Guide
02 Sep 2026
X
Min read

EU data residency: What European healthcare builders need to know

TL;DR

  • EU healthcare buyers require proof, not claims, that patient data is stored and processed within the EU, including through subprocessors.
  • Country-specific standards apply on top of GDPR: BSI C5 for Germany, HDS for France, UK GDPR for UK customers.
  • Verify vendor claims via DPA, subprocessor list, and current ISO 27001/SOC 2/BSI C5 attestations.
  • Sovereign deployment (data isolated to a specific national infrastructure) is becoming a procurement requirement, not a differentiator.

If you are building healthcare software in Europe and evaluating AI infrastructure, data residency is the most important question someone should ask. Regulators, procurement teams, and hospital IT departments all ask the same thing: where does our data go, and can you prove it stays there?

This guide explains what EU data residency means in practice, what regulations require it, and exactly how to verify that your AI vendor can back up their claims.

Why data residency matters for EU healthcare builders

The GDPR requires that personal data, including patient health data, is processed lawfully. For healthcare applications, this means data cannot be routed to or stored in jurisdictions without adequate protection. 

The practical implication: your AI infrastructure must process and store data within the European Union (EU) or an approved equivalent jurisdiction, unless you have explicit legal basis and contractual protections for cross-border transfer.

For healthcare-specific markets, the requirements go further. Germany's BSI C5 standard requires that sensitive health data remains within their respective national or EU-zone infrastructure. In Germany, BSI C5 is a de facto requirement for public sector and hospital procurement.

The consequence for builders: if your AI vendor cannot demonstrate verified data residency, your product cannot be sold into regulated health systems in these markets.

What 'EU data residency' actually means

What you need to verify is not just where a vendor's headquarters are, but where data is processed, stored, and which subprocessors have access to.

Processing vs. storage

These are distinct. A vendor might store data in the EU but route audio or text through a US-based processing service. For clinical audio, which is the most sensitive data class in healthcare AI, both storage and processing must remain within the EU, for EU data residency. 

Subprocessors are part of the perimeter

If your vendor uses third-party services for speech-to-text, model inference, or cloud infrastructure, those subprocessors are part of your data boundary. You are responsible for knowing where they operate. Your DPA should list all subprocessors and their processing locations.

When Corti processes EU customer data, both storage and processing remain within the EU. Audio data processed through Corti’s speech-to-text pipeline is handled in the EU, specifically in Ireland, and Corti’s infrastructure is configured so that EU patient data does not cross to the US.

Regulations you need to understand

GDPR: the baseline for all EU markets

GDPR applies to any processing of EU personal data, regardless of where the vendor is based. Key requirements for healthcare builders: you need a Data Processing Agreement (DPA) with your AI vendor, a lawful basis for processing, and a documented subprocessor list of where data is processed and stored. Corti also maintains an ISAE 3000 assurance report, providing independent assurance over relevant controls and compliance practices. Where international transfers are required, Corti supports appropriate transfer mechanisms, including the EU-US Data Privacy Framework and the UK and Swiss extension and the Standard Contractual Clauses with a Transfer Impact Assessment (TIA) as a fallback mechanism. 

BSI C5: German cloud security assurance

BSI C5 is a cloud security criteria catalogue published by Germany’s Federal Office for Information Security. It is a key assurance standard for cloud services used by German public authorities and is increasingly relevant in German healthcare procurement as it provides a structured framework for assessing cloud security, transparency, operational controls, and data location commitments.

Corti is aligned with German BSI C5 requirements for health-data cloud security and demonstrates this through an external audit. For German public-sector and healthcare customers, this provides important assurance that Corti can support regulated clinical workflows where EU data residency, cloud security, and independently assessed controls are procurement requirements.

UK GDPR: UK market data protection requirements

The UK maintains its own version of GDPR under the Data Protection Act 2018. UK patient data must be processed under UK GDPR rules. Practically, this means your DPA must be updated for UK customers, and data flows between the UK and EU require appropriate transfer mechanisms. Corti is compliant with UK GDPR requirements and supports UK customers through appropriate contractual terms, transfer mechanisms where required, and documented safeguards for patient data. 

The questions to ask before you build

Before integrating any AI vendor into your clinical product, ask these questions. The answers determine whether your product can be approved for use in EU health systems.

Requirement What to ask your vendor Corti answer
Where is data stored? Which countries or regions? Which cloud provider? Which data centres? EU only (Microsoft Azure & Scaleway)
Where is data processed? Does processing of the patient's data remain in the EU? EU, no cross-border routing
Who are your subprocessors? Full list with locations and certifications. Is the list publicly available? Yes, published at corti.ai/legal/subprocessors
Do you have a signed DPA available? Is your DPA GDPR-compliant? Yes, standard DPA available at corti.ai/legal/data-processing-agreement
Are you BSI C5 certified? For German public health market requirements. Yes, Corti is C5 Type II certified.
Do you use HDS certified infrastructure? Required for French health data hosting. Yes, Azure and Scaleway are HDS certified.
How are subprocessor changes communicated? Which is the notice period? What is the objection process? 30-day notice plus customer objection rights per DPA.
What happens in a data breach? According to Article 33 of GDPR, 72-hour notification to the regulator is required. How does your vendor notify you? Corti will notify within 72 hours of becoming aware of a data breach.

How to verify a vendor's claims

Here is how to verify EU data residency before you sign a contract.

  • Ask for the Data Processing Agreement. Read the subprocessor list carefully. Every service named must have documented EU processing locations.
  • Check the vendor's public trust page or compliance status page. Look for independently verified certifications: ISO 27001, SOC 2, BSI C5. Each should have a current attestation date.
  • Request the vendor's own DPIA. A vendor that has done proper privacy engineering will have one. It should identify data categories, processing locations, risk mitigations, and residual risks.
  • Ask for sovereign cloud evidence. Sovereign deployment means patient data never leaves the customer's jurisdiction, even for processing. 

Corti's compliance documentation is available via our public Trust Centre at https://trust.corti.ai/ including ISO 27001, SOC 2, BSI C5, GDPR ISAE 3000, ISO 42001, ISO 27017 and ISO 27018. View our full subprocessor list.

What sovereign deployment means in practice

Sovereign deployment is a stronger commitment than data residency. It means that data never leaves the customer's control zone, not just the EU, but a specific national infrastructure. This matters because it removes the residual question in data residency: what if the vendor's EU infrastructure fails over to another region? In a sovereign deployment, that cannot happen. The infrastructure is isolated.

For healthcare builders targeting German or French public health systems, sovereign deployment is increasingly a procurement expectation rather than a differentiator.

Getting to production

European healthcare procurement is long. The compliance questions above are asked at the start, but the evidence is verified during technical due diligence and compliance review. The builders who move fastest are those who arrive at the procurement conversation with the documentation already assembled.

Corti provides a compliance pack DPA, subprocessor list, certification attestations as a standard part of onboarding. The goal is to reduce the institutional cost of deploying clinical AI: when you build on Corti, part of your regulatory approval process is already done.

Start your compliance evaluation with confidence. Access Corti's Trust Center https://trust.corti.ai/. For compliance documentation, Privacy or Security questions, contact privacy@corti.ai or security@corti.ai

Build faster. Ship safer. Scale smarter.

Get started with healthcare-native APIs built to power real clinical workflows.

More stories from Corti

View all