What EU Data Residency Actually Gets You
“Our data is in the EU” gets used as if it settled the question. It settles part of it. Whether the part it settles is the part you were worried about depends on which of three things you meant.
Those three things are where the bytes sit, where they get worked on, and which legal system can order the company holding them to hand them over. Vendors sell the first, imply the second, and rarely address the third.
We build an EU-hosted video tool, so we have an obvious interest in this argument. That is also why it is worth being precise about it rather than loud.
Storage location: this part residency genuinely solves
If your concern is that recordings of your team’s internal walkthroughs are sitting on disks in Oregon, choosing an EU region fixes that. Completely. No qualifiers.
What follows from it is real:
- Data at rest in the EEA is not a restricted transfer, so Chapter V of the GDPR does not apply to the storage itself. No Standard Contractual Clauses, no transfer impact assessment, no adequacy decision to defend.
- Your transfer documentation gets shorter, which matters more than it sounds when a customer’s security team sends you a 90-question vendor form and every “we transfer to the US under the DPF” line is a follow-up question.
- Some sectoral and public-sector rules require storage in a named country. Residency is how you satisfy those, and nothing else will.
- Latency and delivery improve, which is not a compliance point but is a real one for video.
If a vendor has no EU region at all, that is a genuine gap. If it has one, credit where it is due — and then keep reading, because storage is the easiest of the three.
Processing location: the part vendors are vaguest about
A transfer under the GDPR is not defined by where a hard drive is. The EDPB’s Guidelines 05/2021 set out three cumulative criteria, and the second is that the exporter “discloses by transmission or otherwise makes personal data available” to an importer. Remote access from a third country satisfies it. A support engineer outside the EEA opening your workspace to debug a playback issue is a transfer, even though every byte stayed in Frankfurt.
For a video tool specifically, the processing surface is larger than most people expect:
- Transcription and AI summarisation, which frequently run on a third-party model API rather than the vendor’s own infrastructure
- Thumbnail and preview generation
- Support tooling and admin consoles
- Error monitoring, which happily ships stack traces containing URLs, filenames and user identifiers
- Email and notification delivery
- CDN edge caches, which hold the actual video segments
The honest vendors document the boundary rather than blurring it. Atlassian’s Loom publishes exactly which data is pinned to your chosen region — videos, comments, transcripts, AI summaries, workspace settings — and which data stays global regardless: user authentication and session data, user preferences, organisation membership, cross-workspace notifications. Germany (Frankfurt) became available in May 2026, alongside Oregon. It is a real EU option and the documentation is clearer than most.
The useful reading of that page is not “gotcha.” It is that a residency feature has a perimeter, the perimeter has a shape, and you should be able to see it. When a vendor cannot produce an equivalent list, the honest conclusion is that nobody has drawn the perimeter, not that everything is inside it.
Corporate control: the part residency does not touch
This is where the argument usually gets shouted, so here is the statute instead. 18 U.S.C. § 2713, added by the CLOUD Act in 2018, in full:
A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.
Two phrases do the work. “Possession, custody, or control” is a test about the company, not the server. “Regardless of whether … located within or outside of the United States” removes geography from the analysis entirely.
So a US-owned vendor storing your recordings in Frankfurt is, on the plain text, still a provider with control over that data and still subject to the obligation. Moving the disks to Europe was never the thing being tested.
From the European side this creates a conflict rather than a clean answer. Article 48 says a third-country court or authority order is only recognisable if based on an international agreement in force. The EDPB and EDPS, in their 2019 joint assessment for the LIBE committee, concluded that a foreign authority’s request is not in itself a lawful ground for transfer, and that the CLOUD Act’s extraterritorial reach leaves providers exposed to a conflict of laws. A US-owned EU subsidiary sits in that conflict. An EU-owned company with no US entity, no US parent and no US assets mostly does not, because there is nothing for a US court to assert jurisdiction over.
That, precisely, is the difference in risk profile. Not that one is safe and the other is a wiretap. That one company can be ordered to comply and the other cannot be ordered at all.
Now the fair part: the risk is smaller than the rhetoric
Overstating this is common and it makes the whole argument easier to dismiss. Several things are true at once.
It is legal process, not a back door. A CLOUD Act demand is a warrant, order or subpoena, reviewed under US law, and providers can and do challenge them. § 2703(h) provides a comity mechanism for moving to quash where a demand conflicts with the law of a qualifying foreign government.
The volumes are low and, for some vendors, public. Atlassian’s transparency report lists 36 US government requests it responded to in 2025, 25 international requests, and zero national security requests — the account count for the latter given as a 0–250 band because US law does not allow more precision. Germany leads international requests at 22 across 2015–2025. These are not the numbers of a dragnet.
The most honest public statement on this came from a US vendor. Asked by the French Senate on 18 June 2025 whether he could guarantee under oath that French data in Microsoft’s cloud would never be handed to US authorities without the French government’s approval, Microsoft France’s Anton Carniaux answered: “No, I cannot guarantee that, but, again, it has never happened before.” (The Register) Both halves of that sentence are the truth of the situation.
Transfers to the US are lawful today. The EU–US Data Privacy Framework adequacy decision is in force. The General Court dismissed the Latombe challenge on 3 September 2025, finding the Data Protection Review Court sufficiently independent. An appeal was filed on 31 October 2025 and is pending before the Court of Justice, which is the court that struck down both predecessor frameworks. Anyone who tells you the outcome is obvious in either direction is guessing.
So the accurate description is: a low-probability event, of unknown magnitude, that you cannot influence, governed by a legal framework whose durability has a poor track record. Not a crisis. Not nothing.
Where that leaves an actual decision
The question is not “is US ownership acceptable.” It is “what is in the recordings.”
A product marketing screencast with no personal data in frame: the jurisdiction question is close to irrelevant, and a team spending three weeks on it is spending three weeks badly.
Recordings that routinely capture a patient record system, a legal matter under privilege, an unreleased acquisition model, a works council meeting, or a customer’s production database: now the residual risk has a magnitude, and “it has never happened before” stops being reassuring, because the cost of the first time is the thing you are insuring against.
Between those two, most teams land somewhere that a real DPIA answers and a slogan does not.
Two things residency is not
It is not security. An EU region does not encrypt anything, does not stop a shared link from being forwarded to the wrong person, does not set a retention policy and does not stop a departing employee’s 200 recordings from sitting in a workspace forever. Those are product controls, and they are where most actual data incidents come from.
It is not a substitute for knowing the ownership chain. “Hosted in Germany” and “operated by a company incorporated in Germany” are different sentences, and only the second one bears on the § 2713 test. When you ask a vendor about residency, ask about the operating entity in the same breath: who owns it, which jurisdictions it has a legal presence in, and who its parent is.
If you are working through this for a specific tool, the vendor questions we would send cover the rest of the list. And if the answer for your team is that the operating company itself needs to be outside US reach, that is the constraint SendRec was built around — though for plenty of teams it will not be the constraint that matters, and saying so is more useful than pretending otherwise.