UK data residency after Brexit: should you host in the EU?

UK data residency after Brexit: should you host in the EU?

You are a UK founder or CTO picking a region for a new deployment, and someone in the room says "we can't put personal data in the EU any more, we left." That claim is wrong, and acting on it will cost you money for no compliance benefit. Here is the actual post-Brexit position, what an EU-hosted workload really costs a UK controller in paperwork, and the three places where hosting location genuinely does matter.

The short version: EU hosting is legal for a UK controller today

Since the end of the Brexit transition period, the UK runs its own version of the GDPR (the "UK GDPR"), sitting on top of the Data Protection Act 2018. Under that regime, sending personal data to an organisation outside the UK is a "restricted transfer," and you need a lawful route for it — adequacy, an Article 46 safeguard like the IDTA, or an Article 49 derogation.

The important part for anyone comparing hosting regions: the UK government has granted full adequacy to the entire European Economic Area. That is all 27 EU member states plus Iceland, Norway and Liechtenstein. The ICO says it plainly — when a transfer is covered by adequacy regulations, "information can flow freely from the UK without you needing to put in place any additional safeguard."

So a UK controller putting workloads on a server in Frankfurt, Amsterdam or Stockholm is making a restricted transfer that is already covered. No Standard Contractual Clauses. No International Data Transfer Agreement. No transfer risk assessment. The paperwork cost of EU hosting, in transfer terms, is effectively zero. This is the opposite of the fear you sometimes hear.

Where the paperwork actually appears

SCCs, the IDTA and a transfer risk assessment come into play when you send data somewhere the UK has not deemed adequate — the classic example being the United States when data lands with a provider not covered by the UK Extension to the EU-US Data Privacy Framework. That is a real cost, and it is worth understanding, but it is triggered by the destination's legal regime, not by the fact that the destination is "abroad." The EEA is not that case.

The ICO refreshed its international transfer guidance in January 2026, tightening how you scope restricted transfers and streamlining the transfer risk assessment. If your architecture keeps EU-controller data inside the UK and EEA, most of that guidance simply doesn't bite. Where it earns its keep is the moment a sub-processor, a support desk or a backup target sits in a non-adequate country — which can happen quietly inside an "EU region" if you don't read the sub-processor list.

The three things that actually change with hosting location

If legality is settled, what are you really deciding? Three things, in rough order of how often they matter.

1. Who regulates you — and hosting location is not the answer

A common myth is that putting servers in Germany drags you under German data protection law, or that keeping them in the UK keeps you "under the ICO." That is not how jurisdiction works. Under the GDPR's one-stop-shop, your lead supervisory authority is determined by where your main establishment is — broadly, where the decisions about processing are made — not where the disks spin. The EDPB guidance is explicit that server location does not set your regulator.

For a UK-only company, the ICO is your regulator whether you host in Coventry or Copenhagen. What changes the picture is establishment and targeting: if you open an EU office, or you actively offer goods and services to people in the EU, you can pull the EU GDPR into scope and need an Article 27 representative in the EU. That obligation follows your customers and your corporate footprint, not your rack. Do not choose a hosting region to manage regulator jurisdiction; it won't.

2. Sector rules that override the general position

The general "EEA is fine" answer has exceptions written by specific regulators, and if you are in one of these sectors they beat the default.

  1. Health and social care. NHS England's guidance on off-shoring and public cloud permits patient data to be hosted in the UK, the EEA, or other UK-adequate countries — but hosting outside the UK typically requires sign-off from your SIRO and executive team, and a documented rationale. EU hosting is allowed; it is not automatic.
  2. Financial services. The FCA's FG16/5 does not ban hosting outside the UK. It requires you to control and justify the jurisdictions where data is processed, keep effective access and audit rights, and — the line firms forget — you cannot outsource accountability. Operational resilience rules (PS21/3, with the impact-tolerance deadline having passed on 31 March 2025) push firms to map and test third-party dependencies wherever they sit.
  3. Public sector. Central government and its suppliers often carry contractual or policy requirements around OFFICIAL data and "UK sovereignty" that go beyond bare legality. Read the contract, not just the law.

If none of these apply to you, they are noise. If one does, it is the whole decision.

3. Adequacy is a political decision with an expiry date

This is the honest long-term risk, and it cuts in an under-appreciated direction. The much-discussed "cliff edge" in December 2025 was about the EU's adequacy finding for the UK — i.e. EU-to-UK data flows. The European Commission renewed those decisions on 19 December 2025 for a six-year term expiring 27 December 2031, with a mid-point review after four years, following the UK's Data (Use and Access) Act 2025. That renewal keeps EU customer data flowing into UK-hosted systems without friction.

