EU Data Residency Questionnaire Tool: An 11-Point Check
Choosing an EU data residency questionnaire tool: map the 11 stages where evidence can leave the region, score vendors, and send them your own due-diligence questions.

An EU data residency questionnaire tool is one where every stage that touches your uploaded evidence — file storage, text extraction, embeddings, the model call that drafts the answer, logs, backups and support access — sits in a named EU region, and where the vendor will put those region names in a document you can keep. "EU-hosted" on a pricing page usually describes exactly one of those stages: the application server. The other ten are where evaluations go wrong.
This is a procurement exercise, not a settings screen. What your organisation is obliged to do with European data is a question for your counsel and for the contracts your buyers have already signed; what follows is the inspection routine — what to map, how to score it, and which answers should end an evaluation before the demo.
The five words that end most residency claims
Where does model inference run?
Ask it early. In a drafting tool, the text of your information security policy travels considerably further than the app tier: it is extracted, chunked, embedded, stored in an index, and then sent — verbatim, inside a prompt — to a model endpoint. Each of those can be a different provider on a different plan in a different region, and none of them are visible from the outside.
A usable answer names a provider and a region: "storage in Frankfurt, inference against the provider's EU endpoint." An answer like "our AI partner meets European standards" is marketing copy with nothing in it you can verify. Neither answer is disqualifying on its own. The difference is that one of them gives you something to check against the DPA.
The eleven places your evidence can leave the region
| Stage | What of yours sits there | What to ask | Answer that should slow you down |
|---|---|---|---|
| 1. Upload & object storage | Original policy PDFs, the buyer's workbook | Which provider, which region? | "Multi-region, for durability" |
| 2. Text extraction / OCR | Full text of every page | In-process, or a third-party API? | An OCR service with no region setting |
| 3. Embedding generation | Every chunk of your policies | Which embedding provider and endpoint? | "We just use a standard embeddings API" |
| 4. Vector index / answer library | Reusable answers and evidence excerpts | Same region as the app, or a separate SaaS? | Search index on a US-only plan |
| 5. Model inference | Prompt = your evidence + the buyer's question | Named provider and region, in writing? | "The model provider handles that" |
| 6. Prompt & output logging | Verbatim prompts, meaning your evidence | Retention period, region, who reads them? | Indefinite retention "for quality" |
| 7. Primary database & backups | Answers, users, questionnaire metadata | Backup region and restore path? | Backups on another continent |
| 8. Disaster-recovery replica | Everything, continuously | Which region does failover land in? | "Warm standby in us-east-1" |
| 9. Telemetry & error traces | Payload fragments inside stack traces | Is the monitoring tenant EU-based? Is payload scrubbed? | US-hosted APM, no scrubbing rule |
| 10. Notification email | Answer text in the message body | Where is the relay, what does the body contain? | Full drafted answers emailed out |
| 11. Support & admin access | Everything a support engineer can open | Who can read tenant data, from where, is it logged? | Global support rota, unlogged break-glass |
Stage 5 deserves its own arithmetic. Take a 180-question workbook where each draft pulls three evidence excerpts: that is roughly 540 retrieval events and 180 inference calls in a single run. If inference sits outside your named region, the crossing does not happen once at signup — it happens 180 times per questionnaire, carrying the sharpest paragraphs you own.
A weighted scorecard you can run in an afternoon
Score each shortlisted vendor out of 100. The weights below reflect how hard each gap is to fix after signature, not how impressive it sounds in a demo.
| Criterion | Weight | Full marks | Zero |
|---|---|---|---|
| Named regions for storage and inference, in a document | 30 | Both named in the DPA or trust page | Region named for hosting only |
| Public subprocessor list with a region column | 20 | Published before signup, with a change-notice period | "Available on request" |
| Prompt/output retention and training posture | 20 | Retention stated in days; no training on tenant data | "We may use data to improve our services" |
| Support access model | 15 | Named roles, access logged, log available to the tenant | "Engineers access data as needed" |
| Contractual hooks | 15 | DPA readable pre-signup; region change triggers notice | DPA only after signature |
How to read the total: 70 and above, run the pilot. Between 50 and 69, get written answers on the specific gaps before you spend a week loading policies. Below 50, the evaluation is teaching you more about the vendor's documentation habits than about their infrastructure.
One hard fail overrides the arithmetic. If a vendor will not name the region where inference runs, the score is irrelevant and the tool leaves the shortlist — because that is the one stage that carries your evidence off the vendor's own infrastructure by design.
