African governments want greater control over strategic data and a larger share of the cloud economy. Achieving both will require more than directing data to remain within national borders.
As data becomes more important to financial services, government administration, trade, artificial intelligence and national security, African governments are paying closer attention to where it is stored, who processes it and which laws apply.
This has made digital sovereignty and data localisation central to the continent’s policy debate. Although the terms are sometimes used interchangeably, they represent different ideas.
Data localisation concerns the physical location of data. It generally requires certain information to be stored, processed or backed up within a country.
Digital sovereignty is broader. It concerns a state’s ability to govern data and digital infrastructure effectively. This includes regulatory authority, security controls, audit rights, access to information, enforceable legal remedies and the capacity to respond when something goes wrong.
A server may be located inside a country without giving the government meaningful control over the technology, encryption keys or operating environment. Conversely, data may be processed in another jurisdiction under an arrangement that provides clear legal authority, security assurance and regulatory access.
The important question is therefore not only, “Where is the server?” It is also, “Who exercises effective control over the data, and under what safeguards?”
Sovereignty should reflect risk
African governments have legitimate reasons to exercise stronger control over sensitive data. Defence information, national security records, critical government systems and some categories of financial or health data may require strict domestic safeguards.
But not every dataset carries the same level of risk. Applying identical localisation requirements to national security information, publicly available data and ordinary commercial records could increase costs without producing a corresponding security benefit.
A more proportionate approach would classify data according to its sensitivity and impose controls that reflect the risks associated with each category.
“Sovereignty is risk-based; it is classification-based,” said Dr Aristotle Onumo, Director, National Information Technology Development Agency, while representing Kashifu Inuwa Abdullahi, Director-General, National Information Technology Development Agency, during the “Governing the Digital Continent” panel at Hyperscalers Convergence Africa 2026.
Under such a model, highly sensitive data could be required to remain in accredited domestic facilities. Other regulated information could be processed regionally under approved contractual, technical and regulatory safeguards. Low-risk data could move more freely, subject to applicable privacy and cybersecurity rules.
This would give governments stronger control where it is most necessary while avoiding blanket restrictions that could limit access to efficient cloud and digital services.
The economic case for localisation
Localisation can help create demand for domestic infrastructure. When banks, public institutions, telecommunications companies and other enterprises are required or encouraged to store more data locally, they need data centre capacity, cloud platforms, connectivity, cybersecurity services and technical expertise.
That demand can improve the commercial case for infrastructure investment and create a boon for the available operators in-country. It can also help develop local cloud ecosystems, create skilled employment and reduce dependence on distant facilities.
“Policy drives investment, whether we like it or not,” said Tony Emoekpere, President, Association of Telecommunications Companies of Nigeria, during the HCA panel.
A clearly designed localisation policy can signal to investors that demand will grow. Data centre operators can use that demand to justify new facilities, while connectivity and energy providers can invest in the infrastructure needed to support them.
Keeping frequently accessed content closer to users can also reduce latency and improve service performance. Local infrastructure may offer additional resilience when faults on international submarine cables disrupt access to services hosted outside the continent.
The opportunity extends beyond individual national markets. The African Union has estimated that continued digital transformation and implementation of the African Continental Free Trade Area could help create an African data-centre market worth approximately $3.85 billion by 2030.
However, regulation can create demand; it cannot by itself create the capacity required to serve that demand reliably.

Localisation without capacity creates risk
Domestic data storage depends on more than constructing a data centre building. Facilities require stable power, diverse fibre routes, secure land, skilled personnel, cooling systems and reliable access to equipment and replacement parts.
They also require geographical redundancy. Critical systems should not depend on one building, one fibre route, one electricity source or one city.
If localisation requirements move large volumes of data into a small number of facilities concentrated in Lagos, Nairobi, Johannesburg, Cairo or another major city, they may replace international dependency with domestic concentration risk.
A major power incident, fibre cut, flood, fire or other disruption affecting one infrastructure cluster could interrupt numerous services simultaneously. Localisation intended to improve resilience could therefore make systems more vulnerable if domestic capacity is insufficiently distributed.
