{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-07-28T13:58:35.823Z"},"content":[{"type":"documentation","id":"faecdc6f-bdc0-4312-911a-4ef3c7be9a55","slug":"research-data-residency-international-transfers","title":"Research Data Residency and International Transfers: Where Your Interview Data Actually Lives","url":"https://www.koji.so/docs/research-data-residency-international-transfers","summary":"Data residency is where data is stored, data sovereignty is whose law governs it and who can compel access, and data localisation is a statutory requirement to keep data in country. Under GDPR, any transfer outside the EEA is restricted and needs a Chapter V mechanism: adequacy decision, the EU-US Data Privacy Framework for certified US recipients, Standard Contractual Clauses under Implementing Decision 2021/914, Binding Corporate Rules, or Article 49 derogations (occasional transfers only). Since Schrems II, SCCs require a transfer impact assessment plus supplementary measures; pseudonymisation before transfer is the highest-value measure for research. The DPF remains valid but the Latombe appeal is pending at the CJEU and PCLOB lost quorum in 2025, so pair DPF reliance with SCCs. Research is exposed because transcripts contain incidental identifiers and the processing chain spans recruitment, interviewing, transcription, LLM analysis, and storage. Ask vendors about storage and processing countries, sub-processors, transfer mechanism, model training, deletion SLA, and pseudonymisation support. Koji shortens the chain, supports anonymisation before sharing, allows deletion at any time, and its six structured question types reduce how much narrative data crosses any border.","content":"## The short answer\n\n**\"Where is our data stored?\" is the wrong first question. The right one is \"who can lawfully compel access to it, and under which country's law?\"** Storage location is one input to that answer, not the answer itself. A dataset sitting in a Frankfurt data centre operated by a company subject to another country's disclosure laws is not automatically protected by its postcode.\n\nFor research teams, three distinct concepts get collapsed into one word:\n\n- **Data residency** — the geographic location where data is stored at rest. Usually a contractual commitment you choose.\n- **Data sovereignty** — whose laws govern that data, including who can compel disclosure. Follows the operator and the legal entity, not just the server.\n- **Data localisation** — a legal requirement that data must stay in a country. Imposed by statute, not chosen.\n\nUnder GDPR, moving personal data outside the EEA is a **restricted transfer** and needs a Chapter V mechanism regardless of where you store it. Getting this right takes an afternoon. Getting it wrong surfaces during a security review, three weeks before you needed the research.\n\n## Why this lands on research teams\n\nInterview data is unusually exposed. Survey responses are short and often anonymous; interview transcripts are long, narrative, and full of incidental identifiers — a person naming their employer, their manager, a medical condition, a customer account. Recorded voice adds another layer, since in some jurisdictions voiceprints are biometric data with their own rules.\n\nMeanwhile the processing chain is long. A single study can touch a recruitment tool, an interview platform, a transcription service, an LLM analysis provider, and a repository — potentially in four countries. **Your transfer analysis has to cover the whole chain, not just the platform you bought.** The most common finding in a research security review is not that the vendor is in the wrong country; it is that nobody mapped the sub-processors.\n\n## GDPR Chapter V: the transfer mechanisms\n\n| Mechanism | When to use | Practical notes |\n|---|---|---|\n| **Adequacy decision** (Art 45) | Destination country recognised by the European Commission | Simplest route. Covers the UK, Switzerland, Canada (commercial), Japan, South Korea, New Zealand, and others |\n| **EU-US Data Privacy Framework** | US recipient that has self-certified | An adequacy decision adopted 10 July 2023. Only covers **certified** recipients — verify the certification, do not assume it |\n| **Standard Contractual Clauses** (Art 46) | The default for most vendors | Commission Implementing Decision 2021/914; four modules for different controller/processor relationships. Requires a transfer impact assessment |\n| **Binding Corporate Rules** | Intra-group transfers in large organisations | Slow to approve; rarely relevant to a research purchase |\n| **Article 49 derogations** | Occasional, non-repetitive transfers | Explicit consent or contractual necessity. **Not** a basis for systematic, ongoing research operations |\n\n### A note on the Data Privacy Framework's stability\n\nThe DPF remains valid law and is the simplest route for certified US vendors, but it is under active challenge. The EU General Court dismissed the *Latombe* action on 3 September 2025, upholding the framework; that ruling was appealed to the Court of Justice on 31 October 2025 and the appeal is still pending. Separately, the US Privacy and Civil Liberties Oversight Board lost its quorum in January 2025 when three of its five members were removed — and PCLOB oversight was one of the safeguards the Commission relied on in finding US protections adequate.