Where its personal data, its contracts and its users point, and for most timber businesses that is a smaller part of the data than it seems. Scale tickets, volumes, prices, inventory and stand records are business data, not personal data. The records that concern people, such as employees, individual landowners, self-employed contractors and drivers, are personal data, and they are what data protection law mainly governs. Decide hosting by data type, know which legal mechanism covers any personal data that crosses the Atlantic, check what customer and landowner contracts require, and keep a tested way to move the data.
What the usual answer says
The usual answer is a checklist: data protection compliance, residency requirements, latency, cost and the provider's certifications. The better guides add that EU law does not require EU hosting; one puts it plainly: "the GDPR does not mandate that data must physically reside within the European Union", though it "does heavily regulate any transfer of personal data" outside it. That is right. It treats all of a business's data as if it were personal.
Hosting is also a separate question from due diligence on timber origin. Records kept to show where timber came from are a legal duty about the wood, and they can be hosted anywhere the business chooses.
Three frameworks in ten years
The IAPP, reporting on the latest ruling, recalls "the first two challenges invalidating the EU-U.S. Safe Harbor Framework in 2015 and the EU-U.S. Privacy Shield in 2020". On 3 September 2025 the EU's General Court upheld the third, the Data Privacy Framework. An appeal was brought on 31 October 2025 and is pending before the Court of Justice.
When a framework has fallen before, businesses mostly didn't move their data. They relied on standard contractual clauses, the model contract terms the Commission adopted in 2021 for transfers of personal data to third countries, with an assessment of the risks of each transfer. So the practical lesson is to know which mechanism covers each transfer and to have the fallback ready. A tested export is still good practice, for this and for changing vendors.
Local is not automatically safer
Cisco's 2026 Data and Privacy Benchmark Study, from over 5,200 professionals, found that 86% still associate local data storage with greater security, down from 90% in 2025, and that 82% of multinational organisations believe global-scale providers are better at managing cross-border data flows. Most people still hold the belief. Whether it is true depends on the provider's controls, which is what to check.
Where AI adds a question
AI adds a second location: where the model runs. A business may store its data in one region and send questions and records to a model hosted in another. Prompts often carry the sensitive part, such as a landowner's name, a contractor's pay or a customer's margin. Ask the AI provider where inference happens, whether it can be pinned to a region, and whether prompts and outputs are kept.
Which timber data is personal
Personal data includes employee and payroll records, driver logs, individual landowners' names, addresses and payments, and self-employed contractors' invoices. It doesn't include a stand's volume, a mill's tally or a product's price. Many records mix both: a settlement names a landowner and lists loads. Such records can be split, with the personal fields held more strictly than the rest.
How to decide
Map the data, separating personal from business data and noting whose personal data it is and where those people are. A mill with only domestic employees and suppliers has a simple answer. A business with operations, landowners or customers on both sides has to meet the stricter rules for the personal data that crosses. Read customer and landowner contracts for any terms on where data may be held. Ask the vendor where data, backups and processing sit, which subprocessors touch it, and which transfer mechanism covers personal data that crosses.
When it doesn't apply
A business whose data, people and customers are all in one jurisdiction can host there and move on. Some regulated data comes with fixed residency rules that decide the question. And this is not legal advice. Where personal data crosses borders, a data protection adviser should confirm the mechanism.
Quarri's security page sets out how customer data is isolated, encrypted and audited.
Sources
- IAPP, "European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework", September 2025: iapp.org
- Court of Justice, "Case C-703/25 P: Appeal brought on 31 October 2025 ... against the judgment of the General Court ... of 3 September 2025", Official Journal C/2025/6610 (title shortened; names the appellant): eur-lex.europa.eu
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries, 2021: eur-lex.europa.eu
- Digital Samba, "Does GDPR Require EU Data Hosting?": digitalsamba.com
- Cisco, "Cisco 2026 Data and Privacy Benchmark Study": cisco.com
Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.