As more New Zealand organisations move mission-critical systems and sensitive datasets to hyperscale cloud infrastructure, “data sovereignty” has become a key focus. The term is often reduced to “keeping data in New Zealand” and subject to New Zealand law.

This article presents a four-pillar framework - control, security, resilience, and location - for assessing data sovereignty in operational terms and provides a short checklist directors can use to evaluate whether cloud decisions are defensible and aligned to their organisation’s risk appetite.

Key takeaways

Data sovereignty is a risk and governance outcome, not a hosting-location decision.

When considering a move to hyperscale cloud, organisations should assess the decision across four pillars - control, security, resilience, and location. Any trade-offs between them should be explicitly identified and justified.

Treat sovereignty as an outcome. Test whether your organisation can control who accesses and uses the data, can meet its legal obligations, and can recover and/or exit if circumstances change.

Over-localisation can increase risk by concentrating exposure to seismic, weather, and infrastructure failure. For critical workloads, cross-border replication or backup to a trusted offshore region may improve resilience, and that option should be assessed alongside legal and regulatory obligations and data-locality assumptions.

Sovereignty governance is ongoing, not a one-time decision. Organisations should revisit their sovereignty posture regularly as technology, threats, regulation, and provider arrangements evolve.

Understanding hyperscale cloud

Hyperscale cloud refers to cloud computing platforms operated through large, globally distributed data centres. They can deliver vast computing, storage, and network resources on demand, scaling rapidly in response to changing workloads. These environments are designed to handle very large volumes of data and processing activities efficiently, supporting high availability and performance at scale.

Because data is stored and processed across globally distributed infrastructure managed by third‑party providers, hyperscale cloud can create challenges in determining where data physically resides, how it is accessed, and which legal regimes apply.

What data sovereignty is - and what it is not

There is no single settled definition of data sovereignty, and its meaning can be context dependent. For example, from a business perspective, it may mean a company’s ability to retain control and ownership of its data, and the ability to prevent access by cloud providers, foreign governments, and other parties. From a legal and regulatory perspective, it can mean the data is governed by the laws of the country where it is held or the laws of the country where the people the data relates to are located.

In practical terms, for any organisation considering use of cloud services, both perspectives will be relevant and will involve consideration of:

  • governance and decision rights (access, use, sharing, retention).

  • security controls (identity, encryption, monitoring, incident response).

  • legal and regulatory compliance (New Zealand and relevant foreign exposure).

  • resilience, recovery, and exit (backups, disaster recovery, portability, vendor/contract leverage).

Data sovereignty is broader than data localisation. Storing data in New Zealand does not automatically prevent foreign legal access, guarantee stronger security, or ensure operational resilience. Localisation can reduce resilience if it concentrates services into a small number of domestic facilities or legacy environments. Such concentration can increase exposure to seismic and weather events, power disruptions, and operational fragility, and can limit failover and recovery options.

In considering a move to hyperscale cloud, a practical first step for the board could be to distinguish between locality requirements that are non-negotiable (such as those that are driven by regulation) and those that reflect internal policy choices. Where a requirement is confirmed as non-negotiable, it should be treated as a hard constraint. Where it reflects an internal policy position, it remains a legitimate consideration but one that can be assessed alongside broader considerations of resilience, functionality, and operational complexity.

The following issues illustrate why the four-pillar assessment matters in practice. Each risk category should be considered not in isolation, but by reference to the organisation’s ability to maintain control, meet legal obligations, recover from disruption, and explain its decisions.

Foreign access

Foreign legal access is one of the most practically significant sovereignty risks for New Zealand organisations using hyperscale cloud. A common misconception is that storing data in New Zealand prevents foreign government access. It does not necessarily do so. For example, the US Clarifying Lawful Overseas Use of Data Act 2018 (CLOUD Act) allows US law enforcement agencies to compel US-headquartered providers to produce data held anywhere in the world via warrant or court order served on the US parent entity. The critical point is that, generally, it is the location of the provider, not the location of the data, which determines exposure.

The CLOUD Act also contains important limitations that are frequently overlooked. Cloud providers can legally challenge requests where compliance would create a conflict with the laws of another country. Boards should therefore assess CLOUD Act exposure in context ie as a structured legal process with procedural safeguards, rather than an unrestricted access right.

The CLOUD Act is not the only foreign legislation with potential extraterritorial reach. China's Data Security Law 2021 and Cybersecurity Law impose data localisation and outbound transfer obligations on China-connected entities and can require providers with Chinese operations to assist in national security investigations. The United Kingdom's Investigatory Powers Act 2016 similarly has extraterritorial reach. Organisations should consider the home jurisdiction and corporate structure of their provider, not just the location of the data centre, when assessing foreign access risk.

Privacy compliance

Where personal information is involved, the Privacy Act 2020 imposes obligations that cannot be derogated from by moving to cloud infrastructure. Information Privacy Principle 12 (IPP 12) prohibits an agency from disclosing personal information to an overseas recipient unless it believes on reasonable grounds that (amongst other things) the recipient is subject to privacy laws that provide comparable safeguards to the Privacy Act. The fact that a hyperscale provider has signed a Data Processing Addendum (DPA) does not automatically satisfy IPP 12. The substance of the protections in that DPA, the rights of the provider to use the data, and the legal regime to which the provider is subject, must be assessed.

The Office of the Privacy Commissioner (OPC) has published guidance on the use of cloud services, including how to assess whether comparable safeguards exist and what contractual protections are expected. Agencies subject to the Privacy Act should ensure they have reviewed the DPA offered by their cloud provider against the IPP 12 standard and the OPC's guidance.

