---|
| Adequacy decision | For countries the Commission has found to provide adequate protection |
| Standard contractual clauses | The normal route, with a supplementary transfer impact assessment |
| Binding corporate rules | Within a group, laborious |
| Derogations under Art. 49 | To be read narrowly, not for regular transfers |
With standard contractual clauses an assessment of the law in the recipient country is required: where public authority access powers exceed what would be lawful in the Union, supplementary measures are needed.
Supplementary measures that actually work
- Encryption with your own key, where the provider does not hold it. Usually impossible for model inference, because the model needs the plaintext.
- Pseudonymisation before transmission. Effective and almost always possible.
- Processing within your own network. Solves the problem rather than managing it.
- On-device processing. Routinely possible for image and sensor data, see edge AI.
The first row is why technical measures are limited for language models: a model cannot process encrypted text. What remains is pseudonymisation, data economy and location choice.
Sovereignty as a selection criterion
For organisations with high protection needs the question is not only legal but operational: what happens when a provider discontinues the service, triples the price, or ends access for legal reasons? That question belongs in the same assessment as the data protection one and often leads to the same answer: a fallback path to local models, rehearsed rather than merely planned. See Local and open models.
Related courses and sources
CNIL on artificial intelligence
The French supervisory authority publishes the most practical guidance on AI and data protection in Europe, in English as well as French.
For data protection leads who need a supervisory reading rather than the bare text of the law.