An open, cited, date-stamped dataset answering the questions a DPO, privacy or security team actually asks before onboarding a SaaS tool under the GDPR:
- Does it offer EU data residency? (data kept at rest in the EU)
- Which legal transfer mechanism does it rely on for EU→US flows — Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework, or EU-hosted-only?
- Who are its sub-processors, and where is the live list?
- Is a GDPR Data Processing Agreement (DPA) available, and on which plan tier?
Every verdict is sourced from the vendor's own DPA, sub-processor list, trust-center or data-residency documentation and carries the date it was last verified. The goal: one honest, machine-readable reference you can check before a transfer impact assessment, not after a regulator's letter.
At a glance — 10 SaaS vendors tracked (verified 2026-06-02): ✅ 4 offer EU data residency on standard plans · 🟡 5 only on an enterprise/add-on tier · ❌ 1 have no EU residency option (data leaves the EEA).
This repository is a periodic snapshot. The full, continuously-updated version — a detail page per vendor, the underlying policy quotes, sub-processor lists and verification history — lives at DPA Atlas → GDPR vendor finder. Each vendor name in the table below links to its live detail page. If a verdict here looks stale, the live page is the source of truth.
Of the 10 vendors tracked, 4 offer EU data residency on standard plans (Atlassian (Jira & Confluence), HubSpot, Intercom, Salesforce). A further 5 offer it only on an enterprise plan or as a paid add-on (Slack, Zendesk, Asana, monday.com, Notion), and 1 offer no EU residency option at all — their data is hosted outside the EEA (Calendly). Every verdict below links a dated primary source.
They are not the same control, and conflating them is the most common GDPR procurement mistake. A DPA is the contract that governs how a processor handles your data; almost every paid SaaS vendor offers one. EU data residency is where the data physically sits at rest. A vendor can hand you a perfectly valid DPA while still storing your data in the US under SCCs. Watch the plan tier too: Asana does not include a DPA on the free plan — the minimum compliant tier for processing others' personal data is a paid plan. This dataset tracks residency, transfer mechanism, sub-processors and DPA availability as separate columns for exactly that reason.
Standard Contractual Clauses are the legal safeguard most US-headquartered vendors use to transfer EU personal data to the US. They are valid, but they are not a free pass — after Schrems II you are expected to run a transfer impact assessment and, where needed, apply supplementary measures. Even vendors that offer EU residency usually still rely on SCCs, because support, security monitoring and some sub-processors move data across borders. That nuance is captured per-vendor in the table.
No SaaS tool is "GDPR compliant" as a standalone property — there is no such certification, and GDPR compliance is a shared responsibility. You are the data controller; the vendor is your processor. A tool can only be used in a GDPR-compliant way once you have a current DPA, you've checked where the data is stored and transferred, and you've assessed the sub-processors against your own risk posture. So "Is [vendor] GDPR compliant?" really means "what residency, transfer mechanism and DPA does it offer?" — which is exactly what this dataset tracks.
Does Notion offer EU data residency? Only on higher tiers — Notion (Notion Labs, Inc.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU data-at-rest residency (Frankfurt, AWS) is available free of charge to Enterprise-plan workspaces, whose owners can choose US or EU storage. Free, Plus and Business workspaces are hosted in the US with no EU residency option — this is the plan-tier moat. (Verified 2026-06-02.)
Is Notion GDPR compliant? Notion (Notion Labs, Inc.) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. Notion launched EU data residency (Frankfurt, AWS) in 2025 free of charge — but ONLY on the Enterprise plan. Plus/Business workspaces are hosted in the US and rely on Standard Contractual Clauses. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ Notion on DPA Atlas · primary source
Does Slack offer EU data residency? Only on higher tiers — Slack (Slack Technologies (Salesforce)) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. Slack EU Data Residency pins messages and files to an EU region, but it is available only on Business+ and Enterprise Grid plans (and historically as a paid add-on). Free and Pro workspaces have no EU residency option. (Verified 2026-06-02.)
Is Slack GDPR compliant? Slack (Slack Technologies (Salesforce)) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. Slack offers EU data residency, but only as an add-on on Business+ and Enterprise Grid — not on Free or Pro. It is EU-US DPF certified (via Salesforce) and uses SCCs for transfers. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ Slack on DPA Atlas · primary source
Does Calendly offer EU data residency? No — Calendly (Calendly LLC) does not offer EU data residency; data is hosted outside the EEA. Calendly hosts customer data in the United States and does not offer an EU/EEA data residency region on any plan. EU personal data processed through Calendly therefore leaves the EEA. (Verified 2026-06-02.)
Is Calendly GDPR compliant? Calendly (Calendly LLC) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. Calendly has NO EU data residency option — customer data is hosted in the US. It self-certifies to the EU-US Data Privacy Framework and relies on Standard Contractual Clauses for EU personal-data transfers. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ Calendly on DPA Atlas · primary source
Does HubSpot offer EU data residency? Yes — HubSpot (HubSpot, Inc.) offers EU data residency. New customers can have their account hosted in HubSpot's EU (Frankfurt, AWS) data region. The hosting region is set when the account is created and is not changed afterward, so EU residency is a signup-time decision rather than a per-feature toggle. (Verified 2026-06-02.)
