Key takeaways:
- Not every workload running on AWS, Azure, or GCP needs to move to a local cloud.
- A multi-cloud approach is often the right fit: keep global workloads on hyperscalers while placing critical workloads on local cloud infrastructure.
- Prioritize workloads that handle personal data, customer data, transaction data, sensitive information, or AI data.
- The decision should be based on the full data flow, including backups, logs, telemetry, AI prompts, embeddings, and third-party APIs.
For businesses operating workloads on AWS, Azure, or Google Cloud Platform (GCP) in Vietnam, the question is not whether to leave hyperscalers altogether. The question is which workloads should remain on hyperscalers, which should move to a local cloud, and how to operate these environments within a multi-cloud architecture.
In most cases, businesses should retain workloads that require global scale, advanced managed services, or support for multiple markets on AWS, Azure, or GCP. At the same time, they should assess whether workloads containing customer data, sensitive data, transaction data, AI data, or latency-sensitive applications in Vietnam should be placed on a local cloud.
For CIOs, CTOs, and IT Directors, this is not only an infrastructure decision. It is a balance between innovation speed, data control, compliance, performance, operating cost, and business resilience.
Short answer: Businesses should prioritize moving workloads that contain customer data or sensitive data in Vietnam, critical transaction systems, low-latency applications, backup and disaster recovery environments, and AI workloads that process internal data. Workloads serving global markets, development and test environments that do not use production data, or services deeply dependent on hyperscaler ecosystems can often remain on their current platforms.
Which workloads should move from AWS, Azure, or GCP to a local cloud?
Businesses should begin with one practical question: which workloads create the greatest data risk, governance burden, or operational constraint when they continue to be processed entirely outside Vietnam?
The starting point should not be “move everything off AWS, Azure, or GCP.” A full exit can create new forms of lock-in, increase operational complexity, and disrupt systems that remain well suited to hyperscalers.
Instead, businesses should classify workloads based on the data they process, where that data is stored, latency requirements, business criticality, and the organisation’s ability to demonstrate effective control. Each workload can then be placed in the most appropriate environment within a multi-cloud architecture.
When should a business consider moving a workload?
A workload should be added to the assessment list when one or more of the following signals apply.
| Signal | Question for the IT team | Multi-cloud architecture implication |
|---|---|---|
| Vietnamese personal data is processed outside Vietnam | Where is the data stored, backed up, analysed, or sent through APIs outside Vietnam? | Review the full data flow, cross-border data transfer obligations, and whether relevant data or processing layers should be placed on a local cloud. |
| The workload contains sensitive or transaction data | Who can access the data? Who manages encryption keys? Are audit logs complete? | Prioritize environments with clear access controls, encryption, logging, and audit evidence. |
| The application requires low latency in Vietnam | Does latency directly affect transactions, customer experience, or operations? | Consider placing the application, database, cache, or processing layer closer to users and business systems in Vietnam. |
| The business must demonstrate control for audit purposes | Can the business produce evidence of data residency, access controls, and access history? | Review IAM, logging, backup, disaster recovery, and governance processes across cloud environments. |
| AI processes customer or internal data | Where are prompts, embeddings, inference logs, and fine-tuning data processed? | Assess private AI or Sovereign AI Cloud options to establish clearer control over data, models, and AI operations. |
A local cloud is not the default requirement for every system. It should be considered when the type of data, risk profile, operating requirements, or evidence required for governance makes the current architecture difficult to manage.
In this context, data localization is not only about placing servers in-country. Businesses need to understand where data is stored, copied, backed up, processed, and accessed. They also need to identify who controls access rights, encryption keys, and audit evidence. Workload placement decisions should therefore be based on the complete data flow, not only on the location of an application server.
For personal data, businesses should also assess whether their processing activities create obligations related to cross-border data transfers. This depends on the type of data, processing flow, the organisation’s role, and the applicable legal requirements. This article is not a substitute for professional legal advice.
Five workload categories to assess first
1. Systems that hold customer and personal data
This is often the first workload category to assess, especially for retail, FMCG, e-commerce, fintech, digital services, and platforms with large user bases in Vietnam.
- Customer Data Platforms (CDPs)
- CRM and customer service platforms
- Loyalty platforms
- E-commerce account, order, and behavioural data
- Mobile application backends
- Marketing automation and customer analytics systems
- Call recording and chatbot conversation histories
- Data lakes or data warehouses containing personally identifiable information
The risk is not limited to names, email addresses, or phone numbers. Identifiable data can also exist in device IDs, browsing history, transaction records, account identifiers, conversation content, behavioural data, application logs, and datasets joined across multiple systems.
