You Cannot Claim Digital Sovereignty Without Asking Where the Data Is Physically Hosted

Share
EXPERT ANALYSIS | INFRAPICK

The debate around digital sovereignty has become considerably more sophisticated. Jurisdiction, encryption, Cloud providers, operational control, intellectual property, cybersecurity, skills and technological dependencies are now all part of the conversation.

Yet as the debate becomes more sophisticated, one fundamental question sometimes seems to be pushed into the background: Where is the data physically hosted?

For a State, this is not simply an architectural detail. Physical location determines the infrastructure on which national data relies, the territory in which that infrastructure sits, the connectivity dependencies involved, the resilience arrangements that can be put in place and, to some extent, the legal and operational environment surrounding that data.

Even though data localisation alone is not enough to achieve digital sovereignty, it is equally difficult to claim genuine national sovereignty while treating the physical location of a country's most strategic data as a secondary consideration.

Data always has a physical address

Cloud computing has gradually made infrastructure less visible to the end user. Data is "in the Cloud". Applications are cloud-native. Workloads move between regions. Computing capacity is consumed on demand. That abstraction is precisely one of the advantages of the Cloud.

For a State, however, it has its limits.

Behind every Cloud service are servers. Those servers sit in Data Centers. Those Data Centers depend on power, cooling systems, telecommunications networks, security infrastructure and operational teams.

Data may also be replicated across multiple sites. Backups may be stored in another country. A Disaster Recovery environment may depend on infrastructure located thousands of kilometres away from the primary system.

When a State defines its digital sovereignty strategy, therefore, the geography of its digital infrastructure cannot simply disappear behind the Cloud layer. This does not mean that every piece of data generated within a country should necessarily remain there. The more relevant question is:

Which data is sensitive, critical or strategic enough for its physical location to become a matter of national sovereignty in its own right?

That is where the distinction becomes important.

Nigeria is already making this distinction

Nigeria's Cloud policy provides a particularly interesting example. The national policy establishes a data classification system and links certain levels of sensitivity to residency requirements. Sovereign data falling within the highest classifications must be hosted in Nigeria, subject to specific exceptions. The associated technical guidance also favours Cloud infrastructure located within the country for certain categories of sensitive government data. The important point is that Nigeria is not saying: "All Nigerian data must remain in Nigeria." Instead, it introduces a much more useful principle: classify first, then determine where the data should reside.

The more sovereign or sensitive the data, the greater the requirement to control its physical location.

This approach avoids two extremes: requiring every category of data to remain within national borders, or assuming that physical location no longer matters in the Cloud era.

For a closer look at what Nigeria’s 2026 Cloud Computing Guideline means for Cloud and Data Center providers, read our analysis here.

Local hosting gives a State something tangible

Let's consider two scenarios.

In the first, a government retains legal ownership of its data, regulates its use and requires encryption, while its most critical workloads are hosted exclusively in Data Centers located thousands of kilometres outside its territory.

In the second, those workloads are physically hosted within the country, but on infrastructure and technologies over which the State has limited contractual, technical or operational control.

Neither scenario amounts to complete sovereignty. But neither creates the same dependencies.

Domestic hosting can reduce reliance on international connectivity for services consumed locally. It can facilitate national resilience architectures. It creates demand for domestic Data Center and Cloud capacity. It can also contribute to the development of local skills and operational capabilities.

Most importantly, it gives the State the ability to exercise greater control over infrastructure located within its own territory.

The important word here is ability. Localisation creates some of the conditions for control. It does not guarantee control.

A Data Center inside the country can still host a dependency

This is precisely where the argument for localisation needs to be qualified.

Imagine a government workload physically hosted in Lagos, Dakar or Cotonou.

Who owns the Cloud platform? Where is the provider legally incorporated? Who actually administers the environment? Who controls the encryption keys?

Can a foreign authority compel the provider to disclose information? Can the customer migrate its workloads without excessive technical or contractual dependency? Who intervenes when the platform experiences a major incident? And can the service continue to operate if access to foreign licences, technologies or expertise is disrupted?

These questions do not make localisation irrelevant. They simply show what needs to come with it.

France's State Cloud doctrine illustrates this logic well. For certain categories of particularly sensitive data, European localisation is not the only requirement: cybersecurity and protection against certain extraterritorial laws also form part of the equation.

In other words, a mature sovereignty policy does not replace one criterion with another.

It combines different layers of control: Location, Jurisdiction and Control.

These are three separate questions:

Where is the data physically located? That is the question of location.

Which laws and jurisdictions is it exposed to? That is the jurisdiction question.

Who can actually access, administer, transfer, restore or delete the data and the service supporting it? That is the question of control.

This is why saying "data localisation is not sovereignty" is correct, but incomplete.

