The Honest No · Decision note 06

“All data stays in-country.” Your architecture cannot guarantee it.

Illustrative situation · Not a customer case
The buyer’s question

Confirm that all customer data is stored, processed and accessed exclusively within [required country], including subcontractors and support.

A regional database setting answers only part of this requirement. Do not confirm exclusivity until storage, secondary copies, support and access are verified for the proposed configuration. A permitted international transfer can still fail the buyer's narrower contractual rule.

A response to adapt

We cannot confirm exclusive storage, processing and access within [required country] for all data in the proposed [service, configuration and service plan]. For [verified data category], storage at rest is [verified location and applicable configuration]. The current exceptions are [named data category, operation, provider or entity, location and purpose; include unresolved facts explicitly]. In particular, [verified backup, logging, support or remote-access exception] is not covered by an exclusive in-country commitment. [Only if verified: The safeguards applicable to the identified processing are described in [approved document and version].] These safeguards do not by themselves satisfy your exclusive-location requirement. We can propose [approved alternative configuration or bounded exception, if any], subject to [documented technical, contractual and deployment conditions]. Please confirm via [authorised clarification channel] whether this alternative may be assessed. Unless the required buyer decision is recorded, we will mark the exclusive-location requirement as unmet and will not describe the service as wholly in-country.

Replace every bracketed field with verified facts. Remove any optional sentence you cannot substantiate. Do not submit this wording unchanged.

What makes the wording defensible

Disclose an exclusive data-residency gap by mapping storage, backups, logs, subprocessors and remote access, without confusing a lawful transfer with buyer acceptance.

  • Resolve the noun “data” before the geography

    Establish whether the clause covers customer content, personal data, account metadata, telemetry, support attachments, security logs, backups and deleted-data remnants. Do not silently substitute the provider's definition of customer data for the buyer's broader “all data”. Microsoft's EU Data Boundary documentation, for example, distinguishes data categories and documents limited transfers. It demonstrates why a region or boundary label needs its actual terms, not that any particular exception is acceptable.

  • Separate residence from access and recovery

    Inspect where each copy rests, where processing takes place, and where authorised people or entities can access it. A primary database in-country does not answer where backups restore, where support attachments go or who can read records remotely. Failover can alter the normal arrangement precisely when the service is under pressure. Map the exceptional path as well as routine operations before stating an absolute commitment.

  • Keep legal transfer analysis separate from procurement fit

    For GDPR contexts, the EDPB identifies three cumulative criteria for a Chapter V transfer, including making data available to another controller or processor in a third country. Not every overseas employee-access scenario has the same classification. Have the privacy or legal owner assess the actual entities and flows. Even where an arrangement is legally permissible, it does not automatically meet an exclusive-country buyer requirement; assess those questions separately.

Five paths hidden behind one region setting

Give each path its own verified location, entity and exception. An empty field is an unresolved fact, not proof of in-country processing.

Primary content
Verify the exact service, deployment region and category covered by the storage commitment.
Backup and recovery
Check replicas, restore destinations, disaster recovery and residual retention after deletion.
Logs and telemetry
Identify whether records contain personal or customer information and where those records are processed.
Support and subprocessors
Trace ticket attachments, diagnostics, integrations and the relevant responsible entities.
Remote access
Identify who can access which data from where, under which controls; obtain the appropriate privacy and contractual review.

The evidence to obtain

  • A data-path inventory for this offer

    Name each relevant data category, operation, country, responsible entity, service and evidence owner. Include primary storage, replicas, recovery, logging, support, analytics and any optional integration actually proposed. Record unknown locations as unknown. Ask infrastructure and application owners for configuration evidence; a diagram or policy without a link to the offered deployment should not carry the entire exclusivity claim.

  • Current supplier terms and access boundaries

    Review relevant contracts, processing terms, subprocessors, service-specific region commitments and documented exceptions. Check whether the proposed plan supports the claimed restriction and whether configuration is required. Identify the controls and approval process for remote access. A supplier's marketing summary or a historical subprocessor list is not enough to establish today's proposed data path. Keep versions and review dates with the answer.

  • Lifecycle and change evidence

    Check what happens during export, incident investigation, failover, account closure and retention expiry. Establish who can change geography or enable another service after deployment. Where an alternative is offered, obtain the technical owner's approval, contractual scope, implementation conditions and buyer's authorised acceptance. Do not claim a future restriction is already enforced, or promise that backups are instantly deleted unless that fact is verified.

The decision to approve

Decision owners
Infrastructure and application owners verify the data path; security validates access controls; privacy or legal reviews transfer questions; the Bid Manager and commercial owner manage fit, permitted clarification and commitments.
Proceed
Proceed when the verified offered configuration meets the stated scope, or an authorised buyer decision accepts the precisely disclosed deviation. State separately what is stored, processed and accessed in each location.
Do not proceed
Do not claim exclusivity while an in-scope path is outside the boundary or unverified. If the unchanged mandatory requirement cannot be met, keep it unmet; a safeguard or reassuring phrase is not an exception.
Escalate
Escalate undefined data categories, remote-access entities, recovery locations, supplier exceptions or legal mechanisms. Request a narrower definition through the official process rather than narrowing the answer unilaterally.

Keep the decision in the final files

The residency answer, architecture evidence, processing attachment, supplier list and exception schedule must describe one approved configuration. A newly enabled integration or revised support arrangement can invalidate an earlier answer. REQVERA's final-control proposition is about consistency of requirements, responses, approved evidence and final files; this page neither evaluates a customer's architecture nor certifies lawful processing.

See the authentic final-control workflow

Scope & primary references

Illustrative response guidance. GDPR references concern GDPR contexts only and are not a global legal rule; countries, sectors and buyers may impose different obligations. No legal conclusion about a deployment is provided. Named provider documentation illustrates scope distinctions, not REQVERA's architecture or a universal substitute for exclusivity. Complete or remove every conditional field before use.

  • Microsoft — What is the EU Data Boundary?

    Primary provider documentation distinguishes data categories, configuration and limited transfers; a boundary headline must be read with its scope and exceptions. Reviewed 11 October 2026.

  • EDPB — Guidelines 05/2021, final version 2.0

    Primary GDPR guidance on the cumulative criteria for international transfers and situations where processing abroad is not a Chapter V transfer. Actual legal assessment remains case-specific.

  • EDPB — International data transfers

    Official explanation of GDPR transfer conditions; does not determine contractual or procurement acceptance of exclusive-country requirements.