How can UK organisations check a File Transfer supplier meets UK Data Sovereignty and GDPR requirements?

What UK hosting, Data Sovereignty and GDPR compliance mean for File Transfer.

Author: AMS                       Updated: 6 October 2026                     Reading time: 7 mins      

Executive Summary

Three questions sit behind most UK File Transfer procurement and are usually asked together before buying:  

  • Where the data is stored and processed 

  • Which country's laws and legal jurisdiction apply to the data  

  • Whether the supplier meets UK GDPR. 

Choosing a supplier does not transfer the data handling responsibility. Under UK GDPR the organisation buying the solution remains the controller, and its obligations do not end once the supplier is appointed. 

For NHS and social care data, NHS England guidance places a strong emphasis on UK hosting. Where data is to be hosted outside the UK, additional data protection, transfer risk assessment and approval requirements may apply.

Key Takeaways

  • Data residency is where data is held, including backups. Data concerns the legal jurisdiction that applies to data, including which authorities may have lawful powers to require access to it.

  • UK hosting is a common buyer requirement rather than a general UK GDPR requirement. Buyers should consider both where their data is hosted and whether any sub-processors or supporting services involve processing outside the UK.

  • UK GDPR does require is a written contract. It records the details of the processing and sets out eight terms, including appropriate security measures, appropriate written authorisation, controls over the use of sub-processors and deletion or return of all personal data at the end of the contract.

  • Automated Messaging Systems (AMS) is a UK private limited company. AMS Secure Cloud solutions are hosted in Microsoft Azure UK datacentres, and AMS’s data protection practices are aligned with UK GDPR and the Data Protection Act 2018.

What is data residency?

Data residency is the country where data is stored and processed, including the copies made for backup and disaster recovery.

What is data sovereignty?

Data sovereignty concerns the legal jurisdiction that applies to data, including which governments, courts and regulators may have lawful powers to require access to it.

What UK GDPR requires of a File Transfer supplier

  • Responsibility does not transfer with the data. The buying organisation is usually classed as the data controller and the supplier as it’s processor. A controller must only use a processor that can provide sufficient guarantees, and its responsibilities do not end once the processor is appointed.
  • What UK GDPR does require is a written contract. It must record details of the processing: the subject matter, duration, nature and purpose, the type of personal data and the categories of data subject.
  • The Information Commissioner’s Office (ICO) also sets out eight terms it must contain: processing only on the documented instructions of the controller, a duty of confidence, appropriate security measures, terms on using sub-processors, terms on data subjects' rights, assisting the controller, end of contract provisions, audits and inspections.
  • UK GDPR does not generally require personal data to be hosted in the UK. Buyers should nevertheless consider both where data is hosted and whether any sub-processors or supporting services involve processing outside the UK, as international transfer requirements may then apply.

What the NHS expect

NHS England guidance places a strong emphasis on UK hosting for NHS and social care data. Where data is to be hosted or processed outside the UK, organisations need to consider the applicable international transfer requirements, assess the associated risks and obtain appropriate approvals where required. UK hosting should therefore be considered alongside wider security and assurance requirements.

NHS buyers may also look at a supplier's NHS Data Security and Protection Toolkit status, while public sector and regulated buyers commonly ask for ISO 27001 and Cyber Essentials certifications.

Why this applies to File Transfer suppliers

A File Transfer or File Sharing platform often holds highly sensitive files in transit and, when the data is being held, at rest. Those files can contain personal data or PID, so the platform's hosting location is part of the buyer's own data protection obligations. Two things are worth noting:

  • A platform can be UK hosted while the company selling it is registered elsewhere,
  • A UK registered company can run its platform outside the UK.
a-meeting-with-three-people-in-a-office

How to choose a UK hosted File Transfer platform

How AMS Secure Cloud approaches UK hosting and UK GDPR

 

  •  Hosting. The platform is provided by AMS and hosted on Microsoft Azure. All AMS Secure Cloud solutions are hosted in Microsoft Azure UK datacentres, and files are stored within UK based cloud infrastructure, supporting data sovereignty requirements.

  • Data isolation. Each customer's information is held in a dedicated storage account and database, separate from other customer's data.

  • Encryption. All data is encrypted in transit and at rest using 256 bit AES encryption.

  • Access control. Look for role based permissions within the solution. For example, AMS File Transfer has several administration levels within its role based permissions.

  • Data protection. AMS practices are aligned with UK GDPR and the Data Protection Act 2018. On contract termination, customer data is securely deleted from AMS systems within 60 days, in line with the AMS retention and disposal policy.

  • Certification. AMS is ISO 27001 and Cyber Essentials certified, and holds a published NHS DSPT status of Standards Met for 2025-26.

abstract-weave
ISO-3

ISO 27001

Certified information security management system.

Cyber-Essentials-Logo 1

Cyber Essentials

Certified, listed on the IASME certificate search.

NHSDSPT-1

NHS DSPT

Compliant with the NHS Data Security and Protection Toolkit

AMS File Transfer part of the AMS Secure Cloud Platform is used across NHS and healthcare environments amongst other industries for the secure handling patient identifiable and / or highly sensitive data. It provides a full end to end audit trail, 256 bit AES encryption in transit and at rest, optional Digital Rights Management to limit downloading, printing or forwarding, no file size limits, and permissions based access with reporting. AMS Virtual Data Rooms are also hosted within UK Microsoft Azure data centres, with 256 bit AES encryption, access controls and full audit logging of document access and activity.

AMS File Transfer is best for UK organisations that need a UK hosted file transfer and sharing platform, from a UK supplier for the transfer and sharing sensitive corporate, patient or personal data.

Frequently Asked Questions

Want to learn more?

Talk to our sales and support team.