Encryption alone is not sovereignty either. Nor is national ownership of an operator. Nor a national Cloud strategy. Nor the construction of a national Data Center.

Digital sovereignty is better understood as the ability to maintain sufficient control over all of these dependencies, particularly when normal operating conditions no longer apply.

Sovereignty does not mean closing digital borders

It would be equally problematic to turn this argument into a case for systematic data localisation. African economies need cross-border data flows: financial services, telecommunications, research, AI, digital trade, multinational businesses and regional public services increasingly rely on distributed architectures.

The African Union's Data Policy Framework itself seeks to reconcile stronger national data governance with the creation of conditions for secure data exchange across the continent. The right question, therefore, is:

Which data should remain local, which data can move across borders, under what conditions, with what safeguards, and for what purpose?

Sovereignty should enable a State to determine the conditions under which its data moves. It should not automatically mean preventing that movement.

The sovereignty question eventually becomes an infrastructure question

There is one practical reality that cannot be avoided. A State can only require critical data to remain within its territory if the infrastructure required to host it under the expected conditions actually exists within that territory.

Is sufficient Data Center capacity available? Do those facilities meet the required resilience and security standards? Is enough power available? Are there multiple connectivity routes? Can the domestic Cloud ecosystem support the workloads concerned? Can available capacity scale as demand grows? Can a genuine backup or Disaster Recovery architecture be implemented without reproducing the exact same dependencies as the primary site? A localisation policy that is not supported by an infrastructure policy risks becoming difficult to implement — or prohibitively expensive.

This is precisely where data policy and infrastructure policy meet.

It is difficult to sustain a serious conversation about sovereign Cloud, sovereign AI or data localisation without eventually addressing Data Centers, energy, connectivity, Cloud capacity and operational resilience.

AI makes that connection even more important.

Tomorrow, the question will no longer be only where data is stored, but also where it is processed, where models are trained or deployed, and where the computing capacity supporting a country's strategic AI services is located.

Physical location is not the end goal. It is part of the foundation.

The digital sovereignty debate should avoid two shortcuts.

The first is assuming that data automatically becomes sovereign simply because it is physically hosted within national borders.

The second is assuming that physical location has become secondary because sovereignty can now be achieved through contracts, encryption or governance alone.

Neither position is sufficient.

For a State's strategic data, physical location remains an important component of control. But it needs to be complemented by other forms of control: legal, technological, operational, cybersecurity, contractual and human.

Nigeria's approach is particularly interesting because it begins to translate this principle into practical decisions: identify the nature of the data, determine its level of sensitivity, and then apply the appropriate residency and hosting model.

For African States, the next stage of the digital sovereignty debate may therefore need to start with much more practical questions:

Where is the data physically hosted? Who operates the infrastructure? Under which jurisdiction? Who can access it? Where are the backups? What happens when a dependency becomes unavailable? And do we actually have the domestic infrastructure required to exercise the level of control we claim to want?

Because digital sovereignty is, ultimately, about the ability to make choices — and to enforce them. And where a State's strategic data physically resides is one of those choices.


A DATA CENTER, CLOUD OR AI CHALLENGE IN AFRICA?

Infrapick supports companies, institutions and investors in their infrastructure decisions: Data Center selection and hosting strategy, Operational Intelligence, Market Intelligence & Investment Due Diligence, AI & Cloud Sovereignty Readiness Assessments, and On-Demand Expert Consultations.


ABOUT THE AUTHOR

A telecommunications engineer by training, Azimath Olayemi Adjassa has spent more than fourteen years working across digital infrastructure, telecommunications and critical environments. Her areas of interest include the intersection of connectivity, Data Centers, digital sovereignty and artificial intelligence.

She is a Data Center consultant and the founder of Infrapick, an advisory practice specializing in Data Center hosting decisions and capacity intelligence within the African infrastructure ecosystem. Her approach combines supporting organizations in making informed hosting decisions with improving the visibility of available infrastructure capacity for operators.

Her ambition is to bridge the gap between user requirements and the operational realities of the industry, while contributing to a more transparent and accessible market—one where investment, hosting and development decisions are driven by reliable data and a shared understanding of critical infrastructure challenges.

Read more

On ne peut pas revendiquer la souveraineté numérique sans se demander où les données sont physiquement hébergées

On ne peut pas revendiquer la souveraineté numérique sans se demander où les données sont physiquement hébergées

Le débat sur la souveraineté numérique s’est considérablement enrichi. Il est désormais question de juridiction, de chiffrement, de fournisseurs Cloud, de contrôle opérationnel, de propriété intellectuelle, de cybersécurité, de compétences et de dépendances technologiques. A mesure que le débat gagne en sophistication, une question pourtant fondamentale semble parfois reléguée

By Infrapick Africa