Sikgen AI
International4 min read

Data Residency Questions to Ask Any EdTech Vendor

The eight questions that decide whether an education platform clears your procurement — and why 'GDPR compliant' on a vendor's website means nothing on its own.

By Sikgen AI Team·

Every education platform's website says it takes security seriously. That sentence has never once been the deciding factor in a procurement, and it is not what your legal team will ask about.

These are the questions that actually decide whether a vendor clears review. They are worth asking early, because the expensive version of this conversation is the one that happens in week six of an evaluation.

1. Where is the data physically held?

Not "in the cloud". Which provider, which region. A vendor who cannot answer this immediately has either not thought about it or does not want to say, and both are informative.

Then ask whether that can change without telling you. A provider who can silently migrate your students' records to a different jurisdiction is a provider whose answer to question one has a shelf life.

2. Who else touches the data?

Almost no platform is a single system. There is usually a hosting provider, a database, an email service, an analytics tool, and — for anything with AI in it — a model provider. Each is a sub-processor, each is a place your students' data goes.

Ask for the list. Ask whether you are notified before it changes. A vendor with a maintained sub-processor list has thought about this properly; a vendor who has to go and find out has not.

3. What does the AI do with our content?

This is the newest question and the one most vendors answer badly.

Three things are worth separating. Is content used to train models that serve other customers? Is it sent to a third-party model provider, and under what terms? Is one customer's content ever retrievable in another customer's results?

"We don't train on your data" is a good answer to the first question and silent on the other two.

4. Show me the DPA

No vendor is "GDPR certified" — the certification does not exist. Compliance under UK or EU GDPR is a property of the arrangement between you as controller and the vendor as processor, and the instrument that establishes it is a written contract with specific required terms.

So ask for the Data Processing Agreement itself, and read it. A vendor who has one ready has done this before. A vendor who offers to "put something together" has not.

5. What happens in a breach, and how fast?

Most jurisdictions put a notification clock on you, not on your vendor — which means a vendor who tells you a week late has caused you to miss a statutory deadline.

Ask for the notification commitment in writing, in hours. Then ask what "aware" means, because a vendor whose clock starts at internal confirmation rather than detection has given you a number that does not mean what you think.

6. What do we get back if we leave?

Ask three things: what is exported, in what format, and for how long it remains available after termination.

A platform that exports a proprietary archive nobody else can read is a platform you cannot leave. This is worth settling before signature, because your leverage is never higher than it is now.

7. Who owns the content we upload?

It should be you, unambiguously, in the contract. Watch for licences broad enough to permit use beyond serving your own users — particularly for AI training, where the wording is often wider than the marketing implies.

8. Do you hold an independent audit report?

SOC 2 Type II or ISO/IEC 27001 mean a third party has examined the controls rather than the vendor asserting them. Whether you need one depends on your own risk position — plenty of good software has neither.

What matters is a straight answer. A vendor who says "we are not certified, here is what we do instead" is being useful. A vendor who gestures at "enterprise-grade security" and changes the subject is telling you something too.

The pattern

Every one of these is a question a vendor either has an answer to or does not. The ones who do will answer in a single email. The ones who do not will send a case study.

You are not looking for perfect answers — you are looking for a vendor who has thought about the questions before you asked them.


Sikgen AI's answers are on our security page, including an explicit section on what we do not claim, and our DPA is available before signature rather than after. If you are evaluating from outside India, the international overview covers language support, billing currency and support hours as directly.

Frequently asked questions

Is 'GDPR compliant' a meaningful claim from a vendor?

On its own, no. There is no GDPR certification, so no vendor can hold one. Compliance is a property of the arrangement between you as controller and them as processor, and the instrument that establishes it is a Data Processing Agreement with specific terms. Ask for the DPA, not the badge.

Does our data have to be stored in our own country?

It depends entirely on who you are and where. Most private training providers face no residency requirement at all, only conditions on how transfers are governed. Public bodies in some jurisdictions do face genuine in-country rules. The answer comes from your own legal position, not from the vendor's marketing.

What if a vendor cannot answer these questions?

That is itself the answer. A vendor who cannot say where data is held, who sub-processes it, or how quickly you would be told about a breach has not done the work — and you will be the one explaining that to your regulator, not them.

Ready to see this in action?

Book a free 30-minute demo of Sikgen AI and see these capabilities working on your own course material.

WhatsAppBook Free Demo