Data practice · 28 Sep 2026

Where should a timber business host its data, US or EU?

← Data practice

Where its personal data, its contracts and its users point, and for most timber businesses that is a smaller part of the data than it seems. Scale tickets, volumes, prices, inventory and stand records are business data, not personal data. The records that concern people, such as employees, individual landowners, self-employed contractors and drivers, are personal data, and they are what data protection law mainly governs. Decide hosting by data type, know which legal mechanism covers any personal data that crosses the Atlantic, check what customer and landowner contracts require, and keep a tested way to move the data.

What the usual answer says

The usual answer is a checklist: data protection compliance, residency requirements, latency, cost and the provider's certifications. The better guides add that EU law does not require EU hosting; one puts it plainly: "the GDPR does not mandate that data must physically reside within the European Union", though it "does heavily regulate any transfer of personal data" outside it. That is right. It treats all of a business's data as if it were personal.

Business data Scale tickets Volumes and prices Inventory Stand records Host where contracts and users point. Check contract terms on location, and keep a tested export. Personal data Employees and payroll Individual landowners Self-employed contractors Drivers Governed by data protection law. Know the mechanism that covers any transfer across the Atlantic. Mixed records, such as a settlement that names a landowner and lists loads, can be split.
Most timber data is business data. Data protection law mainly governs the smaller personal part, so hosting is decided by data type, with mixed records split. Not legal advice. Diagram: Quarri.

Hosting is also a separate question from due diligence on timber origin. Records kept to show where timber came from are a legal duty about the wood, and they can be hosted anywhere the business chooses.

Three frameworks in ten years

The IAPP, reporting on the latest ruling, recalls "the first two challenges invalidating the EU-U.S. Safe Harbor Framework in 2015 and the EU-U.S. Privacy Shield in 2020". On 3 September 2025 the EU's General Court upheld the third, the Data Privacy Framework. An appeal was brought on 31 October 2025 and is pending before the Court of Justice.

When a framework has fallen before, businesses mostly didn't move their data. They relied on standard contractual clauses, the model contract terms the Commission adopted in 2021 for transfers of personal data to third countries, with an assessment of the risks of each transfer. So the practical lesson is to know which mechanism covers each transfer and to have the fallback ready. A tested export is still good practice, for this and for changing vendors.

Local is not automatically safer

Cisco's 2026 Data and Privacy Benchmark Study, from over 5,200 professionals, found that 86% still associate local data storage with greater security, down from 90% in 2025, and that 82% of multinational organisations believe global-scale providers are better at managing cross-border data flows. Most people still hold the belief. Whether it is true depends on the provider's controls, which is what to check.

Where AI adds a question

AI adds a second location: where the model runs. A business may store its data in one region and send questions and records to a model hosted in another. Prompts often carry the sensitive part, such as a landowner's name, a contractor's pay or a customer's margin. Ask the AI provider where inference happens, whether it can be pinned to a region, and whether prompts and outputs are kept.

Which timber data is personal

Personal data includes employee and payroll records, driver logs, individual landowners' names, addresses and payments, and self-employed contractors' invoices. It doesn't include a stand's volume, a mill's tally or a product's price. Many records mix both: a settlement names a landowner and lists loads. Such records can be split, with the personal fields held more strictly than the rest.

How to decide

Map the data, separating personal from business data and noting whose personal data it is and where those people are. A mill with only domestic employees and suppliers has a simple answer. A business with operations, landowners or customers on both sides has to meet the stricter rules for the personal data that crosses. Read customer and landowner contracts for any terms on where data may be held. Ask the vendor where data, backups and processing sit, which subprocessors touch it, and which transfer mechanism covers personal data that crosses.

When it doesn't apply

A business whose data, people and customers are all in one jurisdiction can host there and move on. Some regulated data comes with fixed residency rules that decide the question. And this is not legal advice. Where personal data crosses borders, a data protection adviser should confirm the mechanism.

Quarri's security page sets out how customer data is isolated, encrypted and audited.

Sources

  1. IAPP, "European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework", September 2025: iapp.org
  2. Court of Justice, "Case C-703/25 P: Appeal brought on 31 October 2025 ... against the judgment of the General Court ... of 3 September 2025", Official Journal C/2025/6610 (title shortened; names the appellant): eur-lex.europa.eu
  3. Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries, 2021: eur-lex.europa.eu
  4. Digital Samba, "Does GDPR Require EU Data Hosting?": digitalsamba.com
  5. Cisco, "Cisco 2026 Data and Privacy Benchmark Study": cisco.com

Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.

See it on your own data.

Live in two weeks, on the systems you already run.