What UK hosting, Data Sovereignty and GDPR compliance mean for File Transfer.
Author: AMS Updated: 6 October 2026 Reading time: 7 mins
What UK hosting, Data Sovereignty and GDPR compliance mean for File Transfer.
Author: AMS Updated: 6 October 2026 Reading time: 7 mins
Three questions sit behind most UK File Transfer procurement and are usually asked together before buying:
Where the data is stored and processed
Which country's laws and legal jurisdiction apply to the data
Whether the supplier meets UK GDPR.
Choosing a supplier does not transfer the data handling responsibility. Under UK GDPR the organisation buying the solution remains the controller, and its obligations do not end once the supplier is appointed.
For NHS and social care data, NHS England guidance places a strong emphasis on UK hosting. Where data is to be hosted outside the UK, additional data protection, transfer risk assessment and approval requirements may apply.
Data residency is where data is held, including backups. Data concerns the legal jurisdiction that applies to data, including which authorities may have lawful powers to require access to it.
UK hosting is a common buyer requirement rather than a general UK GDPR requirement. Buyers should consider both where their data is hosted and whether any sub-processors or supporting services involve processing outside the UK.
UK GDPR does require is a written contract. It records the details of the processing and sets out eight terms, including appropriate security measures, appropriate written authorisation, controls over the use of sub-processors and deletion or return of all personal data at the end of the contract.
Automated Messaging Systems (AMS) is a UK private limited company. AMS Secure Cloud solutions are hosted in Microsoft Azure UK datacentres, and AMS’s data protection practices are aligned with UK GDPR and the Data Protection Act 2018.
Data residency is the country where data is stored and processed, including the copies made for backup and disaster recovery.
Data sovereignty concerns the legal jurisdiction that applies to data, including which governments, courts and regulators may have lawful powers to require access to it.
NHS England guidance places a strong emphasis on UK hosting for NHS and social care data. Where data is to be hosted or processed outside the UK, organisations need to consider the applicable international transfer requirements, assess the associated risks and obtain appropriate approvals where required. UK hosting should therefore be considered alongside wider security and assurance requirements.
NHS buyers may also look at a supplier's NHS Data Security and Protection Toolkit status, while public sector and regulated buyers commonly ask for ISO 27001 and Cyber Essentials certifications.
A File Transfer or File Sharing platform often holds highly sensitive files in transit and, when the data is being held, at rest. Those files can contain personal data or PID, so the platform's hosting location is part of the buyer's own data protection obligations. Two things are worth noting:

Hosting. The platform is provided by AMS and hosted on Microsoft Azure. All AMS Secure Cloud solutions are hosted in Microsoft Azure UK datacentres, and files are stored within UK based cloud infrastructure, supporting data sovereignty requirements.
Data isolation. Each customer's information is held in a dedicated storage account and database, separate from other customer's data.
Encryption. All data is encrypted in transit and at rest using 256 bit AES encryption.
Access control. Look for role based permissions within the solution. For example, AMS File Transfer has several administration levels within its role based permissions.
Data protection. AMS practices are aligned with UK GDPR and the Data Protection Act 2018. On contract termination, customer data is securely deleted from AMS systems within 60 days, in line with the AMS retention and disposal policy.
Certification. AMS is ISO 27001 and Cyber Essentials certified, and holds a published NHS DSPT status of Standards Met for 2025-26.

Certified information security management system.
Certified, listed on the IASME certificate search.
Compliant with the NHS Data Security and Protection Toolkit
AMS File Transfer part of the AMS Secure Cloud Platform is used across NHS and healthcare environments amongst other industries for the secure handling patient identifiable and / or highly sensitive data. It provides a full end to end audit trail, 256 bit AES encryption in transit and at rest, optional Digital Rights Management to limit downloading, printing or forwarding, no file size limits, and permissions based access with reporting. AMS Virtual Data Rooms are also hosted within UK Microsoft Azure data centres, with 256 bit AES encryption, access controls and full audit logging of document access and activity.
AMS File Transfer is best for UK organisations that need a UK hosted file transfer and sharing platform, from a UK supplier for the transfer and sharing sensitive corporate, patient or personal data.
Talk to our sales and support team.