When assessing these workloads, businesses should identify where data is stored, where copies of data exist, who has access, and whether third-party analytics, monitoring, CRM, or AI tools receive any of that data.
2. Transaction systems and financial data
For financial institutions, banks, fintech companies, insurers, payment providers, or businesses with critical financial processes, workloads to assess may include:
- Transaction processing
- Fraud detection
- Credit scoring
- eKYC and document verification
- Billing, reconciliation, and financial reporting
- APIs that connect to payment partners
- Data platforms containing transaction histories
- Document processing, approval, and workflow systems
The objective is not to move an entire core system mechanically. Businesses need to understand where data is stored, where it is replicated, how backup works, how privileged access is managed, and what evidence can be provided during an audit.
For these workloads, GreenNode can be added as a local cloud layer in a multi-cloud architecture. Businesses can keep selected services on AWS, Azure, or GCP while placing data layers, backups, disaster recovery environments, or critical applications in a local environment based on the level of control required.
Learn more about Sovereign Cloud for BFSI
3. AI workloads that use internal or customer data
AI expands the scope of data governance. When businesses use chatbots, RAG applications, AI agents, document AI, or large language model APIs, data can appear across far more components than in a conventional application.
- Prompts entered by employees or customers
- Files and documents used as a knowledge base
- Embeddings in a vector database
- Inference logs and conversation history
- Fine-tuning datasets
- Model weights after fine-tuning
- Telemetry, monitoring, and error logs
- API requests sent to model providers or third-party AI tools
As a result, placing GPUs or application servers in Vietnam is not enough to conclude that an AI workload is fully controlled. Businesses need to assess where and how prompts, source files, vector databases, inference logs, models, API endpoints, telemetry, and AI agent permissions are managed.
For AI workloads involving customer data, internal information, source code, business documents, or trade secrets, businesses should consider private AI or Sovereign AI Cloud to gain clearer control over data processing locations, access mechanisms, encryption, and audit logs.
4. Latency-sensitive applications in Vietnam
Some workloads should be assessed not only for data governance reasons, but also for their operational performance in the Vietnamese market.
- E-commerce checkout and order management
- POS integrations
- Mobile application backends
- Real-time inventory systems
- Fraud scoring
- Customer service applications
- Logistics tracking
- Manufacturing execution systems
- APIs connecting local partners, branches, or stores in Vietnam
Businesses should not assume that a local cloud will always provide lower latency. Technical teams should measure actual performance for each application, including peak-hour latency, API response time, packet loss, error rates, database performance, and dependencies on international connectivity.
If latency directly affects revenue, transactions, customer experience, or production operations, the workload should be prioritized for placement assessment within a multi-cloud architecture.
Learn more about Sovereign AI for retail operations
5. Backups, disaster recovery, and security logs
Many businesses assess only their production environment and overlook where data is copied afterward. This is often a blind spot in cloud governance.
- Database snapshots
- Object storage archives
- Application backups
- Disaster recovery sites
- Security information and event management (SIEM)
- Application performance monitoring
- Log analytics
- Identity and access management logs
- Source code, artifact repositories, and CI/CD secrets
An application may operate in Vietnam while its backups, logs, monitoring data, or disaster recovery replicas remain outside Vietnam. Businesses should map the full data lifecycle before concluding that a workload meets data residency, control, or auditability requirements.
Multi-cloud example: Keep global workloads on hyperscalers and place critical data in Vietnam
A retail or e-commerce business can continue to use AWS, Azure, or GCP for CDN delivery, development and test environments, analytics that do not contain personally identifiable information, and services that support international markets.
At the same time, the business can place its Customer Data Platform, loyalty data, customer profiles, order data, transactional databases, backups, disaster recovery environments, or RAG knowledge base on GreenNode. These workloads often require stronger data residency, access control, auditability, or lower latency for users in Vietnam.
This multi-cloud model enables businesses to retain the speed and ecosystem advantages of hyperscalers while increasing control over workloads containing critical data in Vietnam. Network connectivity, data replication, IAM, backups, disaster recovery, observability, and monitoring should be assessed separately for each workload.
See this guide to designing a multi-cloud architecture for businesses operating AWS, Azure, or GCP in Vietnam.
Which workloads can remain on hyperscalers?
A local cloud does not replace hyperscalers in every situation. AWS, Azure, and GCP remain well suited to workloads that require multinational deployment, advanced managed services, global ecosystems, or rapid scaling.
