๐Ÿ“‹ How-To Guide

Data Sovereignty in Southeast Asia

Where your data lives, who can access it, and what each ASEAN country requires โ€” a practical guide for financial institutions operating across the region.

Southeast Asia's data sovereignty landscape is moving faster than any other region in the world. Vietnam enacted ASEAN's first standalone AI law in December 2025. Indonesia's comprehensive data protection law became fully enforceable in October 2024, though its enforcement agency has yet to be established. Thailand issued its first major PDPA fines in 2025. Malaysia allocated RM2 billion for a sovereign AI cloud. Cambodia's National Bank mandates data residency for financial institutions. And ASEAN endorsed a cross-border cloud computing framework with Trusted Data Corridors in January 2026. For financial institutions operating across the region โ€” banks, fund managers, insurers, fintechs โ€” each country presents different requirements, different enforcement realities, and different risks. This guide maps the landscape country by country, with specific regulatory references, enforcement status, and practical implications for institutions that need to know where their data can go and who can compel access to it.

Step-by-Step Checklist

1. Understand the Three Concepts

Data sovereignty, data residency, and data localisation are three different legal concepts. Conflating them is how institutions end up non-compliant despite believing their data is protected. Understanding the distinction is the foundation for every decision that follows.

Data sovereignty is the legal principle that a nation's laws govern data collected within its borders or about its citizens. It does not matter where the data is physically stored โ€” if you process data about Indonesian residents, Indonesian law applies. If your cloud provider is incorporated in the United States, US law also applies via the CLOUD Act, which lets US authorities compel American-headquartered providers to hand over data regardless of where it sits. This jurisdictional overlap is the core problem that data sovereignty decisions must address.

Data residency means keeping data physically within a specific country's borders. It is a choice you make with your infrastructure provider. Hosting your servers in Singapore means your data resides in Singapore โ€” but if your provider is a US company, the data is still subject to US jurisdictional reach. Residency addresses geography. Sovereignty addresses legal authority.

Data localisation is a government mandate requiring certain categories of data to remain within the country. Indonesia's GR 71/2019 requires strategic public sector data to be stored domestically. Cambodia's NBC requires financial data to remain in-country. Some ASEAN countries have sector-specific localisation rules even when they lack general localisation mandates. Localisation is not optional โ€” it is law.

For financial institutions, the practical implication is that choosing a data centre location is necessary but not sufficient. You must also consider the legal jurisdiction of your provider, the nationality of the data subjects, the sector-specific rules that apply, and the cross-border transfer mechanisms available in each country where you operate.

Recommended tools
  • Jurisdictional mapping: For each data type your institution processes, map the applicable laws: country of data subject, country of data storage, country of provider incorporation, and country of processing.
  • CLOUD Act assessment: Identify which of your technology providers are US-headquartered and therefore subject to CLOUD Act compulsion, regardless of where they host your data.
Regulatory references
  • US CLOUD Act (2018): Compels US-incorporated providers to produce data stored anywhere in the world when served with a warrant. Applies to all major US cloud and AI providers.
Verification checklist
  • Distinguish between sovereignty (legal authority), residency (physical location), and localisation (legal mandate) in your data strategy
  • Map every technology provider's country of incorporation โ€” not just their server locations
  • Identify which data types are subject to localisation mandates in each country where you operate
  • Assess CLOUD Act exposure for all US-headquartered providers in your technology stack
Key question

Do you know which governments can legally compel access to your institution's data โ€” and through which providers?

2. Singapore โ€” The Regional Standard

Singapore's Personal Data Protection Act 2012 is the most mature data protection framework in Southeast Asia. With mandatory DPO appointment since June 2025, active enforcement, and proposed AI-specific guidelines, Singapore sets the benchmark that other ASEAN countries are converging toward.

The PDPA governs collection, use, disclosure, and storage of personal data. It applies to all organisations in Singapore and to overseas organisations processing data of Singapore residents. The Personal Data Protection Commission (PDPC) has been actively enforcing since 2014, with over 200 enforcement decisions published. Mandatory breach notification requires PDPC notification within three calendar days of assessing a notifiable breach.

Singapore does not impose general data localisation requirements. The PDPA's transfer limitation obligation (Part 5A) allows cross-border transfers provided the receiving jurisdiction offers comparable protection, or appropriate contractual safeguards are in place. This flexibility has made Singapore a regional data hub โ€” but it also means that financial institutions must conduct transfer impact assessments for every cross-border data flow.

