
Before you compare databases or pick a cloud region, one question quietly decides both: where may this data legally live? For regional and public-sector work, data residency rules narrow the vendor shortlist before any technical criteria are applied. Unfortunately, most published guidance on Southeast Asia is wrong in a specific and expensive way.
The myth that drives bad architecture
You will read that “Country X requires data localization.” However, usually it does not. Three different things get flattened into that one phrase:
- Hard localization. The data must physically stay in the country.
- Transfer conditions. The data may be released, provided you meet the stated conditions.
- Sectoral rules. Only banks, hospitals or government agencies are bound.
The distinction matters enormously. Consequently, teams overbuild in-country infrastructure they never needed or miss a sectoral rule that genuinely applied.
Vietnam: the strictest rule, and it just moved.
Vietnam is the real one, and its statutory footing just moved. Law on Cybersecurity No. 116/2025/QH15 took effect on 1 July 2026 and repealed the 2018 Cybersecurity Law. Consequently, the localization duty now sits in Article 25(3) of the new law, rather than in the older decree that most guidance still cites.
The duty also splits into two parts, which most summaries miss. Domestic enterprises handling the listed data must store it in Vietnam unconditionally — no sector list, no trigger. Foreign enterprises are caught only within roughly ten enumerated service categories, and only after the Minister of Public Security issues a specific decision, with twelve months to comply.
One caution for planning. Decree 53/2022/ND-CP still applies transitionally insofar as it does not conflict with the new law, and its replacement decree remains in draft as of August 2026. Therefore, confirm the current decree before you design around the detail.
Where else localization applies — and how narrowly
Indonesia is narrower than its reputation. Government Regulation PP 71/2019, Article 20(2), is genuine hard localization — but it binds only public-scope electronic system operators. Meanwhile, Article 21(1) expressly permits private-scope operators to store data outside Indonesia. The financial sector is carved back out by Article 21(4).
The Philippines changed recently — but narrowly. Executive Order No. 119, s. 2026, signed 13 July 2026, requires that government data classified as Top Secret or Secret remain on Philippine territory. Crucially, it binds private companies whenever they process government data, and a phased runway of up to three years applies. However, the Data Privacy Act 2012 still imposes no localization on ordinary private-sector data.
Read that band carefully. None of these three is a general residency rule for private business data. Vietnam reaches listed service categories, Indonesia reaches the public sector, and the Philippines reaches government data. Consequently, whether any of them touches you depends entirely on what you build and for whom.
Where the rule is a condition, not a location
Singapore has no general data-residency requirement. No provision of the Personal Data Protection Act 2012 or the 2021 Regulations requires storage in Singapore. Instead, section 26(1) sets a condition: transferred data must receive comparable protection. Part 3 of the Regulations spells out how.
That surprises people, so it is worth stating the consequence plainly. Do not shortlist “Singapore region only” for PDPA reasons. Additionally, MAS imposes no data-residency requirement on financial institutions, and the Healthcare Services (General) Regulations 2021 contain no data-location rule either.
Malaysia abolished its transfer whitelist. The Personal Data Protection (Amendment) Act 2024 replaced it, and Guidelines No. 3/2025, dated 29 April 2025, now govern cross-border transfers. Thailand operates an adequacy-or-safeguards model under PDPA sections 28 and 29, which has been operational since the PDPC notifications were gazetted.
Cambodia: no general law, but real sectoral rules
Cambodia has no comprehensive personal data protection law in force. Currently, the draft Law on Personal Data Protection remains at consultation stage. Accordingly, there is no general restriction on international transfers of personal data.
However, two real constraints exist. First, the National Bank of Cambodia’s Technology and Cyber Risk Management Guidelines, issued in January 2026, require licensed banks and financial institutions to maintain a primary data center in-country. Second, government digital projects carry their own hosting directions. Therefore, “no law” never means “no constraint” on public-sector work.
The sectoral trap
Notice the pattern above. In four of these countries, the binding rule was sectoral rather than national. Consequently, the general privacy statute is the wrong place to stop reading.
Always check three layers: the general data-protection law, the sector regulator, and the procurement terms of the specific contract. Public-sector engagements routinely impose hosting conditions that appear nowhere in any statute.
Where the law and the vendors collide
Here is the part that breaks real projects. Specifically, even where residency is required or promised, the infrastructure may not exist.
As of August 2026, AWS operates in-country regions in four ASEAN states: Singapore, Indonesia, Malaysia and Thailand. Google Cloud runs three, and Azure runs three. Notably, none of the three has a region in Vietnam or the Philippines — the two jurisdictions with the strongest localization rules.
AI features make this sharper. Anthropic’s Claude API offers only us and global inference geographies, so no Southeast Asian residency option exists on the first-party API. OpenAI’s residency program covers only Singapore within ASEAN and provides in-region storage without in-region processing. Meanwhile, Amazon Bedrock’s cross-region inference can route requests into regions you never enabled.
Therefore, verify the actual guarantee. “Data residency” from a vendor may mean storage only, processing only, or a specific SKU.
The transfer mechanisms you will actually rely on
Saying “we meet the transfer conditions” is not a plan. Specifically, each jurisdiction names its own mechanisms, and they rank differently.
