Over the past few years, I have had the opportunity to speak with hundreds of leaders across industries, CIOs, CTOs, compliance heads, in Vietnam, Thailand, Singapore, and across Southeast Asia. The conversations are different in tone, sector, and geography. But one question surfaces in almost every one of them:
"Can we trust that our data stays where we need it to stay?"
It is the right question to ask. And today, I want to answer it directly, not as a product announcement, but as a statement of where we stand and where we are going.
Because the honest answer is: that depends entirely on what "stays" means. And most enterprises across Southeast Asia are working with an incomplete definition — one that is about to become even more costly as AI enters the picture.
Southeast Asia's Data Laws Have Changed. Most Cloud Strategies Haven't.
The regulatory ground across Southeast Asia has shifted in ways that most enterprise cloud decisions have not yet caught up with.
Law No. 91/2025/QH15, Vietnam's first comprehensive Personal Data Protection Law, passed in June 2025 and took effect January 1, 2026. Decree 356/2025/ND-CP followed on December 31, landing with immediate effect. The rules are specific: using a foreign cloud provider to process Vietnamese personal data is classified as a cross-border transfer.
Mandatory Transfer Impact Assessments must be submitted to the Ministry of Public Security within 60 days. Penalties for breaches reach 5% of annual revenue. Financial institutions face additional obligations, approved technical standards, end-to-end processing logs, annual compliance assessments.
Thailand has tightened its PDPA enforcement. Indonesia's omnibus Personal Data Protection Law came into full effect in October 2024. Malaysia's amended PDPA, with adequacy-based cross-border transfer rules, took effect April 2025.
Every one of these frameworks does the same thing: it draws a legal boundary around data that a physical server location alone cannot satisfy.
This is precisely the moment GreenNode was built for.
Data Residency vs. Data Jurisdiction: Why CIOs Are Asking the Wrong Question
When a CIO asks "is our data stored locally?", what they are really asking is: "is our data safe from foreign access, regulatory overreach, and jurisdictional uncertainty?"
Those are not the same question. And the gap between them is where most cloud decisions fall short.
Data residency means your data is physically stored within a specific geography. It is a necessary condition in many regulated sectors. But a server can sit in Ho Chi Minh City, Bangkok, or Jakarta and still be under foreign jurisdiction. The physical location of hardware tells you almost nothing about who has legal authority over the data running on it.
The question that actually protects your organization is simpler and harder at the same time: "Under whose legal jurisdiction does our data sit?"
A Law Most Regional CIOs Have Not Fully Absorbed
In 2018, the United States passed the CLOUD Act, the Clarifying Lawful Overseas Use of Data Act. Its effect is straightforward: US law enforcement can compel US-domiciled technology companies to produce data stored on their infrastructure, regardless of where that infrastructure is physically located.
If your cloud provider is a US company, regardless of whether they operate local zones in your country, the US government has a legal pathway to your data. The provider cannot refuse on the grounds that the servers are overseas.
Now overlay that against Vietnam's Decree 356/2025 and Indonesia's PDP Law: using a foreign cloud provider's local zone is still classified as a cross-border transfer in the eyes of regulators. The compliance architecture most enterprises have built around global hyperscalers was not designed for this. It was designed for a simpler world.
The world changed. The contracts haven't.
A Question Worth Asking Before the Next Contract Cycle
Global hyperscalers have made significant infrastructure investments across Southeast Asia, full Availability Zones in Singapore, Indonesia, Thailand, and Malaysia. Real commitments. Real capabilities. I am not suggesting enterprises ignore them.
But here is a question I think every CIO should sit with before signing a multi-year cloud contract: when a provider builds full infrastructure in some markets and operates through lighter local arrangements in others, while growing revenue in all of them, what does that tell you about their long-term commitment to each market? And about what their 'local' offering actually is?
I don't have a definitive answer for every provider. But the question is worth sitting with. Because the answer tells you something about how your data will be treated, not in the best case, but in the hard cases.
What True Sovereignty Requires
Sovereignty is not a feature. It is a structural property of how infrastructure is owned, operated, and governed. For enterprises in regulated sectors across Southeast Asia, it requires three things:
- The operating entity must be locally domiciled. Not a regional hub. Not a subsidiary of a foreign parent. The company operating your infrastructure must be incorporated in-country, subject to local law, accountable to local regulators. Legal accountability follows corporate domicile, not server location.
