Skip to the UK buyer guide
UK Commerce FieldbookContracts · locations · working hours

Buyer worksheet 06 · system geography

Data Residency and Subprocessor Checklist for UK Magento Work

Map every place where Magento or Adobe Commerce code, customer data, logs, backups and support access may be processed. Record the legal entity, technical system, access role and country separately. A UK office, UK account manager or UK hosting region does not answer the whole data-location question.

UK buyer guide. Not affiliated with Adobe Inc. Not legal or tax advice.

Check 01

Inventory data and systems before asking where they sit

Start with the planned architecture and delivery workflow. Different records may use different systems, regions, suppliers and retention periods.

Data and system inventory
Record or systemExamples to mapBuyer question
Storefront and commerceCatalogue, account, basket, quote, order and customer recordsWhich service and region stores each dataset?
IntegrationsERP, PIM, OMS, WMS, CRM, payments, tax and delivery messagesWhere are payloads queued, logged, retried or archived?
EngineeringSource code, commits, CI/CD, artefacts, secrets and environmentsWhich supplier and named users can reach each system?
OperationsLogs, traces, alerts, tickets, recordings and support exportsCan production or personal data appear in these tools?
ResilienceBackups, replicas, snapshots, recovery copies and archivesWhich regions and retention rules apply to every copy?
AnalyticsWeb analytics, session tools, data warehouse and reporting extractsWhich identifiers are sent, and to which entities and regions?

Check 02

Record controller, processor and access roles

Do not assign a legal role from a job title or hosting diagram. Give the actual purposes, instructions, entities and access paths to privacy counsel.

1

Purpose owner

Record who decides why each category of personal data is used and the business process it supports.

2

Instruction receiver

Record each entity that handles data under another party’s documented instructions.

3

Supplier’s own purpose

Ask whether any supplier uses data for its own purpose and how that changes the contract record.

4

Named access role

Map each delivery role to the minimum systems, permissions and data fields required.

5

Subprocessor chain

Identify separate entities that may process data for a contracted processor.

6

Approval owner

Name the buyer’s privacy, security and system owners who validate the completed map.

Use the ICO controller–processor contract guidance as an official starting point, then obtain advice for the planned arrangement.

Check 03

Record production hosting and database regions

A region shown in a cloud console is one evidence item. It does not describe every replica, backup, support path or connected platform.

Application

Record production, staging, development and preview service regions separately.

Database

Record primary, replica, failover, search, cache and queue regions.

File storage

Map media, exports, imports, invoices, documents and generated reports.

Recovery

Record backup, snapshot, archive and disaster-recovery locations and restore controls.

Connected service

Map every ERP, PIM, payment, tax, delivery and analytics platform separately.

Check 04

Map code, CI/CD, tickets, logs, analytics and backups

Delivery tools can contain customer information, credentials, production exports or screenshots even when the main store database stays in a chosen region.

Engineering path

  • Repository owner, service region and authorised identities
  • Build workers, artefact stores and deployment credentials
  • Development, test and staging datasets
  • Secrets manager, key custody and rotation owner
  • Temporary exports and local developer copies

Operations path

  • Ticket, chat, video and screen-recording platforms
  • Application logs, traces, monitoring and alert payloads
  • Analytics, experimentation and session-replay services
  • Backup copies, restore tests and recovery access
  • Incident exports, evidence packs and retained audit records

Check 05

Record remote support and administrator locations

Hosting geography and access geography are separate. Connect the named roster to each system permission and review the result when a person or country changes.

Remote-access register
FieldEvidenceControl question
Person and entityNamed user, employer or subcontractorIs access tied to a current approved roster entry?
Connection countryNormal and permitted access countriesWhat happens before access from a new country?
System and dataRole, environment, dataset and privilegeIs the permission the minimum needed for the task?
AuthenticationIdentity provider, MFA, device and privileged-access controlsWho approves, reviews and revokes access?
Time limitStart, expiry and review dateDoes access end with role, assignment or engagement?
EvidenceAccess log, review record and removal confirmationHow can the buyer inspect the control?

