Proofpoint extends DSPM to Europe with Frankfurt data residency

Proofpoint's expanded data security posture management platform launches from Frankfurt in August, covering six languages and EU-specific data classifiers.

Proofpoint extends DSPM to Europe with Frankfurt data residency

Proofpoint has announced expanded Data Security Posture Management (DSPM) and data access governance capabilities for European customers, hosted from its existing Frankfurt data centre. The enhancements are scheduled for general availability in August 2026 and are positioned by the company as a response to growing regulatory and data residency pressure accompanying enterprise AI adoption across the region.

The upgrade extends Proofpoint's AI-powered data discovery and classification to six European languages: English, French, German, Spanish, Portuguese and Italian. The company is also broadening its library of EU-specific data classifiers to include national personal identifiers, passport numbers, tax identification numbers, mobile phone numbers and postal addresses, providing coverage across all EU member states. Proofpoint's release cited its own AI and Human Risk Report, which found that 42% of surveyed organisations reported a suspicious or confirmed AI-related incident.

What the platform does

The updated platform connects data discovery and classification with access governance, data loss prevention, insider risk management and AI-specific data security controls. Proofpoint says shared classifiers and policy frameworks across the platform allow security teams to automate DLP policy creation from DSPM findings, rather than managing discovery and enforcement in separate tools. Coverage spans cloud, SaaS, endpoint, email and on-premises environments.

Kent Breaux, SVP for EMEA at Proofpoint, said the company wants European customers to avoid being forced to choose between innovation, compliance and data residency. "As AI adoption accelerates, organisations need visibility into their sensitive data and confidence that it is governed appropriately," he added.

The company also says the updated platform helps organisations map data risk to controls aligned with the EU AI Act and more than twenty-five additional compliance and regulatory frameworks, though it did not specify which frameworks are covered or how the mapping methodology works.

Market and regulatory context

DSPM has become a crowded category over the past two years, with established security vendors and a wave of specialist startups competing on breadth of data-store coverage, classifier accuracy and integration depth. Proofpoint competes in this space against vendors including Microsoft Purview, Varonis and Securiti, as well as cloud-native offerings from hyperscalers. The Frankfurt hosting commitment gives Proofpoint a direct argument against solutions that rely on transatlantic data transfers, which remain a commercially sensitive issue for European enterprise buyers following years of legal uncertainty around EU-US data flows.

The regulatory backdrop is tightening on multiple fronts. The EU AI Act's obligations for general-purpose AI systems are phasing in through 2025 and 2026, and the Act places specific requirements on organisations deploying AI in high-risk categories to maintain documentation and oversight of the data used to train and operate those systems. GDPR enforcement has also intensified, with data protection authorities in Germany, Ireland and France among those issuing significant fines for inadequate controls on sensitive personal data. For security and compliance teams, the combination creates demand for tools that can demonstrate continuous visibility rather than point-in-time audits.

Proofpoint's move to localise its DSPM offering in Europe follows a broader industry pattern: cloud security vendors that built their platforms primarily for US enterprise customers are now investing in regional infrastructure and classifier libraries to compete for European contracts, where procurement teams are increasingly including data residency and sovereignty requirements as mandatory criteria rather than nice-to-haves.