This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
Once an organisation has decided that data location matters, the harder question is what a vendor's residency statement actually covers. This comparison separates storage, processing and legal reach, then provides a repeatable source test for checking a specific product and plan.
In short: A residency claim normally describes selected data stored at rest. It does not automatically keep model processing, safety monitoring, support access, connected apps or subprocessors in the same region. The useful comparison is therefore not "Does this vendor offer residency?" but "Which data, on which plan, under which contract, stays where?"
Vendor documentation checked on 4 September 2026. Product terms and regional availability can change without notice.
Residency, processing location and sovereignty answer different questions
Data residency identifies where specified data is stored at rest. A vendor might apply it to prompts, responses and uploaded files while excluding account records, telemetry, support data or new features.
Processing location identifies where work is performed on the data. Model inference, content filtering, abuse monitoring, routing and connected services can occur somewhere other than the storage region. Some vendors publish separate inference or processing commitments, which is why a storage statement cannot answer this question by itself.
Data sovereignty concerns which laws and public authorities can reach the data. The answer can depend on the provider, contracting entity, subprocessors and applicable laws, not only the physical location of a server. Regional storage may support a policy requirement, but it does not settle sovereignty or establish legal compliance.
| Term | Question it answers | What it does not establish |
|---|---|---|
| Residency | Where is the covered data stored at rest? | Where every processing step occurs |
| Processing location | Where do inference and other operations occur? | Which laws can reach the provider or data |
| Sovereignty | Which legal systems may apply? | That the data is physically stored in one country |
What Microsoft, Google and OpenAI publish
The comparison below records vendor statements, not independent guarantees. Each row needs to be checked against the customer's current edition, tenant configuration and contract.
| Vendor and product | Storage statement | Processing statement | Important boundary |
|---|---|---|---|
| Microsoft Copilot | Microsoft says prompts, responses and related interaction data are stored in alignment with the organisation's Microsoft 365 contractual commitments. Its residency documentation points to Product Terms, Advanced Data Residency and Multi-Geo conditions. | Microsoft says EU traffic stays within the EU Data Boundary, while traffic elsewhere can be processed in the US, EU or other regions. It also notes that some third-party models and connected experiences have separate terms. | The applicable commitment depends on tenant geography, purchased residency options and enabled experiences. Microsoft source |
| Google Workspace with Gemini | Google's data-region documentation lists Gemini for Workspace prompts and responses as covered data. Available storage choices are the United States, Europe or no preference, subject to edition eligibility. | Google says customers can confine Gemini in Workspace processing to the US or EU. Its Workspace documentation places processing-region policies on eligible Enterprise Plus, Enterprise Essentials Plus and Frontline Plus configurations. | Storage and processing controls have different edition requirements. NotebookLM and third-party integrations need separate checks because Google documents exceptions to ordinary Workspace controls. Google data coverage and region configuration |
| ChatGPT Business | OpenAI says residency controls the selected region for primary customer content at rest, including prompts and responses. Its documentation says the feature is rolling out and is not yet available to every Business customer. | OpenAI explicitly says ChatGPT Business residency does not include inference residency. It also says abuse-monitoring data remains in the US and that a copy of prompts and responses from non-US workspaces is held there temporarily for safety and enforcement. | Business has different terms from Enterprise and Edu. The available Business regions are selected during checkout but are not enumerated on the cited page. OpenAI Business source |
Microsoft's published position is relatively detailed but conditional. Its Copilot privacy documentation, checked on 4 September 2026, distinguishes stored interaction content from LLM processing and warns that agents, web search and third-party models can introduce different handling. Microsoft's Data Location Card guidance also distinguishes current geography from committed geography, an important difference when a migration is incomplete.
Google's public documents, checked on 4 September 2026, say Gemini for Workspace prompts and responses can be covered for both storage and processing. The edition comparison shows that Business Standard and Business Plus offer a single at-rest policy, while regional processing controls require eligible enterprise configurations. This is a clear example of why the product name alone does not answer the residency question.
OpenAI's Business and Enterprise documentation describes different arrangements. The Enterprise and Edu page lists supported storage regions and offers eligible customers inference residency in a smaller set of regions, but says non-GPU processing and external integrations may still operate elsewhere. Those Enterprise statements should not be applied to ChatGPT Business.
