30 Tage Risikoerkennung für generative KI:Jetzt starten
Zum Hauptinhalt springen
EU & UK buyer guide

AI data residency requirementsfor EU and UK security teams

Check where personal data is processed, stored and accessed. Use a practical review record for the AI service and the security controls around it.

In diesem Leitfaden

Does AI data have to stay in the EU or UK?

Neither EU GDPR nor UK GDPR imposes a general rule that all personal data must stay locally. International transfers require the applicable conditions to be met, alongside the other data-protection obligations.

Local hosting can support a residency requirement. It does not by itself resolve processing elsewhere, access by an overseas recipient, backups or onward transfers. Map the actual recipients and data flows before reaching a conclusion.

Sources checked 20 September 2026. General procurement guidance, not a legal opinion. Have qualified counsel assess the actual arrangement.

Separate the security service from the AI provider

A single hosting-region answer cannot describe every part of an employee AI interaction.

Security backend
Where configuration, account records and retained events are hosted.
Prompt inspection
Where prompts or files are processed, and which content is retained.
Destination AI provider
The AI account's own processing, storage, training and retention terms.
What evidence should accompany each answer?

Record the data categories, processing and storage locations, retention and deletion terms, subprocessors and support access. Link the applicable contract, architecture or configuration evidence, and name an owner for unanswered questions. A local storage region does not establish the location of every processing or access path.

Download the blank data-handling review (CSV)

Blank review worksheet. It contains no observed product results.

EU GDPR

What the EU rules ask you to verify

The EDPB identifies a transfer where a controller or processor subject to GDPR makes personal data available to another organisation outside the EEA. Chapter V provides routes through adequacy decisions, appropriate safeguards, and exceptions for specific circumstances.

Where a relevant adequacy decision applies, additional Article 46 safeguards are not required for that transfer. When using safeguards such as standard contractual clauses, assess whether they work in the destination and whether supplementary measures are needed. Other GDPR obligations still apply.

Schrems II invalidated the former EU-US Privacy Shield and clarified the assessment needed for Article 46 transfer tools. Use the current regulator guidance and adequacy list for the recipient and transfer in question.

EDPB: International data transfers

UK GDPR

Check the UK transfer route separately

The ICO's January 2026 guide uses a three-step test: UK GDPR applies to the processing, you initiate the transfer to an organisation outside the UK, and the recipient is a separate legal entity. Making information accessible can count, even without moving the stored copy.

A restricted transfer needs UK adequacy regulations, appropriate safeguards or an applicable exception. Safeguards can include the UK IDTA, the UK Addendum or UK binding corporate rules. The ICO requires a transfer risk assessment when relying on safeguards; UK legislation now calls this a data protection test.

Keep the legal-entity and contract map with the technical data-flow map. An EU answer does not automatically document a UK transfer.

ICO: A brief guide to international transfers

Illustrative procurement example

A local database with overseas access

A UK organisation stores personal data in London. A separate support provider in India can access it under the support contract.

The ICO uses this kind of access arrangement to illustrate a restricted transfer. The storage address has not changed, but personal information is made accessible to a separate overseas organisation. Check the applicable transfer conditions and support controls.

This illustrates a review question. It is not a description of Aona's support arrangements or a decision about your deployment.

Five checks for the procurement record

Use the blank worksheet above and attach the evidence for each answer.

  1. 1. Processing and storage

    Name each location for prompts, files, configuration, events and backups. Confirm which data is transient and which is retained.

  2. 2. Recipients and access

    Identify the legal entities, subprocessors and support locations that can receive or access personal data. Local servers do not settle remote-access questions.

  3. 3. Transfer mechanism

    For a relevant international transfer, document the applicable adequacy decision, safeguards and assessment, or narrowly applicable exception. Check EU and UK routes separately.

  4. 4. Retention and deletion

    Record content and event retention separately, including backups, deletion at exit and any legal or security exceptions.

  5. 5. Operating evidence

    Keep the applicable agreement, architecture, configuration and assurance evidence with a named review owner. A marketing region list alone is not the complete record.

Where Aona fits

Aona secures employees' AI use. Backend hosting can be in your cloud, on-premises or on Aona-managed servers. Prompt processing is a separate choice: the user device, your environment or Aona-managed servers, subject to the required feature configuration.

Aona-managed regional options include France (Paris), Germany (Frankfurt) and the United Kingdom (London), alongside Australia, the United States, Singapore and Hong Kong. Agree which content and records are processed or retained in the selected configuration. The destination AI provider has its own handling terms.

Aona has completed a SOC 2 Type II examination covering Security, Confidentiality and Availability. Request the report to review the auditor’s findings and the full system scope. Data retention is configurable per customer, for example 30, 90 or 180 days. Agree retention and deletion settings for the data in your selected deployment.

Review Aona's hosting and processing choices ↗

Primary references

FAQ

EU and UK residency questions

Does GDPR require AI data to stay in the EU?
No. EU GDPR provides conditions for international transfers rather than a general local-storage mandate. Relevant transfers can rely on an applicable adequacy decision, appropriate safeguards or an exception in specific circumstances. Local storage alone does not settle access by overseas recipients, subprocessors or onward processing. Other GDPR obligations still apply.
Does UK storage remove the need for a transfer review?
No. The ICO's test considers whether UK GDPR applies, whether you initiate a transfer to an organisation outside the UK and whether that recipient is a separate legal entity. Making personal information accessible can qualify even if the stored copy stays in the UK. Assess the actual arrangement.
Is the UK transfer risk assessment now called a data protection test?
The ICO states that UK legislation now calls it a data protection test, while its guidance continues to use transfer risk assessment and TRA. The ICO requires this assessment when relying on appropriate safeguards. Check the applicable current guidance and transfer route with your legal or privacy team.
Do AI security tools need their own data-handling review?
Yes. Separately record where the security backend is hosted, where prompts and files are inspected, and which content or events are retained. Review recipients, support access and deletion as well as storage. The destination AI provider's terms and configuration need a separate entry.
Which Aona-managed regions are available for EU and UK buyers?
Aona-managed regional options include France (Paris), Germany (Frankfurt) and the United Kingdom (London). Backend hosting and prompt processing are separate choices; confirm the supported configuration, retained fields, access and contractual scope. These choices do not establish the third-party AI provider's location or legal compliance. Aona has a SOC 2 Type 2 report, and retention is configurable per customer.
A focused data-handling review

Bring the required region. Trace the actual data flow.

Review Aona hosting, prompt processing, retained records and the destination AI provider as separate parts of your evaluation.

AI Data Residency Requirements: EU and UK Guide