Sector-specific requirements

Some sectors may impose additional regulatory requirements that will need to be assessed separately from general privacy and contractual protections when considering any potential hyperscale cloud move. For example, for organisations in the health sector, the Health Information Privacy Code 2020 imposes additional requirements on the handling of health information. Public sector organisations are also subject to the Public Records Act 2005, which imposes obligations around the retention, disposal and accessibility of official records that may interact with cloud storage and portability arrangements. These sector-specific regimes should be assessed separately.

Any sector-specific constraints should be identified early, so they can be built into the cloud architecture and contracting strategy rather than treated as an afterthought.

Māori data sovereignty

Any move to hyperscale cloud may also require consideration of Māori rights and interests in data about Māori people, communities, resources and taonga. For many organisations, this is central to trust and legitimacy where services affect Māori outcomes. These considerations are primarily about governance, consent, and stewardship (not just storage location). Cloud decisions may need to align with Te Tiriti o Waitangi commitments, and engagement and decision rights designed into the operating model.

AI and data sovereignty

AI introduces additional sovereignty considerations. Data may be processed through multiple pathways (including prompts, logs, embeddings, fine-tuning datasets). These create secondary use risks, particularly if provider terms permit use of customer data for model training, service improvement, or analytics. Boards should be satisfied that AI workloads are subject to explicit controls over data use, retention, access, and onward disclosure.

Why data sovereignty matters for New Zealand organisations

Sovereignty matters because it underpins the ability to achieve regulatory compliance and operational continuity. It requires boards to make informed decisions about the trade-offs between control, resilience, cost, and capability, particularly as mission-critical systems and sensitive datasets move to third-party platforms.

New Zealand’s Cyber Security Strategy 2026-2030 reinforces this framing. Boards are expected to prioritise cyber resilience, preparedness, and coordinated response across critical suppliers. Sovereignty decisions should be judged by whether they improve control, assurance, and recovery in practice, not by location alone.

Directors should be able to explain, in plain terms, how the organisation prevents unauthorised access, complies with applicable law, will recover from disruption, and will govern secondary uses such as analytics and AI.

A practical framework: four pillars of data sovereignty

The following four pillars provide a practical way to assess sovereignty and to test whether the proposed cloud arrangements produce the intended risk and governance outcomes:

  1. Control - governance over who can access data, for what purposes and on what terms, including identity management, encryption controls, contractual protections and exit rights.

  2. Security - strong technical and organisational safeguards to protect data from unauthorised access and cyber threats.

  3. Resilience - the ability to withstand and recover from disruption, supported by tested backup, disaster recovery and (where appropriate) geographic redundancy.

  4. Location - an informed understanding of where data is stored and processed, and how location interacts with legal and regulatory risks, without treating geography as determinative.

These pillars are interdependent. Optimising for one pillar can weaken another, for example strict localisation may reduce resilience. The organisation's choices across these pillars need to be balanced to ensure they are appropriately calibrated to the organisation’s regulatory obligations, risk tolerance, and operational priorities. Any trade-off should be identified and understood.

Key questions to ask before moving workloads to hyperscale cloud

The following questions are designed to help operationalise the four pillars. These questions should be raised with management and cloud advisors during decision-making and periodic reviews. They can assist boards in assessing whether sovereignty risks have been identified, mitigated, and aligned to the organisation's risk appetite.

1. Control

  • Is there clear board/executive accountability for data sovereignty, with documented risk acceptance and alignment to risk appetite?

  • Are access, encryption/key control, audit rights, and practical exit/portability clearly defined in contracts, avoiding lock-in that could undermine future decisions?

  • Have we identified which of our data-sovereignty and data-locality requirements are statutory or regulatory obligations (non-negotiable) and which are internal policy positions, and do we understand the resilience and functionality trade-offs each policy choice entails?

  • For AI workloads, are prompts/logs/outputs governed with explicit controls preventing vendor model training or secondary use?

2. Security

  • Does the cloud model improve security capability, with clear responsibilities, incident notification, and assurance reporting?

  • Can we point to independent third-party attestation (e.g. ISO 27001, SOC 2, or IRAP assessment) confirming that the provider’s security controls are implemented and operating effectively?

3. Resilience

  • Do we have tested redundancy/DR/BCP arrangements that avoid single points of failure and meet recovery objectives?

  • Does our cloud strategy support long-term operational continuity, innovation, and sustainability objectives, with resilience arrangements that match the criticality of each workload?

  • Have we considered whether cross-border replication or backup to a trusted offshore region is appropriate for our most critical workloads?

4. Location

  • Have we assessed New Zealand law (including Privacy Act 2020), sector requirements and expectations, and foreign jurisdictional exposure, with practical mitigations?

  • If data is hosted locally, have we assessed seismic, weather, and power risks, and whether localisation improves sovereignty outcomes or reduces resilience?

Closing remarks

Data sovereignty is ultimately about governance outcomes rather than the physical location of infrastructure alone. Boards that test cloud decisions against the four pillars of control, security, resilience, and location will be better positioned to make defensible, risk-aligned choices as hyperscale cloud adoption accelerates. The right balance will shift over time, so directors should ensure sovereignty settings are reviewed regularly, documented clearly, and adjusted as technology, threats, regulation and provider arrangements evolve. If your organisation is considering or already using hyperscale cloud, we recommend reviewing your current sovereignty posture against this framework and engaging early with legal, technology and risk advisors to ensure decisions are well-informed and defensible.

Get in touch with one of our experts.

Related Articles