The Sovereignty Stack: When Your Cloud Strategy Becomes a National Concern
- By Winston Thomas
- January 28, 2026

It’s mundane infrastructure, the digital equivalent of a Post-it note. But when Matthew Oostveen, the chief technology officer for Asia Pacific and Japan at Everpure (formerly Pure Storage), explains data sovereignty to nervous bank executives, he starts with the meeting room scheduler that nobody worries about and nobody should.
“Do we need sovereign control over that? Absolutely not,” Oostveen said, during the Pure Leadership Series panel discussion titled “Data Sovereignty: Building Your Geopolitical Firewall Before You Need One.” Then he pivots. “But core banking systems? Mission-critical applications handling fiduciary data? Those can’t risk exposure to foreign legal frameworks.”
This is the new math of enterprise IT: sorting thousands of workloads into two buckets: “fine if country A sees it” and “national security incident if country A sees it.” Get it wrong, and you’re facing more than a compliance fine.
Welcome to 2026, where 70 countries now have data sovereignty laws on the books, and your cloud provider might be taking orders from a government that isn’t yours.
The honeymoon is over
The fracture happened fast. Rewind eighteen months, and IT leaders were still optimizing for efficiency, latency, cost and global reach. GDPR was the gold standard, and hyperscalers were the heroes. Then geopolitical reality crashed the party.
We had trade wars, physical wars and a U.S. administration pivoting inward. Suddenly, CIOs at banks and critical infrastructure firms realized that a foreign government could shut down their entire operations with the right court order.
Karthikeyan Vuyyala, the executive director for global funds and fiduciary product at Standard Chartered Bank, who joined the discussion as a panelist, has watched the conversation transform. “If you go back 18-24 months, it was primarily driven by operational efficiencies and cost optimization,” he says. “Today it’s pivoted. It’s more around resilience and control.”
The questions he is asked now aren’t about performance metrics. Rather, they are existential: Which providers can we trust? What happens if our hyperscaler relocates data without telling us? How do we protect against what Vuyyala calls “sovereignty shock waves”, overnight policy changes that render entire architectures illegal?
Oostveen watched the wave build as Europe passed consumer data protection laws in 2023 and 2024, while U.S. companies were still fixated on AI innovation. “Forged in the crucible of these three forces,” he says, “out pops data sovereignty.”
Watch the entire online panel discussion between Matthew Oostveen and Karthikeyan Vuyyala here.
The Cloud Act’s long shadow
Here’s what keeps infrastructure chiefs up at night: You buy “sovereign” cloud services that aren’t sovereign at all.
Take Australia. Hyperscalers market availability zones there as sovereign because the data centers physically exist on Australian soil. Sounds good. Except the U.S. Cloud Act doesn’t care about geography. It cares about corporate ownership. If a U.S. company operates that data center, U.S. intelligence agencies can compel access through court orders, regardless of where the servers actually sit.
“You don’t want to find that you have a U.S. organization offering what is labeled as a sovereign service, but when you pull back the covers, it really isn’t,” Oostveen warns. “Legislative frameworks like the U.S. Cloud Act have tentacles… to access that data."
This is already a global concern. Denmark recently discovered that the buses it purchased could be controlled remotely from China. Critical infrastructure, compromised at the firmware level, surfacing only after deployment.
For financial services firms, the exposure is worse. They’re not just managing infrastructure; they’re also responsible for fiduciary duties across dozens of jurisdictions with conflicting rules. China’s PIPL, India’s DPDP Act and the U.S. Cloud Act may look similar. Still, each has a different definition of what constitutes personally identifiable information, and comes with different rules about data collection, processing and utilization.
“It’s no longer just compliance,” Vuyyala says. He cites a survey from Pure Storage, conducted in collaboration with the University of Technology Sydney, that shows that over 90% of industry leaders now view sovereignty as a reputational risk, not just a regulatory checkbox.
Stack ranking the apocalypse
So how do you decide what stays sovereign and what goes global?
Otstveen’s advice is clear: Stack rank everything, from every application and every workload to every dataset. Then draw a line based on actual risk tolerance, not fear.
“Think about how many small workloads you’ve got inside your organization,” he says. “If you’re a larger organization, the number is going to be in the thousands. At what point are you willing to say this is something that we must have control over?”
The meeting room scheduler? Below the line. The algorithm detecting real-time fraud? Way above it.
But executing this triage requires what Vuyyala calls “a rigorous, multi-layered review” — comprehensive data mapping, regulatory overlays for every jurisdiction in which you operate, risk modeling for geopolitical volatility, and vendor audits that go deeper than marketing materials.
“You cannot just rely on a labeled solution these days,” Vuyyala says. “You do have to lift the hood.”
The pitfalls are subtle and expensive. Organizations focus on where data is collected while ignoring where it’s processed or utilized. They adopt a “gold standard” compliance approach — usually GDPR — without realizing that sovereignty regulations are intentionally non-uniform. Each country is building its own moat.
“It all depends upon where the data originates, where the data is stored, where the data is used,” Vuyyala explains. “All those three elements are very, very key.”
The sovereignty tax
None of this is cheap. Repatriating data from global clouds to sovereign infrastructure is expensive. Maintaining hybrid architectures across jurisdictions is complex. But Oostveen argues the alternative — getting blindsided by a sovereignty shock wave — is worse.
“We’re meeting the expectations of an always-on economy, of an always-on business,” he says. “There is very little patience for downtime.”
The good news: tools exist now that didn’t a decade ago when cloud migration began. On-premises infrastructure can match or exceed hyperscaler capabilities while maintaining sovereign control. The hybrid model works if you’re ruthless about what belongs where.
“What I expect to see is sovereignty plus,” Oostveen predicts. “Cloud migrations with a sovereignty band. Application modernization with a sovereignty angle cast through it. Whatever you’re doing to improve your systems will have sovereignty woven in.”
But sovereignty can’t be bolted on. It has to be architected from the start, which means co-creation between suppliers, integrators, and customers. “Unless you are very specifically and deeply embedded within a customer and co-creating what the solution will look like, there is too much room for error,” Oostveen says.
The new center of gravity
For Vuyyala, the shift goes beyond technology into operating models. “The way we approach it today — typically any business rolls out a program, then you consider what sovereignty elements you need to bring in,” he says. “I think as we move forward, we will have the reverse: How do you have sovereignty at the center and create the full operating model around it?”
That inversion demands new expertise. Not just technologists or compliance officers, but cross-functional teams that understand geopolitics, law, infrastructure, and business strategy simultaneously. The CDO and CIO become what Vuyyala calls “the driving centrifugal force,” the hub pulling together diverse intelligences to build resilient systems.
It’s hard work with no finish line. Expect more regulations, constant updates and jurisdictions to diverge as nations compete for digital autonomy deliberately.
But there’s opportunity in the chaos. “If you’ve got the competence and the confidence and you can navigate this path forward, be that lighthouse, be that North Star for your organization,” Oostveen says.
The alternative is waiting for the first outage — the moment you discover that your conference room scheduler is fine, but your core banking system is hosted in a jurisdiction that just became a geopolitical flashpoint.
By then, sovereignty isn’t a strategy but an existential threat.
Disclaimer: The views from Karthikeyan Vuyyala are personal and do not represent Standard Chartered’s.
Image credit: iStockphoto/Seng kui Lim
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.