Data Sovereignty and Cloud Governance in Africa: A New Digital Power Play
Across Africa, governments, regulators and enterprises are rethinking where their data lives and who ultimately controls it. As hyperscale cloud regions proliferate from Johannesburg to Nairobi, “Data Sovereignty and Cloud Governance in Africa” has shifted from a niche legal issue to a board-level priority. The stakes are high: decisions taken in the next few years will shape how African businesses access AI, how states protect citizens’ rights, and whether the continent can avoid a new era of digital dependency.
Why Data Sovereignty Is Back on the Agenda
“Data sovereignty” is the idea that data generated within a country should be subject to that country’s laws and oversight, even when stored or processed elsewhere. For African policymakers, it has become a proxy for broader questions about economic power, security and digital industrialisation.
Two developments are pushing the issue up the agenda:
- Rapid cloud expansion: Global providers like Microsoft, Amazon Web Services and Google Cloud have launched or expanded African regions in South Africa, with edge locations and smaller regions emerging in countries like Kenya, Nigeria and Egypt.
- New regulatory frameworks: Countries across the continent are rolling out or tightening data protection and cybersecurity laws, often modelled on the EU’s GDPR but adapted to local realities.
In 2024, South Africa adopted a National Policy on Data and Cloud that explicitly links cloud infrastructure, national security and digital industrialisation, signalling that data is now seen as a strategic national asset rather than a mere by-product of digital services.[1]
South Africa’s Policy Pivot on Data and Cloud
South Africa is emerging as a bellwether for Data Sovereignty and Cloud Governance in Africa. The country’s Protection of Personal Information Act (POPIA) has already set a baseline for lawful processing, breach notification and data subject rights. But the 2024 National Policy on Data and Cloud goes further.
According to a Government Gazette publication of the policy, all data collected within South Africa’s borders must be processed in line with South African laws, and certain categories of sensitive government data must be stored only on infrastructure located in the country.[1] A subsequent analysis by law firm ENSafrica notes that the policy aims to “guarantee the secure and reliable storage of data in the cloud” and align with POPIA’s security requirements.[2]
For South African enterprises, this policy shift has practical implications:
- Cloud contracts: Organisations need greater transparency on where data is stored, which jurisdictions apply, and how cross-border transfers are justified under POPIA.
- Hybrid architectures: Many are adopting hybrid and multi-cloud strategies to keep certain workloads in local data centres while leveraging global platforms for AI, analytics and collaboration.
- Vendor selection: Preference is growing for providers that can demonstrate compliance with local law, support data residency requirements and offer clear incident response processes.
At the same time, policymakers must balance sovereignty goals with the need to attract cloud investment and avoid isolating South African firms from global data flows.
Data Sovereignty and Cloud Governance in Africa: A Patchwork of Laws
Zooming out, Data Sovereignty and Cloud Governance in Africa is currently defined by a patchwork of national laws, regional strategies and emerging continental frameworks rather than a single, unified regime.
The African Union’s 2024 Data Policy Framework describes data sovereignty as the expectation that data generated in or passing through national networks should be controlled under local jurisdiction and governance.[3] It urges member states to align national laws with shared principles on privacy, cross-border data flows and digital trade, echoing earlier instruments like the Malabo Convention on cybersecurity and data protection.
In practice, however, implementation varies widely:
- Mature regimes: Countries such as South Africa, Kenya, Nigeria and Morocco have functioning data protection authorities, detailed regulations and active enforcement.
- Emerging regimes: Several states have passed data protection laws but lack the institutional capacity to enforce them consistently.
- Regulatory gaps: A minority remain without comprehensive data protection frameworks, relying on sectoral rules or general privacy provisions in their constitutions.
Research cited in an “African quest for digital sovereignty” report notes that as of 2024, a majority of African data protection laws regulate or restrict cross-border data transfers, often requiring some form of adequacy assessment or safeguards before personal data can be exported.[4] Yet definitions of “adequate protection”, “critical data” and “public interest” can differ significantly from one jurisdiction to another.
Kenya, Cross-Border Transfers and the Politics of Flow
Kenya provides a useful case study of how regulators are trying to govern data flows without shutting the door on global cloud services. The country’s Data Protection Act (2019) and associated regulations require data controllers and processors to ensure appropriate safeguards when transferring personal data abroad, including proof of adequate protection or explicit consent from data subjects.[5]
Guidance from the Office of the Data Protection Commissioner (ODPC) emphasises:
- Legal bases for transfer: Transfers can rely on adequate safeguards, an adequacy decision by the Data Commissioner, necessity (for contracts, public interest or vital interests) or consent.
- Regulatory oversight: Organisations must notify the ODPC about cross-border transfers to enable monitoring and enforcement.
- Onward transfers: Additional restrictions apply to ensure data is not passed on to third parties in jurisdictions with weak protections.
These rules directly affect cloud strategies for Kenyan organisations in sectors like fintech, health and logistics, where international platforms are common. They also influence how regional cloud providers design their networks: edge locations, caching, and mirrored storage are now as much about regulatory optimisation as they are about performance.
Balancing Digital Sovereignty and Digital Colonialism
Debates around Data Sovereignty and Cloud Governance in Africa are deeply intertwined with concerns about “digital colonialism” – the idea that foreign firms could dominate African data infrastructures and reap most of the economic value from local data.
A 2026 article in the journal Data & Policy on artificial intelligence and digital colonialism argues that African countries need to safeguard digital sovereignty by promoting data localisation, investing in local infrastructure and ensuring AI systems align with national priorities.[6] Meanwhile, a policy analysis by New America warns of an “Africa’s digital sovereignty trap” in which aggressive localisation policies might inadvertently reinforce dependence on a small set of large providers capable of meeting stringent requirements.[7]
This tension plays out in several ways:
- Infrastructure ownership: Many African data centres and undersea cables are financed or operated by foreign consortia, raising questions about operational control and jurisdiction.
- AI and cloud services: Access to advanced AI models, analytics and security services often depends on foreign cloud platforms, which may be governed by non-African law.
- Local industry growth: Overly restrictive localisation rules could raise costs for local startups and SMEs, making it harder for them to compete regionally or globally.
Policymakers are therefore walking a tightrope: asserting sovereignty without stifling innovation or cutting off access to the very tools needed for digital transformation.
Emerging Models: Data Embassies and Regional Trust Frameworks
Beyond traditional localisation, new models are being explored to reconcile sovereignty with the reality of distributed networks. Academic work on “data embassies” – secure data centres in foreign jurisdictions that remain under the legal control of the home state – suggests one way African countries could back up critical data while maintaining jurisdictional control.[3]
On a regional level, the African Union’s Data Policy Framework calls for:
- Harmonised definitions: Standardising concepts like “sovereign data” and “critical infrastructure” to reduce regulatory fragmentation.