Skip to content
All insights

Data Residency Explained: Why UK-Hosted Matters

On this page
  1. What data residency actually means
  2. Residency versus sovereignty versus encryption
  3. Why UK-hosted matters in practice
  4. How 99 Data Rooms handles data residency
  5. Keep your documents in the UK, free
  6. Sources

UK data residency means your data is physically stored on servers located in the United Kingdom, rather than in the United States, the EU, or wherever a provider's default cloud region happens to be. It sounds like a technical footnote, but for anyone sharing documents that contain personal or commercially sensitive data, where those files physically live has real consequences: it shapes your GDPR position, the legal regimes your data is exposed to, and how confidently you can answer a client or investor who asks "where is our data held?" This guide explains what data residency actually is, why UK-hosted matters in plain terms, the difference between residency and related ideas like sovereignty, and how to check where your documents really sit. It is general information, not legal advice.

The phrase gets used loosely, so it is worth being precise. Below we separate data residency from data sovereignty, explain why the answer to "which country?" is not academic, and set out what UK founders, accountants and small businesses should look for before they trust a tool with sensitive files.

What data residency actually means

Data residency is a straightforward physical question: in which country are the servers that store your data located? When you upload a document to a cloud service, it lands in a data centre somewhere. That somewhere might be London, Dublin, Frankfurt, Virginia or Singapore, depending on the provider's infrastructure and the region they assigned you, often without telling you. Data residency is simply the answer to where that data centre is.

It is easy to assume a British company means British-hosted data, but the two do not follow from each other. Plenty of tools sold to UK customers store their data in US or EU regions by default, because that is where the underlying cloud capacity is cheapest or was set up first. The company can be registered in London while your files sit in Virginia. Residency is about the servers, not the letterhead.

Why the physical location matters comes down to law. Data stored in a country is generally subject to that country's laws, including laws about government access to data. Data held in the United States, for instance, can fall within the reach of US legislation regardless of who owns it. Data held in the UK sits under UK law, which for a UK business is the regime you already understand and operate within. That predictability is much of the value of UK residency, and it connects directly to your data protection duties, which we cover in UK GDPR and document sharing.

Residency versus sovereignty versus encryption

Three ideas often get muddled, and separating them helps you ask the right questions.

Data residency is about where the data physically sits. UK residency means UK servers.

Data sovereignty goes a step further: it is about which country's laws and jurisdiction govern the data, which usually follows residency but can be complicated by the nationality of the provider or its parent company. A US-owned provider hosting data in the UK may still face conflicting legal demands. For most UK small businesses the practical priority is UK residency with a provider whose arrangements are transparent, rather than chasing absolute sovereignty.

Encryption is a different axis entirely: it is about protecting data from being read by anyone unauthorised, wherever it sits. Strong encryption at rest and in transit is essential, but it is not a substitute for residency. Encrypted data in a foreign jurisdiction is still in that jurisdiction. The two work together: you want your data hosted in the UK and encrypted, not one or the other. When you evaluate a tool, look for both, and treat a provider that is vague about either as a warning sign. A serious security and compliance page should state plainly where data is hosted and how it is encrypted.

Why UK-hosted matters in practice

The abstract legal points become concrete in a few everyday situations.

Answering the client or investor question. Regulated professionals and cautious enterprises increasingly ask suppliers where their data is held before they will share anything. "It's in the UK, hosted in London, encrypted at rest and in transit" is a clean answer that closes the question. "I'm not sure, somewhere in our cloud provider's network" does not, and it can cost you the engagement. For accountants handling client financial records, this is close to a baseline expectation now, as we discuss in secure document sharing for accountants.

Simplifying your GDPR position. UK GDPR imposes extra conditions on international transfers of personal data. If your data never leaves the UK, a whole category of transfer-mechanism complexity simply does not arise. That does not make you automatically compliant, but it removes one of the harder questions from your plate. Where your data lives is one of the first things to establish, and it dovetails with having the right paperwork in place, namely a Data Processing Agreement with your provider.

Trust and reputational signal. Beyond the legal mechanics, UK hosting signals that a provider has thought about UK customers specifically rather than treating them as an afterthought to a US product. For sensitive workflows, an investor data room, an HR file, a set of accounts, that signal matters to the people on the other side of the share. This is one of the criteria we weight heavily when comparing tools, and it is a genuine differentiator rather than marketing gloss.

The honest caveat: residency is necessary but not sufficient. UK hosting does not by itself make a tool secure or compliant; you still need encryption, access control, a DPA and sensible sharing practices. But it is a foundation, and a tool that cannot tell you where your data lives has failed the first question.

How 99 Data Rooms handles data residency

99 Data Rooms is UK-hosted in London, with data resident in the UK. That is a deliberate design choice rather than an accident of infrastructure, and it means the answer to "where is our data?" is simple and repeatable. Documents are encrypted with AES-256 at rest and protected with TLS 1.2 or above in transit, so residency and encryption work together rather than standing in for each other. The platform uses no third-party viewer trackers, so viewer data is not quietly shipped off to advertising networks in other jurisdictions, and a DPA is available on request to support the controller-processor paperwork UK GDPR expects.

One point we are careful to state honestly: the underlying infrastructure providers, such as Supabase and Cloudflare, hold their own certifications like SOC 2 and ISO, but those are the providers' certifications, not 99's own. What 99 controls and commits to is UK residency, encryption, no viewer trackers, and a 24-month audit trail, and that combination is what lets a UK founder or accountant answer the data-location question cleanly. Residency then sits inside the wider controlled-sharing journey, gate, tracked revocable link, page-by-page analytics that separate a raw visit from a verified viewer, watermarking on the Business tier, so that "where does it live" and "who can see it" are both answered in one place. If you are new to the idea of a controlled room, our explainer on what a virtual data room is covers the fundamentals, and our guide to visits versus verified analytics covers what the tracking actually shows. You can start from the homepage to see how it fits together.

Keep your documents in the UK, free

Where your documents live is the first question serious clients and investors ask, and with 99 Data Rooms the answer is simple: UK-hosted in London, data resident in the UK, encrypted at rest and in transit, no third-party viewer trackers. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, upload a document, and share it from a system whose location you can actually state. The platform is in beta and improving fast, but UK residency is built in from the ground up. This is general information, not legal advice.

Sources

Questions, answered
What is UK data residency?

It is the property of having your data physically stored on servers located in the United Kingdom. It answers the question "which country is my data held in?" and matters because data is generally subject to the laws of the country it sits in. 99 Data Rooms is UK-hosted in London with data resident in the UK.

Does a UK company always store data in the UK?

No. A company can be registered in the UK while storing customer data in US or EU cloud regions by default, often because that is where capacity is cheapest. Residency is about where the servers are, not where the company is incorporated, so you should check rather than assume.

Is data residency the same as encryption?

No. Residency is about where data is stored; encryption is about protecting it from unauthorised reading wherever it sits. Encrypted data in a foreign jurisdiction is still in that jurisdiction. You want both UK residency and strong encryption, not one instead of the other.

Why does UK hosting matter for GDPR?

UK GDPR places extra conditions on international transfers of personal data. If your data stays in the UK, that category of complexity does not arise. It also makes it easy to answer clients and investors who ask where their data is held. We cover the wider picture in UK GDPR and document sharing.

Does UK hosting make a tool automatically secure and compliant?

No. Residency is a foundation, not a guarantee. You still need encryption, access control, a DPA and good sharing practices. But a tool that cannot tell you where your data lives has failed a basic test.

Keep reading