Sovereignty pillar

EEA data residency in fintech — what it means, and what it doesn't

The most-used and most-misunderstood requirement in European fintech procurement. Layer 1 of the digital sovereignty framework, verified for 540 providers: 352 Yes · 67 Partial · 121 No.

What EEA data residency means

EEA data residency means customer data is stored and processed inside the European Economic Area — the EU 27 plus Iceland, Liechtenstein and Norway. Both halves matter: a database in Frankfurt counts for little if support tooling, logs or analytics pipe the same data through a US region. And two familiar neighbours are not in the EEA: the UK (left with Brexit) and Switzerland (never joined) — both hold EU adequacy decisions for transfers, but data there lives under a different legal regime.

Residency is also not the same thing as sovereignty. It answers one question — where the data lives — and says nothing about who controls the company holding it. That second question is Layer 2 of the framework, and the reason this catalogue records residency and ultimate ownership as separate, independently verified fields.

What residency does not guarantee

The uncomfortable part: an EEA data centre does not, by itself, put data beyond US legal reach. The US CLOUD Act (2018) obliges providers subject to US jurisdiction to produce data in their “possession, custody or control” regardless of where it is stored. An EEA-hosted subsidiary of a US parent therefore still carries CLOUD Act exposure — while GDPR Article 48 says a third-country order is not, by itself, a lawful basis to hand the data over. EEA subsidiaries of US groups sit exactly in that legal squeeze.

So the honest test has two parts: where is the data, and who ultimately controls the operator. Residency plus European control closes the gap; residency alone only narrows it.

How the requirement came to be — four legal acts

  1. GDPR, Chapter V — personal data may leave the EEA only under an adequacy decision or appropriate safeguards. Note what it does not say: the GDPR never mandates localisation.
  2. US CLOUD Act (2018) — extends US legal process to data held abroad by providers under US jurisdiction. This is what turned “where is the server?” into “who owns the operator?”.
  3. Schrems II (CJEU, July 2020) — invalidated the EU-US Privacy Shield overnight; standard contractual clauses survived only with case-by-case risk assessments. The lesson buyers internalised: transfer mechanisms can vanish mid-contract.
  4. EU-US Data Privacy Framework (2023) — restored an adequacy path for certified US companies; it survived its first annulment challenge before the EU General Court in September 2025, and further appeals remain possible. Data kept in the EEA under European control simply does not depend on how that story ends.

Yes / Partial / No — how we verify the column

Every provider in the catalogue carries an EEA flag, checked at source rather than copied from marketing:

Method, sources and limits: how we verify. Spotted a stale flag? Report a correction — residency claims change with every infrastructure migration.

Where residency actually bites

For most buyers the binding constraint is not the GDPR itself but the rules wrapped around it:

And one layer is habitually forgotten: the cloud underneath. A European provider on a US hyperscaler pulls the question straight back in. Genuinely European alternatives exist — see the sovereign cloud & hosting providers — and ownership changes that move data control are tracked on the Radar.

Four questions for your RFP

  1. Where is customer data stored and processed — production, backups, support tooling, analytics?
  2. Which subprocessors touch the data, and in whose jurisdiction of control is each one — not just where their servers are?
  3. Are there UK, Swiss or US legs anywhere in the stack, and can they be carved out for your programme?
  4. What do you get for the DORA register and audits — location disclosures, notification of changes, exit and data-portability terms?

Score your current stack in two minutes with the sovereignty scorecard — residency is the heaviest-weighted axis — filter the catalogue by “Data in EEA” directly, or jump to the pre-cut list: BaaS providers with EEA: Yes.

FAQ

What exactly counts as EEA data residency?

Customer data stored AND processed inside the European Economic Area - the EU 27 plus Iceland, Liechtenstein and Norway. The UK and Switzerland are not in the EEA: both hold EU adequacy decisions for transfers, but data there sits under a different legal regime, which is why the catalogue marks those legs separately (Partial, or No (CH) for Swiss providers).

Does the GDPR require data to stay in the EEA?

No. The GDPR regulates transfers (Chapter V) rather than mandating localisation - transfers are lawful with adequacy or appropriate safeguards. Residency becomes a hard requirement through other doors: EBA outsourcing guidelines and DORA registers for regulated buyers, public procurement rules, and enterprise DPAs. Keeping data in the EEA also removes the risk of a transfer mechanism being struck down, as happened to Privacy Shield in 2020.

Is data in an EEA data centre safe from the US CLOUD Act?

Not automatically. The CLOUD Act reaches providers subject to US jurisdiction and the data in their possession, custody or control, wherever it is stored. EEA hosting removes that exposure only when the operator - and its ultimate parent - sit outside US jurisdiction. That is why the catalogue verifies EEA residency and ultimate ownership as two separate fields.

Need providers that keep data in the EEA — verified, not claimed? Request a match — we hand-pick three source-verified European providers against your markets, licence and residency requirements. Free, neutral, zero pay-to-rank.