EU data residency: What European healthcare builders need to know

TL;DR
- EU healthcare buyers require proof, not claims, that patient data is stored and processed within the EU, including through subprocessors.
- Country-specific standards apply on top of GDPR: BSI C5 for Germany, HDS for France, UK GDPR for UK customers.
- Verify vendor claims via DPA, subprocessor list, and current ISO 27001/SOC 2/BSI C5 attestations.
- Sovereign deployment (data isolated to a specific national infrastructure) is becoming a procurement requirement, not a differentiator.
If you are building healthcare software in Europe and evaluating AI infrastructure, data residency is the most important question someone should ask. Regulators, procurement teams, and hospital IT departments all ask the same thing: where does our data go, and can you prove it stays there?
This guide explains what EU data residency means in practice, what regulations require it, and exactly how to verify that your AI vendor can back up their claims.
Why data residency matters for EU healthcare builders
The GDPR requires that personal data, including patient health data, is processed lawfully. For healthcare applications, this means data cannot be routed to or stored in jurisdictions without adequate protection.
The practical implication: your AI infrastructure must process and store data within the European Union (EU) or an approved equivalent jurisdiction, unless you have explicit legal basis and contractual protections for cross-border transfer.
For healthcare-specific markets, the requirements go further. Germany's BSI C5 standard requires that sensitive health data remains within their respective national or EU-zone infrastructure. In Germany, BSI C5 is a de facto requirement for public sector and hospital procurement.
The consequence for builders: if your AI vendor cannot demonstrate verified data residency, your product cannot be sold into regulated health systems in these markets.
What 'EU data residency' actually means
What you need to verify is not just where a vendor's headquarters are, but where data is processed, stored, and which subprocessors have access to.
Processing vs. storage
These are distinct. A vendor might store data in the EU but route audio or text through a US-based processing service. For clinical audio, which is the most sensitive data class in healthcare AI, both storage and processing must remain within the EU, for EU data residency.
Subprocessors are part of the perimeter
If your vendor uses third-party services for speech-to-text, model inference, or cloud infrastructure, those subprocessors are part of your data boundary. You are responsible for knowing where they operate. Your DPA should list all subprocessors and their processing locations.
When Corti processes EU customer data, both storage and processing remain within the EU. Audio data processed through Corti’s speech-to-text pipeline is handled in the EU, specifically in Ireland, and Corti’s infrastructure is configured so that EU patient data does not cross to the US.
Regulations you need to understand
GDPR: the baseline for all EU markets
GDPR applies to any processing of EU personal data, regardless of where the vendor is based. Key requirements for healthcare builders: you need a Data Processing Agreement (DPA) with your AI vendor, a lawful basis for processing, and a documented subprocessor list of where data is processed and stored. Corti also maintains an ISAE 3000 assurance report, providing independent assurance over relevant controls and compliance practices. Where international transfers are required, Corti supports appropriate transfer mechanisms, including the EU-US Data Privacy Framework and the UK and Swiss extension and the Standard Contractual Clauses with a Transfer Impact Assessment (TIA) as a fallback mechanism.
BSI C5: German cloud security assurance
BSI C5 is a cloud security criteria catalogue published by Germany’s Federal Office for Information Security. It is a key assurance standard for cloud services used by German public authorities and is increasingly relevant in German healthcare procurement as it provides a structured framework for assessing cloud security, transparency, operational controls, and data location commitments.
Corti is aligned with German BSI C5 requirements for health-data cloud security and demonstrates this through an external audit. For German public-sector and healthcare customers, this provides important assurance that Corti can support regulated clinical workflows where EU data residency, cloud security, and independently assessed controls are procurement requirements.
UK GDPR: UK market data protection requirements
The UK maintains its own version of GDPR under the Data Protection Act 2018. UK patient data must be processed under UK GDPR rules. Practically, this means your DPA must be updated for UK customers, and data flows between the UK and EU require appropriate transfer mechanisms. Corti is compliant with UK GDPR requirements and supports UK customers through appropriate contractual terms, transfer mechanisms where required, and documented safeguards for patient data.
The questions to ask before you build
Before integrating any AI vendor into your clinical product, ask these questions. The answers determine whether your product can be approved for use in EU health systems.
How to verify a vendor's claims
Here is how to verify EU data residency before you sign a contract.
- Ask for the Data Processing Agreement. Read the subprocessor list carefully. Every service named must have documented EU processing locations.
- Check the vendor's public trust page or compliance status page. Look for independently verified certifications: ISO 27001, SOC 2, BSI C5. Each should have a current attestation date.
- Request the vendor's own DPIA. A vendor that has done proper privacy engineering will have one. It should identify data categories, processing locations, risk mitigations, and residual risks.
- Ask for sovereign cloud evidence. Sovereign deployment means patient data never leaves the customer's jurisdiction, even for processing.
Corti's compliance documentation is available via our public Trust Centre at https://trust.corti.ai/ including ISO 27001, SOC 2, BSI C5, GDPR ISAE 3000, ISO 42001, ISO 27017 and ISO 27018. View our full subprocessor list.
What sovereign deployment means in practice
Sovereign deployment is a stronger commitment than data residency. It means that data never leaves the customer's control zone, not just the EU, but a specific national infrastructure. This matters because it removes the residual question in data residency: what if the vendor's EU infrastructure fails over to another region? In a sovereign deployment, that cannot happen. The infrastructure is isolated.
For healthcare builders targeting German or French public health systems, sovereign deployment is increasingly a procurement expectation rather than a differentiator.
Getting to production
European healthcare procurement is long. The compliance questions above are asked at the start, but the evidence is verified during technical due diligence and compliance review. The builders who move fastest are those who arrive at the procurement conversation with the documentation already assembled.
Corti provides a compliance pack DPA, subprocessor list, certification attestations as a standard part of onboarding. The goal is to reduce the institutional cost of deploying clinical AI: when you build on Corti, part of your regulatory approval process is already done.
Start your compliance evaluation with confidence. Access Corti's Trust Center https://trust.corti.ai/. For compliance documentation, Privacy or Security questions, contact privacy@corti.ai or security@corti.ai.
Build faster. Ship safer. Scale smarter.
Get started with healthcare-native APIs built to power real clinical workflows.




