Glossary

Data residency

The requirement that data is physically stored and processed within a specified geographic location, such as a particular country or region.

Data residency refers to the physical or geographic location where an organisation’s data is stored and processed. A data-residency requirement specifies that data must remain within a defined boundary — a particular country, an economic area, or a named region — often to satisfy a regulation, a contractual commitment or an internal policy that ties data to a jurisdiction.

Residency is frequently confused with data sovereignty, but the two are distinct. Residency is about where the data physically is; sovereignty is about which laws apply to it and who can compel access. Data can reside in one country yet still be reachable under another jurisdiction’s legal powers if the operating provider is subject to that jurisdiction, so meeting a residency requirement does not on its own guarantee sovereignty.

For AI deployments, residency requirements shape where models can be hosted and where inference can take place. A hosted AI service may process requests in data centres outside the required region, which can breach a residency commitment even if storage is compliant. In-region private deployment, or on-premises deployment, keeps both storage and processing within the required boundary, which is why residency is a common trigger for moving away from unconstrained cloud AI.

Discuss a secure AI deployment

We help organisations adopt AI inside their own security and compliance perimeter — vendor-neutral, and designed around the constraints you actually operate under.

Get in touch

← Back to the glossary