14 // Data Governance & Compliance

Data Localization Just Hit 62 Countries. Caribbean Banks Are Still Building AI on Someone Else's Servers.

The number of countries requiring certain data to stay inside their own borders rose from 35 to 62 in a few years, according to the Information Technology and Innovation Foundation, and financial services carry the strictest version of that rule almost everywhere it exists. Jamaica's Office of the Information Commissioner can now fine a company up to 4% of its global turnover and jail a director for up to ten years under the Data Protection Act. Cloud Carib has put US$7 million since 2025 into sovereign data centre pods across Bermuda, Curaçao, and Guyana, because banks and governments are asking for exactly that. None of it touches the deeper problem. Most of the credit models, fraud engines, and claims tools running inside Caribbean banks and insurers were trained on data collected for a different population, under a different law. Localizing the server does not localize the intelligence running on it.

Rows of illuminated server racks with blue cabling in a data centre, representing the physical infrastructure data localization law regulates
TL;DR
  • Jurisdictions requiring data to stay onshore rose from 35 to 62 between 2017 and 2021, with the underlying restrictions nearly doubling, per the Information Technology and Innovation Foundation. Compliance trackers count at least 34 dedicated national laws in force by 2026.
  • Jamaica's Data Protection Act is no longer theoretical. Fines reach JMD 5 million and up to 10 years in prison for individuals on indictment, and up to 4% of global turnover for companies, enforced by the Office of the Information Commissioner.
  • Cloud Carib put US$7 million into Caribbean data centres across 2025 and 2026, building sovereign pods in Bermuda, Curaçao, and Guyana because regional banks and governments are asking to keep data onshore.
  • The Inter-American Development Bank estimates closing the Caribbean's digital infrastructure gap could add 6 to 12% to regional GDP over the medium term, a return many times the cost of building it.
  • A localized server does not mean localized intelligence. Most credit scoring, fraud detection, and claims automation running inside Caribbean regulated entities still depends on foreign-trained models and foreign-hosted inference, which is the actual exposure sitting under every localization headline.
62
Countries with data localization rules (ITIF, up from 35)
4%
Max corporate fine, Jamaica Data Protection Act (of global turnover)
10 yrs
Max prison term, individuals, indictable DPA offences
$7M
Cloud Carib's investment in Caribbean sovereign data centres

Data Localization Went From Fringe Rule to Default Setting

In 2017, thirty-five countries had some form of data localization control on the books. By 2021, that had climbed to sixty-two, and the number of individual restrictions those countries imposed had roughly doubled, from 67 to 144, according to research from the Information Technology and Innovation Foundation. Industry compliance trackers now count at least 34 dedicated national data localization laws in force worldwide in 2026, on top of the broader data protection statutes that already touch cross-border transfer. Financial services and health data face the tightest versions of the rule in almost every jurisdiction that has one, because regulators treat those categories as the ones a foreign court order or a foreign vendor outage can do the most damage to.

None of this started as an AI story. Most of these laws predate the current wave of AI deployment by years and were written to answer a narrower question: who can compel access to a citizen's financial or health record, and under which country's law. AI changes what the rule actually requires in practice, because a credit model or a fraud engine does not just store data, it moves data, repeatedly, every time it runs an inference call. A regulator asking "where does this data live" in 2020 was asking about a database. The same question in 2026 is asking about every API call a bank's AI vendor makes on its behalf, several thousand times a day.

Palm tree leaning over turquoise Caribbean water at sunset, a coastline view of the region where these data residency rules now apply
The rule now reaches every institution operating under it, from Kingston to Bridgetown to Georgetown.

Jamaica's Data Protection Act Has Teeth Now

Jamaica's Data Protection Act sets out a tiered penalty structure that regulated entities in the country can no longer treat as background reading. Processing personal data without registering as a data controller with the Office of the Information Commissioner carries a fine of up to JMD 2 million and up to six months in prison. Failing to meet the Act's eight data-handling standards carries a fine of up to JMD 5 million and up to seven years. Serious violations tried on indictment carry the same JMD 5 million ceiling and up to ten years' imprisonment for individuals. Corporate bodies face a separate ceiling entirely: fines of up to 4% of annual global gross turnover, the same figure regulators use under the EU's GDPR.

The Office of the Information Commissioner had not brought formal enforcement action against a data controller as of early 2026. Treat that as a starting gun, not an all-clear. Registration has been mandatory since 2024, the penalty tiers are already written into law, and every regulator in a young enforcement regime eventually picks a case to make an example of. Jamaica is the most tested example in the region, but it is not unusual. Most CARICOM member states have passed or drafted comparable data protection legislation, which means a bank operating across Jamaica, Trinidad and Tobago, and Barbados is already carrying three separate registration and enforcement regimes, on top of whatever regional AI-specific guidance eventually lands from bodies such as the Caribbean Telecommunications Union's AI Task Force.