MAS has proposed AI Risk Management Guidelines (AIRG) for financial institutions, consulted on in late 2025, covering the full AI lifecycle. The proposed AIRG introduces mandatory AI inventories, risk materiality assessments, and human oversight requirements. While not yet in force, the guidelines signal that MAS will regulate AI as a subset of existing technology risk management (TRM Guidelines), not through separate AI-specific legislation.

Singapore's role as an ASEAN data governance leader is formalised through its co-leadership of the ASEAN Guide on AI Governance and Ethics (2024) and the ASEAN Framework on Cross-border Cloud Computing (January 2026). For financial institutions, Singapore-based infrastructure provides the strongest combination of regulatory maturity, enforcement predictability, and cross-border transfer flexibility in the region.

Recommended tools
  • Singapore-hosted infrastructure: Self-hosted or Singapore-region cloud infrastructure eliminates cross-border transfer complexity for Singapore-regulated entities.
  • PDPC Transfer Impact Assessment: Structured assessment framework for evaluating cross-border data transfers under PDPA Part 5A.
Regulatory references
  • Personal Data Protection Act 2012 (PDPA): Singapore's comprehensive data protection framework. Mandatory DPO since June 2025. Breach notification within 3 calendar days.
  • PDPA Part 5A (Transfer Limitation Obligation): Cross-border transfers require comparable protection or appropriate safeguards.
  • MAS Technology Risk Management Guidelines (January 2021): Comprehensive technology risk framework for financial institutions covering governance, security, resilience, and access management.
  • MAS Proposed AIRG (Consultation 2025): Proposed AI Risk Management Guidelines for financial institutions. 12-month implementation from issuance.
Verification checklist
  • Confirm DPO appointment is current and registered with PDPC
  • Conduct transfer impact assessments for all cross-border data flows
  • Align technology infrastructure with MAS TRM Guidelines
  • Assess readiness for proposed MAS AIRG requirements
  • Review data processing agreements with all vendors for PDPA compliance
  • Ensure breach notification procedures can meet the 3-calendar-day PDPC deadline
Key question

Are your cross-border data transfers documented with transfer impact assessments for each receiving jurisdiction?

3. Indonesia โ€” Comprehensive Framework, Enforcement Pending

Indonesia enacted its Personal Data Protection Law (UU PDP, Law No. 27 of 2022) with a two-year transition that ended on 17 October 2024. All organisations must now comply. However, the national Data Protection Agency has not yet been established, and implementing regulations remain in draft. The law is live, but enforcement infrastructure is still being built.

The UU PDP is modelled on the EU's GDPR and consolidated more than 30 fragmented regulations into a single framework. It distinguishes between data controllers and data processors, requires legal bases for processing (including consent and legitimate interest), mandates breach notification, and imposes criminal penalties of up to six years imprisonment and IDR 6 billion fines for intentional violations. Administrative sanctions include written warnings, suspension of processing, deletion of data, and compensation to data subjects.

Data localisation is required for certain categories under GR 71/2019, which mandates that public electronic system operators store strategic data domestically. Financial sector regulations add further localisation requirements โ€” OJK Regulation 3/2024 requires fintech data centres and recovery centres to be located within Indonesia. For financial institutions, this means certain data cannot leave Indonesia regardless of contractual safeguards.

The draft implementing regulation (RPP PDP) has been in the harmonisation stage at the Ministry of Law since October 2025. The PDP Agency is targeted to become operational in 2026, but no appointment has been made as of August 2026. Despite this gap, Komdigi (the Ministry of Communication and Digitals) has conducted active compliance monitoring โ€” reviewing approximately 350 digital platforms during 2024-2025 and identifying violations on 41% of websites and 34% of mobile applications.

For financial institutions operating in Indonesia, the practical situation is that the law is enforceable, violations carry criminal liability, but the dedicated enforcement agency does not yet exist. Sector regulators (OJK for financial services, BI for payment systems) have their own data protection provisions that apply concurrently. The safest approach is full compliance with the UU PDP now, rather than waiting for the PDP Agency to be established and begin enforcement.

