Residency commitments arrive from three directions: regulation (public-sector and financial rules in various countries require in-country storage), contracts (enterprise customers write “EU-only” into the DPA or order form), and market pressure (European buyers who simply prefer it). For a SaaS company the translation is architectural — region-pinned storage and backups, region-aware processing, and subprocessors whose own regions don’t quietly break the promise.
Storing data in Frankfurt doesn’t mean only European law reaches it. Sovereignty asks whose legal jurisdiction and whose personnel can touch the data — a US-headquartered provider may face US legal process wherever the disks sit, and a support engineer in another country reaching into an EU region moves data across borders in the moment of access. Residency is a storage fact; sovereignty is a control-and-jurisdiction question. Sophisticated buyers ask both, and conflating them in a questionnaire answer reads as not understanding the difference.
A good residency answer names regions for primary data, backups, and logs, lists which subprocessors process where, and explains the access controls governing cross-border support work. Those facts come out of the same data-flow mapping a GDPR transfer analysis needs, so mature teams maintain one inventory that feeds both.