What is UK data residency?
Data residency is the physical location where your data is stored and processed; UK data residency means it stays on servers within the United Kingdom rather than being moved abroad.
Data residency is about geography: which country's servers actually hold your data. It matters because the location can determine which laws apply, which authorities could compel access, and whether a transfer abroad triggers extra legal safeguards. For UK and EU organisations handling personal or commercially sensitive information, keeping data close to home is often a contractual or regulatory requirement.
Residency is related to but distinct from data sovereignty. Residency is simply where the data sits; sovereignty concerns whose laws govern it, which can differ from the storage location if the provider is headquartered elsewhere. Knowing both is part of any serious vendor assessment.
Under UK GDPR, moving personal data outside the UK is a 'restricted transfer' that needs a lawful basis such as adequacy or standard contractual clauses. Choosing a UK-resident provider avoids much of that complexity by keeping the data in-country from the start.
In 99 Data Rooms
How it works here.
99 Data Rooms is UK-hosted in London: your documents are stored in the United Kingdom, encrypted at rest, and never require a room owner to arrange an international transfer to use the service. A Data Processing Agreement is available on request, and there are no advertising or cross-site tracking cookies on your recipients.
Common questions
Data residency, in short.
What is the difference between data residency and data sovereignty?
Residency is where the data is physically stored; sovereignty is whose laws govern it. They usually align, but a provider based abroad could be subject to foreign legal demands even while storing data in the UK, so both are worth checking.
Where does 99 Data Rooms store my documents?
In the UK, hosted in London, encrypted at rest. The service is built for UK and EU teams that need their documents to stay in-country.
Related terms
What is SOC 2?
SOC 2 is an independent audit report on how a service provider handles data against five trust criteria - security, availability, processing integrity, confidentiality and privacy.
DefinitionWhat is ISO 27001?
ISO 27001 is the international standard for information security management, certifying that an organisation runs a systematic, audited process for identifying and controlling security risks.
DefinitionWhat is a virtual data room?
A virtual data room (VDR) is a secure online space for sharing sensitive business documents with outside parties, where every viewer is controlled and every view is tracked.
Try it on a real document. Turn a PDF into a tracked, revocable link in a couple of minutes. Three rooms stay free for as long as you want them, no card required.