Is HubSpot GDPR compliant? HubSpot (HubSpot, Inc.) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. HubSpot offers EU (Frankfurt) data hosting selectable at account creation across paid tiers, is certified to the EU-US Data Privacy Framework, and uses Standard Contractual Clauses for transfers. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ HubSpot on DPA Atlas · primary source
Does Salesforce offer EU data residency? Yes — Salesforce (Salesforce, Inc.) offers EU data residency. Customers can provision orgs in EU Hyperforce regions (e.g. Germany, France) so core CRM data stays at rest in the EU. Region is chosen at provisioning; migrating an existing org to Hyperforce is a managed process, not a toggle. (Verified 2026-06-02.)
Is Salesforce GDPR compliant? Salesforce (Salesforce, Inc.) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. Salesforce offers EU data residency through Hyperforce regions (incl. Germany and France), is certified to the EU-US Data Privacy Framework, and falls back to Standard Contractual Clauses for transfers. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ Salesforce on DPA Atlas · primary source
Does Asana offer EU data residency? Only on higher tiers — Asana (Asana, Inc.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU (Frankfurt) data residency is purchasable as an add-on for Enterprise organisations/divisions and is included in Enterprise+; customers must contact Sales to opt in and migrate. Lower tiers are hosted in the US. Some data (e.g. authentication, certain user data) may sit outside the selected region even when residency is enabled. (Verified 2026-06-02.)
Is Asana GDPR compliant? Asana (Asana, Inc.) can be used in a GDPR-compliant way, but GDPR compliance is not a property of the vendor alone — you are the data controller and it depends on your configuration. Asana's EU data center (Frankfurt) is an Enterprise add-on (included in Enterprise+), reached only by contacting sales — and its Free plan carries no DPA at all. It relies on SCCs for transfers. Confirm the current DPA, residency and sub-processor terms with the vendor and run a transfer impact assessment before processing EU personal data. (Verified 2026-06-02.) This is cited public information, not legal advice.
→ Asana on DPA Atlas · primary source
Every tracked vendor — "Does <vendor> offer EU data residency?" (click to expand all 10)
Does Atlassian (Jira & Confluence) offer EU data residency? Yes — Atlassian (Jira & Confluence) (Atlassian Pty Ltd) offers EU data residency. Data residency is available on Standard, Premium and Enterprise Cloud subscriptions, with pinning to EU (Frankfurt/Dublin) or Germany among the region options. It is NOT enabled by default — an admin must configure it in Cloud admin settings, and only in-scope product data (Jira, Jira Service Management, Confluence) is pinned. (Verified 2026-06-02.) (detail · source)
Does HubSpot offer EU data residency? Yes — HubSpot (HubSpot, Inc.) offers EU data residency. New customers can have their account hosted in HubSpot's EU (Frankfurt, AWS) data region. The hosting region is set when the account is created and is not changed afterward, so EU residency is a signup-time decision rather than a per-feature toggle. (Verified 2026-06-02.) (detail · source)
Does Intercom offer EU data residency? Yes — Intercom (Intercom, Inc.) offers EU data residency. EU data hosting (Dublin, AWS) is selectable when the workspace is first created. Critically, the hosting region is permanent — an existing US-hosted workspace cannot be migrated to the EU region, so EU residency must be chosen up front. (Verified 2026-06-02.) (detail · source)
Does Salesforce offer EU data residency? Yes — Salesforce (Salesforce, Inc.) offers EU data residency. Customers can provision orgs in EU Hyperforce regions (e.g. Germany, France) so core CRM data stays at rest in the EU. Region is chosen at provisioning; migrating an existing org to Hyperforce is a managed process, not a toggle. (Verified 2026-06-02.) (detail · source)
Does Slack offer EU data residency? Only on higher tiers — Slack (Slack Technologies (Salesforce)) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. Slack EU Data Residency pins messages and files to an EU region, but it is available only on Business+ and Enterprise Grid plans (and historically as a paid add-on). Free and Pro workspaces have no EU residency option. (Verified 2026-06-02.) (detail · source)
Does Zendesk offer EU data residency? Only on higher tiers — Zendesk (Zendesk, Inc.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU data hosting is delivered through the Data Center Location option, part of the Advanced Data Privacy and Protection (ADPP) paid add-on. Standard accounts are not guaranteed EU storage without it, so EU residency is an add-on purchase rather than a base-plan feature. (Verified 2026-06-02.) (detail · source)
Does Asana offer EU data residency? Only on higher tiers — Asana (Asana, Inc.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU (Frankfurt) data residency is purchasable as an add-on for Enterprise organisations/divisions and is included in Enterprise+; customers must contact Sales to opt in and migrate. Lower tiers are hosted in the US. Some data (e.g. authentication, certain user data) may sit outside the selected region even when residency is enabled. (Verified 2026-06-02.) (detail · source)
