Most video data residency questions get answered with a region dropdown. The dropdown covers the storage bucket.
It does not cover the relay the call went through, the server that recorded it, the replica written to another region for durability, or the transcription service that turned it into text. Video data residency — the requirement that media and the personal data around it stay within a particular jurisdiction — is a property of every component that touches the media, and the law behind it varies far more than most teams assume. This post sets out what the EU, US and India actually require, from the legal text, and then what "in-country" has to include. It describes how the rules read, not legal advice for a specific case.
What video data residency law actually requires
The three regimes approach location in three different ways.
Jurisdiction | The general rule | Where a location mandate exists |
|---|---|---|
EU | No general requirement to store in the EU. Transfers outside it need a legal basis under the GDPR's transfer rules. | Indirectly, where no transfer basis is available |
US | No general residency law. | Sector and contract requirements; nothing that applies to video generally |
India | DPDP Act allows transfers except to countries the government restricts. | Sector rules — e.g. RBI requires V-CIP recordings to be stored in India |
The details of video data residency are what decide an architecture. Start with the regime most often misread as a storage mandate.
EU: the GDPR regulates transfers, not storage
The GDPR does not say personal data must be stored in the EU. It says data leaving the EU needs a basis under Chapter V: an adequacy decision for the destination, or safeguards such as standard contractual clauses under Article 46.
For the US, the relevant adequacy decision is the EU-US Data Privacy Framework, adopted in July 2023. It is narrower than it sounds. The European Data Protection Board's information note is explicit that "transfers to entities in the US which are not included in the 'Data Privacy Framework List' cannot be based on the Adequacy Decision and will require appropriate data protection safeguards … in accordance with Article 46 GDPR."
In practice, that makes EU residency a design choice rather than a legal mandate for most organisations. Keeping video in the EU avoids the transfer question entirely; sending it to a US provider is lawful if that provider is on the DPF list or the right safeguards are in place. The obligation is to know which one applies — for every component that receives the data.
US: no general residency rule — and reach regardless of location
US federal law has no general rule about where video must be stored. Location requirements that do exist come from specific sectors, government contracts or customer agreements, not from a law that applies to video as such.
What US law does have is reach. Under 18 U.S.C. § 2713, covered providers must disclose data within their "possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States." That is the reason storing data in-country is not the same as controlling it — the argument made in what each deployment model lets you claim.
India: open by default, mandated by sector
India's general law is permissive on location — there is no blanket data localization rule for video. Section 16(1) of the Digital Personal Data Protection Act, 2023 lets the Central Government "restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." Transfers are allowed unless a destination is restricted — the reverse of a storage mandate.
The mandates come from sector regulators, and the Reserve Bank of India is the most specific:
- Video KYC. The RBI's Master Direction on KYC requires that "the entire data and recordings of V-CIP shall be stored in a system / systems located in India." For a bank's video verification calls, residency is not a preference; it is the rule.
- Payment data. A separate RBI direction from April 2018 requires payment system operators to ensure "the entire data relating to payment systems operated by them is stored in a system only in India," and where processing happens abroad, the RBI's FAQ says the data "should be deleted from the systems abroad and brought back to India not later than the one business day or 24 hours from payment processing, whichever is earlier." It applies to payment data rather than video, but it shows how strictly the RBI defines "in India" — including processing abroad.
The consent, notice and retention obligations that sit alongside these location rules are covered in what each recording regime demands.
Across all three regimes, one question decides video data residency compliance: which components actually hold or process the data.
Video data residency is a property of every component
A video call touches more systems than the storage bucket. Each one below holds media or personal data, and each has its own location.