Recommended tools
  • UU PDP compliance assessment: Gap analysis against the full UU PDP requirements: legal bases, consent management, breach notification, cross-border transfers, and DPO appointment.
  • Indonesian data localisation mapping: Identify which data categories are subject to localisation mandates under GR 71/2019 and OJK sectoral regulations.
Regulatory references
  • Law No. 27 of 2022 (UU PDP): Indonesia's comprehensive Personal Data Protection Law. Fully enforceable since 17 October 2024. Criminal penalties up to 6 years and IDR 6 billion.
  • Government Regulation No. 71/2019: Requires strategic data from public electronic system operators to be stored domestically. Defines data localisation for certain categories.
  • OJK Regulation No. 3 of 2024: Requires fintech data centres and data recovery centres to be located within Indonesia.
Verification checklist
  • Assess full UU PDP compliance โ€” do not wait for the PDP Agency to be established
  • Map data categories against GR 71/2019 localisation requirements
  • Review OJK sectoral regulations for financial services-specific data obligations
  • Ensure Indonesian data processing infrastructure meets domestic hosting requirements where applicable
  • Prepare for PDP Agency establishment โ€” have compliance documentation ready for potential inspection
  • Monitor Komdigi enforcement activity and RPP PDP development
Key question

Are you compliant with the UU PDP today, or are you waiting for the PDP Agency to be established before acting?

4. Vietnam โ€” First AI Law in ASEAN

Vietnam became the first Southeast Asian country to enact standalone AI legislation when its National Assembly adopted Law No. 134/2025/QH15 on 10 December 2025, effective 1 March 2026. Combined with its new Personal Data Protection Law (effective 1 January 2026), Vietnam now has the most comprehensive data and AI regulatory framework in ASEAN.

Vietnam's AI Law adopts a risk-based classification system modelled on the EU AI Act, categorising AI systems into high, medium, and low risk tiers with corresponding compliance obligations. High-risk categories include AI in healthcare, education, and finance โ€” all directly relevant to financial institutions. The law also prohibits certain AI uses entirely, including non-consensual facial recognition and malicious deepfakes. The National AI Committee is to be established by July 2026.

The AI Law places specific emphasis on data sovereignty. Unlike the EU AI Act, which prioritises multilateral frameworks, Vietnam's approach asserts state oversight of data flows and requires AI providers to protect Vietnamese data sovereignty, cultural values, and national security. Foreign companies operating AI systems with Vietnamese users are covered, including SaaS platforms. Most businesses have until March 2027 to comply; healthcare, education, and finance entities have until September 2027.

Vietnam's Personal Data Protection Law (PDPL), passed June 2025 and effective January 2026, replaced the earlier Decree 13/2023. It establishes comprehensive consent requirements, recognises alternative legal bases for processing (legitimate interest, contractual necessity), and requires breach notification. Implementing Decree 356/2025 provides granular rules on consent methods. The PDPL applies to all processing of Vietnamese personal data, regardless of where the processing entity is located.

For financial institutions, Vietnam presents the most complex regulatory environment in ASEAN. The combination of a comprehensive data protection law, a standalone AI law with sector-specific timelines, and a government that prioritises sovereign control over data flows means that any AI-powered financial service touching Vietnamese users must navigate multiple concurrent compliance obligations. Self-hosted infrastructure within Vietnam may be the most practical path to compliance.

Recommended tools
  • Vietnam AI risk classification: Self-assessment framework for classifying AI systems under the three-tier risk model. Financial sector AI systems are likely high-risk.
  • PDPL compliance mapping: Gap analysis against Vietnam's PDPL requirements, including consent, legal bases, breach notification, and cross-border transfers.
Regulatory references
  • Law No. 134/2025/QH15 (AI Law): ASEAN's first standalone AI legislation. Risk-based classification, mandatory self-assessment, transparency requirements. Effective 1 March 2026.
  • Personal Data Protection Law (PDPL, June 2025): Comprehensive data protection framework replacing Decree 13/2023. Effective 1 January 2026.
  • Decree 356/2025: Implementing decree for the PDPL providing granular rules on consent, legal bases, and data subject rights.
Verification checklist
  • Classify all AI systems operating in Vietnam under the three-tier risk framework
  • Register high-risk AI systems with the competent authority before the sector deadline (September 2027 for finance)
  • Ensure PDPL compliance for all processing of Vietnamese personal data
  • Assess whether AI systems comply with Vietnam's data sovereignty requirements
  • Appoint a local coordinator if operating AI systems from outside Vietnam
  • Monitor establishment of the National AI Committee (due July 2026)
Key question

Have you classified your AI systems under Vietnam's risk framework, and do you know which compliance deadline applies to your sector?

