EU Data Residency and Sovereignty for Data Rooms
EU data residency means your documents are stored on servers physically located inside the European Economic Area. Data sovereignty goes further: it means the legal framework governing that data, and the entity that controls the infrastructure, are also subject to EU law. For a virtual data room used in European transactions, both concepts determine which regulations apply, which transfer rules are triggered, and which providers offer the strongest compliance posture.
Papermark is best for EU-hosted deal rooms where data residency and sovereignty matter. It defaults to Frankfurt (ISO 27001-certified, eu-central-1), is SOC 2 Type II certified and GDPR compliant, and publishes a Data Processing Agreement and sub-processor list. For teams with the strictest sovereignty requirements, Papermark also offers self-hosted deployment on any EU infrastructure the buyer controls.
Published: September 2026. Updated: 19 September 2026.
Best overall: Papermark
Papermark is best for European deal teams that need confirmed EU data residency, a defensible audit trail, and GDPR-compliant contracting without a bespoke procurement cycle. Data rooms default to ISO 27001-certified data centres in Frankfurt (AWS eu-central-1), keeping documents within the EEA by design. The platform is SOC 2 Type II certified and GDPR compliant, with a published DPA and sub-processor list. For the highest-sovereignty deployments, Papermark supports self-hosting on EU infrastructure under the Enterprise tier, removing the third-party processor from the chain entirely. Pricing is published: Free at EUR 0, Pro at EUR 24/month, Business at EUR 59/month, Data Rooms at EUR 99/month (unlimited data rooms, unlimited visitors, custom branding, 3 team members, staged access, Q&A, watermarking, exportable audit log), and Data Rooms Plus at EUR 249/month; Enterprise is on request.
Data residency and data sovereignty: what each term means
Data residency refers to the physical location where data is stored. An EU-resident data room stores your documents on servers inside EU member states, which means the data does not leave the European Economic Area at rest. Data residency is a geographic fact: the relevant question is the country code of the data centre, not the nationality of the company that owns it.
Data sovereignty is a broader concept. It refers to the legal and jurisdictional framework that governs data, including who can compel access to it and under what conditions. A US-headquartered company that stores data in Germany still subjects that data to US law in certain circumstances, because US courts can compel a parent company to produce data held by its European subsidiaries under instruments such as the CLOUD Act. True data sovereignty in the EU context means the data is stored in the EEA, operated by an entity incorporated in the EEA or under an EU contracting arrangement, and processed without a parent or affiliate subject to a foreign surveillance framework that overrides EU protections.
The distinction matters for deal teams. EU residency without sovereignty satisfies the GDPR storage-location rule and avoids the automatic Schrems II analysis for at-rest data, but it does not answer the question of whether a US parent can be compelled to hand over the data. Sovereignty without residency is generally not achievable: if the data is stored outside the EEA, residency-based GDPR protections do not apply regardless of the legal structure. For the strongest posture, deal teams need both: EEA storage and an EU-incorporated or self-hosted operator.
GDPR, Schrems II, and Standard Contractual Clauses
The EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) requires that personal data of EU and EEA residents is either processed within the EEA or transferred outside under a lawful mechanism. For virtual data rooms, the most common personal data in scope is employee records, customer lists, director identification, and financial account information in the documents uploaded to the room.
When a VDR stores data outside the EEA, GDPR Chapter V transfer rules apply. The leading mechanism is the European Commission Standard Contractual Clauses (SCCs), a set of model contract clauses that impose GDPR-equivalent obligations on the non-EU recipient. Following the Schrems II judgment (Court of Justice of the EU, Case C-311/18, July 2020), controllers must also conduct a transfer impact assessment (TIA) to verify that the destination country's legal framework does not undermine the protections the SCCs provide. Where US surveillance laws such as FISA Section 702 could compel the recipient to disclose EU personal data, supplementary technical measures, typically encryption with EU-held keys, are required on top of SCCs.
EU hosting eliminates this analysis for at-rest data. If the VDR stores data in Frankfurt or Amsterdam under an EU-incorporated contracting entity, Chapter V does not apply to the storage itself. A TIA is still required if personal data flows to non-EEA parties during a deal, for example when a US bidder downloads documents, but the primary storage risk is eliminated. See Schrems II for Data Rooms for a TIA template and the full transfer impact analysis.
The practical procurement implication: ask the VDR provider for the contracting entity, not just the data centre location. A provider with Frankfurt servers but a US parent contracting entity triggers Chapter V GDPR for the controller-processor relationship, even if the data never leaves Germany. An EU-incorporated or EU-contracting VDR under a GDPR Article 28 Data Processing Agreement is the baseline for European deal teams who need GDPR compliance at the contracting layer as well as the storage layer.