The mirror image — the UK's adequacy finding for the EEA, which is what makes your EU hosting frictionless — is a UK government decision and has been stable. But it is a decision, reviewable and revocable, not a treaty right. If a future government ever narrowed it, UK-to-EEA transfers would need an IDTA and a transfer risk assessment overnight. That risk is low, but it is the one genuine argument for keeping a UK controller's data in the UK: it removes the transfer question entirely and cannot lapse.

UK vs EU hosting for a UK controller: the trade-off on one page

ConsiderationHost in the UKHost in the EU/EEA
Lawful under UK GDPR?Yes (no transfer)Yes — covered by UK adequacy for the EEA
SCCs / IDTA / TRA needed?NoNo, while EEA adequacy stands
Your regulatorICO (set by establishment, not location)ICO (unchanged by hosting location)
Exposure to adequacy lapseNoneLow, but non-zero — you'd need an IDTA + TRA
Latency to UK usersLowestSlightly higher; usually immaterial for web apps
Latency to EU / Nordic usersHigherLower — the main practical reason to pick EU
US government access via CLOUD ActPossible if provider is US-ownedPossible if provider is US-owned — region label doesn't fix this

The last row is the caveat that weakens both easy answers. Picking an "EU region" on a US hyperscaler does not deliver sovereignty from US legal process, and neither does a UK region on the same provider. If government access is your actual concern, the ownership and control of the operator matters far more than the flag on the data centre.

A decision checklist

  1. Are you in health, finance or public sector? If yes, start from that regulator's rules — they may require UK hosting, approvals, or specific audit rights regardless of the general position.
  2. Where are your users? If they are UK-and-Nordic, a two-region setup (UK plus an EU point of presence) often beats forcing everything into one country.
  3. Do any sub-processors, backups or support teams sit outside the UK/EEA? That, not the primary region, is where an IDTA and a transfer risk assessment appear.
  4. Do you have (or plan) an EU establishment, or do you target EU customers? If so, budget for EU GDPR scope and an Article 27 representative — independent of where you host.
  5. Is protection from foreign-government access a real requirement? Then evaluate the operator's ownership and control, not just the data-centre location.

What we would do

For a UK controller with mostly UK users and no special sector rules, host in the UK. It's not because EU hosting is illegal — it plainly isn't — but because keeping data domestic removes the one long-term variable you don't control (the UK's EEA adequacy finding) at no real cost. The moment you have meaningful users in the Nordics or the wider EU, put a region close to them; the latency win is concrete and the transfer paperwork stays at zero while EEA adequacy holds. That's the same reason we run VPS in both Coventry and Stockholm, and it's a question worth asking any provider before you sign — where exactly does the data live, and who can be compelled to hand it over? A good answer names the country, the legal operator and the sub-processors. If you want the full picture of where a workload can sit, our data centre locations page lists what's on offer.

Sources

  1. Is the restricted transfer covered by adequacy regulations? — ICO (2026-01)
  2. A brief guide to international transfers — ICO (2026-01)
  3. Data Protection Act 2018 — legislation.gov.uk (2018-05)
  4. European Commission Renews UK Data Adequacy Decisions — Hunton (2025-12)
  5. NHS and social care data: off-shoring and the use of public cloud services — NHS England Digital (2018-01)
  6. FG16/5: Guidance for firms outsourcing to the cloud — FCA (2019-09)
  7. Guidelines for identifying a controller or processor's lead supervisory authority — EDPB (2017-04)

Frequently asked questions

Is it legal for a UK company to host personal data in the EU?

Yes. The UK grants adequacy to the entire EEA, so a transfer of personal data from a UK controller to an EU/EEA server is covered without SCCs, an IDTA or a transfer risk assessment. This is the ICO's stated position.

Does hosting in the EU change my data protection regulator from the ICO?

No, not by itself. Your lead supervisory authority is set by where your main establishment is, not where your servers are. A UK-only company stays under the ICO whether it hosts in the UK or the EU. Opening an EU office or targeting EU customers is what can bring the EU GDPR and an EU regulator into scope.

When would I actually need SCCs or the IDTA for hosting abroad?

When data goes to a country the UK has not deemed adequate — for example a US provider not covered by the UK Extension to the Data Privacy Framework. EEA hosting doesn't trigger this while UK adequacy for the EEA stands. Watch sub-processors and backups, which can sit in non-adequate countries.

Can NHS or public sector data be hosted in the EU?

NHS England guidance permits patient data in the UK, the EEA or other UK-adequate countries, but hosting outside the UK usually needs sign-off from your SIRO and executive team plus a documented rationale. Public sector contracts may add UK-sovereignty requirements beyond the law.

Will the UK lose EU data adequacy?

The European Commission renewed the UK's adequacy decisions on 19 December 2025 for six years, to 27 December 2031, with a review after four years. That covers EU-to-UK flows. The UK's own adequacy finding for the EEA, which makes your EU hosting frictionless, is stable but remains a revocable government decision.

Related reading

Deploy your server ← Back to blog