5. Thailand โ€” Active Enforcement, AI Act Emerging

Thailand's PDPA has moved from awareness-building to active enforcement. The PDPC issued its first major fines in 2024-2025, totalling over THB 21.5 million. A draft AI Act is under development. Thailand does not currently mandate data localisation, but financial institutions face sector-specific requirements from the Bank of Thailand.

The PDPA, fully enforced since June 2022, is modelled on the EU's GDPR. Thailand's enforcement has accelerated significantly โ€” the landmark THB 7 million fine involved a customer data leak exploited in scam operations, with findings of insufficient security and failure to appoint a DPO. The Worldcoin enforcement action in late 2025, ordering deletion of approximately 1.2 million users' iris scan data, demonstrated the PDPC's willingness to act against major international technology companies.

Thailand does not impose general data localisation requirements. Cross-border transfers require one of several mechanisms: adequacy decisions (none issued as of 2026), PDPC-approved standard contractual clauses, binding corporate rules, or explicit informed consent. The absence of adequacy decisions means most institutions rely on contractual safeguards or consent โ€” creating compliance complexity for multi-jurisdictional operations.

A draft AI Act was published for consultation in mid-2026, proposing Thailand's first dedicated AI legal framework. It would create a risk-based system similar to Vietnam's and the EU's, with extraterritorial reach โ€” foreign AI providers whose systems affect people in Thailand fall within scope even without Thai presence. The Bank of Thailand has separately issued AI guidelines for financial services focusing on risk management and transparency.

PDPA amendments are also under consultation. Proposed changes include clarifying controller and processor definitions, restructuring legal bases to reduce over-reliance on consent, and improving the framework for AI-driven processing. No amendments have been enacted as of August 2026, but the direction of travel is toward stricter and more AI-aware regulation. The ETDA has also launched consultations on AI data protection guidelines specifically addressing the intersection of PDPA and AI processing.

Recommended tools
  • PDPA compliance framework: Comprehensive assessment against Thailand's PDPA requirements including consent, DPO appointment, breach notification, and transfer mechanisms.
  • Bank of Thailand AI alignment: Assessment of AI systems against Bank of Thailand guidelines for AI in financial services.
Regulatory references
  • Personal Data Protection Act B.E. 2562 (2019): Thailand's comprehensive data protection law. Fully enforced since June 2022. Active enforcement with fines exceeding THB 21.5 million.
  • Draft AI Act (2026): Proposed standalone AI legislation with risk-based classification and extraterritorial reach. Under consultation.
  • Bank of Thailand AI Guidelines: Sector-specific AI guidance for financial institutions focusing on risk management, transparency, and governance.
Verification checklist
  • Ensure full PDPA compliance โ€” enforcement is now active with significant fines
  • Appoint a DPO if not already done (failure was a factor in the THB 7M fine)
  • Document cross-border transfer mechanisms for all Thai personal data leaving the country
  • Review AI systems against Bank of Thailand guidelines
  • Monitor the draft AI Act consultation โ€” extraterritorial provisions may apply to your operations
  • Implement biometric data handling procedures (the Worldcoin action signals high scrutiny)
Key question

If the Thai PDPC investigated your data handling today, would they find a DPO appointed, transfers documented, and security measures adequate?

6. Malaysia โ€” Sovereign AI Cloud and PDPA Reform

Malaysia is making the largest sovereign AI infrastructure investment in ASEAN โ€” RM2 billion for a sovereign AI cloud announced in the 2026 budget. Simultaneously, the PDPA was significantly amended in July 2024 to align with international standards. Malaysia does not mandate general data localisation, but the direction of travel is clearly toward greater sovereign control.

The PDPA 2010 was substantially amended in 2024, introducing direct obligations for data processors, a more flexible cross-border transfer regime, mandatory breach notification, and appointment requirements for Data Protection Officers. The amendments align Malaysia's framework more closely with the EU's GDPR. The Personal Data Protection Commissioner has issued supplementary guidelines on consent, data protection by design, and transfer mechanisms.