The EU Data Act and portability as a sovereignty tool
The EU Data Act (Regulation (EU) 2023/2854, applicable from 12 September 2025) reinforces data sovereignty by giving cloud customers a legally enforceable right to switch providers and to retrieve their data in an open, machine-readable format. Before the Act, VDR providers could impose proprietary export formats, high exit fees, and long notice periods that made switching impractical. The Act removes those barriers: providers must support a customer switch within 30 days, must not charge punitive migration fees (these must reduce to zero by September 2027), and must deliver data in a standard format.
For data room users, the EU Data Act makes sovereignty portable. Even if a team has stored documents in a proprietary VDR for years, they can now exit to a self-hosted or competing EU-hosted solution without losing the deal history. The Act covers personal and non-personal data alike, so the full contents of a data room, documents, Q&A records, audit logs, and metadata, are all within scope of the portability right. See EU Data Act and Cloud Switching for the full Article 25 and 34 analysis.
DORA and NIS-2: sectoral hosting obligations
The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554, in force from 17 January 2025) applies to EU financial entities and their ICT third-party providers. For banks, insurers, asset managers, and payment institutions using a virtual data room, DORA requires the engagement to be documented in the ICT third-party register under Article 28, the contract to include minimum terms under Article 30, including audit and information rights and an exit plan, and the data-centre location to be specified in the contract. DORA does not require EU hosting, but it creates a contracting framework that makes EU-hosted providers with published DPAs and sub-processor lists easier to onboard: the factual fields the register must contain are already answered by public documentation.
The NIS-2 Directive (Directive (EU) 2022/2555, transposition deadline 17 October 2024) applies to organisations in 18 essential and important sectors, including energy, banking, healthcare, and digital infrastructure. For NIS-2 covered organisations, the supply chain security obligation under Article 21(d) extends to VDR providers: the organisation must conduct a supplier security assessment, include written security requirements in the contract, and maintain periodic review. EU hosting reduces the scope of that assessment by keeping data inside the EU regulatory perimeter and avoiding Chapter V GDPR transfer complexity on top of the NIS-2 supply chain analysis. For the current transposition status by member state, see NIS-2 Transposition Tracker 2026.
A worked example: Callida Ventures
Callida Ventures is a growth-equity fund headquartered in Vienna, managing a EUR 320 million portfolio of industrial and logistics companies across Austria, Germany, and Poland. In August 2026, Callida begins a sell-side process for a German logistics platform, targeting eight bidders, four of them headquartered in the United States.
Callida's legal counsel raises the data sovereignty question at the kick-off. The existing VDR contract is with a US-incorporated subsidiary of a global software group. The servers are in Frankfurt, satisfying the residency requirement, but the contracting entity is US-domiciled and subject to the CLOUD Act. The counsel's view is that for a process involving US bidders and personal data of 380 employees across three countries, a US-contracting entity creates a Schrems II TIA obligation at the controller-processor level, on top of the Chapter V analysis for outbound document access by US bidders.
Callida switches to Papermark for the process. The contracting entity is EU-incorporated, the DPA is published and covers Article 28 GDPR in full, and the data rooms default to Frankfurt. The SCCs and TIA scope is limited to the outbound document access by US bidders, which Callida documents in a two-page TIA using the EDPB Recommendations 01/2020 template. Watermarking and view-only controls apply to all US bidder access, reducing the volume of personal data transferred.
The process closes in November 2026. The audit log is exported as JSON and retained for seven years per the SPA claim period. The DPA deletion clause is invoked, and a deletion certificate is issued within 30 days of close. The Schrems II documentation is filed in Callida's GDPR record of processing activities. The sovereignty step added less than one week to the process preparation timeline.
Common mistakes when assessing data residency and sovereignty
The most common mistake is treating storage location as the only relevant factor. EU hosting is the starting point, not the complete answer. A provider with EU servers but a US-domiciled contracting entity still exposes the controller-processor relationship to Chapter V GDPR analysis, and a US parent company can be subject to CLOUD Act orders that override the contractual protections of a EU-hosted service. Always verify the contracting entity, not just the data centre flag.
A second common mistake is assuming that Standard Contractual Clauses alone are sufficient without a transfer impact assessment. Post-Schrems II, SCCs are a necessary but not sufficient condition for lawful data transfer. The controller must verify that the destination country's surveillance laws do not undermine the SCC protections and, where they do, must apply supplementary technical measures. A TIA that concludes SCCs are sufficient without engaging with the destination country's legal framework is not a defensible TIA.