\n\nNone of this means you should avoid the DPF. It means you should **not build a research programme whose only transfer mechanism is the DPF.** The resilient pattern is DPF certification *plus* SCCs as fallback in the same contract. That way an adverse ruling is a paperwork event rather than a fieldwork stoppage. Ask your vendor directly whether their DPA includes SCCs alongside any DPF reliance.\n\n### Transfer impact assessments\n\nSince *Schrems II* (2020), relying on SCCs is not enough on its own. You must assess whether the destination country's law undermines the protection the clauses promise, and add supplementary measures where it does — encryption with keys held in the EEA, pseudonymisation before transfer, or contractual commitments to challenge and report access requests.\n\nFor research specifically, the highest-value supplementary measure is **pseudonymisation before transfer**. If names, employers, and direct identifiers are stripped and held separately in the EEA, what crosses the border is far less sensitive and your TIA becomes considerably easier to write.\n\n## Beyond the EU\n\n- **UK GDPR** — separate regime. Transfers out of the UK use the International Data Transfer Agreement or the UK Addendum to the EU SCCs. The UK's own adequacy status under EU law has been extended rather than made permanent and is subject to periodic review, so confirm the current position rather than assuming it holds.\n- **Switzerland** — its own framework and a Swiss-US arrangement; the EU SCCs need Swiss-specific amendments.\n- **Brazil (LGPD)** — transfers require adequacy, contractual clauses, or specific consent; the ANPD has issued its own standard clauses.\n- **Canada (PIPEDA)** — no localisation requirement federally, but transfers require comparable protection and transparency to individuals about offshore processing. Some provincial public-sector rules are stricter.\n- **India (DPDP Act)** — a blocklist model rather than an allowlist: transfers permitted except to countries the government restricts.\n- **China (PIPL)** — genuinely restrictive, with security assessments, standard contracts, or certification required, plus localisation duties for some operators. Treat China research as a separate project with local counsel.\n\n**Practical implication:** if you run global research, do not try to satisfy every regime with one policy. Segment by participant region, apply the strictest applicable rule per segment, and document the segmentation.\n\n## Six questions to ask any research vendor\n\nSend these before the security review, not during it:\n\n1. **In which countries is interview data stored at rest, and in which is it processed?** These are different answers.\n2. **List every sub-processor** that touches participant data — transcription, LLM inference, storage, email. Which are on your DPA's sub-processor list?\n3. **Which transfer mechanism applies**, and does the DPA include SCCs *in addition to* any adequacy or DPF reliance?\n4. **Is data used to train models?** For a research platform, the answer should be no for customer content. Get it in the contract, not the FAQ.\n5. **What is the deletion path and its SLA**, including backups?\n6. **Can you support pseudonymisation before data leaves our control?**\n\nQuestion 4 is the one that changed most in 2026. Model-training terms move faster than security pages; verify against the current DPA rather than a blog post.\n\n## How Koji reduces the surface area\n\nMost transfer risk in research is created by the *shape* of the data, not the route it travels. Koji is built so that less sensitive data exists in the first place.\n\n**Structured questions collect bounded values.** Koji supports six question types — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no. A `scale`, `single_choice`, or `yes_no` answer is a value, not a narrative that might contain a name, a diagnosis, or a customer's identity. Every question you convert reduces what crosses any border. See the [structured questions guide](/docs/structured-questions-guide).\n\n**Anonymisation before sharing.** Transcripts can be anonymised before they are shared or exported, which is exactly the supplementary measure a transfer impact assessment asks for. See [anonymizing customer interview data](/docs/anonymizing-customer-interview-data).\n\n**A short chain.