Malaysia's RM2 billion sovereign AI cloud, announced by Prime Minister Anwar Ibrahim in the 2026 budget speech, aims to keep AI models trained, stored, and deployed locally under Malaysian law. The broader 2026 budget allocated RM5.9 billion to AI and digital infrastructure. Malaysia launched Southeast Asia's first sovereign full-stack AI infrastructure in May 2025, using Huawei's Ascend chips โ€” a choice that has drawn geopolitical attention given US-China tensions.

Cross-border data transfers are permitted under section 129 of the PDPA, provided the receiving jurisdiction has substantially similar data protection laws or the Commissioner grants approval. No strict data localisation mandate exists. However, for sensitive AI applications in healthcare and finance, the practical guidance increasingly recommends using Malaysian data centres, processing data locally before sending only aggregated or anonymised data overseas, or deploying AI on-premise.

The National AI Office (NAIO), established in December 2024 under the Ministry of Digital, coordinates AI policy, regulation, and adoption. The AI Governance and Ethics (AIGE) guidelines provide a voluntary framework for responsible AI. Malaysia's AI Technology Action Plan 2026-2030 sets the goal of becoming an AI Nation by 2030. For financial institutions, Malaysia's combination of PDPA reform, sovereign AI investment, and strategic AI ambitions creates a jurisdiction where data sovereignty is becoming a national priority, not just a compliance checkbox.

Recommended tools
  • Malaysian PDPA compliance assessment: Gap analysis against the amended PDPA 2010, including the new processor obligations, DPO requirements, and breach notification provisions.
  • Sovereign infrastructure evaluation: Assessment of whether Malaysian sovereign AI cloud options meet your institution's processing requirements and data sovereignty needs.
Regulatory references
  • Personal Data Protection Act 2010 (amended July 2024): Malaysia's data protection framework, significantly amended in 2024. Direct processor obligations, mandatory breach notification, DPO appointment.
  • PDPA Section 129 (Cross-border transfers): Permits transfers to jurisdictions with substantially similar laws or with Commissioner approval.
  • National AI Office (NAIO, December 2024): Coordinates AI policy under the Ministry of Digital. Oversees AIGE guidelines and AI Technology Action Plan 2026-2030.
Verification checklist
  • Assess compliance with the amended PDPA 2010 including new processor obligations
  • Evaluate sovereign AI cloud options for Malaysian operations
  • Document cross-border transfer mechanisms under PDPA section 129
  • Review AI systems against AIGE voluntary guidelines
  • Monitor NAIO developments and potential mandatory AI regulations
  • Consider geopolitical implications of sovereign infrastructure choices (US vs Chinese technology)
Key question

Are your Malaysian operations prepared for a jurisdiction where sovereign AI infrastructure is becoming national policy?

7. Cambodia โ€” Banking Sector Data Residency

Cambodia's data protection framework is less mature than its ASEAN neighbours, but the National Bank of Cambodia (NBC) imposes specific data residency requirements on financial institutions. For banks, payment service providers, and fintechs operating in Cambodia, NBC regulations are the binding constraint โ€” not a general data protection law.

Cambodia does not have a comprehensive data protection law comparable to Singapore's PDPA or Indonesia's UU PDP. A draft Law on Personal Data Protection has been under development, but enactment timelines remain uncertain. In the absence of general legislation, data protection is governed by sector-specific regulations, particularly from the NBC for financial services.

The NBC requires licensed financial institutions to maintain data centres and core banking systems within Cambodia. This is a hard localisation requirement โ€” not a preference, not a guideline. Financial data must reside on infrastructure physically located in the country. For international banks and fintechs entering the Cambodian market, this means local infrastructure deployment is mandatory, not optional.

Cambodia's financial sector is rapidly digitalising. Mobile payments, digital banking, and fintech services are growing quickly, creating large volumes of financial data subject to NBC data residency mandates. The NBC has also been developing guidelines on cybersecurity and operational resilience for financial institutions, which include requirements around data handling, access controls, and incident response.

For financial institutions with Cambodian operations, the key challenge is deploying compliant infrastructure in a market with limited local data centre options compared to Singapore or Malaysia. The practical choices are co-location in Cambodian data centres, managed infrastructure from regional providers with Cambodian presence, or self-hosted servers within the country. Cloud-only approaches using regional data centres in Singapore or elsewhere do not satisfy NBC localisation requirements.

