Skip to main content

A Merchant Payments Provider Scales EU-Resident Merchant Data Exchange Across Hundreds of Accounts With Files.com

The exchange has run for nine years, while a site-level setting has kept every file in EU storage throughout.

A European merchant payments provider builds payment infrastructure for small merchants, including card readers, point-of-sale systems, and business banking services.

A business built that way runs on data about its merchants, and operating it means exchanging some of that data with outside parties. Under European privacy law, that kind of exchange came with a condition attached before any workflow question could be asked: where the files physically lived.

Over nine years in production, the provider's file-exchange footprint has grown to several hundred users. Files.com kept the growing workload on EU-resident storage without turning that growth into a new infrastructure project.

Where the Data Lives Was the Gating Question

In 2017, the provider's Information Security Officer set the requirement for any service that would carry information about the company's customers: file storage in the EU, for privacy reasons, and entirely. The question he pressed was not whether an EU region was available, but whether every byte could reside in a single EU region with nothing remaining in the United States. Residency was not a feature to weigh against other features. It was the condition of using a file-exchange service at all.

GDPR then turned the condition into a deadline. The provider's data storage had to be in Europe before enforcement began in 2018.

The exchange also had to support SFTP and administer hundreds of named user accounts as a service rather than as infrastructure the provider would have to build and operate inside the EU. The provider selected Files.com to be that exchange.

Residency as a Setting, Not an Infrastructure Project

Files.com became the EU-resident layer between the provider's own systems and the outside parties it exchanged merchant information with.

Storage residency was handled by Files.com's geographic region selection. The provider's file storage was placed in an EU region ahead of the GDPR deadline, and it has resided there since. Every file that lands on the exchange lands in EU storage. The residency guarantee is a property of the site itself, not a rule anyone applies transfer by transfer.

Counterparty access ran over SFTP, a standard protocol. Each user had a named account on the site, so hundreds of accounts could be administered in one place with their own credentials.

Nine Years in Production at Growing Scale

With the exchange running on EU-resident storage, the provider replaced a compliance blocker with a configured property of its platform. What followed is the strongest evidence for the design:

  • The exchange has run continuously in production for years, carrying processes the provider described as critical.
  • Its user population has grown to several hundred.
  • The same Files.com site absorbed that growth through additional named accounts, with each new user's files residing in the EU from the first byte.

An Exchange That Carries Its Compliance With It

The condition the security team set in 2017, that all of it live in the EU, travels with every file. An EU residency mandate on customer data exchange did not have to become an infrastructure project inside the EU. Files.com satisfied it at the file-transfer layer, where geographic region selection keeps storage in Europe as the exchange grows.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes