Choosing a survey platform for EU or UK research usually starts with a question about compliance in general: is this vendor GDPR-compliant? That question is too broad to be useful on its own. A more specific one gets you further: where does the data actually live, and who can reach it? This guide covers what “EU data residency” means in practice, and gives a checklist for evaluating any platform’s answer to it.

Restricted transfers, briefly explained

Under GDPR, moving personal data outside the European Economic Area is a “restricted transfer” and needs a lawful basis of its own, separate from the lawful basis for collecting the data in the first place. The two most common bases are an adequacy decision, where the European Commission has decided a country’s data protection laws are good enough, and Standard Contractual Clauses, a set of contract terms both parties sign to fill the gap where no adequacy decision exists.

This matters to a researcher for reasons beyond ticking a compliance box. Data that leaves the EEA can become subject to another country’s laws on government access to data, which may not offer the same protections participants were told to expect. Even where a valid transfer mechanism is in place, keeping data inside the EEA in the first place removes an entire category of risk and legal complexity.

What “data residency” actually means in practice

A vendor’s marketing page saying “EU hosting” is a start, not the whole answer. Three things matter more than the headline claim.

Primary storage location. Where is the database that holds survey responses physically located? This should be a specific, stated fact, not an assumption.

Backup and disaster recovery location. A platform can host the primary copy of the data in the EU while replicating backups somewhere else entirely. Ask about backup location specifically; it is often left out of the headline claim.

Encryption in transit and at rest. Data residency limits where data can be read if someone gains unauthorised access to storage or network traffic, but it does not replace encryption. Both matter together: TLS for data moving between the participant’s browser and the server, and storage-level encryption for data at rest, including backups.

A nuance worth understanding: access is not the same as transfer

One point trips people up when evaluating a vendor: does a support engineer working from outside the EU count as a data transfer? Not necessarily. If that engineer views data remotely, with the data itself never leaving the EU storage location, and that access is authorised, logged, and read-only, this is remote access rather than a restricted transfer. The data’s legal location has not changed; only where it was looked at from has.

This distinction is worth asking any vendor about directly: do staff, wherever they are based, ever copy or download participant data onto systems outside the EU, or is access always in-place and logged? A platform with a genuinely global team can still keep data residency intact, provided access is structured this way. The failure mode to watch for is not “staff outside the EU exist” but “data physically moves to wherever those staff are”.

A checklist for evaluating any platform

Before committing to a survey platform for EU or UK research, ask directly:

  • Where is the primary data storage located, specifically?
  • Where are backups and disaster recovery copies stored?
  • Do staff, regardless of where they are based, ever copy, download, or store participant data outside that storage location, or is access always remote and in-place?
  • Are third-party sub-processors (hosting, email delivery, analytics, and similar) bound by Article 28-compliant data processing agreements, and where are they located?
  • Is there a written data processing agreement covering all of this, rather than a general privacy policy alone?
  • What is the vendor’s breach notification commitment, and does it meet or exceed the 72-hour authority-notification expectation under GDPR Article 33?

A vendor that can answer all of these specifically and in writing is a safer choice than one whose answer is a single line about being “GDPR-compliant”.

Summary

Data residency is a more specific and more useful question than a general compliance claim. Ask where data is stored, where it is backed up, whether staff location ever translates into data actually moving, and whether sub-processor and breach commitments are written down. That checklist applies to any research survey platform under consideration, and it will tell you more than a badge on a marketing page ever will.

For the related question of who is responsible for what once data is collected, see GDPR-compliant survey design.