Data residency used to be a question only lawyers asked, and IoT teams could pick a platform without knowing which continent their data slept on. That era is over. European customers ask where telemetry is stored before they ask about features, public tenders make residency a pass-fail gate, and sectors from health to utilities carry national rules about data leaving the country. For anyone selling IoT services, the platform’s residency options quietly define your addressable market: a platform with one US region is a ceiling on who you can sell to, no matter how good the product is.
Evaluating residency properly comes down to a handful of questions, and they separate real answers from marketing ones.
What residency is, and what it is not
Data residency is the physical and legal location where your data is stored. It is related to, but not the same as, three neighbors it gets confused with. Data sovereignty is whose laws apply to the data, which follows from residency but also from who operates the infrastructure. Data ownership is who has rights over the data, a contractual question we covered in who owns your IoT data. And GDPR compliance is a legal regime that constrains transfers but does not by itself require EU storage.
A vendor who answers a residency question with “we are GDPR compliant” has answered a different question, and that substitution is worth noticing when it happens.
The five questions that expose weak answers
First: which regions can our data be stored in, and can we choose per deployment? The strongest answer is a documented list of regions with customer choice at profile or tenant level. TagoIO, for example, operates separate US and European clusters and the choice is yours at signup. If the answer is one region, that is a market ceiling, not a dealbreaker, but price it in.
Second: does all of the data stay in the region, or only the telemetry? This is where weak residency stories fall apart. Time-series data may sit in Frankfurt while account metadata, file storage, or backups quietly live elsewhere. Ask specifically about metadata, backups, and logs, and get the answer in writing.
Third: does data transit outside the region during processing? Some platforms store in-region but process, run analytics, or route notifications through services elsewhere. If your customers care about residency, they usually care about transit too. This includes the AI layer: if the platform runs analytics and AI on your data, ask where those workloads execute and whether any of it leaves the region. A platform that runs its intelligence inside the same infrastructure as the storage has a much cleaner answer than one that ships data to third-party model APIs by default.
Fourth: what happens if we need to move regions later? Migration between regions is the residency version of vendor lock-in: possible everywhere, painful in different amounts. Documented export APIs and a stated migration path are the honest answer; “contact support” is a flag.
Fifth: who can access the data, from where? Residency of bytes matters less to some regulators than residency of access. Support staff jurisdiction, subprocessor lists, and the legal entity you contract with all belong in the diligence, and a platform with a signed DPA and an ISO 27001 certification, as TagoIO carries, gives your compliance reviewer an audited baseline instead of assurances.
Matching the requirement to the deployment
Not every deployment needs the strictest answer, and over-specifying residency costs money too. A useful sorting: commercial-sensitivity deployments (most industrial monitoring) need a region choice and a DPA. Personal-data deployments (anything touching occupants, workers, vehicles) need region choice, transit answers, and the GDPR machinery, the full checklist from our GDPR evaluation guide. Regulated-sector deployments (health, utilities, government) need all of the above plus sector rules, and sometimes they genuinely need on-premises components, which is where an edge option like TagoCore keeps the sensitive processing local while the rest of the fleet stays in the cloud.
If you resell IoT services, do this sorting for your customers before they ask. A reseller who can say “your data stays in Europe, here is the document” wins tenders against competitors who need three weeks to find out.
The test that settles it
Ask the vendor to show, not tell: a signed DPA template, the region list in public documentation, the subprocessor list, and the certification. Ten minutes of documents beat an hour of assurances. Residency done right is boring, and boring is exactly what your customer’s compliance team is buying.
TagoIO runs European and US clusters, signs DPAs, and is ISO 27001 certified, with the details public on the trust page. Book a demo or start free.