Gimba Mohammed, Director, Government and External Relations, IHS Towers, warned that requiring all data to be brought within national borders could “create the risk of concentration and lead to massive failures.”
The issue is not whether local infrastructure should be developed. Africa needs more data centres, cloud regions, internet exchanges, terrestrial fibre and reliable power. The issue is how policy should sequence demand requirements with the development of resilient capacity.
Before enforcing extensive localisation requirements, governments should assess available computing capacity, facility standards, power reliability, connectivity diversity and disaster-recovery options. They should also establish realistic implementation periods that allow operators and customers to prepare.
Sovereignty cannot be achieved through geography alone
Requiring data to be stored domestically does not automatically address foreign dependence. A locally situated data centre may still rely on imported hardware, proprietary cloud platforms, foreign software, external technical support and technologies governed from outside the country.
Meaningful sovereignty therefore requires a broader capability agenda.
Countries need strong institutions, skilled regulators and technical professionals capable of assessing cloud and cybersecurity risks. They need enforceable contracts, incident-response capacity, encryption and identity-management systems, reliable infrastructure and clear rules governing access to data.
They also need visibility. Governments should know which entities process sensitive information, where copies are stored, how the data is protected and what happens when a service provider fails.
Sovereignty should ultimately be measured by effective authority and operational capability, rather than geography alone.
National control and regional scale can coexist
A purely national approach to data governance could fragment Africa’s cloud market into dozens of relatively small jurisdictions, making it harder for infrastructure providers to achieve scale and more expensive for African businesses to operate regionally. More importantly, fragmented demand may prevent individual markets from reaching the scale required to attract major global investors and support commercially viable, long-term infrastructure investment.
The African Union Data Policy Framework offers a more balanced direction. It seeks to strengthen national data systems while enabling secure cross-border flows and establishing shared standards for a trustworthy continental data environment.
African Union guidelines also encourage countries to use the economies of scale offered by cloud infrastructure while permitting cross-border data flows under appropriate security standards. They recognise that trusted intra-African data flows will be essential to creating a common market and realising the African Digital Single Market.
Regional cooperation does not require countries to abandon sovereignty. Participating governments could agree on minimum facility standards, common data classifications, approved transfer mechanisms and mutual recognition of selected security certifications.
Data could then move between trusted African jurisdictions while remaining subject to defined protections and enforceable rules.
A practical policy model
Africa needs a layered approach rather than a binary choice between unrestricted data flows and universal localisation.
Governments should define data categories clearly. Businesses need to know what constitutes critical, sensitive, personal, public and ordinary commercial data.
Restrictions should also be proportionate to risk. The most demanding controls should be reserved for information whose exposure or loss would cause serious harm.
Localisation requirements should be tied to infrastructure-readiness assessments. Policies should account for domestic capacity, reliability, redundancy, costs and the availability of essential technical skills.
Governments should establish approved mechanisms for transferring data between trusted jurisdictions. These could include common contractual clauses, adequacy arrangements, certification schemes and regulator-to-regulator cooperation.
Lastly, policymakers should coordinate their directives. Conflicting requirements from financial, telecommunications, cybersecurity and data-protection authorities increase uncertainty and make investment more difficult.
“The processes should allow these agencies and regulatory regimes to operate as one coherent system,” Mohammed told the HCA panel.
Control without isolation
Africa’s objective should not be to prevent data from moving. It should be to ensure that data moves under rules that protect citizens, preserve national authority and create economic value on the continent.
Well-designed localisation can stimulate domestic infrastructure investment and strengthen resilience. Poorly designed localisation can raise costs, concentrate risk and divide the continent into isolated digital markets.
The most effective model will combine national control with regional cooperation. Sensitive data should receive stronger protection, governments should retain enforceable authority, and trusted cross-border arrangements should allow businesses and infrastructure providers to operate at African scale.
Digital sovereignty should give African countries meaningful control over their digital futures. It should not require them to pursue that control alone.