- Physical control of the network boundary must be possible. Enterprises in financial services and government need to control their own perimeter: connectivity, security stack, hardware. A shared public cloud architecture, however local, cannot satisfy this for the most sensitive data categories.
- No foreign jurisdiction can override local law. This is the condition most "local zone" offerings cannot satisfy. If your provider is a US-domiciled company, the CLOUD Act gives US law enforcement a legal pathway to your data, regardless of where the servers sit. Vietnamese and Indonesian regulators classify this as a cross-border transfer. Your provider cannot refuse. You may not be notified.
If any of those three conditions is absent, you have data residency. You do not have sovereignty.
Now Adding AI, The Stakes Get Higher.
Everything above applies to data at rest and in transit. But the conversation has moved. Enterprises across Southeast Asia are now making a second, deeper set of decisions — about AI. And most are making them without understanding the sovereignty implications.
Let me be direct about three risks I am seeing that are not yet widely discussed.
1. Your training data is leaving — and you may not know it.
Every time enterprise data is fed into a hyperscaler's AI service — for fine-tuning, retrieval-augmented generation, or inference — it transits foreign infrastructure under foreign jurisdiction. Under Vietnam's Decree 356 and Indonesia's PDP Law, that is a cross-border transfer. Most enterprises doing this today have not filed the required regulatory assessments. They are accumulating compliance exposure with every API call.
2. The model itself is a foreign-controlled system.
The dominant AI models available through hyperscaler platforms — trained predominantly on Western data, governed by US or European companies, updated on their schedules — are not neutral tools. You have no visibility into what goes into the next version. You have no control over what your AI learns from. When regulators ask you to demonstrate oversight and auditability of the AI systems you deploy — and they will, as the EU AI Act's August 2026 obligations and South Korea's AI Basic Act already make clear — a foreign-controlled model running on foreign infrastructure is a very difficult answer to give.
3. The lock-in is deeper than it looks.
Once your workflows, agents, and automations are built on a hyperscaler's AI stack, the exit cost is high — technically and commercially. Regulations will continue to tighten across this region. An enterprise that discovers in 2027 that its AI architecture is non-compliant, but cannot migrate without 18 months of disruption, has a problem that no amount of legal creativity will solve. The time to design sovereignty into your AI architecture is before you are locked in, not after.
Sovereign AI cloud means the infrastructure where your models are trained, fine-tuned, and run inference is locally operated, legally anchored in-country, and not subject to foreign override. You control what the model learns from. You own the stack. You stay portable.
Several SEA governments already understand this. Singapore launched its SEA-LION sovereign language model in 2023. Malaysia completed its first sovereign AI data center in 2025 and launched its own LLM. Vietnam's AI Law, effective 2026, requires foreign AI providers to appoint local representatives and meet transparency obligations.
The direction is clear: AI sovereignty is becoming a policy priority, not just a technical preference.
Where GreenNode Stands and Where We Are Going
GreenNode is a Vietnamese company. That is not a detail, it is the foundation of everything we do.
We built our first Availability Zones in Vietnam, and followed by Thailand. We are expanding that corridor across Southeast Asia. Vietnam and Thailand are live. More markets follow.
In practice: our operating entities are subject to Vietnamese and Thai law, not the laws of a foreign parent. We are not subject to the CLOUD Act. Enterprises can control their network boundary at the physical layer. And as sovereign AI workloads grow — model training, fine-tuning, inference on sensitive data — our infrastructure provides the jurisdictional clarity and physical control that regulated enterprises need.
We are not the largest cloud provider in this region. We are the one built specifically for this regulatory moment by a team that understands Southeast Asia not as a market to enter, but as home.
Let's Have the Conversation
The compliance questions have changed. The AI questions are arriving fast behind them. Infrastructure decisions that were defensible three years ago may not hold up today and the window before regulators begin enforcing in earnest is narrowing.
If you are a CIO, CTO, or compliance lead in financial services, government, or critical infrastructure in this region, one question is worth asking before the next contract cycle: does your current architecture actually satisfy what Decree 356 now requires? Does your AI stack? We built GreenNode to help answer that. Come pressure-test it with us.
Ask us the hard questions. That is what we built GreenNode for, a high-performance, sovereign AI cloud built for Southeast Asia.