Where Your Data Physically Sits Is a Legal Question, Not a Technical One

Key takeaway: Cross-border data transfer restrictions attach to where data physically resides and moves, and that is determined by infrastructure decisions engineers make routinely without necessarily knowing a legal question was involved.
Where the Decision Actually Gets Made
A team selects a cloud region based on latency to their primary user base, or because it was the default in the deployment template, or because a disaster recovery replica needed a second location. None of these decisions were framed as a legal question, and each one determines where personal data physically resides — which is exactly what cross-border transfer regulation cares about.
The gap is organisational rather than technical: the people equipped to evaluate legal transfer adequacy are rarely in the room when a region is selected, and the people selecting the region are rarely aware a legal question was embedded in that choice.
What Regulation Actually Restricts
Frameworks governing cross-border data transfer generally do not prohibit moving data across borders outright. They require that the destination provide an adequate level of protection, established either by a governmental adequacy determination for that country, or by contractual and technical safeguards the transferring organisation puts in place itself.
| Transfer scenario | Typical requirement |
|---|---|
| Within a recognised adequate jurisdiction | Standard processing terms |
| To a jurisdiction without an adequacy finding | Standard contractual clauses or equivalent safeguard |
| Involving a government access risk in the destination | Additional technical measures, sometimes encryption with keys held elsewhere |
| Backup and disaster recovery replicas | Same rules as primary — DR does not exempt this |
The backup and disaster recovery case is the one most commonly overlooked. A DR replica in a different region is still a transfer of personal data to that region, and it is subject to the identical requirements as the primary copy — an assumption that DR infrastructure sits outside the compliance conversation because its purpose is technical rather than customer-facing is incorrect and a common source of gaps found during audits.
Where the Practical Exposure Concentrates
Third-party service dependencies are frequently the largest unmapped transfer risk. A SaaS analytics tool, a customer support platform, or an email delivery service may process data in a region the contracting organisation never explicitly considered, because the vendor relationship was evaluated on functionality and price rather than on where the vendor’s infrastructure actually sits.
Support and engineering access from a different jurisdiction than the data’s home region is a similar and less visible case — an engineer in one country accessing a production database in another is a transfer in the same sense a stored replica is, even though nothing was copied to new physical infrastructure.
Building an Accurate Map
A cross-border transfer inventory has to be built jointly between legal or privacy staff and infrastructure teams, because neither has full visibility alone — legal cannot enumerate cloud regions and vendor infrastructure locations without asking, and infrastructure teams cannot evaluate legal adequacy without the framework to assess it against.
Include every data store, every backup and DR location, every third-party processor, and every location from which support or engineering staff routinely access production data. Treat each as a transfer requiring an adequacy basis, not merely the primary production database.
Making New Decisions Correctly
The sustainable fix is embedding a transfer review into infrastructure decisions rather than discovering exposure retroactively. A new region selection, a new vendor integration, or a new support access arrangement should trigger a lightweight transfer adequacy check as a standard step, the same way a security review might, rather than being evaluated only if someone happens to remember the legal dimension exists.
The Bottom Line
Map every location where personal data physically resides or is accessed from, including backups, disaster recovery replicas and third-party processors, and treat each as a transfer requiring an adequacy basis. Build transfer review into infrastructure decision-making directly, since the gap exists precisely because these decisions are usually made by people not positioned to evaluate the legal question embedded in them.