Recommended tools
  • NBC compliance assessment: Review of data residency and infrastructure requirements specific to NBC-licensed financial institutions.
  • Cambodian infrastructure options: Evaluation of local data centre, co-location, and managed infrastructure options within Cambodia.
Regulatory references
  • NBC Prakas on Data Residency: Requires licensed financial institutions to maintain data centres and core systems within Cambodia.
  • NBC Cybersecurity Guidelines: Operational resilience and cybersecurity requirements for financial institutions including data handling and incident response.
Verification checklist
  • Verify that all financial data for Cambodian operations resides on infrastructure physically in Cambodia
  • Ensure core banking systems meet NBC localisation requirements
  • Evaluate local data centre options for Cambodian infrastructure deployment
  • Monitor development of Cambodia's draft Personal Data Protection Law
  • Align Cambodian operations with NBC cybersecurity guidelines
  • Plan for increasing regulatory maturity โ€” build infrastructure that can accommodate future data protection requirements
Key question

Does your Cambodian financial data reside on infrastructure physically located within Cambodia, as NBC regulations require?

8. Philippines โ€” Mature Framework, Growing Enforcement

The Philippines enacted the Data Privacy Act (DPA) in 2012, making it one of the earliest comprehensive data protection frameworks in ASEAN. The National Privacy Commission (NPC) has been actively enforcing since 2016. For financial institutions, the Philippines offers a relatively predictable regulatory environment with established enforcement precedent.

The Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations provide a comprehensive framework covering personal data processing, data subject rights, mandatory breach notification, and cross-border transfers. The law applies to processing of personal data by government and private entities, including those outside the Philippines that process data of Philippine residents or use equipment located in the Philippines.

The NPC has issued numerous enforcement decisions and guidance circulars since becoming operational in 2016. Breach notification is mandatory within 72 hours of discovery or reasonable belief that a breach has occurred. The NPC maintains a public register of Data Protection Officers and publishes compliance orders, enforcement decisions, and advisory opinions. This transparency makes the Philippines one of the more predictable data protection environments in ASEAN.

Cross-border data transfers are permitted subject to conditions including consent, contractual obligations, international agreements, or when necessary for legal claims. The DPA does not impose general data localisation requirements, but the Bangko Sentral ng Pilipinas (BSP) has issued sector-specific guidelines for financial institutions on technology risk management and cloud computing that include data handling requirements.

For financial institutions, the Philippines' combination of mature legislation, active enforcement, and relatively flexible cross-border transfer rules makes it a manageable jurisdiction. The key risk is complacency โ€” the NPC's enforcement capacity has been growing, and the 72-hour breach notification requirement is among the strictest in ASEAN.

Recommended tools
  • DPA compliance assessment: Gap analysis against the Data Privacy Act and NPC guidance circulars, including registration, breach notification, and DPO appointment.
  • BSP technology risk alignment: Assessment of AI and data systems against BSP guidelines on technology risk management for financial institutions.
Regulatory references
  • Data Privacy Act of 2012 (Republic Act No. 10173): Philippines' comprehensive data protection law. Mandatory 72-hour breach notification. Active NPC enforcement since 2016.
  • NPC Circular 16-03 (Breach Notification): Requires notification to NPC and affected data subjects within 72 hours of discovery or reasonable belief of a personal data breach.
  • BSP Technology Risk Management Guidelines: Sector-specific requirements for financial institutions on technology risk, cloud computing, and data handling.
Verification checklist
  • Register your Data Protection Officer with the NPC
  • Ensure 72-hour breach notification capability is operational
  • Review cross-border transfer mechanisms for Philippine personal data
  • Align with BSP technology risk guidelines for financial operations
  • Monitor NPC advisory opinions and enforcement decisions relevant to your sector
  • Document data processing activities and maintain records of processing as required by the DPA
Key question

Can your institution notify the NPC within 72 hours of discovering a personal data breach affecting Philippine residents?

9. ASEAN Frameworks โ€” Cross-Border Coordination

ASEAN has been developing regional frameworks to coordinate data governance and AI regulation across member states. The key developments โ€” the Cross-border Cloud Computing Framework, the Guide on AI Governance and Ethics, and the ASEAN Responsible AI Roadmap โ€” provide a common language and direction, even as individual countries implement different rules at different speeds.

