Skip to main content

Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal

You're hosting my European board's data in Japan. Walk me through your Article 44 transfer basis — and don't tell me "the cloud is global.?

The question a Chief Privacy Officer / DPO asks.

The short answer

Japan holds an EU adequacy decision, so the Tokyo transfer is lawful under Article 45 without SCC gymnastics — and if you need data that never leaves the EU, our own code (residencyOffered) forbids us claiming that until the EU cell, already built and config-ready, is provisioned on committed demand.

The full executive answer

The transfer basis is stronger than most vendors' because of a specific legal fact: Japan holds a European Commission adequacy decision — one of the short list of countries the EU has formally determined provides essentially equivalent protection — so an EU-to-Japan transfer under Article 45 does not require Standard Contractual Clauses or transfer impact assessments the way a US transfer does. Our production cell runs on AWS in Tokyo (ap-northeast-1) via Supabase, with encryption in transit (TLS 1.2+) and at rest (AES-256). For the sub-processor chain, where processing touches entities outside adequacy protection — the AI providers, for instance — our DPA flows down Standard Contractual Clauses under Article 46 as the fallback mechanism, alongside the technical supplementary measures (PII redaction before any AI call, encryption, pseudonymisation) that Schrems II analysis expects.

Now the part I'll say before you probe for it: if your requirement is not "lawful transfer" but "data never leaves the EU," we cannot satisfy that today, and our own code refuses to let us pretend otherwise. The architecture is multi-region by design — EU and India cells are fully coded and configuration-ready — but they are not provisioned, and a function in our codebase called residencyOffered() gates every marketing and onboarding surface so the product is structurally incapable of offering a residency choice that isn't physically live. There's even a guard that throws an error if anyone tries to pin an organisation to a non-provisioned region. We built honesty about this into the software because a false residency claim is the kind of thing that ends vendor relationships and DPO careers alike.

The path: an EU cell is provisioned on committed demand — it's configuration and cost, not engineering, with a realistic stand-up measured in weeks — and an anchor European customer's contract is exactly the trigger. Until then, the honest offering is adequacy-based transfer to Japan with full Chapter V compliance, DPA transparency about every sub-processor's location, and your right to object to changes. For India: DPDP's transfer regime currently operates on a government blacklist basis, and Japan is not restricted — the same architecture serves, with the India cell ready when data-localisation rules or customer requirements demand it.

Grounded in: GDPR Art. 45 (Japan adequacy decision, 2019), Art. 46 (SCCs), Chapter V generally; Schrems II (C-311/18) supplementary measures; India DPDP Act 2023 s.16 (transfer restrictions).

Want this answered live, on your data?