Posted on — Leave a comment

Why Singapore firms fear data sovereignty failures but remain underprepared

Singapore’s position as one of Asia’s most advanced digital economies is built on a simple promise: global companies can move data, capital and operations through the city-state with confidence. A new study suggests that promise is becoming harder to keep.

Research released by data storage and management company Everpure found that 89 per cent of Singapore-based enterprise leaders believe a data sovereignty failure could cost them their jobs. The fear is not only personal. The same proportion said such a failure could damage their organisation financially and reputationally.

Also Read: The new border: Why server farms are the battleground of AI sovereignty

Yet the more striking finding is the gap between concern and action. According to Everpure’s Global Data Sovereignty Report 2026, 81 per cent of Singaporean enterprises surveyed do not have a formal data sovereignty strategy in place, the highest share among the eight markets covered in the study.

That matters because data sovereignty is no longer just a legal question about where information is stored. It has become a business continuity, geopolitical and vendor risk issue.

At its simplest, data sovereignty refers to the idea that data is subject to the laws and controls of the country or jurisdiction in which it is stored, processed or accessed. In practice, the challenge is more complicated: companies must know who can access their data, which foreign laws may apply, and whether a cloud or software provider could be forced to hand over information or suspend services during a political dispute.

For Singapore, a regional headquarters for banks, tech companies, logistics players and digital platforms, the issue cuts especially close. The country’s economy depends on trusted cross-border flows of information. At the same time, its companies often rely on global cloud, software-as-a-service (SaaS) and cybersecurity vendors whose infrastructure may span several jurisdictions.

Awareness is high, preparedness is not

Everpure commissioned research firm Vanson Bourne to survey 2,100 C-suite and IT leaders from large enterprises across the UK, France, Germany, Australia, Japan, South Korea, Singapore and India in June 2026. Singapore accounted for 100 respondents.

The study found that 93 per cent of Singapore organisations recognise data sovereignty as a business concern, compared with 90 per cent globally. Some are already changing procurement behaviour. About 41 per cent of Singapore respondents said they are limiting their use of SaaS providers that rely on non-domestic infrastructure, while 86 per cent said they would compromise on advanced features to work with a local or sovereign provider.

Also Read: Should cybersecurity be nationalised?

But recognition has not translated into operational readiness. In Singapore, 63 per cent of enterprises said they lack full visibility into who can access, control and manage their data. More worrying, 68 per cent said they have no mitigation plans for geopolitical data exfiltration or service disruption.

This is the heart of the “sovereignty gap” highlighted in the report: executives know the risk is material, but many organisations have not built the governance, technical controls or response plans needed to manage it.

Nathan Hall, Vice President and General Manager for Asia Pacific and Japan at Everpure, said the risk for Singapore lies in the disconnect between digital maturity and organisational preparedness.

“Singapore is one of the most digitally mature markets in the world, yet 81 per cent of enterprises here are operating without a formal data sovereignty strategy. That gap between awareness and action is the real risk,” he said. “Sovereignty is not simply about where data sits — it is about knowing who can access it, which jurisdictions apply, and whether critical services could be disrupted.”

The point is especially relevant in Southeast Asia, where regulation is still uneven across markets. Singapore has a mature data protection regime under the Personal Data Protection Act, while neighbouring economies are developing or refining their own privacy, cybersecurity and localisation rules. For regional companies, this creates a patchwork problem: data may be generated in Indonesia, processed in Singapore, analysed through a US-headquartered SaaS platform, and stored on infrastructure distributed across several markets.

The AI factor

The sovereignty question is becoming more urgent because of artificial intelligence. As companies feed more enterprise data into AI systems, the boundaries around storage, access and reuse become harder to track. Sensitive operational data may move into model-training environments, analytics platforms or third-party applications without executives fully understanding where it goes or how it is governed.

Also Read: AI governance is moving from promises to proof

This is not just a theoretical risk. Banks, insurers, healthcare groups and government-linked enterprises in Southeast Asia are under growing pressure to adopt AI while maintaining strict controls over customer data. For startups and scaleups, the challenge is different but no less serious. Many depend on global cloud platforms and AI tools from day one, often without the resources to conduct deep vendor risk reviews.

Everpure’s survey suggests that companies are still treating sovereignty as an extension of cybersecurity or compliance. That may be too narrow. Cybersecurity focuses on preventing unauthorised access or attacks. Compliance focuses on meeting legal obligations. Sovereignty adds another layer: whether an organisation retains effective control over its data when foreign laws, vendor dependencies or geopolitical shocks come into play.

Rahiel Nasir, Research Director and Lead Analyst for Worldwide Digital Sovereignty at IDC, described the shift as a board-level issue. “The challenge for executives is not just about knowing where their data are hosted,” he said. “It is about being in total control of all data access and transfers, including all metadata, guaranteed protection against extra-territorial data requests, and managing IT and vendor risks in the light of geopolitical uncertainties.”

From compliance checklist to operating model

Everpure argues that companies should move towards “sovereignty by design”, where governance and controls are applied based on the risk of each data set, application and workload. In practical terms, that means mapping critical data, classifying it properly, understanding vendor access, and deciding which workloads require stricter controls.

The distinction matters. Not every piece of enterprise data needs the same level of protection. A marketing dashboard, payroll file and national infrastructure system carry different risks. A blanket localisation strategy can be expensive and restrictive; a purely global cloud approach can leave companies exposed. The harder but more useful path is to decide which data must remain under tighter corporate control and which can safely sit within global platforms.

Also Read: Southeast Asia’s AI buildout is racing toward a power wall

For Singapore, the findings should be read less as an indictment and more as an early warning. The country has spent years building itself into a trusted digital hub for Asia. Maintaining that position will require not only strong national regulation, but also stronger internal discipline among enterprises using cloud, SaaS and AI systems.

The boardroom fear captured in Everpure’s report may sound dramatic. But in a region where data flows underpin finance, trade, healthcare and digital services, sovereignty failures are no longer abstract policy debates. They are operational risks, and increasingly, leadership risks.

The post Why Singapore firms fear data sovereignty failures but remain underprepared appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *