18 August 2026 · 4 min read
“Data residency” usually arrives as a checkbox on a vendor form, and the question actually behind the box is the one nobody asks. Where does the data sit while it is idle, where does it go when it is being worked on, who can look at it, and can the provider tell you the difference?
Four different questions
Residency is usually treated as one thing. It is at least four.
Storage. Where the bytes at rest live: which machines, in which region, in which country.
Processing. Where the data is read and changed while it is in use. For many setups that is the same place as storage. It does not have to be.
Access. Where the people who can open the data are. The provider’s support team, a contractor with an admin account, the sysadmin at 2am. Encryption and good practice can manage this, but it is a separate question from where the hardware sits.
Backups. The copy that gets left out of the conversation. A backup replicated to a region the main deployment is not in means the data left the country before anyone noticed.
A provider can be perfectly honest about one of these and vague about the rest. That is why the answers need to be broken out rather than bundled into a single “the data stays onshore” claim.
When location actually matters
Law. Some sectors have real rules about where certain data may sit: health records, financial services, government work, and a long tail of industry codes. If you are in one, the residency question is settled by the rule, and the job becomes making sure your providers can actually demonstrate compliance when it is checked.
Contracts. Customer contracts often flow location requirements down the chain. “We need it local” and “our customer’s contract says it must be local” lead to different requirements, and it is worth knowing which one you are answering before you scope anything.
Australian privacy law. The Privacy Act gives the cross-border question an odd middle position. Under APP 8, if an Australian entity discloses personal information to a recipient overseas, it must take reasonable steps to make sure the recipient handles it in a way consistent with the Australian Privacy Principles, unless an exception applies, such as the individual’s consent, a legal obligation, or a similar enforceable law overseas. The point is that the law is not a “keep it in the country” rule. It is a “if it leaves, there had better be a paper trail” rule, and that changes what you should be asking.
Trust. Some customers, and some employees, simply want the data local. That is a legitimate preference and it is not a law. It is worth saying so, because then you can weigh it against what it actually changes about your security.
When it does not
A brochure site with a contact form handles a name, an email address, and a message. For data like that, the risk lives in whether it is backed up, who can read it, and what happens if it leaks. Not in whether the rack it sits in is in Perth or Singapore. This is where the residency conversation can quietly displace the plain controls that do the protecting, so it is worth saying out loud that for a lot of small sites, the basics matter more.
The questions to ask
Five questions separate a real answer from a marketing one.
- Where does the primary data at rest sit, and can you name the region?
- Where do the backups go?
- Where is data processed while it is not at rest?
- Who can access the data, including support staff, and where do they work?
- Can you put all of the above in writing in a form we can keep?
If the answer to any of them is “let’s have a conversation about that,” you have learned something about how the data is actually managed.
Ask the exit question while you are there: if you later decide the data should live somewhere else, what does the move involve? A provider that can state the process plainly is usually one that has thought it through.
The short version
Residency is one control, and a good one when law, contract, or trust requires it. It only works when you can tell the difference between where data sits and who can reach it. Ask the four questions, want the answers in writing, and you will usually know within a meeting whether a provider means what it says.