These are two separate questions. ISO 27001 certifies your management system — how you assess risk, run controls and evidence both — rather than where your servers sit. Data residency is a legal and contractual question: which country’s law and which customer clauses govern the data. The ISMS has to answer the residency question, and the certificate on its own does not.
“Are you ISO 27001 certified?” and “Where does our data live?” arrive in the same questionnaire, frequently in adjacent rows. Different parties set the answers, and different documents evidence them.
| Question | Who sets the answer | What proves it |
|---|---|---|
| Are you certified? | An accredited certification body, against the international standard | The certificate and its scope, plus the Statement of Applicability behind it |
| Where does our data live? | Law in the relevant jurisdictions, plus your customer contracts | Your asset inventory, supplier agreements and architecture records |
ISO 27001 certifies a management system: the loop of risk assessment, controls, internal audit and management review, checked at Stage 1 and Stage 2 and re-checked at every surveillance audit. Nothing in that loop fixes data to a country, so a company hosting entirely in Frankfurt and a company hosting entirely in Sydney can hold identical certificates.
The relationship runs the other way as well: hosting in-country establishes nothing about security. A server in the correct jurisdiction with no access control, no monitoring and no incident process satisfies the contract clause while failing what the clause was written to protect.
The certificate therefore cannot answer the residency question, and the residency answer cannot substitute for the certificate. Buyers who understand the distinction — health and government buyers in particular — ask both at once because they are different. For Australian health specifically, the sector picture is in our health tech guide, where the two-question pattern is standard.
Location-agnostic is not location-silent. The standard does not specify where data goes, and it requires the ISMS to know and to evidence it. Under the Organisational theme’s controls, that covers four things.
Identified legal and contractual requirements. The ISMS keeps a register of what applies: each jurisdiction’s law where you operate or host, and every residency clause your customers have signed. Where infrastructure sits in Europe or the United States, those markets’ data-residency and disclosure considerations belong in that register.
Supplier controls over the hosting arrangement. A cloud or datacentre provider is a supplier. The agreement, what it commits to about location, and how that commitment is verified, all fall under supplier management inside the ISMS.
Records of where data resides. An asset inventory naming the system, the data, the provider and the country, matching the current architecture rather than a previous one.
Written transfer decisions. Where data crosses a border — a support tool, an analytics pipeline, a replica — the decision is assessed and recorded at the time.
Residency obligations rarely arrive labelled as such. They arrive as a clause in a government contract, a condition in a health-data agreement, a European enterprise customer’s data-processing terms, or a line in procurement’s standard schedule. Each lands in the same register, which is what makes the register useful: one place where sales can check what has already been committed before committing to something new, and where the next commitment is tested against the infrastructure in operation.
With that in place, the residency question has a documented answer the auditor can verify and the buyer can read. Without it, the question returns from the auditor as a finding and from the buyer as a stalled deal.
Responding to “where will our data be stored?” with a statement of ISO 27001 certification answers a different question, and experienced reviewers read the substitution as either a misunderstanding of the distinction or an attempt to avoid it.
The strong response has two parts. Location: this country, this provider, under this agreement, with the record attached. Assurance: certified by an accredited certification body, with a scope covering the systems that hold the customer’s data. Each part supports the other, and merging them weakens both.
We make both answers true at once. The ISMS we build carries the residency obligations — the legal register, the supplier controls, the inventory recording where everything resides — and one security platform runs the monitoring and evidence behind it. Delivery infrastructure via Rackcorp across Australia, Asia-Pacific and Central Asia means collection and storage can stay in-country where a contract requires it. The certificate comes from an accredited certification body, and our work is getting you to the point where their audit and your buyer’s questionnaire receive the same two clean answers. Secure60 holds ISO 27001:2022 certification.
Does ISO 27001 require data to be stored in a particular country?
No. The standard is location-agnostic: it certifies how information security is managed rather than where the servers are. Residency requirements come from law and from customer contracts.
If our data is hosted in Europe or the US, does that affect our certificate?
Not the certificate itself. It affects what the ISMS must contain: the hosting arrangement sits under your supplier controls, and those jurisdictions’ legal considerations join your legal-requirements register.
A customer asked where their data lives and whether we're certified. Is that one question?
It is two, and each needs its own answer: a factual one covering country, provider and agreement, and an assurance one covering certification, the accredited certification body, and the scope. Health and government buyers ask both together and notice when one answer is substituting for the other.
Can we exclude our hosting provider's datacentre from the ISMS scope?
The provider remains in scope as a supplier, covered by the supplier and legal-requirement controls in the Organisational theme. The ISMS can be scoped around your own organisation, and accountability for where the data sits stays with you.
Who decides what our residency obligations are?
The law of the jurisdictions you operate in, plus whatever customer contracts add. Not the certification body: the auditor checks that the ISMS identified and met those obligations rather than determining what they are.