Does monday.com offer EU data residency? Only on higher tiers — monday.com (monday.com Ltd.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU data residency / regional hosting is an Enterprise-plan capability. Free, Basic, Standard and Pro accounts do not get a guaranteed EU storage region, so EU residency is enterprise-gated. (Verified 2026-06-02.) (detail · source)
Does Notion offer EU data residency? Only on higher tiers — Notion (Notion Labs, Inc.) offers EU data residency, but it is gated behind an enterprise plan or a paid add-on. EU data-at-rest residency (Frankfurt, AWS) is available free of charge to Enterprise-plan workspaces, whose owners can choose US or EU storage. Free, Plus and Business workspaces are hosted in the US with no EU residency option — this is the plan-tier moat. (Verified 2026-06-02.) (detail · source)
Does Calendly offer EU data residency? No — Calendly (Calendly LLC) does not offer EU data residency; data is hosted outside the EEA. Calendly hosts customer data in the United States and does not offer an EU/EEA data residency region on any plan. EU personal data processed through Calendly therefore leaves the EEA. (Verified 2026-06-02.) (detail · source)
| Vendor | Company | EU data residency | Transfer mechanism | DPA | Sub-processors | Last verified | Source |
|---|---|---|---|---|---|---|---|
| Atlassian (Jira & Confluence) | Atlassian Pty Ltd | ✅ EU data residency available | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| HubSpot | HubSpot, Inc. | ✅ EU data residency available | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Intercom | Intercom, Inc. | ✅ EU data residency available | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Salesforce | Salesforce, Inc. | ✅ EU data residency available | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Slack | Slack Technologies (Salesforce) | 🟡 EU residency on higher tiers | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Zendesk | Zendesk, Inc. | 🟡 EU residency on higher tiers | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Asana | Asana, Inc. | 🟡 EU residency on higher tiers | Relies on SCCs | DPA on paid plans only | list | 2026-06-02 | primary source |
| monday.com | monday.com Ltd. | 🟡 EU residency on higher tiers | Relies on SCCs | DPA available | list | 2026-06-02 | primary source |
| Notion | Notion Labs, Inc. | 🟡 EU residency on higher tiers | Relies on SCCs | DPA available | list | 2026-06-02 | primary source |
| Calendly | Calendly LLC | ❌ No EU data residency | EU-US DPF + SCCs | DPA available | list | 2026-06-02 | primary source |
| Symbol | EU data residency |
|---|---|
| ✅ EU data residency available | EU/EEA data-at-rest residency offered on standard/most paid plans. |
| 🟡 EU residency on higher tiers | Residency exists, but only on an enterprise plan or as a paid add-on. |
| ❌ No EU data residency | No EU residency option; customer data is hosted outside the EEA. |
| ❓ Residency not documented | No public documentation of an EU residency option. |
Transfer mechanism: EU-hosted, no transfer (data stays in the EEA) · EU-US DPF + SCCs (Data Privacy Framework certified, SCCs as fallback) · Relies on SCCs (Standard Contractual Clauses are the primary safeguard).
DPA: DPA available (self-serve / pre-signed) · DPA on paid plans only (Free tier excluded) · DPA on request · No DPA offered.
- Every verdict is derived from the vendor's own DPA, sub-processor list, data-residency, or trust-center documentation (linked in the Source column) — not from third-party summaries where a primary source exists.
- Each row is date-stamped (
Last verified). A verdict is only as current as that date — vendors change residency regions and sub-processors, so re-check the source for anything high-stakes. - The dataset leads with the variance-rich axes — EU residency, transfer mechanism, sub-processor exposure — because that is where vendors genuinely differ. DPA availability is a supporting column, not the headline: nearly every paid vendor offers a DPA, so "do they sign a DPA?" rarely discriminates. Where the DPA carries real plan-tier nuance (e.g. "no DPA on the Free plan"), that nuance is recorded.
- An unverified / unknown entry never outranks a sourced verdict; we would rather show
❓than guess (a guardrail for a compliance reference). - EU residency reduces but rarely eliminates transfers — support, security monitoring and sub-processors often still move data — so most EU-hosting vendors still rely on SCCs. That is reflected per row.
- This is a documentation reference, not legal advice. You are the controller: confirm coverage in your own executed DPA and run a transfer impact assessment before processing EU personal data.
gdpr-dpa-verdicts.json— full dataset (JSON) with residency, transfer mechanism, sub-processor URL, DPA availability, primary-source URL, atlas detail URL, and date.gdpr-dpa-verdicts.csv— spreadsheet mirror.
Columns: name, vendor, category, eu_residency, residency_verdict, scc_reliance, dpa_availability, subprocessors_url, dpa_url, last_verified, source_url, atlas_url.
Maintained by the team behind DPA Atlas (dpa-atlas.foundagent.net) — a free, independent GDPR vendor tracker for DPOs, privacy and security teams. This repo is the open-data snapshot; the live finder has the per-vendor detail pages and is updated more frequently.
Data in this repository is licensed under CC BY 4.0 — reuse it with attribution to DPA Atlas (dpa-atlas.foundagent.net). See LICENSE. Any code in this repo is MIT-licensed.