Data Residency GDPR Security DSAR

GDPR Data Residency: Why Where Your DSAR Data Is Hosted Matters

DSAR responses are full of sensitive personal data. Where that data is hosted — and which sub-processors touch it — is a core GDPR question. Here's what to check, with references.

May 13, 2026 4 min read

A DSAR response is one of the most sensitive data sets your organisation will ever assemble: HR files, financial records, complaint material, special-category data, and personal data about other people. Where that data is stored, processed, and transferred isn’t a technical footnote — it’s a core part of your GDPR obligations.

Why data residency matters for DSARs

When you use any DSAR platform, that platform becomes a processor acting on your behalf, and you remain the controller. Two things follow:

  1. You need a Data Processing Agreement (Article 28) governing how the processor handles the data.
  2. If personal data is transferred outside the EEA, you must satisfy the rules in Chapter V of the GDPR (Articles 44–50).

Keeping data within the European Economic Area avoids a whole category of risk — which is why EEA data residency is a genuine differentiator, not just a marketing line.

The transfer problem in one paragraph

In the Schrems II judgment (CJEU, July 2020), the Court invalidated the EU–US Privacy Shield and made clear that exporters relying on Standard Contractual Clauses must verify, case by case, whether the destination country offers protection essentially equivalent to the EEA — and add supplementary measures where it doesn’t (EDPB news, EDPB SME guide on international transfers). A later EU–US adequacy framework restored a route for certified US organisations, but it remains subject to legal challenge. The cleanest way to avoid the whole assessment is simply to keep the data in the EEA.

What to check before you trust a platform with DSAR data

Run through these questions with any vendor:

  • Where is the primary data processing located? Look for a named EEA region, not just “the cloud.”
  • Is there a Data Processing Agreement? It should state the hosting location and the Article 28 terms.
  • Who are the sub-processors, and where are they? A published sub-processor list is the sign of a mature provider.
  • What safeguards apply to any transfers? If any sub-processor is outside the EEA, the provider should document the transfer mechanism and supplementary measures.
  • Is data encrypted in transit and at rest? TLS in transit, strong encryption (e.g. AES-256) at rest.
  • Can you export and delete the data in line with your retention policy?

How SAR Portal approaches data residency

SAR Portal is designed around EEA data residency:

  • Primary processing in the EEA. Case data, documents, and audit logs are processed in Microsoft Azure’s West Europe (Netherlands) region.
  • Encryption throughout. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with key management backed by hardware security modules.
  • A published sub-processor list so you can see exactly who is involved in delivering the service, and a Data Processing Agreement that sets out the Article 28 terms and hosting location.
  • Documented safeguards. Where any sub-processor or transfer is involved, the safeguards are documented in our DPA and sub-processor list rather than left to assumption — so your own due diligence is straightforward.
  • Export and deletion. You can export case data (JSON or PDF) and delete it in line with a defined retention policy, supporting your own accountability obligations.

Our Trust & Security page sets out the full technical and organisational measures.

Why this helps your sales and procurement conversations too

If you sell to enterprises or operate in a regulated sector, your own customers will ask you where their data lives. Being able to answer “our DSAR data is processed in the EEA, encrypted in transit and at rest, under a DPA with a published sub-processor list” is a procurement advantage — it shortens security reviews and removes a common blocker.

Frequently asked questions

Does GDPR require data to stay in the EU? Not strictly — but any transfer outside the EEA must satisfy Chapter V (adequacy, appropriate safeguards such as SCCs plus supplementary measures, or a derogation). Keeping data in the EEA avoids that assessment entirely.

What is a sub-processor and why should I care? A sub-processor is another company your provider uses to deliver the service (hosting, email, payments, and so on). You’re entitled to know who they are; a published list is best practice.

Where is SAR Portal’s data hosted? Primary processing is in Microsoft Azure’s West Europe (Netherlands) region. Sub-processors and any safeguards are documented in our DPA and sub-processor list.


Related guides:


Keep your DSAR data in the EEA, encrypted and under a DPA. Start a free trial, read our Trust & Security page, or see the pricing.

Sources

Ready to simplify your DSAR process?

SAR Portal automates GDPR compliance with AI-powered redaction, deadline tracking, and audit trails.

Related Articles