Compliance
UK and EU residency are not the same question.
Nearly every comparison of email providers treats “EU hosting” as the answer to a data residency question. Since the end of the Brexit transition period that has been two questions, and conflating them is how a vendor assessment gets answered confidently and wrongly. This page separates them.
Written by an email provider, about a question that affects which email provider you pick — so read it as a starting point and not as legal advice. Where the position is time-limited or contested this page says so and points at the source rather than summarising it into something that will quietly go stale.
Are the UK and the EU the same jurisdiction for data protection?
No. Since the end of the Brexit transition period the UK has had its own regime — UK GDPR, sitting alongside the Data Protection Act 2018 — and the EU has EU GDPR. The two texts are very close, because UK GDPR began as the EU regulation retained in domestic law, but they are separate laws with separate regulators. The ICO supervises the UK; EU supervisory authorities do not.
Is eu-west-2 in the EU?
No. eu-west-2 is AWS's identifier for its London region, which is in the United Kingdom. The eu- prefix is regional naming from before Brexit and is not a statement about jurisdiction — eu-west-1 is Ireland, which is in the EU, and eu-west-2 is London, which is not. This trips people up often enough that it is worth checking the region name against AWS's own list rather than reading the prefix.
Does an EU region satisfy a UK data residency requirement?
It depends entirely on what the requirement says, which is why the honest answer is not yes or no. If the requirement is about lawful transfer, the EU and the UK currently recognise each other's regimes, so a transfer between them is not the problem a non-adequate destination would be — but adequacy is time-limited and has been extended, so check its current status rather than relying on any page's summary. If the requirement is literally that data stays in the United Kingdom, as some public sector and financial services reviews are, then an EU region does not meet it and no amount of adequacy makes it meet it.
Where does YourMail send from?
Sending is in the UK — London (eu-west-2), on AWS SES: it is the region the code configures and it is visible in the headers of mail you receive, so it is checkable rather than asserted. Storage residency at rest is not claimed, because we do not have it in writing from our database provider. That limit is stated here rather than left for a reviewer to discover.
What should I actually put in a vendor assessment?
Separate the two questions the form usually merges: where processing happens, and what the processor has committed to in writing. The GDPR and UK data residency page is written for exactly that form — it covers Article 28 terms, the sub-processor list and its notice period, retention, data subject rights, and the parts of the position this product does not claim.
Does any of this matter for most projects?
Honestly, no. For most applications sending receipts and password resets, the region a provider sends from will never come up. It starts mattering when a customer's security review asks the question and expects a specific answer, or when you sell into UK public sector, healthcare or financial services, where a reviewer wants to see it written down rather than inferred from a list of region names.
Where to go next
Sending is in the UK — London (eu-west-2), on AWS SES. Storage residency at rest is not claimed.
Two pages go further in the two directions people usually need. The UK sending page answers “where does the mail actually go” for whoever is wiring the API up, and the GDPR and UK data residency page is written for the person filling in the assessment, including the Article 28 terms and the sub-processor list.
If you are weighing providers rather than reviewing one, the comparison pages set out where each incumbent stands on this and where each of them is the better choice regardless.
Send from London (eu-west-2) on the free tier
No card. Send from our shared test address before you have verified a domain, then check the region in the headers of the message that arrives — the point of a checkable claim is that you check it.