Skip to content
GDPR Guide

GDPR compliance for cloud storage

A practical guide for European businesses evaluating cloud providers. What GDPR actually requires, why "EU region" is not the same as sovereign EU storage, and how to check a provider's data residency, DPA, and technical measures in one sitting.

The four pillars of GDPR-compliant cloud storage

GDPR does not certify products — it sets outcomes controllers must achieve. When you pick a cloud storage provider, you inherit their answers to these four questions. Get them wrong and the accountability principle (Article 5(2)) makes it your problem.

1. Data residency

GDPR Chapter V restricts personal-data transfers outside the EU/EEA. Storing and processing exclusively in EU-operated data centres removes the transfer-mechanism problem — no SCCs, no TIA, no adequacy debate.

2. Data Processing Agreement

Article 28 requires a written DPA that pins down purpose, duration, sub-processors, security measures, and breach-notification duties. Verify the provider offers one by default, not on request.

3. Technical & organisational measures

Article 32: encryption in transit and at rest, availability and restoration after incidents, regular testing. Look for ISO 27001, documented DR procedures, EU-hosted key management, RBAC and audit logs.

4. Jurisdictional exposure

Schrems II made clear: EU location alone isn't enough if the operator is subject to US extraterritorial law (CLOUD Act, FISA 702, EO 12333). Prefer providers with no US parent, no US infrastructure vendor, no US legal entity in the chain.

Sovereign EU cloud storage vs US-based providers

After Schrems II, the question stopped being "where is the data?" and became "who controls the operator?" Here is how the two models compare against the GDPR pillars.

CriterionSovereign EU (vBoxxCloud)US-hyperscaler "EU region"
Data centre locationNetherlands & Germany, vBoxx-ownedEU region, US-operated
Legal operatorEU entity (vBoxx B.V., NL)US parent + EU subsidiary
CLOUD Act / FISA 702 exposureNoneYes — extraterritorial reach applies
Schrems II transfer riskNo transfer to third countryOngoing legal debate
DPA offered by defaultYes, included in subscriptionAvailable, often per contract
Sub-processorsEU-only, published listGlobal, often incl. US affiliates
ISO 27001 certifiedYesYes
Key managementEU-hostedOften US-hosted by default

Provider evaluation checklist

Before signing, ask the provider — in writing — for a clear answer on each of the following. If any answer is "it depends" or "on request", the accountability burden is silently shifting back to you.

  • Where is customer data physically stored, and by which legal entity?
  • Is there a US parent, sub-processor, or infrastructure vendor in the chain?
  • Is a GDPR Article 28 DPA offered by default, and can we review it before signing?
  • Which sub-processors have access, and how are we notified of changes?
  • Is data encrypted in transit and at rest? Where are the keys managed?
  • Which certifications back the technical measures (ISO 27001, ISAE 3402, C5)?
  • What is the RTO/RPO for restoration after an incident?
  • How are data-subject access, rectification and erasure requests handled?
  • What is the breach-notification SLA to the controller?
  • On termination, how long is data available for export, and when is it deleted?

Frequently asked questions

Is GDPR-compliant cloud storage possible with a US provider?

Not fully. Even when data is stored in an EU region, US-headquartered providers remain subject to the US CLOUD Act and FISA 702, which can compel disclosure of customer data regardless of physical location. The Schrems II ruling invalidated Privacy Shield precisely because of this exposure. To be GDPR-compliant end-to-end you need a provider with no US parent, no US operator, and no US legal entity in the processing chain.

What does 'data residency' mean under GDPR?

Data residency is the physical and legal location where personal data is stored and processed. GDPR does not ban transfers outside the EU/EEA, but Article 44+ requires an adequacy decision or supplementary measures. Keeping data in EU-operated data centres removes the transfer-mechanism problem entirely.

What must a GDPR Data Processing Agreement (DPA) contain?

Article 28 GDPR requires the DPA to define subject-matter, duration, nature and purpose of processing, categories of data subjects and personal data, and the controller's rights. It must also list sub-processors, describe security measures, and commit the processor to assist with data-subject requests and breach notification.

Which technical measures does GDPR expect from a cloud provider?

Article 32 requires appropriate measures including encryption in transit and at rest, integrity and availability of systems, ability to restore access after an incident, and regular testing of controls. Look for ISO 27001, documented backup and disaster-recovery procedures, EU-hosted key management, and role-based access with audit logging.

How is vBoxxCloud different from Microsoft 365 or Google Workspace 'EU regions'?

Microsoft's EU Data Boundary and Google's Sovereign Controls keep data in EU data centres but are operated by US companies. That leaves them exposed to US extraterritorial law. vBoxxCloud is operated by vBoxx B.V. in the Netherlands, on infrastructure we own in NL and DE, with no US parent and no US sub-processor — so lawful access requests from US authorities cannot compel disclosure.

Move your files to a sovereign EU cloud

vBoxxCloud is built, hosted and operated inside the EU — no CLOUD Act exposure, DPA included, ISO 27001 certified.