When you run a digital assembly, you are processing personal data. The names and contact details of your shareholders or members. Their identity credentials. Their votes — which, even where secret from other participants, are known to the system (on secret-ballot items the vote itself is stored without the voter’s identity, but the fact that they voted is still recorded). Their IP addresses and device information. The timestamps of their actions. In some cases, their identity verification records.
As the organisation running the assembly, you are the data controller under GDPR. The platform you use is the data processor. That relationship has specific legal consequences — and most organisations using digital assembly tools have not examined those consequences carefully enough.
The most important of those consequences is this: where your data lives matters. Not just where the vendor is headquartered, not just which law the vendor says it complies with — but where the bytes are physically stored. For European organisations running assemblies on digital platforms, this question is not theoretical. It is a GDPR compliance requirement.
What GDPR Article 46 requires
The General Data Protection Regulation governs the transfer of personal data from the European Economic Area to third countries — meaning countries outside the EEA. Chapter V of GDPR, and Article 46 in particular, sets out the mechanisms by which such transfers may lawfully take place.
The baseline rule is that personal data may not be transferred to a third country unless that country is subject to an adequacy decision from the European Commission — a formal determination that the country's data protection framework provides an essentially equivalent level of protection to GDPR — or unless the transfer is subject to one of the approved safeguards, most commonly Standard Contractual Clauses (SCCs, also called standard data protection clauses).
SCCs are pre-approved contractual terms that impose GDPR-equivalent obligations on the data importer in the third country. They are the primary mechanism used by most multinational technology vendors to justify transfers of EU personal data to non-EU data centres — most commonly to the United States. The legal validity of SCCs was confirmed by the Court of Justice of the EU in the Schrems II decision (2020), but with an important qualification: SCCs are valid only where the data importer can actually comply with them, which requires an assessment of the legal framework of the destination country. For data transferred to the US, this creates ongoing legal uncertainty that has not been fully resolved.
The EU-US Data Privacy Framework (2023) has partially resolved the post-Schrems II uncertainty for transfers to certified US companies. However, the Framework has been challenged and its long-term status is not guaranteed. Organisations that rely on adequacy decisions or SCCs for their assembly platform data should review whether their vendor's compliance position has been updated to reflect the current state of this rapidly evolving area.
What "EU data residency" actually means
The phrase "EU data residency" is used liberally in SaaS marketing and means different things in different contexts. Understanding what it actually means — and what it does not — is essential for evaluating whether a vendor meets your compliance requirements.
At a minimum, "EU data residency" should mean that the physical servers on which your data is stored are located within the European Economic Area. This is a verifiable fact: a specific data centre in a specific country. It is distinct from several things that are sometimes confused with it.
It is distinct from the vendor being headquartered in the EU. A company registered in Denmark, Germany, or France may store its customer data in US-based cloud infrastructure. Conversely, an American technology company may store EU customer data in Frankfurt data centres. Corporate domicile and data residency are independent questions.
It is also distinct from the vendor "complying with GDPR." GDPR compliance is a process commitment, not a location fact. A vendor that stores data in the US but uses SCCs for the transfer "complies with GDPR" in the sense that it has a legal mechanism for the transfer — but data stored in the US is accessible to US government agencies under laws that do not have equivalents in the EU, which is precisely the concern that motivates EU data residency as a requirement.
True EU data residency means: the data is stored in EU data centres; it does not leave EU infrastructure; the sub-processors handling the data are also EU-based or subject to transfers with appropriate safeguards; and the vendor can provide documentation demonstrating each of these facts.
"We comply with GDPR" is a process claim. "Your data is stored in Frankfurt" is a location fact. For assembly data, you need both.
The DPA requirement
GDPR Article 28 requires that processing carried out by a processor on behalf of a controller be governed by a contract — the Data Processing Agreement (DPA). This is not optional. If your assembly platform processes personal data on your behalf — and it does — and you do not have a signed DPA with the vendor, you are in breach of GDPR regardless of where the data is stored.
A valid DPA for an assembly platform must include, at minimum: the subject matter, duration, nature, and purpose of the processing; the type of personal data processed and the categories of data subjects; your rights and obligations as data controller; the processor's obligation to process only on your documented instructions; confidentiality commitments; security measures appropriate to the risk; a requirement to assist you in responding to data subject rights requests; deletion or return of data at contract termination; a right of audit; and a list of sub-processors with the same obligations applied to them.
In practice, most established SaaS vendors have standard DPAs. The quality of those DPAs varies considerably. A DPA that was drafted for a generic SaaS product may not adequately address the specific characteristics of governance and voting data — the sensitivity of identity records, the legal retention requirements for vote records, or the specific chain-of-custody obligations that apply to assemblies. Review the DPA specifically for these points, not just for the presence of the required Article 28 elements.
Questions to ask your current vendor
The following six questions will reveal whether your current assembly platform meets the standard for processing governance data under GDPR. They are specific enough to require substantive answers — and a vendor that cannot answer them specifically has told you something important.
In which specific countries are your data centres located?
You are looking for named EU countries. "We have EU data centres" without specifics is insufficient. The specific location matters because data centre jurisdiction affects which law enforcement authorities can access the data.
