Skip to content

ArticlesCloud services and modern work

Where is your company’s data actually located? The EU data boundary in plain language

4 August 2026 · 4 min read

Emails, customer data and files live in the cloud these days, but few people know which country they are physically located in. Data location is not just a technical detail: it affects data protection, contracts and whose laws apply to your information. This article sorts the matter out without legal jargon.

Why does data location matter?

A cloud service means, in practice, that your data sits in someone else’s data centre. The data centre can be in Finland, Ireland or the United States, and the location determines which country’s authorities have access to the data and which legislation protects it.

For a company, the question is concrete for three reasons. First, the EU’s General Data Protection Regulation, the GDPR, sets conditions for transferring personal data outside the EU. Second, more and more customers and contract partners ask in tenders where the data is located, and the answer “we don’t know” does not inspire confidence. Third, data location affects how fast and reliably the services work.

What does the GDPR say about transfers outside the EU?

The GDPR does not prohibit taking personal data outside the EU and the European Economic Area, but it allows the transfer only under certain conditions. The transfer must have a basis, for example a European Commission decision that the destination country’s level of data protection is adequate, or contractual clauses that oblige the recipient to protect the data to the EU standard.

In practice, a small company does not need to build these bases itself; what matters is knowing what its own service providers do. The responsibility is still yours: as the data controller, your company is responsible for the services it uses processing personal data lawfully. That is why, for every key service, you should know where the data is located and whether it is transferred outside the EU.

What do the major cloud services promise now?

The situation has improved clearly in recent years, because European customers have demanded a home for their data. The most visible example is Microsoft, which completed its EU Data Boundary in February 2025. The boundary means that for customers in the EU and EFTA region, customer data and pseudonymised personal data are stored and processed within the EU and EFTA region in Microsoft’s core cloud services, which include Microsoft 365, Dynamics 365, Power Platform and the majority of Azure services. The boundary also covers data generated in connection with technical support.

Even so, the boundary does not make the location question irrelevant. Individual add-on services may operate under different rules, and many of the smaller software services your company uses offer no EU commitment at all. Moreover, the promise applies only to the service itself: if the wrong region has been selected in your company’s settings, or data is moved from one service to another, the promise will not save you. The overall picture emerges only by going through your own services.

How do you work out your own company’s situation?

The review does not require a lawyer, just a systematic walkthrough. Do this:

  1. List the services that hold your company’s data: email, files, the customer register, finance, the website, backups and communication tools.
  2. Check each service’s privacy terms or admin panel: where is the data located, and can the location be chosen? In many services, the EU region can be selected in the settings.
  3. Look at the subcontractor list. Service providers publish a list of sub-processors, meaning other companies that have access to the data for reasons such as support or analytics.
  4. Write down the results. A simple table of services, data locations and transfer bases goes a long way, and the same table serves as data protection documentation and as an answer to customers’ questions.

Remember backups and new AI tools as well. A backup is a copy of your data, and its location matters in exactly the same way as the original’s. AI services, in turn, have arrived in many companies outside official procurement, so nobody has checked where the data entered into them ends up. Both belong on the same list as the other services.

If a key service’s data turns out to be located outside the EU without a clear basis, there are usually two options: move the data to the service’s EU region if the service allows it, or switch to a service that offers an EU location. Neither is usually a big operation when done in a planned way, and many providers have built ready-made tools for the move.

The walkthrough is worth repeating once a year and whenever the company adopts a new service. That way the picture stays up to date, and you do not need to start the review from scratch the next time a customer or auditor asks about it.

Want certainty without doing the legwork?

Cloud service locations, settings and contract terms are exactly the kind of work that is easy to outsource. Developit’s cloud services map where your company’s data is located today, move services to the EU region where needed, and put the settings and documentation in order. The end result is that you know exactly where your data is, and you can say it out loud to your customers too.

Security moment

Well then. It said “don’t press”, and you pressed anyway.

No worries — curiosity is human. That’s exactly what security attacks count on: the most tempting link is the one you’re not supposed to open. While you’re here, let’s see whether you can tell a genuine message from a scam. You’ll get four messages, and the clock is running.

Back to top