Skip to main content
Start a conversation

Data and deployment guide

UK data residency and UK GDPR decision guide

Data residency is a workload and supplier decision. It is not a blanket label that can be applied to every system, model endpoint or backup route.

When to use this

Use this during discovery, procurement or architecture work when a team needs to decide what data is involved, where it may be processed and which contracts or controls need review.

  1. 01

    Classify the data and purpose

    Identify the data, people affected, purpose, volume, sensitivity, retention needs and whether special-category, criminal-offence or other higher-risk information may be involved.

  2. 02

    Draw the actual data flow

    Include browser, application, API, model provider, storage, logs, analytics, support tools, backups, administrators and subprocessors. The decisive location may be outside the primary hosting region.

  3. 03

    Check supplier terms and configuration

    Confirm the selected product, account, endpoint, region, retention setting, training policy, support access and contractual commitments. Do not rely on generic marketing statements for a different product tier or service.

  4. 04

    Assign controller and processor decisions

    Clarify who determines purpose and means, which suppliers process data, which agreements are needed and which privacy, security and procurement owners must review the proposed route.

  5. 05

    Plan access, retention and deletion

    Define who can access production and support data, how permissions are reviewed, how long inputs and outputs remain, and what happens to logs, backups and exports when an engagement or account ends.

  6. 06

    Record the residual decision

    Document the selected route, alternatives considered, open risks, approvals and conditions. If a UK-only requirement cannot be met for a workload, say so before a commitment is made.

Working prompts to adapt

Data-flow record

[Data type] enters from [source], is processed by [systems/providers], stored in [locations], accessed by [roles], retained for [period] and deleted/archived by [method].

Supplier check

For [service/account/endpoint], we have checked [region], [retention], [training/use terms], [subprocessors], [support access] and [contractual terms].

Decision boundary

This workload can/cannot meet [requirement] because [verified reason]. The accountable owner is [role] and the review date is [date].

Primary guidance