Component | What it holds | What "in-country" requires |
|---|---|---|
Media servers (SFU) | Live audio and video, decrypted in memory | Media servers in-country for every call that must stay in-country |
TURN relays | Encrypted media plus connection metadata | Relays in-country — a relay abroad sends the traffic abroad |
Recorder | Decrypted media while recording | Recording workers in-country |
Storage | The recording at rest | Bucket or storage in-country |
Replicas and backups | Copies of the recording | No replication or backup to another region |
Transcription and AI | Audio or video sent for processing, plus transcripts | Processing in-country, or excluded from regulated recordings |
Playback and CDN | Cached copies for viewing | Delivery nodes in-country, or no CDN caching |
Logs and metadata | Participant names, IDs, IPs, timings | Log storage in-country where it counts as personal data |
Support access | Anything an administrator can view | Remote access from abroad is itself a question to answer |
Two rows are where residency most often breaks without anyone noticing.
The first is relays. When a user cannot connect directly, media goes through TURN, and if the nearest relay a provider offers is in another country, that call's media has left — even though the servers and storage are local. Relay placement and its cost are in The TURN Bill.
The second is replicas. Durability features copy data elsewhere by design. On S3, cross-region replication is opt-in — AWS describes it as copying "objects across Amazon S3 buckets in different AWS Regions" for buckets "configured for object replication" — which makes it easy to check, and also easy for someone to turn on later. A residency requirement should include a control that stops replication and backup outside the jurisdiction, not only a note that none is configured today.
The full inventory of components behind a self-hosted deployment is laid out in what you actually run to self-host real-time video.
How to show that data is resident
A video data residency claim is only as good as the evidence behind it, and the evidence is specific:
- Configuration. The regions of media servers, relays, recorders, storage and any processing service — and the replication and backup settings for each.
- Session records. For each call, which media server and which relay were actually used. WebRTC statistics record the selected path and relay candidate, as set out in where the media flows and what you can prove.
- Network records. Flow logs or firewall logs showing where media traffic went.
- The subprocessor list, with locations. Every third party that receives media or metadata, and where it processes it.
If any of those cannot be produced, the honest answer to "is our video stored in-country?" is "the recordings are" — which is a narrower claim than most questionnaires are asking for.
The Bottom Line
Video data residency law is less uniform than the phrase suggests. The EU regulates transfers rather than storage; the US has no general rule but reaches data regardless of location; India is permissive by default and strict by sector, with RBI requiring V-CIP recordings to be stored in India.
Whatever the rule, residency applies to every component that touches the media — relays, recorders, replicas, transcription and logs included — not just to the bucket.
What's Next
For why in-country storage is not the same as control, read what each deployment model lets you claim. For the consent, notice and retention rules that sit alongside location, see what each recording regime demands.
Frequently Asked Questions
What is video data residency?
It is the requirement that video, recordings and the personal data around them stay within a particular jurisdiction. In practice it applies to every component that handles the media — media servers, TURN relays, recorders, storage, backups, transcription and logs — not only to where recordings are stored.
Does the GDPR require video data to be stored in the EU?
No. The GDPR regulates transfers outside the EU rather than mandating EU storage. Transfers need a basis such as an adequacy decision or Article 46 safeguards. For the US, the Data Privacy Framework covers only organisations on its list; others need safeguards like standard contractual clauses.
Is there a US data residency law for video?
Not a general one. Location requirements come from specific sectors, government contracts and customer agreements. Separately, 18 U.S.C. § 2713 requires covered providers to disclose data in their possession, custody or control regardless of where it is stored.
Does India require video data to be stored in India?
Not generally. The DPDP Act allows transfers except to countries the government restricts. Sector rules can require it: the RBI requires the entire data and recordings of V-CIP video KYC sessions to be stored in systems located in India.
Can a TURN server break video data residency?
Yes. If a user's media is relayed through a TURN server in another country, that call's media leaves the jurisdiction even when the media servers and storage are local. Residency requires relays in-country, not just servers.
How do I prove my video data stays in-country?
Keep the region configuration of every component, per-session records of which media server and relay were used, network flow logs, and a subprocessor list with processing locations. Without those, a residency claim covers only the components you can show.
Can we keep media, relays and recordings in our own jurisdiction?
Yes, if they run on infrastructure you control. Samvyo keeps the media path, TURN and recording on your infrastructure, so each can be placed in the jurisdiction your rules require. Replication, backup and any third-party processing remain decisions to configure and document.