New: ISO 42001 and NIS2 Supply Chain available in the Compliance Tool. View standards and requirements → Careers
Back to the knowledge base
Data ID & Suppliers

Where is data stored in the Compliance Tool?

Our starting point is that customer data is stored and processed within the European Union. But European data storage goes beyond just the location of a data centre.

In brief Storage and processing within the EU Supplier chain assessed Current information on request

Organizations lay in the Compliance Tool information on risks, measures, tasks, documents, audits and evidence. It is therefore logical that customers want to know where this data is and which parties can have access.

De Compliance Afdeling opts for a European data chain. The policy point is that customer data is stored and processed within the European Union. New suppliers and changes in the chain are assessed in advance for privacy, security and continuity.

Important distinction

Data identity tells where data is stored. Data sovereignty also looks at legislation, contracting parties, ownership structure, support access and full supply chain.

What does European data storage mean?

European data storage means that the primary customer data and the storage facilities used for that purpose are within the European Union. For a complete picture you also need to look at backups, logging, monitoring and temporary technical data.

The Compliance Tool includes:

  • information that users enter or upload themselves;
  • risks, measures, tasks and responsibilities;
  • documents, audit information and evidence;
  • backups and information necessary for recovery;
  • technical logging for security and availability.

Why only a European data centre is not enough

A server location within Europe does not yet provide a complete answer to the question of who can access and under which legislation a supplier is covered. That is why we assess several layers of service.

Four relevant layers
Storage

Where are application data, files and backups?

Access

From which countries can managers and support staff access?

Contract

Which legal entity is the subject of agreements and what is the right?

Chain

Which subprocessors provide underlying services?

How do we assess suppliers and subprocessors?

Suppliers are not only selected for functionality and price. Data processing, security measures, continuity and underlying parties are also part of the assessment.

Among other things, we look at:

  • the location and legal entity of the supplier;
  • the locations where data are stored and processed;
  • the deployment and modification of sub-processors;
  • access by support, management and monitoring teams;
  • agreements on incident reports, removal and availability;
  • audit capabilities and available assurance information.

The supplier chain is reviewed periodically. A change with a supplier can also affect the processing of customer data.

How do we deal with transfer outside the EEA?

Unnecessary transfer of customer data outside the European Economic Area does not fit our starting point. Where a possible transfer or access from a third country is at issue, it should be established and assessed in advance.

Not only contractual guarantees are relevant. The nature of the data, technical security, access rights and the practical need for processing also count.

Where can you find verifiable and up-to-date information?

This knowledge bank article explains our approach in understandable language. Due diligence and supplier assessments require current, verifiable information. We therefore provide the latest policy and supplier information on request.

You can request information about data locations, suppliers, subprocessors and relevant security documentation.

Request current information →

What questions can you ask yourself with software providers?

Do you want to properly assess European data storage? Then don't just ask where the server is, check the entire chain.

  • Where are primary data, backups and log files?
  • What legal entity is your contracting party?
  • Which suppliers and subprocessors are involved?
  • From which countries is technical or human access possible?
  • How are you informed about changes in the supply chain?
  • What arrangements apply in the event of incidents, termination and removal?
  • What certificates, reports and contractual guarantees are available?

Conclusion

De Compliance Afdeling's starting point is that customer data is stored and processed in the Compliance Tool within the European Union. However, careful assessment does not stop at the location of the data centre.

That is why we also look at suppliers, subprocessors, jurisdiction, support access, management locations and contractual agreements. The public explanation is in this knowledge base; current and verifiable information is available on request.

Due diligence or supplier assessment?

Request the latest information.

Contact us for supplier information or additional security documentation.

Contact us →
Interactive prototype