Workloads that can often remain on hyperscalers include:
- International websites, landing pages, or content delivery services
- Development and test environments using synthetic or appropriately processed data
- Global SaaS applications that depend heavily on hyperscaler ecosystems
- Workloads serving multiple markets outside Vietnam
- Analytics using aggregated or minimized data, after the data flow has been assessed
- Open-source build pipelines that do not contain customer data, secrets, or sensitive source code
The principle is to keep each workload where it creates the clearest value. However, the convenience of an existing architecture should not become a reason to overlook new data control and operational risks.
Decision matrix: Keep workloads on hyperscalers, move them to a local cloud, or operate multi-cloud?
The table below provides an initial assessment framework for CIOs, CTOs, and IT Directors. Each workload should be evaluated separately based on data sensitivity, residency requirements, operational risk, latency, cloud service dependencies, and migration cost.
| Workload type | Recommended model | Primary reason |
|---|---|---|
| International websites, public content, and CDN | Hyperscaler or multi-cloud | Requires global reach; data is often less sensitive. |
| Development and test environments using synthetic data | Hyperscaler | Benefits from rapid provisioning and managed services. |
| CRM, CDP, and loyalty platforms containing Vietnamese customer data | Multi-cloud with a local cloud for critical data or application layers | Enables stronger control over data flow, residency, access, and audit evidence. |
| E-commerce backends, POS, and order management | Multi-cloud with a local cloud for Vietnam-facing workloads | Involves customer data, latency, and local operations. |
| Financial transactions, eKYC, and fraud analytics | Multi-cloud or local cloud, depending on the architecture | Requires strong control over data, access, logging, and auditability. |
| Data lakes or data warehouses containing personal data | Local cloud or a segmented multi-cloud data architecture | Requires control over data location, access, backup, and retention. |
| AI chatbots or RAG applications using internal documents | Private AI or Sovereign AI Cloud within a multi-cloud architecture | Requires control over prompts, embeddings, logs, models, and access rights. |
| Disaster recovery for business-critical systems in Vietnam | Local cloud or multi-cloud disaster recovery | Improves control, recovery capability, and operational auditability. |
No single decision matrix can replace legal advice, a security assessment, or detailed technical architecture design. However, it gives IT, security, legal/compliance teams, and business owners a common principle: classify workloads first, then choose the right cloud environment.
Workload assessment checklist before moving to a local cloud
Use the checklist below for each workload before deciding whether to keep it on a hyperscaler, move it to a local cloud, or place it within a multi-cloud architecture.
1. Data and compliance
- The workload processes personal data belonging to customers, employees, partners, or users in Vietnam.
- The workload stores sensitive data, transaction data, identity records, behavioural history, or data that can be linked to an individual.
- Data is stored, backed up, copied, or processed outside Vietnam.
- The workload uses APIs, SaaS platforms, analytics, monitoring, or AI services that may receive data outside the primary environment.
- The team does not have a complete data flow map covering production, backup, disaster recovery, logs, telemetry, and test data.
- The business needs to review its cross-border personal data transfer impact assessment obligations where applicable.
- The workload belongs to a sector or business function with heightened control requirements, such as financial services, insurance, healthcare, telecommunications, retail, e-commerce, or digital services.
If three or more of these criteria apply to a workload, the business should prioritize it for a local cloud or multi-cloud architecture review involving IT, security, legal, and compliance teams.
2. Control and auditability
- The business can identify exactly where data is stored, including primary data, replicas, snapshots, and archives.
- The business knows which legal entity operates the infrastructure and which legal framework applies to the data.
- The business controls privileged access, user permissions, and access approval processes.
- Encryption keys are managed by the business or by a party designated by the business in line with internal requirements.
- Access logs, configuration changes, and data processing activities can be retained, retrieved, and provided for audit.
- The business can provide evidence of data residency, access controls, encryption, retention, and incident response when required.
- Provider contracts clearly define responsibilities for data handling, incident notification, investigation support, and data return or deletion processes.
If several answers are “unclear” or “no,” the issue is not only server location. The business should reassess its control model, governance processes, and the evidence available across the full data lifecycle.
3. Performance and business continuity
- The primary users of the workload are located in Vietnam.
- The workload supports real-time transactions, customer interactions, or operations that require low latency.
- Application performance is affected by international connectivity, cross-border traffic, or unexpected external network disruptions.
- The application must connect frequently to systems in local data centres, offices, factories, stores, or partner environments in Vietnam.
- Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) require rapid, controlled, and auditable recovery.
