Data residency is one of those requirements that sounds settled the moment it is written into a specification - "data must remain in the UK" - and then quietly unravels under scrutiny. For a public sector organisation running Oracle Fusion, the platform holds some of the most sensitive information it processes: payroll and bank details, HR records, supplier and financial data. Getting residency right is not a box to tick. It is a duty owed to residents, staff and auditors alike.
The problem is that most conversations about residency stop at the wrong question. They ask where the data is stored and assume the answer resolves everything. It doesn't. The harder, more important question is who can reach the data, from where, and under whose control - and that is where support arrangements, not hosting, decide whether you are genuinely sovereign or merely hosted in the UK.
What is the difference between data residency and data sovereignty?
Data residency is about location: the physical or logical place your data is stored and processed. Data sovereignty is broader - it concerns whose laws, jurisdiction and operational control apply to that data, including who is permitted to access it and under what conditions.
The distinction matters because the two can diverge. Data can reside in a UK data centre while being accessed, administered or supported by personnel outside the UK, potentially bringing it within the reach of another jurisdiction's laws. For the public sector, sovereignty - not just residency - is usually the real obligation, even when the specification only spells out the residency half.
Where does Oracle Fusion data actually live?
Oracle Cloud operates UK-based regions, so Oracle Fusion applications and their data can be hosted within the United Kingdom. For most public sector buyers, insisting on UK hosting for the production environment, its data and its backups is a reasonable and achievable baseline, and it should be confirmed explicitly rather than assumed.
But hosting location is only the first layer. Because Oracle Fusion is a software-as-a-service platform supported by people, the residency question extends to every party that touches the data in the course of running the service - the support teams, administrators, developers and testers who access production and production-like environments. This is precisely the layer that a hosting statement leaves untouched.
The blind spot: it is not where the data sits, it is who can reach it
Here is the exposure most specifications miss. A supplier can honestly promise that all data is hosted in the UK, and still route day-to-day support through teams accessing that UK-hosted data from overseas. The data never "moves" in the storage sense, yet it is routinely viewed and handled from another jurisdiction. If that access is uncontrolled, the sovereignty commitment is hollow, whatever the hosting diagram shows.
This is the single most important thing for public sector buyers to interrogate. The controls that matter are the ones governing access: whether support is delivered by UK-based personnel; where offshore capacity is used, whether it operates through UK-controlled secure environments with no data leaving the UK boundary; how personnel are vetted; and how every access event is logged and auditable. Residency without access control is a promise about geography that says nothing about risk.
Consider a practical example. A payroll query requires a support engineer to look at live employee records to reproduce an issue. If that engineer connects from outside the UK to a screen rendered from a UK-hosted secure environment - with no ability to download, copy or export the record - the data has never left the UK boundary and access remains under UK control. If instead the engineer pulls an extract to a local machine overseas to investigate, the same task has quietly become a cross-border data transfer. The task looks identical from the outside; the risk profile is entirely different. This is why the access path, not the job title or the office location, is what a buyer must examine.
What UK public sector buyers must insist on
A robust data-residency and sovereignty position for an Oracle Fusion support service rests on a handful of non-negotiables:
UK hosting, confirmed in writing for production, non-production and backups, with the Oracle region named.
UK-based control of data access, so that the parties administering and supporting the platform operate under UK jurisdiction.
Controlled offshore access, if any, delivered through UK-hosted secure virtual environments where data cannot be downloaded or egressed beyond the UK boundary - never uncontrolled remote access to live data.
Personnel security, with appropriate vetting (such as BPSS or higher where the data demands it) for anyone accessing the environment.
Recognised certifications, including ISO 27001 and Cyber Essentials Plus, as evidence of a managed security posture rather than a claimed one.
Sub-processor transparency, so you know every party in the chain and can approve or reject changes to it.
A right to audit, with access logs and evidence available on demand for internal audit, external audit and information-rights requests.
If a support proposal cannot satisfy these, the residency clause in the specification is doing less work than it appears to.
The onshore, offshore or hybrid question
Buyers often frame this as a binary between fully onshore delivery, which feels safe but costs more, and offshore delivery, which feels cheaper but raises sovereignty concerns. The more useful framing is a governed hybrid.
A well-designed hybrid keeps all data within the UK boundary and all access to live data under UK-based control, while using offshore capacity only for work that never requires unmediated access to protected data, or that is performed through UK-hosted secure environments with no data egress. Done properly, this delivers the cost efficiency the public purse demands without compromising the sovereignty residents are entitled to. The test is not the geography of every person, but the control over every access path to the data.
The obligations that remain yours
It is worth remembering where accountability ultimately sits. Under UK GDPR and the Data Protection Act 2018, the council remains the data controller. A support partner is a processor acting on your instructions, but the statutory responsibility - and the reputational consequence of a breach - stays with the authority. That is why residency and access controls belong in the contract as enforceable obligations with evidence attached, not as reassuring statements in a bid response. The same logic applies to retention, freedom-of-information disclosure and audit: you must be able to produce evidence, so your supplier's arrangements must be built to produce it.
How to evaluate a supplier's data-residency posture?
A few direct questions separate a genuine sovereignty position from a hosting claim:
Is production, non-production and backup data all hosted in the UK, and in which Oracle region?
Who can access live data, from which country, and under whose jurisdiction?
If offshore capacity is used, does data ever leave the UK boundary - and can you prove it doesn't?
Are ISO 27001 and Cyber Essentials Plus current, and will you see the certificates?
Can the supplier produce access logs and a full sub-processor list on demand?
Clear, evidenced answers indicate a partner that treats sovereignty as an engineered outcome. Vague ones indicate a hosting promise dressed as a residency guarantee.
The bottom line
Data residency for Oracle Fusion is not the simple question it first appears. Storing data in the UK is the easy part; the harder and more consequential question is who can reach that data, from where, and under whose control. Public sector buyers who insist on UK-controlled access, evidenced certifications and an enforceable right to audit - not just a UK hosting statement - are the ones who turn a residency clause into genuine sovereignty.
At VE3, we design Oracle Fusion support to meet UK data residency requirements and to enable sovereign-by-design access controls for public sector organisations. To pressure-test your own position, request our public sector data-residency checklist - a practical tool for separating genuine sovereignty from a hosting promise.