EU hosting and data residency: what it means and when it matters
EU hosting means your data sits on servers within the European Economic Area. That matters because transfers to countries outside it are only permitted if that country offers adequate protection. But hosting is not the same as processing: a vendor can host in the EU and still have data processed outside the EEA through a sub-processor or an AI model. So the question is not only where the servers are, but where the data passes through.
Published on
The rule behind the term
The Dutch Data Protection Authority puts it briefly: personal data may only be transferred from the Netherlands abroad if that country offers adequate protection. Different rules apply within the European Economic Area than outside it; countries outside the EEA are called third countries.
Something particular applies to the United States, and that is the part that surprises business owners. Transfer to the US is not prohibited, but how it works depends on whether the receiving organisation participates in the Data Privacy Framework. So that is not a property of "the US" but of the specific vendor — something you have to check party by party.
What "EU hosting" does and does not cover
The term is often used as though it answers the whole question. It does not. Hosting is about where data sits still; processing is about where it passes through. Those are two different things, and with AI the second is usually the more interesting one.
| Question | Does EU hosting answer this? | What you still need to ask |
|---|---|---|
| Where is my data stored? | Yes | In which country exactly, and with which party |
| Where is it processed? | No | Does the AI model also run inside the EEA? |
| Who else can access it? | No | Which sub-processors, and where do they run? |
| Is it used for training? | No | Is that switched off, and is it in writing? |
| How long is it retained? | No | Which retention period, and who sets it |
Why this is sharper with AI than with ordinary software
With an accounting package your data sits in a database and stays there. With AI every message passes through a model, and that model runs somewhere. If it sits with a provider outside the EEA, there is a transfer — even if storage is neatly in Amsterdam.
That makes "where does the model run" a more important question than "where is the database". And it is precisely the question rarely asked in a sales conversation, because "EU hosting" already sounds reassuring enough.
How to test this with a vendor
Four questions, none of them technical. One: where is storage, and in which country? Two: where does the model that processes the messages run? Three: which sub-processors exist, and where do they run? Four: if anything happens outside the EEA, on what basis — an adequacy decision, standard contractual clauses, or the Data Privacy Framework?
A vendor with a concrete answer to all four does not need to be a lawyer. Anyone who deflects question two into question one has answered the question they find easier.
Incidentally, whoever in fact determines why and how the data is processed also determines who the controller is — and the regulator looks at the actual situation rather than at what the contract says. So that question is connected to this one.
This article is not legal advice and does not replace an assessment of your own situation. What it does do: sharpen the difference between where data sits and where it passes through.