Send the questionnaire tool a questionnaire
You are buying software to answer vendor security questionnaires. Send it one first. Ten questions, each paired with the document that should carry the answer:
- Which region and provider host uploaded files? (DPA, technical measures section)
- Which region and provider run model inference for drafting? (subprocessor list)
- Are embeddings generated by a third party, and where? (subprocessor list)
- Name every subprocessor with its processing region. (published list)
- How long are prompts and completions retained, and by whom? (retention schedule)
- Is tenant content used to train or fine-tune any model? (DPA)
- Where do backups and disaster-recovery replicas live, and which region does failover land in? (DR runbook or trust page)
- What notice do we get before a region or subprocessor changes? (DPA, contract term)
- Which roles can read tenant data, from which locations, and is the access logged? (access control policy)
- On termination, what is the export format and the deletion period? (DPA, deletion clause)
Questions 4, 7 and 8 do most of the work. A vendor that answers 1 and 2 confidently but cannot produce a notice period for 8 has described today's architecture and made no commitment about next quarter's.
Four ways EU residency quietly stops being true
The redundancy leak. A tool is sold as EU-hosted, then replicates to a second region for durability — often outside Europe, often documented only in an SRE runbook nobody sends to procurement. This is a commonly described version of the problem, and it tends to surface during an incident rather than during an evaluation.
The inference detour. The application sits in Frankfurt. The drafting call goes to whichever model endpoint the vendor's SDK defaults to. Regional endpoints usually exist; using them is a deliberate configuration choice, and "we haven't switched it on yet" is a real answer you will occasionally get if you ask plainly.
The support back door. Region assignment covers where data rests, not who opens it. A support engineer with tenant-wide read access and a laptop in another jurisdiction is a residency question that no architecture diagram shows.
Subprocessor drift. The list was accurate at signup. Then a vendor swapped OCR providers, or their model provider moved a workload. Residency claims decay; the useful question is not is it EU-hosted but what happens, contractually, when it stops being.
When residency should not be your shortlist filter
Below roughly four questionnaires a year, with no EU-only clause in your customer contracts and no public-sector or regulated buyers in the pipeline, residency is a tie-breaker — weight it near 10% and spend the evaluation on evidence quality and review controls instead. Above a dozen a year, or with one signed clause naming European storage, it becomes a filter you apply before booking demos.
What to weight instead in the low-volume case: whether drafts are cited back to a specific line in your own documents, whether a reviewer can reject before export, and whether the answer library survives staff turnover. The 14-point buying framework covers those criteria in order, and the step-by-step guide to answering security questionnaires shows the workflow the tooling is supposed to accelerate.
How Compliance Concierge answers its own eleven-stage check
Hosting is in Frankfurt. Tenant separation is enforced with row-level security, customer content is not used to train models, and the data processing agreement — including the full subprocessor list, technical measures and deletion periods — is published before signup rather than after signature, so you can run the ten questions above without talking to sales. Drafts are cited to passages in your own uploaded documents, and nothing leaves the workspace without passing the human-review gate.
Residency is one input among several, and it says nothing about whether a drafted answer is accurate. That is the review gate's job, not the region's. If you are weighing this against a trust-centre-led platform, the decision framework against Conveyor sets out where each shape fits.
Questions that come up before shortlisting
Data sovereignty vs data residency — does the distinction matter here? Residency describes where the bytes sit; sovereignty describes which legal systems can reach them, which can depend on the operator's corporate structure and not only on the datacentre. Treat them as two separate columns in your evaluation: one you can verify from a region name, one you cannot. The second belongs in a conversation with counsel.
Is there a free EU data residency questionnaire tool? Several vendors in this category, including Compliance Concierge, offer a free entry tier; terms change, so read the vendor's current pricing page rather than an article. The thing worth checking before relying on a free path: whether it runs the same storage and inference route as the paid plans. Trial environments sometimes differ, and a residency answer verified on a trial does not automatically describe production.
Are there data residency requirements by country I can just look up? There is no single table worth copying, and sector rules differ from general ones. The practical move is to work backwards: pull the data-location clause from the contracts your buyers have already signed with you, list the jurisdictions those buyers operate in, and take the combined picture to counsel. In most evaluations, the operative constraint is a clause somebody already agreed to, not a rule discovered later.
What to put in the renewal calendar
Re-ask questions 4 and 7 — the subprocessor list and the failover region — thirty days before each renewal, and keep the dated answer with the contract. Region assignments and subprocessor lists change without a product announcement. A residency claim verified in August is a claim about August.
From guidance to finished work
Answer the next questionnaire with evidence.
Upload the questionnaire and the policies behind it. Compliance Concierge drafts cautious, cited answers while every final decision stays with a human reviewer.