Is It Safe to Store Print Data in EU Servers? What Japanese IT Teams Need to Know

By Henning Volkmer on August 11, 2026

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Is It Safe to Store Print Data in EU Servers? What Japanese IT Teams Need to Know</span>

"I'm not comfortable with our data sitting on servers in Europe." If someone on your IT team has said that about cloud print management, the question underneath deserves a real answer rather than reassurance.

Print jobs in ezeep do travel to cloud infrastructure in the EU. They are encrypted in transit and at rest, they are decrypted only for as long as rendering takes, and the legal framework between Japan and the EU was built for exactly this kind of arrangement. This post covers what happens to a document, where it sits, how long it stays there, and which entity you would be contracting with.

This is written for IT and security teams in Japan evaluating cloud print management, and for whoever on your side reads the data processing agreement before anyone signs.

What happens to a print job in ezeep's cloud?

ezeep renders print jobs in the cloud. A job leaves the user's device encrypted, travels to ezeep's infrastructure on Microsoft Azure, is decrypted only for the time rendering takes, then is re-encrypted and sent to the printer through the ezeep Hub or Connector on the local network.

print-job-data-flow

How a rendered job moves through the cloud

Cloud rendering is the reason no print driver has to be installed on any endpoint, and it is also the reason document data passes through the cloud. Some jobs skip the rendering step and pass straight through, depending on the combination of printer, driver, and document. That behavior is determined by the job itself rather than by a customer setting.

A rendered job exists on ezeep infrastructure only for the time it takes to render, re-encrypt, and send. Depending on the job, that happens in memory or on disk.

Secure pull printing works differently

Secure pull printing works differently, because the whole point is that the document waits for the person. A job held for release sits in encrypted storage for up to 72 hours. If nobody releases it in that window, it goes.

What ezeep stores beyond the print job itself

Alongside the job itself, ezeep stores:

  • Configuration and policy data
  • Job metadata: who submitted a job, to which printer, when, and how many pages
  • Authentication records

Reporting is where you have direct control: your administrators configure which sensitive data is retained.

Where is print data hosted, and which ezeep entity do you contract with?

ezeep runs on Microsoft Azure in the North Europe region, located in Ireland. Japanese customers contract with ezeep Inc., a company based in Denver, Colorado, under a data processing agreement governed by German law. ezeep Inc. is certified under the EU-U.S. Data Privacy Framework, along with the Swiss and UK extensions.

The published data processing agreement splits the contracting entity by region. ThinPrint GmbH in Berlin is the processor for the European Economic Area, the UK, and Switzerland. ezeep Inc. is the processor for all other regions, which includes Japan.

Worth knowing before your review starts, because the entity on the signature page and the location of the servers are two different questions.

Subprocessors named in the agreement

The agreement names every subprocessor:

  • Microsoft hosts the service on Azure
  • Freshworks provides the helpdesk, CRM, and chat platforms
  • Cortado Holding AG, the Berlin parent of both ThinPrint and ezeep, handles group IT, security, and business functions

Transfers to the US subprocessors run on the 2021 Standard Contractual Clauses plus Data Privacy Framework certification.

Azure Application Gateway and TLS termination

One more component your security reviewer will want named. Azure Application Gateway sits in front of the service as a web application firewall. It terminates TLS to inspect traffic before forwarding it to ezeep's servers, which is how the layer works, and it operates inside the same Azure environment as the rest of the service.

What does Japan's APPI require for this data transfer?

Japan's Act on the Protection of Personal Information (APPI) restricts transfers of personal data to recipients outside Japan. Two routes make a transfer lawful:

  • A jurisdiction the Personal Information Protection Commission has designated as equivalent
  • A recipient that maintains a system meeting APPI-equivalent standards, established by contract

ezeep uses the second route.

pritning-in-japan

The service is hosted in the EEA, which the Commission has designated. The contracting processor for Japan is ezeep Inc. in Colorado, which is not in a designated jurisdiction, so the transfer runs on the contractual route rather than on designation. This is a standard mechanism under APPI, not an exception carved out for cloud vendors.

The data processing agreement is the instrument that does the work. It sets out the scope and purpose of processing, the technical and organizational measures, breach notification duties, audit and inspection rights, deletion and return obligations, and it binds every subprocessor to the same terms. Your counsel reviews that document against the Commission's standards, and it is published rather than held back for late-stage negotiation.

The contractual route also leaves your organization with an ongoing role. You confirm periodically that the measures remain in place, and you are able to tell a data subject about the transfer if one asks. ezeep provides the documentation for both.

Separately, the EU and Japan adopted mutual adequacy decisions in January 2019, the first reciprocal arrangement of its kind, and the European Commission reconfirmed the decision in April 2023 and moved to a four-year review cycle. That matters here because the infrastructure the data actually sits on is governed by the GDPR, and the measures in the agreement are built on those obligations.

