Antyxsoft Cloud Blog

What EU cloud has to actually mean | Antyxsoft Cloud

Written by Antyxsoft Cloud | Aug 23, 2026, 5:53:57 PM

"Our data is in an EU region" has become the standard answer to a GDPR question, and it is doing far more work than it can support. The region is where the bytes sit. It says nothing about who can reach them, which law compels the operator, or where the metadata about your data ends up.

If you are the person signing off on a processor, these are the questions that actually determine the answer.

1. Who can access it, and from where?

Storage location and access location are different facts. A dataset stored in Frankfurt, administered by a support team in a third country with break-glass credentials, has been transferred as far as the regulation is concerned — access from outside the EEA is a transfer even if nothing is copied.

The questions to ask a provider: which staff can access customer environments, in which countries are they located, and what technical control prevents access from elsewhere? "Policy prohibits it" is not a technical control. Answers worth having involve jurisdictional restrictions on support tooling, and access logs you can inspect.

2. Which legal entity operates the service, and who owns it?

This is the question the region field cannot answer. An EU-incorporated subsidiary of a parent in a third country may be subject to that country's extraterritorial disclosure laws through the parent — the corporate structure, not the datacentre location, determines who can be compelled.

Ask which entity you are contracting with, where it is incorporated, who the ultimate parent is, and whether that parent could be lawfully ordered to produce data held by the subsidiary. Providers who have thought about this will answer directly. Providers who have not will send you the region list again.

3. Where does the metadata go?

Customer data may stay in region while the operational exhaust does not: access logs, telemetry, support tickets, billing records, monitoring metrics, the contents of a crash dump.

Much of this is personal data. Support tickets in particular are a well-known leak — they contain names, email addresses, sometimes the exact records being complained about, and they routinely live in a global helpdesk system with a very different residency story to the platform itself.

4. What do the sub-processors look like?

Every provider has them, and the list is where residency claims usually unravel. A platform hosted entirely in the EU that sends email through a third-country provider, runs its status page on a global CDN, and uses a third-country analytics product in its console has three transfers you inherit.

The published sub-processor list should give the entity, the purpose, and the location. You should also have contractual notice of changes with a right to object. Without notice, your transfer assessment is accurate only on the day you signed.

5. Who holds the encryption keys?

Encryption at rest, where the provider holds the keys, protects you against a stolen disk. It does not protect you against a lawful order served on the key holder, because the provider can decrypt and therefore can be compelled to.

Customer-managed keys change the analysis materially, provided the key management system is genuinely outside the provider's control. If both the data and the key live with the same operator under the same jurisdiction, the encryption is an operational control rather than a legal one, and your transfer assessment should say so plainly.

6. What happens on a government access request?

A serious processor has a documented process: legal review of every request, a challenge where grounds exist, notification to the customer unless prohibited, and a transparency report with numbers in it.

Ask for the process and the numbers. A provider that has never received a request should say so. One that cannot describe what it would do has not thought about the scenario you are asking them to manage on your behalf.

What to put in the DPA

Beyond the Article 28 boilerplate, insist on:

  • Named processing locations — including for support and administration, not just storage.
  • Sub-processor list with prior notice — 30 days, with a right to object and an exit if you do.
  • Breach notification within a defined window — 24 to 48 hours to you, so you can meet your own 72-hour obligation.
  • Audit rights — realistically, the right to receive current certifications and a completed security questionnaire annually.
  • Deletion on termination — with a stated timeframe and written confirmation, including backups.
  • Government access commitments — challenge, notify where lawful, disclose the minimum required.

The honest position

No provider can promise that no authority anywhere will ever compel disclosure. What a provider can do is be precise about which jurisdictions it is exposed to, which staff can reach your data from where, what its sub-processors are, and what it does when a request arrives.

Precision is the deliverable. A processor that answers these six questions with specifics — including the uncomfortable ones — is giving you something you can put in a transfer impact assessment. A region dropdown is not.