# Running Vercel and Supabase in the EU: a checklist

Regions, contracts, access and evidence: what companies should settle before taking applications on Vercel and Supabase into production.

Vercel and Supabase can be operated so that data is processed in EU regions. What matters is the choice of region, contracts, access rules and documented operations. This checklist summarises what we review in our projects.

## Regions

- Create the Supabase project in an EU region, for example Frankfurt (eu-central-1). Migrating later is possible, but costly.
- Pin Vercel server functions to an EU region, for example Frankfurt (fra1).
- Check which additional services, such as email, monitoring or AI models, process data outside the EU.

## Contracts

- Sign the providers' data processing agreements and file them.
- Document all sub-processors.
- Register accounts in the company's name, not in the name of service providers or individuals.

## Access

- Enable Row Level Security on every table and grant permissions explicitly.
- Use service keys on the server side only and rotate them regularly.
- Single sign-on and multi-factor authentication for administrators.

## Evidence

A backup and restore test, a security review before go-live and a short operations manual. With these, questions from data protection officers and customer audits can be answered quickly.

> **Note:** This checklist is not legal advice. The assessment of each individual case belongs with your data protection officer.