The four pillars of GDPR-compliant cloud storage
GDPR does not certify products — it sets outcomes controllers must achieve. When you pick a cloud storage provider, you inherit their answers to these four questions. Get them wrong and the accountability principle (Article 5(2)) makes it your problem.
1. Data residency
GDPR Chapter V restricts personal-data transfers outside the EU/EEA. Storing and processing exclusively in EU-operated data centres removes the transfer-mechanism problem — no SCCs, no TIA, no adequacy debate.
2. Data Processing Agreement
Article 28 requires a written DPA that pins down purpose, duration, sub-processors, security measures, and breach-notification duties. Verify the provider offers one by default, not on request.
3. Technical & organisational measures
Article 32: encryption in transit and at rest, availability and restoration after incidents, regular testing. Look for ISO 27001, documented DR procedures, EU-hosted key management, RBAC and audit logs.
4. Jurisdictional exposure
Schrems II made clear: EU location alone isn't enough if the operator is subject to US extraterritorial law (CLOUD Act, FISA 702, EO 12333). Prefer providers with no US parent, no US infrastructure vendor, no US legal entity in the chain.
Sovereign EU cloud storage vs US-based providers
After Schrems II, the question stopped being "where is the data?" and became "who controls the operator?" Here is how the two models compare against the GDPR pillars.
| Criterion | Sovereign EU (vBoxxCloud) | US-hyperscaler "EU region" |
|---|---|---|
| Data centre location | Netherlands & Germany, vBoxx-owned | EU region, US-operated |
| Legal operator | EU entity (vBoxx B.V., NL) | US parent + EU subsidiary |
| CLOUD Act / FISA 702 exposure | None | Yes — extraterritorial reach applies |
| Schrems II transfer risk | No transfer to third country | Ongoing legal debate |
| DPA offered by default | Yes, included in subscription | Available, often per contract |
| Sub-processors | EU-only, published list | Global, often incl. US affiliates |
| ISO 27001 certified | Yes | Yes |
| Key management | EU-hosted | Often US-hosted by default |
Provider evaluation checklist
Before signing, ask the provider — in writing — for a clear answer on each of the following. If any answer is "it depends" or "on request", the accountability burden is silently shifting back to you.
- Where is customer data physically stored, and by which legal entity?
- Is there a US parent, sub-processor, or infrastructure vendor in the chain?
- Is a GDPR Article 28 DPA offered by default, and can we review it before signing?
- Which sub-processors have access, and how are we notified of changes?
- Is data encrypted in transit and at rest? Where are the keys managed?
- Which certifications back the technical measures (ISO 27001, ISAE 3402, C5)?
- What is the RTO/RPO for restoration after an incident?
- How are data-subject access, rectification and erasure requests handled?
- What is the breach-notification SLA to the controller?
- On termination, how long is data available for export, and when is it deleted?
Frequently asked questions
Is GDPR-compliant cloud storage possible with a US provider?
Not fully. Even when data is stored in an EU region, US-headquartered providers remain subject to the US CLOUD Act and FISA 702, which can compel disclosure of customer data regardless of physical location. The Schrems II ruling invalidated Privacy Shield precisely because of this exposure. To be GDPR-compliant end-to-end you need a provider with no US parent, no US operator, and no US legal entity in the processing chain.
What does 'data residency' mean under GDPR?
Data residency is the physical and legal location where personal data is stored and processed. GDPR does not ban transfers outside the EU/EEA, but Article 44+ requires an adequacy decision or supplementary measures. Keeping data in EU-operated data centres removes the transfer-mechanism problem entirely.
What must a GDPR Data Processing Agreement (DPA) contain?
Article 28 GDPR requires the DPA to define subject-matter, duration, nature and purpose of processing, categories of data subjects and personal data, and the controller's rights. It must also list sub-processors, describe security measures, and commit the processor to assist with data-subject requests and breach notification.
Which technical measures does GDPR expect from a cloud provider?
Article 32 requires appropriate measures including encryption in transit and at rest, integrity and availability of systems, ability to restore access after an incident, and regular testing of controls. Look for ISO 27001, documented backup and disaster-recovery procedures, EU-hosted key management, and role-based access with audit logging.
How is vBoxxCloud different from Microsoft 365 or Google Workspace 'EU regions'?
Microsoft's EU Data Boundary and Google's Sovereign Controls keep data in EU data centres but are operated by US companies. That leaves them exposed to US extraterritorial law. vBoxxCloud is operated by vBoxx B.V. in the Netherlands, on infrastructure we own in NL and DE, with no US parent and no US sub-processor — so lawful access requests from US authorities cannot compel disclosure.