- The current disaster recovery plan does not clearly separate production, backup, and DR environments.
- A disruption to the workload could materially affect revenue, operations, or brand reputation.
4. AI and AI data
- The workload uses a chatbot, AI assistant, RAG application, AI agent, or large language model API.
- Prompts may contain customer data, employee information, internal documents, source code, or trade secrets.
- The knowledge base or vector database contains sensitive information.
- The business does not know where inference data, conversation history, or telemetry is stored.
- The model or API may process data in a location outside the desired control boundary.
- The AI agent has access to CRM, ERP, email, document repositories, or business applications.
- The business requires evidence of access controls, encryption, audit logs, and retention for the AI environment.
For AI workloads, businesses should not assess only the location of GPUs or application servers. The assessment should cover prompts, source documents, embeddings, vector databases, inference logs, model weights, telemetry, API endpoints, and agent access rights.
5. Cost and migration readiness
- The business has accounted for data egress, replication, backup, observability, and multi-cloud operating costs, not only VM or storage pricing.
- The workload can be separated into application, database, storage, and integration layers for phased migration.
- The workload is not deeply dependent on a proprietary managed service without a viable alternative.
- The team has a complete inventory of networks, IAM, secrets, database dependencies, API dependencies, and batch jobs.
- The business can run a pilot or operate workloads in parallel before completing a full migration.
- A business owner is accountable for defining migration success criteria.
- A rollback plan exists if the pilot does not meet performance, cost, security, or user-experience requirements.
How GreenNode supports multi-cloud architecture
GreenNode is designed for businesses that want to continue using hyperscalers for global workloads while adding a local cloud layer for workloads that require a higher level of control in Vietnam.
These workloads may include customer data, transaction data, latency-sensitive applications, backup or disaster recovery systems in Vietnam, and AI workloads that process internal or sensitive data.
GreenNode is a Vietnamese legal entity within VNG Group and operates a Sovereign AI Cloud across six availability zones in Hanoi, Ho Chi Minh City, and Bangkok. GreenNode states that its infrastructure is certified to ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, PCI DSS, and Uptime Institute Tier III standards.
For AI workloads, GreenNode provides GPU infrastructure, H100 bare metal, an AI Platform, Model as a Service, AgentBase, and Intelligent Document Processing. These capabilities can provide an appropriate infrastructure layer for businesses designing AI workflows with stronger control over data, models, and operations.
Infrastructure certifications do not automatically make an application compliant. Businesses must still design the right data flows, access controls, encryption, retention policies, backups, logging, and governance processes. Infrastructure is the foundation; effective control depends on both architecture and workload operations.
Assess workloads before deciding on migration
If your business runs workloads on AWS, Azure, or GCP, migration does not have to be the first step. Start by identifying which workloads should remain on hyperscalers, which should move to a local cloud, and how workloads should be placed within a multi-cloud architecture.
GreenNode can help businesses review data flows, operating requirements, technical dependencies, and the suitability of each workload before designing a multi-cloud architecture or migration plan.
Contact GreenNode to discuss your multi-cloud architecture and Sovereign AI Cloud requirements.
Frequently asked questions
Which workloads should move from AWS or Azure to a local cloud?
Prioritize workloads that process customer data, personal data, transaction data, sensitive internal data, AI workloads using enterprise documents, applications requiring low latency in Vietnam, and backup or disaster recovery systems supporting critical services.
Are businesses in Vietnam that use AWS required to store data in-country?
There is no single answer for every business or data category. Requirements depend on the type of data, industry, processing activities, data flow, and the applicable legal circumstances. Businesses should map their data, identify whether data is stored or processed outside Vietnam, and work with legal counsel to assess their specific obligations.
Should businesses move all systems from AWS, Azure, or GCP to a local cloud?
Usually, no. A multi-cloud architecture allows businesses to retain workloads that require global scale on hyperscalers while moving critical data layers, applications, backups, or disaster recovery environments to a local cloud.
Can multi-cloud keep critical data in Vietnam while applications continue running on AWS?
Yes. A common model is to retain front-end applications, CDNs, development and test environments, or services supporting global markets on hyperscalers, while placing databases, Customer Data Platforms, backups, disaster recovery, or sensitive data processing workloads on a local cloud. Businesses should carefully assess connectivity, replication, access controls, observability, and data egress costs.
Should an AI chatbot that uses Vietnamese customer data run on a local cloud?
Businesses should assess the full AI data flow, including prompts, source documents, embeddings, vector databases, inference logs, telemetry, and model APIs.