Data sovereignty is becoming the industry's default constraint
Data residency isn't a niche compliance concern anymore — it's the backdrop every lab, funder and regulator across the industry is now building around.
Ask why a lab in Nairobi, Harare or Lagos doesn’t use the same cloud ELN a lab in Boston does, and the conversation used to be about internet reliability. Increasingly, it isn’t. It’s a national data protection act, a funder’s grant conditions, or an accreditation body’s residency requirement — and it’s not only an emerging-market story anymore. The constraint that used to sit at the edges of the industry is becoming the default a growing share of laboratories have to design around.
The patchwork keeps getting denser
Ten years ago, “where does the data live” was a question a handful of government and defense-adjacent labs asked. Today it shows up from several directions at once, and rarely from just one:
- National data protection law. South Africa’s POPIA, Nigeria’s Data Protection Act, Kenya’s Data Protection Act and the EU’s GDPR each impose their own rules on where personal and health-linked data can be processed and by whom — and research data tied to identifiable patients or specimens usually gets the strictest treatment in each of them.
- Funder conditions. International funders — the Gates Foundation, the Global Fund, Wellcome Trust and others — increasingly attach data-handling and audit-trail conditions to the grants that fund public-health and research laboratories, layered on top of whatever national law already requires.
- Accreditation scope creep. ISO/IEC 17025 assessors have started asking not just whether a lab’s records are complete, but where the system that produced them actually runs, and who besides the lab can reach it.
- Public-sector procurement. Government-run and government-adjacent labs are, in a growing number of jurisdictions, simply barred from procuring software that stores records outside the country.
None of these forces coordinated with each other. That’s what makes the result a patchwork rather than a single clean rule a lab can look up once and be finished with — and it’s why “we’ll figure out data residency if a customer asks” is no longer a viable product strategy for anyone selling into this space.
Why cloud-first stopped being the safe default
Most ELN and LIMS software was designed for a market where none of this applied — a single-tenant SaaS product, hosted wherever the vendor’s infrastructure happened to run, sold to labs for whom that was a non-issue. That design point still fits plenty of laboratories. It stops fitting the moment any one of the pressures above applies, and, industry-wide, more laboratories cross that line every year, not fewer. A cloud-only vendor doesn’t get to opt out of that trend by building good cloud software — the disqualification happens before a feature comparison ever starts, at the procurement stage or the assessor’s first question.
The honest framing isn’t “cloud vendors versus self-hosted vendors.” It’s that a growing share of the market is being asked a question — can this run entirely under our own control, on our own infrastructure, with no dependency on a jurisdiction we don’t control — that most of the industry’s software was never built to answer.
What this means for tooling, not just policy
The instinct is to treat data sovereignty as a legal problem a compliance officer resolves with a clause in a vendor contract. That works for exactly as long as the vendor’s infrastructure choices don’t change and the lab never needs to prove, on a specific day, exactly where a specific record has lived since it was created. Neither of those holds up under a real audit. A residency clause in a contract is a promise; a deployment the lab actually operates is a fact an assessor can go and look at.
That’s the shift underway across the industry: sovereignty is moving from something a legal team negotiates after the fact to something a lab has to be able to demonstrate on demand, which means it has to be a property of the system, not a paragraph about the system. We wrote about what that looks like for a single laboratory in self-hosting as a compliance requirement — the pattern here is the same argument playing out at the scale of an entire industry rather than one lab’s procurement decision. If your organization is weighing that tradeoff, the docs and the pricing page lay out what running Archon entirely on infrastructure you control actually involves.