kimo
DefinitionAll productsData

Data residency

Definition

Data residency is a requirement or commitment that specific data is stored, and often processed, only in a defined geographic location, such as the EU or a single country. It is related to but narrower than data sovereignty, which concerns whose laws govern the data.

Updated 4 sources3 min read

Data residency is a requirement or commitment that specific data is stored, and often processed, only in a defined geographic location, such as the EU or a single country. It sits next to two related ideas. Data sovereignty asks whose laws govern the data. Transfer rules such as GDPR Chapter V decide when data may move abroad. Residency is the practical answer most teams give to both.

What is data residency?

Residency requirements come from three places: laws (sector or national rules), contracts (a customer’s data processing agreement) and policy (a company’s own risk choices). In the EU, the GDPR is the usual driver. Article 44 says any transfer of personal data to a third country or international organization may only take place if the conditions in Chapter V are met.1 Keeping data in the EU, and limiting who can reach it from outside, is the simplest way to keep transfer analysis small.

Why does data residency matter for analytics?

Transfer rules have changed under teams’ feet. Under Article 45, a transfer to a country the Commission finds adequate needs no specific authorization.2 In July 2020, the Court of Justice invalidated the EU–US Privacy Shield adequacy decision while confirming that standard contractual clauses remained valid.3 On 10 July 2023, the Commission adopted a new adequacy decision for the EU–US Data Privacy Framework.4 Analytics stacks tend to copy data into many tools, and every copy is another location to justify.

TermQuestion it answers
Data residencyWhere is the data physically stored and processed?
Data sovereigntyWhose laws apply to the data?
Data localizationIs there a legal obligation to keep it in-country?
Data transferIs moving or exposing it to another country allowed, and on what basis?

Example: a hybrid set-up

Consider a hypothetical European health-tech company. It keeps patient-level tables in its own data center. Aggregated marketing and billing data can live in a managed cloud. With Kimo Bridge, the clinical database stays in Bridge mode: queries are pushed down, and only aggregates such as “visits per week” leave the server. Marketing sources sync in Cloud mode for speed and history. One dashboard reads from both.

Common misconceptions

  • “EU hosting makes us GDPR compliant.” Location is one control. Lawful basis, minimization, security and access control still apply.
  • “Residency covers backups and logs automatically.” Check where replicas, backups, support access and sub-processors sit.
  • “Aggregates are always safe to move.” Small groups can re-identify people. Set minimum group sizes before data leaves.

How Kimo handles data residency

Kimo lets you choose per source. Bridge mode keeps raw data and credentials on your server and returns only query results, with result caching you can disable. Cloud mode syncs into Kimo’s managed cloud. Mixing the two gives you a hybrid. See Security for hosting details, the on-premise docs, and the hybrid analytics architecture whitepaper. This page is general information, not legal advice.

Frequently asked questions

Does GDPR require data to be stored in the EU?

Not as a general rule. It allows transfers outside the EU when Chapter V conditions are met, such as an adequacy decision or appropriate safeguards. Many organizations still choose EU residency to reduce risk and complexity.

What is the difference between data residency and data sovereignty?

Residency is about where data is stored and processed. Sovereignty is about which jurisdiction’s laws apply to it, which can include laws of the provider’s home country.

Can I use cloud analytics and still keep data on-premise?

Yes, with a hybrid design. Query sensitive sources in place through a bridge and sync less sensitive ones to the cloud, then join them at the semantic layer.

Sources

4 references
  1. Art. 44 GDPR – General principle for transfers (opens in a new tab)
    Regulation (EU) 2016/679, via gdpr-info.eugdpr-info.eu

    Transfers to third countries only under Chapter V conditions.

  2. Art. 45 GDPR – Transfers on the basis of an adequacy decision (opens in a new tab)
    Regulation (EU) 2016/679, via gdpr-info.eugdpr-info.eu

    Adequate countries need no specific authorization.

  3. Press release No 91/20: Judgment in Case C-311/18 (Schrems II) (opens in a new tab)
    Court of Justice of the European Union2020curia.europa.eu

    16 July 2020. Privacy Shield adequacy decision (2016/1250) invalidated; standard contractual clauses decision (2010/87) valid.

  4. EU-US data transfers (opens in a new tab)
    European Commission2023commission.europa.eu

    Adequacy decision for the EU-US Data Privacy Framework adopted on 10 July 2023.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

Used in

Where Data residency shows up in practice

3 resources
GuideIntermediate
All

The Kimo Bridge security model

What leaves your network, what never does, and how every query is authorized and audited.

Rhea Patel
10 min read
Whitepaper
All

Your Data, Your Rules

The hybrid analytics architecture behind Kimo Bridge: live query pushdown, optional cloud sync, and zero-trust by default.

Arno Visser
22 pages

Your data officer is ready.

Connect a source — or install Kimo Bridge and keep data on your servers — then ask a question and get an answer you can audit.