** Recruitment link, AI-moderated interview, automatic transcription, automatic analysis, report — inside one platform. Compare that with the usual stack of a scheduler, a video tool, a separate transcription vendor, an LLM analysis add-on, and a repository, each with its own sub-processors and its own transfer analysis. Fewer hops means a shorter list to assess.\n\n**Deletion you control.** Interview data, transcripts, and analysis belong to your account, and studies and their associated data can be deleted at any time — the concrete evidence a deletion SLA needs.\n\n**Text-only mode as a mitigation.** Where voice recording raises biometric questions in a given jurisdiction, running the study as a text interview removes the issue entirely while keeping the conversational depth and AI follow-up probing. That option does not exist in a video-based research stack.\n\nFor teams with contractual residency requirements or a specific enterprise data-handling posture, contact the Koji team to discuss enterprise options rather than inferring the answer from a docs page.\n\n## Five common mistakes\n\n1. **Treating storage location as the whole answer.** Sovereignty follows the operator and applicable law too.\n2. **Mapping the platform but not the sub-processors.** The transcription and inference layers are where surprises live.\n3. **Relying on Article 49 consent for ongoing operations.** The derogations are for occasional transfers, not a running research programme.\n4. **Relying on the DPF alone.** Pair it with SCCs so a court ruling is a paperwork problem, not an outage.\n5. **Doing the analysis once.** Vendors change sub-processors and regions. Re-check at renewal.\n\n## Related Resources\n\n- [Enterprise Security for AI Research Platforms](/docs/enterprise-security-ai-research-platforms) — SOC 2, SSO, and the vendor review process\n- [GDPR-Compliant AI User Research](/docs/gdpr-compliant-ai-user-research) — lawful basis and participant rights\n- [DPIA for User Research](/docs/dpia-user-research) — the risk assessment that references your transfer analysis\n- [AI Interview Data Privacy and Security](/docs/ai-interview-data-privacy-security) — the buyer's evaluation checklist\n- [Anonymizing Customer Interview Data](/docs/anonymizing-customer-interview-data) — pseudonymisation as a supplementary measure\n- [Research Data Retention and Deletion](/docs/research-data-retention-deletion) — how long data should exist anywhere\n- [Structured Questions Guide](/docs/structured-questions-guide) — the six question types and data minimisation by design","category":"Research Operations","lastModified":"2026-07-27T03:17:35.126341+00:00","metaTitle":"Research Data Residency & International Transfers Guide (2026)","metaDescription":"Data residency vs sovereignty vs localisation for research teams: GDPR Chapter V mechanisms, SCCs, transfer impact assessments, the DPF's current status, and six questions to ask any vendor.","keywords":["research data residency","international data transfers gdpr","standard contractual clauses research","transfer impact assessment","eu us data privacy framework 2026","data sovereignty vs residency","where is interview data stored","gdpr chapter v transfers","cross border research data","vendor sub-processor review"],"aiSummary":"Data residency is where data is stored, data sovereignty is whose law governs it and who can compel access, and data localisation is a statutory requirement to keep data in country. Under GDPR, any transfer outside the EEA is restricted and needs a Chapter V mechanism: adequacy decision, the EU-US Data Privacy Framework for certified US recipients, Standard Contractual Clauses under Implementing Decision 2021/914, Binding Corporate Rules, or Article 49 derogations (occasional transfers only). Since Schrems II, SCCs require a transfer impact assessment plus supplementary measures; pseudonymisation before transfer is the highest-value measure for research. The DPF remains valid but the Latombe appeal is pending at the CJEU and PCLOB lost quorum in 2025, so pair DPF reliance with SCCs. Research is exposed because transcripts contain incidental identifiers and the processing chain spans recruitment, interviewing, transcription, LLM analysis, and storage. Ask vendors about storage and processing countries, sub-processors, transfer mechanism, model training, deletion SLA, and pseudonymisation support. Koji shortens the chain, supports anonymisation before sharing, allows deletion at any time, and its six structured question types reduce how much narrative data crosses any border.","aiPrerequisites":["Familiarity with GDPR basics","Knowledge of your current research tool stack"],"aiLearningOutcomes":["Distinguish data residency, sovereignty, and localisation","Select the correct GDPR Chapter V transfer mechanism","Write a transfer impact assessment with proportionate supplementary measures","Map sub-processors across the full research chain","Evaluate a research vendor with six targeted questions"],"aiDifficulty":"intermediate","aiEstimatedTime":"13 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}