ComplianceISO 27001Data residency
ISO 27001 · Data residency

Data residency and ISO 27001: where data lives vs where you're certified

The short answer

They’re two different questions. ISO 27001 certifies your management system — how you assess risk, run controls and prove it — not where your servers sit. Data residency is a legal and contractual question: which country’s law and which customer clauses govern the data. Your ISMS has to answer the residency question, but the certificate alone never does.

The two questions buyers keep merging

“Are you ISO 27001 certified?” and “Where does our data live?” arrive in the same questionnaire, often in adjacent rows, and get treated as one question. They aren’t — different people set the answers, and different documents prove them.

Question Who sets the answer What proves it
Are you certified? An accredited certification body, against the international standard The certificate and its scope, plus the Statement of Applicability behind it
Where does our data live? Law in the relevant jurisdictions, plus your customer contracts Your asset inventory, supplier agreements and architecture records

ISO 27001 certifies a management system: the loop of risk assessment, controls, internal audit and management review, checked at Stage 1 and Stage 2 and re-checked at every surveillance audit. Nothing in that loop pins data to a country. A company hosting entirely in Frankfurt and a company hosting entirely in Sydney can hold identical certificates.

Residency runs the other way too: hosting in-country proves nothing about security by itself. A server in the right jurisdiction with no access control, no monitoring and no incident process satisfies the contract clause and fails everything the clause was written to protect.

So the certificate can’t answer the residency question, and the residency answer can’t substitute for the certificate. Buyers who know what they’re doing — health and government buyers especially — ask both at once precisely because they’re different. If you’re selling into Australian health, the sector picture is covered in our health tech guide; the two-question pattern there is the norm, not the exception.

What your ISMS has to say about where data lives

Location-agnostic doesn’t mean location-silent. The standard doesn’t tell you where to put data, but it does require your ISMS to know — and to show its working. At the level of the Organisational theme’s controls, that means four things.

Identified legal and contractual requirements. The ISMS keeps a register of what applies: each jurisdiction’s law where you operate or host, and every residency clause your customers have signed you up to. If some infrastructure sits in Europe or the United States, those markets’ data-residency and disclosure considerations belong in that register like any other input.

Supplier controls over the hosting arrangement. Your cloud or datacentre provider is a supplier. The agreement, what it promises about location, and how you check the promise holds — that’s supplier management, and it’s squarely inside the ISMS.

Records that say where data actually is. An asset inventory that names the system, the data, the provider and the country. Not a diagram from two re-platformings ago — a record the current architecture matches.

Written transfer decisions. When data moves across a border — a support tool, an analytics pipeline, a replica — the decision is assessed and recorded, not discovered later.

Be clear about where the obligations come from, because they rarely arrive labelled “residency”. They arrive as a clause in a government contract, a condition in a health-data agreement, a European enterprise customer’s data-processing terms, or a line in procurement’s standard schedule that nobody flagged. Each one lands in the same register, which is the point of keeping it: one place where sales can check what’s already been promised before promising something new, and where the next commitment gets tested against the infrastructure you actually run.

Do that, and the residency question has a documented answer the auditor can verify and the buyer can read. Skip it, and both questions come back — from the auditor as a finding, from the buyer as a stalled deal.

What most people get wrong

Answering the residency question with the certificate. A buyer asks “where will our data be stored?” and the response is “we’re ISO 27001 certified.” True sentence, wrong question — and experienced reviewers read the swap as either not understanding the difference or hoping they don’t.

The strong answer is two clean parts. Where: this country, this provider, under this agreement — and here’s the record. Assurance: certified by an accredited certification body, with a scope that covers the systems holding your data. Each answer makes the other credible. Merged, they weaken both.

How Secure60 handles this

We make both answers true at once. The ISMS we build carries the residency obligations — the legal register, the supplier controls, the inventory that says where everything lives — and one security platform runs the monitoring and evidence behind it. Delivery infrastructure via Rackcorp across Australia, Asia-Pacific and Central Asia means collection and storage can stay in-country where a contract demands it. The certificate itself comes from an accredited certification body, not from us — we get you to the point where their audit and your buyer’s questionnaire read the same clean answers. We’re ISO 27001:2022 certified ourselves.

Frequently asked questions

Does ISO 27001 require data to be stored in a particular country?

No. The standard is location-agnostic — it certifies how you manage information security, not where the servers are. Residency requirements come from law and from your customers’ contracts, never from the certificate.

If our data is hosted in Europe or the US, does that affect our certificate?

Not the certificate itself. It does affect what your ISMS must contain: the hosting arrangement sits under your supplier controls, and those jurisdictions’ legal considerations join your legal-requirements register.

A customer asked where their data lives and whether we're certified. Is that one question?

It’s two, and they deserve two answers: a factual one (which country, which provider, under what agreement) and an assurance one (certified, by an accredited certification body, with this scope). Health and government buyers in particular ask both at once and notice when one answer is doing the work of two.

Can we exclude our hosting provider's datacentre from the ISMS scope?

The provider stays in the picture as a supplier — supplier and legal-requirement controls in the Organisational theme cover the arrangement. You can scope your ISMS around your own organisation, but you can’t scope away accountability for where your data sits.

Who decides what our residency obligations are?

The law of the jurisdictions you operate in, plus whatever your customer contracts add on top. Not the certification body — the auditor checks that your ISMS identified and met those obligations, not what they should be.

Getting both questions in the same questionnaire?

Book a readiness call. We'll help you answer 'where does our data live' and 'are you certified' as two clean answers instead of one muddled one.

Book a readiness call Run a pilot