The ASEAN Framework on Cross-border Cloud Computing, endorsed in January 2026, introduces Trusted Data Corridors between accredited data centres in member states. This is a significant step toward interoperable data governance across ASEAN โ€” it creates a mechanism for data to flow between countries under agreed security and governance standards, without requiring bilateral agreements for each transfer. First corridors are expected between Singapore, Malaysia, and Indonesia.

The ASEAN Guide on AI Governance and Ethics (2024), co-led by Singapore, established voluntary principles including transparency, fairness, accountability, human-centricity, privacy, safety, and reliability. This was extended in January 2025 to cover generative AI with nine areas of concern. Unlike Vietnam's mandatory AI law, ASEAN's regional approach is principles-based and voluntary โ€” which means it provides direction without creating enforceable obligations.

The ASEAN Responsible AI Roadmap (2025-2030) sets a multi-year plan for AI governance coordination across the bloc. It acknowledges that member states are at different stages of AI regulatory development and focuses on building common capacity, shared standards, and interoperable frameworks. For financial institutions, the roadmap signals convergence โ€” even if individual countries move at different speeds, the direction is toward comparable frameworks.

The practical implication for financial institutions operating across ASEAN is that regional frameworks exist but do not replace national law. You must comply with each country's specific requirements while using ASEAN frameworks as guidance for building cross-border data architectures. The Trusted Data Corridors concept, once operational, may simplify multi-jurisdictional compliance โ€” but until corridors are established, country-by-country compliance remains the requirement.

Recommended tools
  • ASEAN framework alignment assessment: Evaluate your institution's data governance against ASEAN-level frameworks to identify alignment gaps and prepare for future interoperability requirements.
  • Cross-border data architecture: Design a multi-jurisdictional data architecture that satisfies national requirements while leveraging ASEAN coordination mechanisms where available.
Regulatory references
  • ASEAN Framework on Cross-border Cloud Computing (January 2026): Introduces Trusted Data Corridors between accredited data centres. First corridors expected between Singapore, Malaysia, and Indonesia.
  • ASEAN Guide on AI Governance and Ethics (2024, extended 2025): Voluntary principles for responsible AI. Extended in 2025 to cover generative AI.
  • ASEAN Responsible AI Roadmap (2025-2030): Multi-year plan for AI governance coordination. Acknowledges different member state maturities. Focus on convergence.
Verification checklist
  • Review your cross-border data flows against the ASEAN Cross-border Cloud Computing Framework
  • Assess AI systems against ASEAN AI Governance and Ethics principles
  • Prepare for Trusted Data Corridor requirements โ€” identify which corridors will be relevant to your operations
  • Document how your institution's data governance aligns with ASEAN-level direction
  • Monitor the ASEAN Responsible AI Roadmap for developments relevant to financial services
  • Engage with national representatives on ASEAN data governance consultations
Key question

Is your institution's cross-border data architecture designed to accommodate both national requirements and emerging ASEAN coordination frameworks?

10. Build Your Regional Data Strategy

Operating across Southeast Asia means navigating seven or more different data protection regimes simultaneously. The alternative to country-by-country reactive compliance is a regional data strategy that establishes clear principles, deploys appropriate infrastructure, and builds in the flexibility to accommodate regulatory change.

Start with a regional data map. For every country where you operate, document what data you process, where it is stored, what laws apply, what transfer mechanisms you use, and what localisation mandates exist. This map is the foundation of your strategy and the first document any regulator will ask for. If you cannot produce it, you do not have a strategy โ€” you have a collection of ad hoc arrangements.

Adopt a sovereignty-first architecture. Rather than defaulting to a single cloud provider and retrofitting compliance, design your data architecture so that data stays in the jurisdiction where it is collected and processed. Use local or regional infrastructure for each country. Transfer only what is necessary, using documented mechanisms. This approach is more complex to build but dramatically simpler to defend when regulators ask questions.

Plan for convergence. Every ASEAN country is moving toward more comprehensive data protection and AI regulation. Vietnam's AI law, Thailand's draft AI Act, Indonesia's PDP Agency, Malaysia's sovereign AI cloud โ€” the direction is consistent even though timelines vary. Building compliance infrastructure that meets the most demanding current requirements (likely Vietnam or Singapore) means you will be prepared when other countries reach the same level.