Can you provide your standard Data Processing Agreement, pre-filled for our account?
A vendor that requires extended commercial negotiation to produce a DPA, or that does not have a standard one available, is signalling that data processing agreements are not a routine part of their compliance practice.
Who are your sub-processors, and where are they located?
The answer should be a list with specific company names, countries, and the purpose for which each sub-processor is used. Email delivery, customer support, and monitoring services are common sub-processors that may be US-based.
How and when is our data deleted if we end our contract?
The GDPR-compliant answer is: all personal data is deleted within a defined, short period of contract termination, and you receive confirmation of deletion. Assembly data — voter records, vote records, identity data — should be distinguished from other account data given its regulatory significance.
What is your breach notification commitment, and how does it align with the 72-hour GDPR notification timeline?
Your DPA should specify a notification commitment from the processor to you that allows you to meet your own 72-hour obligation. If the vendor's SLA says "we will notify you within 5 business days," that is not compatible with your legal obligations.
Has your infrastructure been independently assessed for security — SOC 2, ISO 27001, or equivalent — and is that report available to us?
A vendor that has undergone third-party security assessment demonstrates a level of security governance commitment that a vendor relying only on self-attestation does not. The report does not need to be shared in full — a summary or certificate is usually sufficient to confirm the assessment exists.
Use the checklist below to assess your current vendor against these six criteria. The results will give you a clear picture of your GDPR exposure and what to address.
Interactive tool
Vendor GDPR assessment
Assess your current assembly platform against six GDPR compliance criteria. Mark each as Yes, No, or Unsure based on what you know about your vendor.
Personal data is stored exclusively in EU data centres
Ask: "Where are your data centres located?" Acceptable answers name specific EU locations (Frankfurt, Amsterdam, Dublin, Paris). Unacceptable: "We comply with GDPR" without specifying physical location. "EU jurisdiction" is not the same as "EU data centre." Many US-headquartered vendors route data through EU regions while retaining the right to access or transfer it to servers in the US.
A Data Processing Agreement (DPA) is available and contains Article 28 required elements
Ask: "Can you provide your standard Data Processing Agreement?" Under GDPR Article 28, any processor handling personal data on your behalf must sign a DPA. It must specify the subject matter, nature, purpose, type of personal data, categories of data subjects, and your rights and obligations as controller. If the vendor does not have a standard DPA ready, or requires extended negotiation to produce one, that is a significant signal.
Sub-processors are disclosed and located in the EU or subject to appropriate transfer mechanisms
Ask: "Who are your sub-processors and where are they located?" A vendor may store your data in the EU but use sub-processors — email delivery services, monitoring tools, support platforms — that are not EU-based. Each sub-processor is a potential transfer point. The DPA should list all sub-processors and the legal basis for any transfers outside the EU. If this information is not available, you cannot fully assess your GDPR exposure.
The vendor can demonstrate deletion or return of data at contract termination
Ask: "How is our data deleted when we stop using the service, and what is the timeline?" GDPR Article 28 requires processors to delete or return all personal data at the end of the contract. Some vendors delete data immediately; others retain it for defined periods; some have unclear or contractually vague policies. For an assembly platform specifically, this includes voter records, identity data, and vote records — data with regulatory retention requirements on your side that must be reconciled with the vendor's deletion timeline.
The vendor has documented security measures appropriate to the sensitivity of assembly data
Ask: "What is your security documentation, and what measures apply specifically to governance and voting data?" Acceptable responses include references to specific technical measures (encryption at rest and in transit, access controls, audit logging), organisational measures (access reviews, security training), and third-party validation (ISO 27001 certification, SOC 2 reports, penetration testing). "We take security seriously" is not documentation.
The vendor has a documented process for notifying you of data breaches within 72 hours
Ask: "What is your breach notification process and what is your commitment to the 72-hour notification timeline?" GDPR requires you, as data controller, to notify your supervisory authority (Datatilsynet in Denmark) within 72 hours of becoming aware of a personal data breach. Your processor must notify you promptly enough for you to meet this obligation. If the vendor's SLA or DPA does not specify a notification commitment aligned with this timeline, you are exposed.
Partial compliance — gaps present
Your vendor meets some criteria but has identifiable gaps. Each "no" or "unsure" answer represents a specific compliance risk. You should obtain written confirmation on the items marked "unsure" and address any "no" items before processing further assembly data.
Assembley's approach
Assembley processes all customer data exclusively in EU infrastructure, hosted in Frankfurt, Germany. No personal data is transferred outside the European Economic Area. All sub-processors are EU-based or subject to valid transfer mechanisms, and the sub-processor list is available on request.
A Data Processing Agreement that meets all GDPR Article 28 requirements is available to all customers on request and is required before any assembly data is processed. The DPA is specific to the governance and voting context — it addresses the specific categories of data processed, the retention requirements, and the security measures applied to vote records.
Data is deleted within 30 days of contract termination, with confirmation provided. Breach notification to customers within 24 hours of discovery is a contractual commitment, allowing customers to meet their own 72-hour regulatory obligation.
Running an assembly soon?
Take the AGM Readiness Assessment to identify governance, compliance, and data protection gaps before your next meeting.
Take the assessment →