Check 06

List subprocessors and ask advisers about transfers

Record the factual chain first. Ask privacy counsel to decide whether a restricted transfer exists and which documentation or safeguard is required for the exact parties, countries and access.

Entity

Exact subprocessor name, company country and service supplied.

Purpose and data

Processing purpose, data categories, data subjects and systems touched.

Storage

Primary, replica, backup and recovery countries or regions.

Remote access

Countries from which support or administration may reach the service.

Contract record

Authorisation route, notification period, objection process and flow-down duties.

Adviser decision

Required assessment, transfer document, supplementary measure or recorded exception.

No office-to-residency shortcut

A London office does not prove that Magento data, source code, logs, backups or support access stay in the UK. A UK hosting region does not prove that every connected system or remote administrator is in the UK.

Buyer action: ask counsel to assess the completed map against current ICO international-transfer guidance. This fieldbook does not select a transfer mechanism.

Check 07

Define retention, deletion, restoration and exit

State the lifecycle for each record type and every copy. A general deletion promise may not explain backups, logs, legal holds or recovery media.

Retention rule

Record the purpose, period, trigger, owner and exception for each data class.

Deletion

Define deletion timing, method, system coverage and evidence available to the buyer.

Backups

Record immutable periods, expiry, restoration behaviour and treatment of deleted records.

Return

Specify export format, encryption, transfer route, completeness check and delivery date.

Exit

Set access removal, subprocessor closure, account transfer and final evidence duties.

Check 08

Request incident, audit and security evidence precisely

Ask for the actual artifact, scope, covered entity, period, exceptions and remediation record. Do not turn a provider statement into third-party assurance.

ISO 27001 statement

Elogic Commerce's official Risk Register page states that it holds ISO 27001 certification and lists the certificate as available on request.

ISO 9001 statement

Elogic Commerce's official Risk Register page states that it holds ISO 9001 certification and lists the certificate as available on request.

SOC 2 Type II statement

Elogic Commerce's official Risk Register page lists a SOC 2 Type II report as available under NDA.

Read the Elogic Commerce Risk Register source for all three statements.

Inspection boundary

The artifacts have not been independently inspected. A SOC 2 Type II report is a report, not a certification. Keep the three statements separate.

Do not infer: ISO 27001 does not by itself prove UK data residency or GDPR compliance. Ask for scope, entity, sites, dates and exceptions, then have the buyer’s specialists assess relevance.

Incident schedule

  • Notification event and contact route
  • Clock start and required updates
  • Containment, evidence and cooperation
  • Subprocessor escalation
  • Post-incident report and corrective actions

Evidence schedule

  • Artifact name, owner, scope and period
  • Access conditions and NDA
  • Exceptions and remediation status
  • Penetration-test or audit summary
  • Buyer review and revalidation date

Check 09

Complete the residency and subprocessor schedule

Approve one joined record that connects every system to its data, entities, storage, access, transfer decision, retention and exit controls.

Minimum completed schedule
Record groupMinimum fieldsApproval owner
SystemOwner, service, purpose, data, production and recovery regionsArchitecture / service owner
EntitySupplier or subprocessor, role, company country, contract linkProcurement / privacy
AccessNamed role, person or controlled group, country, permission, expirySecurity / system owner
Transfer questionCountries, access type, adviser decision and required documentsPrivacy counsel
LifecycleRetention, backup, restore, return, deletion and evidenceData owner / operations
IncidentNotification, response contacts, audit access and evidence routeSecurity / legal

Final gate

Do not claim UK-only residency while a connected service, backup, subprocessor or remote-access country remains unknown.

Boundary: this is a technical procurement worksheet, not legal advice. Counsel should determine the required transfer mechanism and contract wording.

Connect the records

Link data access to the named team and supplier

The residency schedule is reliable only when the counterparty and roster records use the same legal entities, people, countries and change controls.