Self-hosted or sovereign infrastructure provides the cleanest answer to multi-jurisdictional compliance. When your institution controls the physical infrastructure in each country, you eliminate CLOUD Act exposure, satisfy localisation mandates automatically, simplify cross-border transfer assessments, and maintain a clear audit trail for every jurisdiction. The trade-off is infrastructure management complexity โ€” which is why managed sovereign infrastructure services exist.

Recommended tools
  • Regional data map: Comprehensive mapping of data types, processing locations, applicable laws, transfer mechanisms, and localisation mandates across all ASEAN jurisdictions where you operate.
  • Sovereignty-first architecture design: Infrastructure design that keeps data in-jurisdiction by default, transfers by exception, and documents every cross-border flow.
  • Regulatory change tracker: Monitoring system for data protection and AI regulatory developments across all ASEAN jurisdictions, with impact assessment and implementation timelines.
Verification checklist
  • Create a regional data map covering every jurisdiction where you operate
  • Design or redesign data architecture with sovereignty as the default, not the exception
  • Assess the most demanding current requirements (Vietnam, Singapore) and build to that standard
  • Evaluate sovereign or self-hosted infrastructure for each jurisdiction
  • Establish a regulatory monitoring process for all ASEAN data protection developments
  • Brief senior management on the total cost of multi-jurisdictional compliance vs. the cost of non-compliance
  • Document your regional data strategy in a format suitable for regulatory inspection in any ASEAN jurisdiction
Key question

Can you produce a complete regional data map โ€” showing what data you process, where, under what law, and with what safeguards โ€” for every ASEAN jurisdiction where you operate?

Frequently Asked Questions

Which ASEAN countries require data localisation?

Cambodia (NBC mandate for financial institutions), Indonesia (GR 71/2019 for strategic public sector data, OJK regulations for fintech), and Vietnam (certain categories under the PDPL and AI Law) have localisation requirements. Singapore, Thailand, Malaysia, and the Philippines do not mandate general localisation but have cross-border transfer conditions. Sector-specific rules may apply in all jurisdictions.

Does the US CLOUD Act affect data stored in Southeast Asia?

Yes. The CLOUD Act compels US-headquartered technology providers to produce data regardless of where it is physically stored. If your data is hosted by AWS, Microsoft Azure, Google Cloud, or any other US-incorporated provider โ€” even in a Singapore or Indonesian data centre โ€” it is within reach of US government access. Self-hosted infrastructure with non-US providers eliminates this exposure.

What is the ASEAN Trusted Data Corridors concept?

Introduced in the ASEAN Framework on Cross-border Cloud Computing (January 2026), Trusted Data Corridors create pathways for data to flow between accredited data centres in different ASEAN countries under agreed security and governance standards. First corridors are expected between Singapore, Malaysia, and Indonesia. Once operational, they may simplify multi-jurisdictional compliance.

Which ASEAN country has the strictest AI regulation?

Vietnam, which enacted ASEAN's first standalone AI law (Law 134/2025) in December 2025, effective March 2026. It uses a risk-based classification system, has extraterritorial reach, and emphasises data sovereignty. Thailand is developing a draft AI Act. Singapore regulates AI through existing MAS technology risk frameworks. Other ASEAN countries rely on general data protection laws and voluntary ASEAN guidelines.

How should a financial institution approach multi-jurisdictional ASEAN compliance?

Build to the most demanding standard (currently Vietnam or Singapore), deploy sovereign infrastructure in each jurisdiction where you operate, document all cross-border data flows with transfer impact assessments, and establish a regulatory monitoring process for all ASEAN developments. A sovereignty-first architecture โ€” where data stays in-jurisdiction by default โ€” is simpler to defend than a centralised cloud architecture with complex transfer mechanisms.

Ready to See DiligenceWorks in Action?

DiligenceWorks deploys sovereign AI infrastructure in the jurisdictions where your institution operates. Each client gets a dedicated environment โ€” not shared, not multi-tenant โ€” hosted on infrastructure you control. Data stays in-jurisdiction by design, not by contractual promise. Book a discovery call to discuss your regional data strategy.

Book a Discovery Call

Content ID: G11.I01.T06.L01 ยท Last updated:

See it in action

Book a live demo with your own deal data. Your box. Your data. Your country.

Trusted by Bluzand Group Sovereign deployment No credit card required