The data residency question rarely arrives on its own. It arrives inside a licence application, an outsourcing register, a bank's due diligence pack or a client's request under a privacy law. All four want the same three facts: which categories of personal data the firm holds, in which countries they are stored and processed, and on what legal basis they cross a border. A firm that cannot answer from memory has usually never mapped it.
Residency is not one rule. It is a stack of separate obligations that happen to point at the same servers. Privacy law governs the transfer of personal data. Financial regulation governs outsourcing and the supervisor's own access to records. Local laws in some markets require certain categories of data to stay inside the country. And commercial contracts with a liquidity provider or a payment processor add their own restrictions. Each layer can be satisfied independently, and each layer can independently sink a hosting decision.
The privacy layer
For a firm touching EU or UK clients, the relevant question is not whether data may leave the region, because it may, but under which transfer mechanism and with what assessment behind it. The regime allows transfers to countries recognised as offering adequate protection, and otherwise on the basis of contractual safeguards plus an assessment of the destination country's law, particularly government access powers. That assessment is a document the firm has to be able to produce. Firms handling identity documents, proof of address and transaction histories are holding exactly the kind of data that makes this scrutiny real, which is why the topic sits next to privacy obligations for trading firms rather than in the IT budget.
The practical consequence for platform choice is that a vendor has to tell you where processing happens, including subprocessors. A support team in a third country reading client records is a transfer. So is a backup replicated to another region, an analytics tool, or an outsourced KYC check. Firms map the primary database and forget everything around it.
The supervisory layer
Financial regulators approach hosting through outsourcing rather than privacy. The recurring themes across regimes are similar even when the wording differs: the firm stays responsible for functions it outsources, it must be able to access and audit them, and the supervisor must be able to as well. That is why cloud contracts written for ordinary businesses fail financial reviews. They lack audit rights, they lack a right for the regulator to inspect, they lack termination and exit assistance, and they let the provider change subprocessors without notice.
Several regimes also require notification of material outsourcing before it goes live, and maintenance of an outsourcing register. In the EU, the operational resilience rules that apply to financial entities push the same clauses harder, including exit planning and testing. Any firm expecting a serious supervisor should read its platform contract against the checklist in cloud outsourcing notifications before signing rather than after.
Residency rules differ by jurisdiction and by data category, and they change. Nothing here is legal advice. Map your own data, then have counsel in each market you serve confirm what may be stored where and on what basis.
Localisation, and where it actually bites
A smaller set of markets requires certain data to remain in country, sometimes for all personal data, sometimes only for payment or identity data, sometimes only for firms holding a local licence. The pattern to watch is not a global one. It is specific: a firm that plans to hold a local licence in a market with a localisation requirement cannot run that entity on a single shared instance hosted elsewhere without an in country copy or a separated deployment. Firms discover this late because it does not affect the offshore entity they started with, and then it blocks the onshore entity they wanted next.
This is the point where residency and structure meet. A group running an offshore entity and a regulated one often needs the regulated entity's records held under different terms, in a different place, with different access. That is a platform architecture question as much as a legal one, and it is easier to solve when the platform supports separated deployments than when everything shares one database. It is closely tied to how a firm handles two entity structures.
What to ask a platform vendor
Ask for the hosting regions of production, backups and disaster recovery separately, because they are often different. Ask for the current subprocessor list and how changes are notified. Ask whether support staff can view client records and from which countries. Ask whether a single tenant or region locked deployment is available and what it costs, because the answer determines whether an onshore licence is possible later without a migration. Ask what happens on exit: format, timeline and cost of getting your data out, which is the clause firms skip and regret. And ask who holds the encryption keys, since encryption at rest handled entirely by the provider answers a security question but not a control question.
SINGUARD sells software, so this is the side of the table we sit on: firms ask us these questions and the honest ones get specific answers, including where a requirement means a separate deployment rather than a shared one. What no vendor can do is tell a firm which regime applies to it. That is counsel's job, in each market the firm serves.
Decide it before the application, not after
Hosting choices are cheap at the design stage and expensive later. Migrating a live trading firm to a new region means downtime, reconciliation, a fresh set of contracts and, if a regulator has already approved the original arrangement, a variation request. A firm applying for a licence with a hosting arrangement that its own counsel has not reviewed will usually get the question in the first round of comments, and answering it well the first time shortens everything that follows.
"Nobody asks where your servers are until the week they ask, and by then the answer is in a contract you signed a year ago."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Residency is four separate layers: privacy transfers, supervisory outsourcing rules, local localisation laws and commercial contract terms.
- Map backups, disaster recovery, support access and subprocessors, not just the production database, because each is a transfer.
- Ordinary cloud contracts fail financial reviews because they lack audit rights, regulator access and exit assistance clauses.
- A localisation requirement in a target market can make a single shared deployment unworkable, so decide architecture before applying for a licence there.
Frequently Asked Questions
Does a broker have to host client data in the country of its licence?
Not usually, but some jurisdictions require certain categories of data to stay in country, and most supervisors require access and audit rights over wherever the data sits. The requirement depends on the regime and the data category, so confirm it with counsel in that market.
What makes a cloud contract acceptable to a financial regulator?
Typically audit and access rights for the firm and the supervisor, notification and control over subprocessors, clear security and incident terms, and exit assistance with a defined format and timeline. Standard commercial terms rarely include all of these without negotiation.
Can a firm run two entities on one hosted platform?
Sometimes, but not where one entity is subject to localisation or to separation requirements that the shared deployment cannot meet. Where a supervisor expects segregated records and separate access, a separated deployment is the cleaner answer.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.