Mark Pestridge, Executive Vice President and General Manager, Telehouse Europe; Sami Slim, CEO, Telehouse France and Takeyuki Yanagisawa, General Manager, Telehouse Business Planning Department, KDDI, on how data sovereignty is reshaping the design, governance and operation of digital infrastructure across global markets.
As digital ecosystems expand, data sovereignty has become a defining consideration in how infrastructure is built and governed. For enterprises, the challenge lies in finding the right balance. Infrastructure must enable global collaboration while respecting local laws, ensuring innovation can continue within data residency and transfer boundaries.
The balance is increasingly being tested, as a growing number of regulators across Europe have imposed billions of euros in penalties for breaches of data protection and data sovereignty rules since GDPR enforcement began, with annual totals now often climbing into the high hundreds of millions.
Authorities in North America, Asia-Pacific, Latin America and the Middle East are following suit, strengthening privacy frameworks and tightening control of cross-border data flows.
This enforcement trend is amplified by emerging and evolving localisation regimes. Markets such as India, Vietnam and Brazil are increasingly specifying which datasets must remain within national borders and the conditions under which they can be transferred or accessed internationally.
Infrastructure decisions are no longer purely technical. They are shaped by regulatory and geopolitical factors, raising the bar for data centre operators. Capacity alone is insufficient; customers now expect clarity and assurance on data sovereignty from the outset.
Demand is now shifting toward carrier-neutral, multi-cloud environments that pair dense connectivity with demonstrable compliance, ensuring flexibility as regulations continue to evolve. In practice, this approach enables organizations to align specific workloads with the appropriate jurisdictions, keep specific data sets within national borders while maintaining access to global services and separate network and cloud choices so that legal obligations can be met without redesigning entire architecture.
Facilities that combine strong cybersecurity, resilience and internationally recognised certifications become strategic because regulation is moving faster than much of today’s infrastructure.
In this shifting environment, decisions about where infrastructure is located and who operates it have become decisions about governance.
The nationality and jurisdiction of the infrastructure operator dictate which legal frameworks apply to data and the extent of extraterritorial claims.
These jurisdictional factors have direct architectural consequences. Data centres must be built for adaptability, able to adjust as rules, risks and technologies evolve and trust must be embedded from the ground up.
Regulatory drivers
Hosting decisions for data and applications are increasingly shaped by data sovereignty and resilience laws, which influence both location and interconnection design. For financial services, the Digital Operational Resilience Act, applicable from January 2025, marks a pivotal regulatory milestone for the EU and the European Economic Area.
It requires regulated financial entities and their technology partners, such as data centres, to demonstrate their ability to withstand ICT disruption and report major incidents swiftly.
This points to a broader direction of travel. By 2030, international standards are likely to provide the backbone for simpler cross-border compliance without unnecessary duplication.
ISO standards provide recognized benchmarks for security, continuity and sustainability. They establish a unified control framework that spans multiple regimes through a single, coherent set of control.
In practice, certifications such as ISO/IEC 27001 and ISO/IEC 27701 are frequently requested and often mapped to NIS2 and DORA requirements in the EU and EEA. Meanwhile, NIST’s updated Cybersecurity Framework reinforces this consistency, giving stakeholders a shared model for risk management as digital operations scale across borders.
For data centres, these frameworks chart a clearer path to evidencing resilience and sustainability at a time when AI, increasing power density and new cooling methods are reshaping operations.
Ultimately, ISO and NIST provide common ground for aligning national rules, supporting the global spread of AI and cloud while keeping within diverse legal boundaries.
Yet, while international convergence is growing, the reality on the ground remains fragmented. GDPR continues to set the baseline across Europe; however, member states often add stricter national provisions, creating complexity for organizations hosting data across borders.
Outside Europe, China’s Personal Information Protection Law governs outbound transfers through security assessments, standard contracts or certification. The 2024 Cyberspace Administration of China rules exempted some data exports yet maintained strict control for ‘important data’, extending data export security assessment validity to three years.
Japan’s Act on the Protection of Personal Information allows transfers of data to designated countries or with consent and adequate safeguards. Vietnam’s Cybersecurity Law and Decree 53 add data-localisation and approval requirements for certain transfers.
In Canada, federal reform stalled in 2025, so obligations lean on provinces such as Québec’s Law 25, which requires transfer privacy impact assessments.
Regional perspectives
Data sovereignty is interpreted differently across markets, so compliance paths vary by region. France requires Health Data Hosting certification for hosting personal health data and the updated scheme requires physical hosting within the EEA with specified controls.