The six-document test for a vendor residency claim
A verifiable residency claim can be traced across six evidence layers. A product page by itself is rarely enough because it may omit plan gates, exclusions and contractual wording.
- Product scope: Does the document name the exact service being assessed, or only the vendor's wider cloud platform? "Microsoft 365" is not automatically a statement about every Copilot experience, and "Google Workspace" is not automatically a statement about NotebookLM.
- Covered data: Does it name prompts, responses, files, conversation history, embeddings, backups, logs and metadata separately? An unmentioned category remains unanswered.
- Storage and processing: Does the vendor make separate commitments for data at rest, model inference and other processing? If only storage is documented, in-region processing has not been established.
- Plan and configuration: Which licence, add-on, tenant geography and administrator setting activates the commitment? The evidence should match the organisation's actual subscription rather than the vendor's most capable tier.
- Exceptions and onward transfers: What happens when web search, agents, plugins, support, feedback or third-party models are enabled? These paths can have different subprocessors and location terms.
- Contract and observable evidence: Is the statement reflected in the data-processing agreement, product terms or order form? Can an administrator see the current and committed region in a console or report?
A compact evidence record can capture the product, edition, region, data categories, storage promise, processing promise, exclusions, source URL, contract reference and date checked. Recording "not stated" is more useful than converting silence into an assumed guarantee.
Where published residency guidance stops
Vendor documentation cannot decide whether a particular arrangement is legally sufficient for a business. It can describe product behaviour and contractual commitments, but the effect of privacy, professional or sector-specific rules depends on the organisation's jurisdiction, data and circumstances.
Documentation also changes faster than many procurement records. New AI features may sit outside an existing residency scope, migrations may take time, and integrations can create separate data paths. Where a location point is material and the public documentation is unclear, the unresolved question belongs in the vendor assessment or with an appropriate adviser rather than being inferred from a marketing statement.
For Australian businesses: APP 8 is about disclosure and accountability
The OAIC's APP 8 guidance focuses on cross-border disclosure and accountability, not on a simple requirement that all personal information stay in Australia. The OAIC says APP 8 and section 16C of the Privacy Act create a framework under which an APP entity may remain accountable for certain handling by an overseas recipient, subject to exceptions. The guidance also says that routing information through an overseas server would not usually amount to disclosure until an overseas recipient can access or modify it. Read the OAIC's APP 8 guidance.
That distinction means a server map alone may not answer the relevant Australian question. A vendor assessment may need to identify recipients, subprocessors, access arrangements and effective control as well as storage regions. Whether APP 8 applies to a particular deployment, and whether an exception is relevant, requires assessment against the business's circumstances and the current Privacy Act 1988.
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: free AI acceptable use policy template, free AI register template, shadow AI audit checklist, guide to assessing AI risk, AI vendor breach response plan template, guide to liability for AI-generated content, and AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Tool Selector to get a personalised AI tool recommendation for your business.
Does data residency mean prompts never leave the selected region?
No. Residency usually concerns covered data stored at rest, while inference, routing, monitoring and integrations may follow separate rules. The vendor's processing and exclusions documents provide the relevant answer.
Can a vendor's trust centre confirm residency?
It can provide useful evidence, but it may not identify the exact product, edition or contract. A stronger check connects the trust-centre statement to product documentation, plan eligibility, contractual terms and an administrator report where available.
Is an EU, US or Australian data centre a sovereignty guarantee?
No. Physical location is one part of the analysis, while sovereignty also depends on the provider, contracting entities, subprocessors and laws that may apply. A vendor's use of the word "sovereign" needs its own definition and scope.
How often should a residency entry be reviewed?
There is no universal interval. A review date can be triggered by contract renewal, a new AI feature, a plan change, a new subprocessor or a vendor documentation update, with the last checked date kept beside the claim.
Methodology: Need to Know AI reviewed current first-party documentation from Microsoft, Google, OpenAI, the OAIC and Australia's Federal Register of Legislation on 4 September 2026. No hands-on location testing or legal assessment was performed. Vendor claims were separated into storage, processing and unresolved scope rather than treated as equivalent.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Use the AI vendor due diligence checklist to record source links, contractual commitments, exclusions and unanswered questions for a shortlisted tool.
Use the AI vendor due diligence...