What should an organization ask its provider?
Scope of residency
-
What exactly is guaranteed to remain in-region: file content, metadata, indexes, thumbnails, previews, logs, encryption keys, backups, and replicas?
-
Does “in-region processing” include AI inference, content extraction, search indexing, malware scanning, and document previews?
-
Are disaster-recovery copies kept in the same region?
Access and transfers
-
Can provider employees, support teams, or sub-processors access the content from outside the region?
-
Which legal entity is the customer contracting with?
-
Where are sub-processors incorporated and where do they process data?
-
What onward-transfer mechanisms and contractual safeguards are used?
The ICO specifically recommends reviewing the provider’s legal entity, global processor network, and transfer arrangements. ICO guidance
Collaboration and lifecycle events
-
What happens when users from different regions collaborate?
-
Which Zone governs a file created in someone else’s folder?
-
Do sharing, copying, ownership transfer, or external collaboration move the content?
-
How are migrations performed, monitored, and verified?
-
Can administrators restrict cross-Zone sharing or downloads?
Evidence and control
-
Can the provider provide a documented data-flow diagram?
-
Can customers see current and historical region assignments?
-
Are residency commitments contractual, configurable, and auditable?
-
-
What alerts or reports identify content leaving a designated region?
-
How quickly can the provider notify customers about a sub-processor or location change?
-
What happens to data and backups at deletion or contract termination?
Bottom line: The strongest provider answer will define residency across the entire content lifecycle - not simply promise that the primary file is stored in a particular country.