Singapore puts legally enforceable obligations first, with five deemed-compliance routes below them. A contract is only one of four ways to create that obligation, alongside law, binding corporate rules, and any other binding instrument. Where you do use a contract, regulation 11(2) requires it to name the specific countries data may reach, so an open-ended cloud clause fails. Additionally, regulation 10(3) invalidates consent that was bundled with other terms, or given without a written summary of protections abroad.
Indonesia operates a strict cascade under Article 56: recipient-country adequacy first, then binding safeguards, and finally data-subject consent as a last resort. Thailand offers a useful carve-out — its PDPC notifications exclude mere transit and storage from “transfer” where no party other than the sending organization can access the data.
One regional caution. The ASEAN Model Contractual Clauses are a voluntary template, not an adequacy mechanism. They help demonstrate compliance, but they confer no automatic benefit.
What non-compliance actually costs
Notably, the penalties are no longer nominal. Vietnam’s PDPL 91/2025 sets the maximum administrative fine for breaching cross-border transfer rules at 5% of the organization’s previous-year revenue, with a floor of VND 3 billion. That is a revenue-linked penalty, not a fixed cap.
Elsewhere, the pressure is operational. Malaysia’s mandatory breach notification took effect on 1 June 2025. Section 12B itself says only “as soon as practicable”; the 72-hour deadline comes from the Commissioner’s Circular 2/2025 and breach guideline, and applies to breaches likely to cause significant harm. Meanwhile, Singapore’s regulator has directly enforced the transfer rule, so it is not theoretical there either.
The decision sequence we use
Six questions, in this order. Crucially, answer them before comparing regions or vendors.
- What data class is this? Personal, government-classified, health, financial, or ordinary business data.
- Whose residents does it describe? Every jurisdiction with data subjects in the set gets a vote.
- Which sector regulator applies? Banking, health, and government rules override the general statute.
- Is this localization or a condition? If a condition, identify the mechanism you will actually rely on.
- Can the vendor commit in writing? Storage location, processing location, sub-processors, and no-training terms.
- Does the region exist? Confirm the provider actually operates where your answer requires.
Most teams start at question six. That is precisely backward, and it is why residency work so often gets redone.
What is still moving
Two items will change this picture. Cambodia’s draft personal data protection law is progressing, and the earlier localization article was removed from a later draft. Indonesia has not yet issued the implementing regulation required by Article 56(5) of its PDP Law, so its transfer regime remains incomplete.
Therefore, recheck both before committing to an architecture in 2027.
A necessary caveat
This article is engineering guidance, not legal advice. Every rule above names its instrument and date so your counsel can verify it quickly. Regardless, confirm the position with qualified local counsel before you commit — particularly in Vietnam and Indonesia, where implementing regulations still shift.
How Pegotec helps
We build for governments, NGOs, and industry across Cambodia, Singapore, and the wider region, so we run this sequence before we scope the architecture. Furthermore, we include the vendor commitments in the contract rather than assume them.
If residency questions are blocking a decision, talk to us.
Read next
- AI LLMs for Business in 2026: A No-Hype Reality Check — where LLMs earn their keep, and the procurement terms that constrain them.
- Building Healthcare Apps: Compliance and Security — the sectoral layer applied to one industry.
- The IDPoor Story: Scaling to Millions of Users in Cambodia — public-sector delivery in the region.
Far fewer than commonly claimed. Vietnam has the genuine rule under Decree 53/2022/ND-CP, Article 26, though it applies only to enumerated service categories and, for foreign firms, only after a specific decision. Indonesia’s PP 71/2019 imposes localization only on public-scope electronic system operators, not private ones. The Philippines requires onshore storage for classified government data under Executive Order No. 119, s. 2026. Singapore, Malaysia and Thailand impose transfer conditions rather than localization, and Cambodia has no general rule at all.
No. Neither the Personal Data Protection Act 2012 nor the Personal Data Protection Regulations 2021 contains a general data-residency requirement. Section 26(1) sets out a transfer condition instead: data sent overseas must receive protection comparable to that under the PDPA, with the mechanisms set out in Part 3 of the Regulations. MAS imposes no residency requirement on financial institutions either, and Singapore’s healthcare regulations contain no data-location rule. The one genuine residency mandate is an internal government procurement standard, which binds public agencies rather than the private sector.
Often not without changing the design. Anthropic’s Claude API offers only ‘us’ and ‘global’ inference geographies, so there is no Southeast Asian residency option on the first-party API. OpenAI’s residency program covers only Singapore within ASEAN and provides in-region storage without in-region processing. Amazon Bedrock’s cross-region inference can route requests into regions you never enabled. Check whether the guarantee covers storage, processing, or both before assuming an LLM feature is compliant.
Cambodia has no comprehensive personal data protection law in force as of 2026; the draft Law on Personal Data Protection remains at consultation stage, so no general restriction on international transfers applies. Two real constraints still exist. The National Bank of Cambodia’s Technology and Cyber Risk Management Guidelines of January 2026 require licensed banks and financial institutions to maintain a primary data center in-country, and government digital projects have their own hosting directions. The absence of a general law does not mean the absence of constraints.
Let's Talk About Your Project
Enjoyed reading about Where Your Data Can Legally Live: A 2026 Data-Residency Decision Framework for Southeast Asia? Book a free 30-minute call with our consultants to discuss your project. No obligation.