Cloud Strategy27 August 20267 min read

No AI Without Information Architecture — Part 8 of 10

Where the data is allowed to live

For a growing number of South African public bodies, the hosting question is settled before the architecture starts — and it removes options rather than reshuffling them.

#Cloud Strategy#Public Sector#Azure Architecture#POPIA

There is a question that decides more about a public-sector data platform than any design decision that follows it, and it frequently gets asked far too late: where is this allowed to run?

Not where would it run best. Where is this institution permitted to put it.

Three places the workload can sitPUBLIC CLOUDFastest to stand upWidest service rangeForeign jurisdictionHYBRIDSensitive data stays putCloud services read itTwo things to runIN-COUNTRY / ON-PREMISESJurisdiction resolvedFewer managed servicesMore to operate yourselfThe question is never which is best — it is which ones this institution is permitted to useAsk it before the design, not after,because it removes options rather than reshuffling them
This is decided on jurisdiction and institutional risk appetite, not on architecture preference. For some public bodies the middle and right columns are the only ones on the table, which constrains the platform before any design work starts.

Why this is being asked more, not less

Most South African government has a cloud strategy, and has had one for some years. What is consumed under it is often fairly basic — email, productivity, some infrastructure. The moment the workload becomes the data that runs a function, the conversation gets noticeably more careful.

Two things are driving that, and it is worth separating them because they call for different responses.

The legal question. Where a cloud provider is subject to a foreign jurisdiction, data held by that provider can in principle be reachable under that jurisdiction's law, regardless of which region it physically sits in. This is a real and well-documented feature of several legal regimes, and institutional lawyers are aware of it. Whether it is a material risk for a given workload depends entirely on what the workload is — and that is a judgement for the institution's legal and risk functions, not for an architect.

The geopolitical question. Separately, and more recently, some institutions have begun asking a blunter question: what happens to this system if the relationship between our government and the provider's government deteriorates? That is a question about concentration risk and continuity rather than about law.

I want to be careful here, because this area attracts a lot of confident third-hand claims. I have heard several accounts of foreign action against specific national institutions that I have not been able to verify, and I would encourage anyone repeating them to check before doing so. What is verifiable and sufficient for planning purposes is narrower: the legal exposure exists, institutions are treating it as material, and it is changing procurement requirements. You do not need the dramatic version to justify taking the question seriously.

What is actually happening in the market

The visible consequence is a growing preference for in-country capability, and a genuine build-out to serve it — sovereign facilities in South Africa, similar moves across the Gulf states, and a broader willingness among institutional buyers to trade capability for jurisdiction.

We have seen this land directly in deals. A solution demonstrated to a government audience is well received, and then the question arrives: can it run on-premises? A parliamentary body wants a system but not in the cloud. A defence-adjacent department cannot begin a conversation about a hosted service at all.

In each case the conversation ends not because the solution was wrong but because the deployment model was non-negotiable and the product could not meet it. That is a product problem, and it is worth naming as one.

What the sovereign option actually costs

If you are going to have this conversation honestly, you need to be clear about the trade, because it is real.

What the sovereign option actually costs youCompute and storageAvailable in-country — this is the easy partManaged databasesAvailable, with more operational work on youManaged AI servicesThinner. Often the deciding constraintRelease cadenceSlower. Feature parity lags, sometimes by yearsDecide this before the architecture, because it changes what the architecture can contain
Sovereignty is rarely blocked by infrastructure. It is decided in the third and fourth rows, and a design that assumed managed AI services will have to be reworked rather than relocated.

Compute and storage are not the issue. The gap is in the third and fourth rows — managed services, and how fast new capability arrives.

This matters enormously for AI workloads specifically. A design that assumes managed AI services will not simply relocate to a sovereign environment; it will have to be reworked, with more components you operate yourself and a slower path to new capability. That is a legitimate choice for an institution to make. It is not a legitimate thing for an architect to discover in month four.

What to do about it

Ask in the first meeting. Before the architecture, before the platform recommendation, before anything is drawn. "Is there any constraint on where this data may be hosted?" It is one question and it removes options rather than reshuffling them — which means asking it late invalidates work rather than adjusting it.

Ask who owns the answer. Frequently nobody has decided, and the delivery team's question is what forces the decision. That is fine, but it means allowing time for it. The people who own it are legal, risk and the information officer — not the technology office, though the technology office will implement whatever comes back.

Design for portability where it is cheap. You cannot make an architecture indifferent to its platform without paying for it. But some choices — keeping data in open formats, keeping business logic out of proprietary services, keeping the semantic layer independent of the reporting tool — cost little at design time and preserve a great deal of optionality. Where the sovereignty question is unresolved, those are worth taking.

Do not oversell hybrid. Hybrid is the right answer for a lot of institutions: sensitive data stays in-country, cloud services do the work that does not require it. But it is two environments to run, two security models to maintain, and a data-movement boundary to police. It is a real option, not a free one.

The narrower question underneath

For most South African organisations, the sharpest form of this question is not geopolitical at all. It is the POPIA one: does this workload process personal information, and if so, what does that require of where and how it is processed?

That is a narrower, better-defined and more immediately answerable question than sovereignty in the abstract, and for a great many systems it is the one that actually binds. It is worth resolving first, because it is often sufficient — and because it produces a defensible written position rather than an unresolved anxiety.

How CloudNala can help

We ask the hosting question in the first conversation now, before anything is designed, because we have watched it invalidate architecture that was otherwise sound. The useful early work is getting the question in front of the people who actually own the answer — legal, risk, the information officer — in a form they can decide on, and then designing to what comes back rather than to what would have been technically preferable.


Work with CloudNala

CloudNala helps organisations move from technology ambition to practical execution across cloud, AI, data, platform engineering and digital services.

Whether you are exploring AI, modernising your cloud environment, building a public-sector digital service, or turning an idea into a working MVP, we can help you shape the roadmap and deliver the next step.

Book an AI Readiness Workshop or write to us at consult@cloudnala.co.za