Compliance

Data Locality, Data Residency, and Data Sovereignty Are Not the Same Thing

These three terms get used interchangeably in Bangladeshi cloud RFPs. They are not interchangeable — and confusing them can sink a procurement.

Anika Chowdhury
·

Three terms, used as synonyms in almost every Bangladeshi cloud RFP. They are not. Confusing them produces clauses that look strict and protect very little.

Where
Locality is a hardware question
Bytes at rest, in flight, in cache
What
Residency is a contract question
What you must keep where
Whose
Sovereignty is a jurisdiction question
Whose laws govern access
Nested
Each one builds on the previous
Locality ⊂ Residency ⊂ Sovereignty
What each concept actually answers — and what it leaves open
  LocalityResidencySovereignty
Question answered Where the bytes sitWhat you must keep whereWhose laws govern access
Type of artefact Topology diagramContract clauseStatute / incorporation
Stops physical exfiltration YesYesYes
Stops contract breach PartialYesYes
Stops foreign legal process (e.g. CLOUD Act) WeakPartialYes
Provider must be in-jurisdiction NoNoYes
Coverage of common data-protection threats by each concept (alone)
Locality only
35 %
Residency only
55 %
Sovereignty only
80 %
All three combined
95 %

Source: Cloud Digit risk-mapping framework, indicative.