
Cloudflare says its Data Localization Suite is now available in three more Asia-Pacific countries — Australia, India and Japan — after supporting European localisation requirements since 2020. The suite is a set of controls inside Cloudflare's network rather than a separate product, and it covers three things: choosing where traffic is inspected, deciding where private keys are held, and building serverless applications restricted to a region.
The company sets the offering against a regulatory trend, saying close to 70 per cent of countries in Asia have passed or drafted data protection and privacy laws, against an internet population it puts at more than 2.5 billion. It also cites its own certifications — ISO 27001, 27701 and 27018 — as evidence the controls meet recognised standards.
Localisation is not sovereignty
The distinction the company is selling is worth keeping straight. Data localisation is about where data is processed and stored; data sovereignty is about who has the legal right to reach it. A suite that keeps traffic inside a country and holds keys there addresses the first and only partly the second: the provider still operates the network, and the legal reach of a government toward a company headquartered elsewhere is a matter of law, not of routing.
The controls do answer a real problem. Organisations with localisation obligations often cannot use a global network because they cannot say where their keys live, and being able to pin a key's location is a concrete step. What the release does not say is which certification applies to which control, or what happens to a customer's traffic during a network incident that crosses a border. Those are the questions a buyer regulated under one of those Asian laws would want answered, and they are not in the announcement.