Multinational Adaptation: Digital Sovereignty Now a Top-Tier Investment Driver Across APAC (IDC/Expereo, September 2026)
New survey evidence quantifies what the regulatory cascade documented in Multinational Adaptation: Digital Sovereignty Now a Top-Tier Investment Driver Across APAC (IDC/Expereo, September 2026) is doing to enterprise behaviour: data sovereignty has moved from legal abstraction to a top-tier technology investment driver in APAC — ahead of global peers. The IDC InfoBrief commissioned by Expereo ("Enterprise Horizons 2026," reported September 15, 2026) found 43% of APAC respondents rank digital sovereignty among the leading drivers of technology investment, versus 30% globally, and 38% view it as a top or high priority (vs 33% globally). Among APAC organisations prioritising sovereignty, 51% want to retain control over sensitive or strategic data, 45% cite regulatory compliance across jurisdictions, and 33% cite cross-border data transfer and jurisdiction concerns.
The market-by-market drivers confirm that compliance strategy can't be uniform across the region:
| Market | Standout sovereignty driver |
|---|---|
| Australia | Retaining control over sensitive/strategic data: 56% |
| Malaysia | Retaining control over sensitive/strategic data: 55% |
| Thailand | Cross-border transfer and jurisdiction concerns: 54% |
| Vietnam | Geopolitical risk mitigation: 47% |
| Indonesia | Alignment with national digital sovereignty policies: 46% |
| Singapore | Customer/partner pressure for data localisation: 24% |
Eric Wong, president Asia Pacific at Expereo, captured the multinational dilemma: "There is no single path to digital sovereignty across Asia Pacific. Businesses are navigating very different regulatory environments, cross-border data requirements and geopolitical risks, while accelerating their adoption of cloud and AI." And on the operational cost: "For multinational organisations, the challenge is maintaining visibility and control over how data and traffic move across markets without creating fragmented operations."
AI is the accelerant: among APAC organisations not yet using AI or only beginning, 60% cite security, data privacy, compliance, or digital sovereignty concerns as a barrier to AI adoption. Read together with the regulatory wave this cycle documents — Korea's 10% global-revenue fines now in force, Indonesia's GR 33/2026 transfer regime, China's large-processor localization draft, Australia's fair-and-reasonable test — the survey suggests multinationals are converging on regionally partitioned data architectures (local storage plus controlled cross-border pathways) rather than waiting for harmonisation1. The compliance-planning implication: sovereignty-driven architecture decisions are being made by boards and CTOs now, and legal teams need to be at that table with jurisdiction-specific transfer maps rather than after the fact.
-
An instance of Centralized regional data hubs cannot survive APAC's escalating revenue-based privacy penalties. — Survey data confirms enterprises are abandoning unified regional architectures for in-country storage as APAC penalty regimes escalate, which is the theme's predicted vendor behavior. ↩︎