
Cloud platforms are now the primary building block for how organisations build and run digital services. As data crosses borders, questions about where it sits, who can reach it and which laws govern it have moved from a compliance detail to an architectural decision.
For organisations spanning Europe and South Africa, data residency and sovereignty already shape cloud architecture, risk management and regulatory strategy. Much of the rest of the continent is heading for the same reckoning as cloud adoption deepens.
Distributed systems make the problem harder. Gartner predicted that 75% of enterprise-generated data would be created and processed outside traditional centralised data centres by 2025, up from around 10% in 2018, driven by cloud, edge computing and AI workloads. As data decentralises, residency and sovereignty get harder to manage, and regulators are paying closer attention – GDPR and the Schrems II ruling in Europe, Popia and a widening set of frameworks across Africa.
For CIOs and CTOs, sovereignty has stopped being a compliance afterthought. It is a design decision.
Residency, sovereignty and localisation
The terms get used interchangeably. They describe different things:
- Data residency is where data is physically stored. Organisations may pick locations for operational reasons, but legal requirements often dictate where certain categories of data must sit. Cloud providers increasingly let customers choose where storage and processing happen.
- Data sovereignty is the legal authority governing that data. A global company’s data remains subject to the laws of the country in which it is stored, which matters when third parties handle it or when governments have the legal power to demand access.
- Data localisation is the strictest form. Governments require certain data to stay within national borders, sometimes with limits on processing or remote access. It is not applied everywhere, but it is becoming more common in financial services, telecommunications and the public sector.
Europe regulates hard and enforces
Europe has one of the most developed regulatory regimes for data sovereignty. GDPR sets strict rules on how personal data is collected and processed, and requires cross-border transfers to offer protection equivalent to EU standards, through mechanisms such as standard contractual clauses and the transfer impact assessments introduced after the Schrems II ruling reshaped EU-US data flows in 2020.
Serious violations can draw fines of up to €20-million or 4% of global annual turnover, whichever is higher. The EU Data Act and AI Act push expectations further on transparency, access governance and the use of AI training data.

Africa is strengthening, and fragmented
African data protection regulation is moving quickly. More than 40 African countries have enacted national data protection laws, and most now have a regulator in place. South Africa’s Protection of Personal Information Act (Popia), Nigeria’s Data Protection Act and Kenya’s Data Protection Act are among the frameworks shaping how organisations handle personal data and cross-border transfers.
Unlike the EU’s single regime, Africa’s rules differ country by country on residency, transfers and oversight. For a multinational, one residency decision has to satisfy several regimes at once.
“Because of the proximity of nations within the African region, the collaborative effort in cross-border business, and the growing proliferation of cloud on the continent, it will be interesting to see how these data protection laws are not only tested, but enacted as the continent takes its seat as a global citizen,” said BBD CIO and head of cloud managed services Tony van der Linden.
Delivery location is part of the conversation too. Organisations have to weigh where data is stored and where the teams building and running those systems sit. That is one reason South Africa has become a trusted delivery location for international technology services, combining Popia’s protections, a mature financial and regulatory environment and close time-zone alignment with Europe. Organisations can add engineering capacity while keeping oversight of data governance.

What goes wrong
Residency decisions get treated as infrastructure detail. The consequences are not:
- regulatory penalties, particularly under GDPR;
- operational disruption if data cannot legally cross borders during an outage or incident;
- vendor lock-in where providers lack compliant regional infrastructure;
- foreign jurisdiction access, where governments can legally compel providers to disclose data;
- AI compliance problems when models are trained on cross-border datasets; and
- loss of customer trust when an organisation cannot say where its data resides.
Designing for sovereignty
Meeting sovereignty requirements does not mean abandoning global cloud platforms. It means deliberate architecture:
- Region-specific deployments: Run workloads in approved jurisdictions or local cloud regions wherever possible.
- Separated storage, processing and access layers: Keep sensitive data in-country while anonymised analytics or metadata processing happen elsewhere.
- Encrypt everything: At rest, in transit and in use, with customer-managed keys.
- Zero-trust access controls: Identity-based governance, so only authorised individuals reach sensitive data. This reduces cross-border and third-party risk.
- Sovereignty-aware AI: Federated learning or local training pipelines let models learn without centralising sensitive data across borders.
Disaster-recovery environments need the same care, so that failover does not move regulated data into a non-compliant jurisdiction.

Practical steps for CIOs and CTOs
Sovereignty should be a standard part of platform governance. That means mapping how data flows across jurisdictions, identifying regulated data categories, validating provider regions and compliance certifications, running regular sovereignty impact assessments, making sure AI workloads respect locality constraints and enforcing data-lifecycle governance.
Compliance as advantage
More than 160 countries now have some form of data protection legislation. Organisations that treat residency and sovereignty as architectural fundamentals reduce regulatory risk, build trust with customers and regulators, and run platforms that work across jurisdictions.
“As cloud adoption accelerates and AI-driven systems become more prevalent, the sovereignty of data will increasingly shape how digital platforms are designed, deployed and governed,” said Van der Linden.
Sovereignty now determines how systems are built and where they run. Treating it as a late-stage compliance check is how organisations end up rebuilding them.
About BBD
BBD is an international provider of bespoke software solutions, with four decades of technical and domain expertise spanning education, financial services, insurance, gaming, telecommunications and the public sector. It employs more than 1 200 IT professionals, drawing flexible teams from hubs in South Africa, India, the Netherlands, Portugal and the UK. BBD is 51% black-owned and a level-1 B-BBEE contributor with 135% recognition. For more, visit www.bbdsoftware.com.
- Read more articles by BBD on TechCentral
- This promoted content was paid for by the party concerned