SecNumCloud further limits eligible cloud services through EU or EEA data residency, EU control of operations and safeguards against extra-territorial access.
In the UK, data centres have been designated Critical National Infrastructure, and the Cyber Security and Resilience Bill is expected to tighten incident reporting and supply-chain requirements. The Data Use and Access Act 2025 reforms UK data law, with changes phasing in through 2026.
In Japan, amendments to the Act on the Protection of Personal Information strengthened rules for third-country transfers, including disclosure and ongoing monitoring obligations. This sits alongside the EU–Japan agreement for an economic partnership, reinforced by a protocol in 2024 that supports the free and trusted flow of personal data between the two jurisdictions while maintaining high privacy standards.
The protocol highlights how state-level cooperation is becoming a prerequisite for frictionless cross-border data exchange. Customers often seek practical guidance against this backdrop, particularly where workloads span domestic and international infrastructure.
Design strategies
As frameworks evolve at different speeds and across regions, adaptability becomes a design requirement. Data centres can no longer be built as static assets; instead, they must evolve in step with regulation and demand.
Modular construction has become a key pillar of data centre strategies, reducing risk by allowing flexibility to adapt with demand or regulatory requirements mid-programme and enabling adjustments without complete redesigns.
Operators can introduce new security zones and monitoring controls that improve resilience in later phases while keeping earlier phases operational. This gives customers the option to migrate sensitive workloads into new halls designed with stricter compliance standards while leaving other environments unchanged.
Instead of a single monolithic facility, capacity arrives in repeatable blocks that can be fine-tuned in phases. When retrofits are required, the scope remains contained and customers can transition between data halls during planned maintenance or delivery windows.
This approach also tracks demand more closely, curbing stranded capacity and shortening time to readiness while aligning investment with real utilisation.
Sustainability gains follow. Modular designs target high-density AI zones, typically around 80–100 kW per rack, with readiness for liquid cooling and measurable gains in PUE, CUE and WUE.
Carrier-neutral campuses amplify these benefits by combining multi-cloud access with a choice of telecoms carriers and service providers, enabling organizations to assemble configurations that meet residency and latency requirements without lock-in.
On a single campus, teams can build diverse network paths through multiple carriers, ISPs and direct cloud on-ramps, reducing concentration risk and latency while keeping data within national boundaries when rules require it.
Operational partnerships and the road ahead
While design sets the framework, achieving sovereignty in practice depends on collaboration. No single operator can meet every regulatory demand. It takes a connected ecosystem built on transparency and shared assurance that includes legal, compliance, operational and technical expertise.
Secure, low-latency exchange rests on three key partnership groups. First, carrier-dense ecosystems and Internet Exchange Points, complemented by software-defined interconnection fabrics, provide short, diverse paths to users and partners.
Second, hyperscale clouds and their private on-ramps provide predictable performance for regulated workloads and enable secure, direct data transfer for AI services.
Third, security and governance partners matter. Guidance and threat intelligence from national authorities, resilient network operators and incident-response specialists support continuous assurance across the supply chain.
Alongside these technical relationships, customers and providers rely on governance tools such as Standard Contractual Clauses, data processing agreements, transfer privacy impact assessments and audit processes to evidence how data is handled and how cross-border flows are controlled.
Brought together on a carrier-neutral data centre campus, these elements deliver the proximity and flexibility customers need alongside real-time visibility into performance and compliance that supports audits and regulatory reporting.
This connected foundation allows operators to reroute or scale instantly when traffic spikes or regulatory conditions tighten. AI adoption then benefits from a three-layer foundation that embeds data sovereignty from the outset rather than adding it retrospectively.
Within this ecosystem, technology ensures systems, storage and transfers follow the rules through controls such as geo-fencing, logging and policy enforcement. Contracts set enforceable terms with providers and give customers audit rights where appropriate.
Operations embed these commitments into day-to-day practice through change management, regular testing and documented incident response. With these layers aligned, organisations can run modern workloads within national boundaries where required, support real-time collaboration across regions where permitted and adapt confidently as regulations evolve.
What comes next
Data sovereignty is no longer a constraint to work around; it is a design principle. By combining modular, high-density data centre facilities with carrier-neutral interconnection and recognised standards, operators can give customers the flexibility to grow, the evidence to satisfy regulators and the latency and resilience that modern services demand.
In this way, infrastructure becomes the stable foundation for innovation in an uncertain geopolitical landscape.