What GDPR obligations does ezeep meet as a processor?

Article 32 of the GDPR requires appropriate technical and organizational measures, with encryption named as one example rather than a universal mandate. Across the ezeep environment, connections are encrypted with TLS 1.2 as a minimum, and print data is encrypted at rest.

On breach notification, the roles matter. The 72-hour clock for reporting to a supervisory authority belongs to the controller, which is you. As processor, ezeep is obligated to notify you without undue delay once it becomes aware of a breach, so you can meet your own deadline.

What the data processing agreement gives you

  • Audit and inspection rights, subject to reasonable notice and confidentiality
  • The same obligations imposed on every subprocessor
  • Registration in the Cloud Security Alliance STAR registry, filed under ThinPrint GmbH
  • Annual security and data protection audits
  • A named external Data Protection Officer for data protection questions

None of this happens by default on self-managed print infrastructure. It has to be implemented, documented, and kept current by the team that owns the server. The practical difference with a processor is that the obligations are contractual and you can ask for evidence.

ezeep is built on ThinPrint technology, which has run in enterprise print environments, including large Japanese organizations with on-premises deployments, for more than 25 years.

What this blog post doesn't cover

Sector regulation is the main one. If your organization operates under additional requirements in financial services, healthcare, or critical infrastructure, those sit on top of APPI and have to be assessed against the service directly. The adequacy framework does not clear them.

The contractual route puts a continuing obligation on your side, not just at signature. You confirm the measures are still being implemented, and you answer a data subject who asks about the transfer. ezeep supplies the documentation, and the checking is yours to do.

Adequacy decisions can be revised in principle. Nothing in the April 2023 review suggests the EU-Japan arrangement is under pressure, but an organization planning over a long horizon should treat it as a monitored condition rather than a permanent one.

And if your internal classification policy treats certain document types as restricted regardless of jurisdiction, that policy governs. Ask for the documentation and run the review.

What this means for your compliance review

Data geography affects legal jurisdiction, which makes the original concern a reasonable one. The specifics here are that documents do reach EU infrastructure, they are encrypted throughout and held only as long as the job requires, and the legal relationship between Japan and the EU was built to make that workable.

Bring your compliance team the agreement and the technical detail above, and let them check it against your own regulatory position.

chrome-extension-print
Looking to Move to the Cloud?
Find out how.
Talk to Sales

 

Frequently Asked Questions

Is it legal for a Japanese company to use ezeep?

Yes. APPI permits cross-border transfers to a recipient that maintains a system meeting APPI-equivalent standards, established by contract, which is what the ezeep data processing agreement provides. Your organization keeps an ongoing duty to confirm the measures remain in place. Sector regulation in finance, healthcare, or critical infrastructure can add requirements on top.

Does ezeep process our print documents?

Yes. Print jobs travel to ezeep's cloud infrastructure, where most are rendered before being re-encrypted and sent to the printer. Some jobs pass through without rendering, depending on the printer, driver, and document. Cloud rendering is what removes the need for print drivers on endpoints.

How long does ezeep keep a print job?

A rendered job exists only for the time it takes to render, re-encrypt, and send, which happens in memory or on disk depending on the job. Jobs held for secure pull printing sit in encrypted storage for up to 72 hours if nobody releases them, then are removed.

Which ezeep entity would we be contracting with?

Japanese customers contract with ezeep Inc., based in Denver, Colorado, which is the processor for all regions outside the European Economic Area, the UK, and Switzerland. The data processing agreement is governed by German law, and ezeep Inc. is certified under the EU-U.S. Data Privacy Framework.

Where is the ezeep service hosted?

ezeep runs on Microsoft Azure in the North Europe region, located in Ireland. Azure Application Gateway operates in front of the service as a web application firewall within the same environment. The data processing agreement lists Microsoft, Freshworks, and Cortado Holding AG as subprocessors.

Can we get a data processing agreement?

Yes. The agreement is published and available for your legal team to review before any conversation about contracts. It sets out the processing scope, subprocessors, technical and organizational measures under Article 32, audit rights, and the named Data Protection Officer.

What does ezeep encrypt, and when is data decrypted?

Print data is encrypted in transit and at rest, with TLS 1.2 as the minimum across the environment. A job is decrypted only for as long as rendering takes, then re-encrypted before it is sent to the printer. Azure Application Gateway terminates TLS to inspect traffic inside the Azure environment.

What security certifications and audits does ezeep have?

The ezeep print service is registered in the Cloud Security Alliance STAR registry under ThinPrint GmbH. ezeep Inc. is certified under the EU-U.S. Data Privacy Framework, plus the Swiss and UK extensions. Security and data protection audits run annually, and a named external Data Protection Officer handles data protection matters.

Back to top
Topics: Cloud Printing