Regional regulatory context
Vendor risk and data privacy in European Union
The EU is governed by GDPR for personal data processing, with additional sector-specific regulations including NIS2 for critical infrastructure and DORA for financial services. International data transfers require Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions.
Applicable regulations
- GDPR
- NIS2
- DORA
- ePrivacy
Hosting considerations
EU data residency is achievable through AWS (Frankfurt, Ireland), GCP (multiple EU regions), and Azure (multiple EU regions). Data localization within specific member states (Germany, France) may be required for some regulated sectors.
Common questions
Does GDPR require data to stay in the EU?
GDPR does not mandate EU data residency per se, but international transfers require appropriate safeguards (SCCs, BCRs, or adequacy decisions). Practically, many EU customers and contracts require EU hosting.
What is an adequacy decision under GDPR?
An adequacy decision is the European Commission's determination that a third country offers equivalent protection to EU data protection law. Countries with adequacy decisions include Japan, Canada, New Zealand, and (as of 2023) the UK under the EU-UK Adequacy Decision.
Which of your vendors operate in EU?
TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.
Book a demo