The first wave of cloud adoption was about consolidation — moving servers out of back offices and into a handful of large public providers. That solved a real problem. It also created a new one: businesses increasingly don't know, or don't have a say in, which country their data actually lives in — and for a growing number of regulators and clients, that question now matters.
Why "Where" Is Becoming a Real Question
- Data protection law is tightening — Kenya's Data Protection Act and similar regulation elsewhere increasingly care about where personal data is processed and stored, not just how it's secured
- AI compute has specific infrastructure needs — running AI workloads efficiently often benefits from infrastructure placed closer to where the data and the users actually are
- Client contracts increasingly specify it — some clients, particularly larger or regulated ones, now ask directly where their data will be hosted before agreeing to work with a vendor
- Resilience concerns — depending entirely on infrastructure in a single distant region carries risk that a hybrid or local setup can reduce
What "Hybrid" Actually Looks Like
This doesn't mean abandoning public cloud providers — it means being deliberate about what runs where. Customer-facing applications might stay on a fast, globally distributed public cloud. Sensitive customer data, particularly anything covered by local data protection requirements, might sit on infrastructure specifically chosen (or contractually confirmed) to stay within a given jurisdiction. The goal is matching the infrastructure choice to what each type of data actually requires, rather than defaulting everything to one provider by habit.
What This Means for a Growing Business
Most small and medium businesses don't need to solve this today with a complex multi-cloud architecture. What's worth doing now is simpler: know where your customer data is actually stored, understand what your local data protection law requires, and ask your vendors the same question you'd expect a client to ask you. The businesses caught off guard by this shift won't be the ones with complicated infrastructure — they'll be the ones who never asked the question at all.
The AI Compute Angle, in Plain Terms
Running AI workloads efficiently often benefits from infrastructure that's physically closer to both the data being processed and the people using the result — latency and data transfer costs both favor proximity. As more businesses build AI features into their own products, this quietly pushes some infrastructure decisions toward regional or local providers, not because of regulation, but because of plain performance and cost, in addition to the compliance angle covered above.
Questions Worth Asking Your Current Provider
- Where physically is our data stored and processed, and can that be confirmed contractually, not just assumed?
- What happens to our data if we switch providers — is it portable, or effectively locked in?
- Does our current setup meet what Kenya's Data Protection Act actually requires, or has nobody checked since it was first set up?
- If this provider's region were unavailable for a day, what would that mean for our business?
What This Doesn't Mean
None of this means public cloud providers are becoming obsolete, or that every business needs a complex hybrid setup immediately. For most small and medium businesses, the actual action item is much smaller: understanding where data currently sits, and building in the flexibility to make a different choice later if requirements change. Overreacting with a costly infrastructure overhaul before it's genuinely needed is its own kind of mistake.