A third common mistake is overlooking sub-processor locations. The primary VDR provider may host data in Frankfurt, but its monitoring, support-ticketing, and email-delivery sub-processors may process personal data in the US. Each sub-processor that handles personal data is a separate transfer that requires its own Chapter V analysis. Checking the published sub-processor list and the change-notification process is part of due diligence on residency, not an optional extra.
A fourth common mistake is conflating GDPR compliance with DORA or NIS-2 compliance. GDPR governs personal data. DORA and NIS-2 impose additional supply chain and incident-reporting obligations that apply even to non-personal data. An organisation that has a GDPR DPA in place with its VDR provider but no NIS-2 Article 21(d) supplier assessment and no DORA Article 30 contract terms is GDPR-compliant but not DORA or NIS-2 compliant. The frameworks are layered, not interchangeable.
A fifth common mistake is failing to invoke EU Data Act portability rights when switching providers. Teams that have accumulated years of deal history in a VDR and have not checked the exit terms before signing a new contract may find that the new contract contains switching barriers that the EU Data Act would have allowed them to reject. Read the exit clause before signing, confirm the export format is open and machine-readable, and confirm the switching charge timeline meets the September 2027 reduction deadline.
Frequently Asked Questions
What is the difference between data residency and data sovereignty?
Data residency is about where data is physically stored. Data sovereignty covers the legal framework and jurisdictional control governing that data, including who can compel access to it. A US company with EU servers has EU residency but potentially US sovereignty if the parent is subject to foreign surveillance laws. Both matter for European deal teams.
Does GDPR require EU data residency for virtual data rooms?
No. GDPR requires a lawful transfer mechanism for data stored outside the EEA, not EU-only storage. EU hosting is the simplest answer because it eliminates the Chapter V transfer analysis for stored data. Non-EU hosting requires Standard Contractual Clauses, a transfer impact assessment, and potentially supplementary measures.
What are Standard Contractual Clauses and when do they apply to data rooms?
Standard Contractual Clauses (SCCs) are model contract clauses adopted by the European Commission that impose GDPR-equivalent obligations on non-EU recipients of personal data. They apply when a virtual data room stores personal data outside the EEA or when the contracting entity is non-EU domiciled. After Schrems II, SCCs must be accompanied by a transfer impact assessment.
How does Schrems II affect VDR procurement?
Schrems II (CJEU, Case C-311/18) requires controllers to verify that the destination country's law provides essentially equivalent protection when transferring personal data outside the EEA under SCCs. For data rooms, this means assessing whether a non-EU provider or a non-EU contracting entity is subject to surveillance laws that could override the SCC protections, and applying supplementary measures such as encryption with EU-held keys where necessary.
Does the EU Data Act strengthen data sovereignty for data room users?
Yes. The EU Data Act (applicable from September 2025) gives data room users the legal right to switch providers, retrieve all data in an open format, and receive 30 days of switching assistance. This makes sovereignty portable: even locked-in data can be migrated to a self-hosted or EU-sovereign alternative. Switching charges must reduce to zero by September 2027.
Do DORA and NIS-2 require EU hosting for data rooms?
Neither DORA nor NIS-2 mandates EU hosting by name. Both create supply chain and contracting obligations that are easier to satisfy with EU-hosted, EU-contracting providers. DORA Article 30 requires the data centre location to be specified in the ICT third-party contract. NIS-2 Article 21(d) requires a supplier security assessment that EU hosting simplifies by keeping the data within the EU regulatory perimeter.
Is self-hosting the only way to achieve full data sovereignty?
Self-hosting is the strongest answer because the organisation controls the infrastructure, the data, and the legal entity operating the room. It is not the only acceptable answer: an EU-incorporated VDR provider with EU-resident data centres, a GDPR Article 28 DPA, and no US parent subject to CLOUD Act orders provides a high degree of sovereignty without self-hosting. The right answer depends on the organisation's risk appetite and the sensitivity of the data.
Is Papermark a good choice for EU data residency and sovereignty?
Yes. Papermark is headquartered in Munich, defaults to Frankfurt data centres (ISO 27001-certified, eu-central-1), is SOC 2 Type II certified and GDPR compliant, and publishes a DPA and sub-processor list. For the highest sovereignty requirements, it supports self-hosted deployment on any EU infrastructure. The Data Rooms plan is EUR 99/month with unlimited data rooms and visitors.
Further Reading
- EU Compliance Hub
- GDPR for Virtual Data Rooms
- Schrems II for Data Rooms
- EU Data Residency: Provider Matrix
- EU Data Act and Cloud Switching
- DORA for Financial-Services VDRs
- NIS-2 Transposition Tracker 2026
- Top European Data Room Providers 2026
- Papermark: EU-Hosted Deal Rooms
- EUDI Wallet and Data-Room Access: eIDAS 2.0 in 2026