The Caribbean's AI Stack Still Runs Offshore

Cloud Carib is the clearest regional answer to the localization pressure. The company put more than US$7 million into its Caribbean expansion across 2025, backed by Silicon Valley growth financing from Partners for Growth, and is building Sovereign Data Center Pods in Bermuda, Curaçao, and Guyana to join an existing footprint across the Bahamas, Jamaica, Barbados, and Panama. Its own framing of the investment is explicit: onshoring sensitive data so Caribbean institutions are not subject to a foreign court's reach. That is a real, useful, and increasingly necessary piece of infrastructure.

It is also only half the compliance question. Storage location tells a regulator where the data sits at rest. It says nothing about where that data goes the moment an AI system touches it. A bank can host its core database in a Cloud Carib facility in Kingston and still send every loan application through a foreign-hosted model API for underwriting, which moves that applicant's data across the exact border the localization rule exists to police. Building the sovereign data centre and stopping there is a half-finished compliance project that looks finished from the outside, which is worse than an obviously unfinished one, because nobody goes looking for the gap until an auditor does.

"Everyone building a data centre in the region calls it sovereignty, and the concrete really is sovereign. What runs on top of it usually is not. The model was trained somewhere else, on somebody else's population, and every inference call still has to phone home to wherever that model actually lives."

Adrian Dunkley, Founder, StarApple AI

What This Costs a Compliance Officer Who Waits

Run the numbers on a mid-sized regional bank with, say, US$40 million in annual turnover. A corporate fine at the 4% ceiling under Jamaica's Data Protection Act would run to roughly US$1.6 million, before legal costs, before the regulatory remediation plan a first enforcement action typically forces on an institution, and before the reputational cost of being the case a young regulator chose to make an example of. Set against that, the cost of mapping a vendor's data flows properly is close to nothing.

The practical work is unglamorous and specific. List every point where customer or claims data leaves the organisation's own systems: every AI vendor, every cloud model API, every third-party analytics tool. For each one, establish the physical location where processing actually happens, the legal basis for any transfer across a border, and whether the vendor contract includes a data processing addendum that would hold up if a regulator asked to see it. In our diligence work at Maestro AI Labs, the exposure almost never sits in the core banking system a compliance officer already audits. It sits in the AI vendor relationship nobody has mapped, because it was signed by a business unit that called it a productivity tool rather than a data processor.

The Data Layer That Actually Complies

The honest fix is not another data centre. It is building the AI itself from data that never had to cross a border in the first place. Maestro AI Labs' Data Archaeology product collects and structures training data directly inside the Caribbean, from government archives, cooperative and SUSU financial records, and regional climate data, so the credit models and risk tools built on it are not depending on a foreign dataset or a foreign vendor's pipeline that the institution cannot audit. Harmonics, the agent framework built on that data, logs every decision with a human override in place, which is the audit trail a data protection regulator asks for the moment it opens a file.

None of this is a quarter's work. Collecting and structuring records that were never digitised in the first place takes years of relationship-building with the archives, cooperatives, and government offices that hold them, not a procurement cycle. It will not close the gap between now and a compliance officer's next audit. What it does is stop the gap from reopening every time the institution renews a vendor contract. That is also the wider case StarApple AI, the first AI company established in the Caribbean, has been building since Adrian Dunkley founded it in Jamaica in 2023. Compliance-minded institutions do not have to choose between using AI and staying inside their own jurisdiction's law. They have to choose which data infrastructure they build that decision on top of. The Caribbean AI Risk Management Council has been doing parallel work on the governance side, building the frameworks regulated boards need to evaluate exactly this kind of vendor exposure before a regulator does it for them.

Sixty-two countries now require data to stay home. Jamaica's regulator has the penalty tiers written and the registration list filled, and has simply not picked its first case yet. Whichever institution it picks will not be the one that built a data centre. It will be the one that never checked where its AI vendor actually sent the data.

SB
Dr S Budall
Research Director, Maestro AI Labs

Dr S Budall leads research at Maestro AI Labs, the data infrastructure arm of the StarApple AI network, covering data governance, regulatory signal, and compliance practice across Caribbean and LATAM AI deployment.

// Frequently Asked Questions

What is data localization and why does it matter for AI in the Caribbean?

Data localization law requires that certain categories of data, usually personal, financial, or health data, be stored and sometimes processed inside the country where it was collected. It matters for AI because most Caribbean banks, insurers, and credit unions run their AI tools on cloud infrastructure and models built outside the region. A localization rule does not ask whether a company uses AI. It asks where the data behind that AI physically sits and who can compel access to it.

How many countries now have data localization requirements?

The number of countries with data localization measures in place rose from 35 to 62 between 2017 and 2021, according to the Information Technology and Innovation Foundation, and the underlying restrictions roughly doubled over the same period, from 67 to 144. Industry compliance trackers count at least 34 dedicated national data localization laws in force by 2026, with financial services and health data facing the strictest versions almost everywhere the rule exists.

What are the penalties under Jamaica's Data Protection Act?

Jamaica's Data Protection Act, enforced by the Office of the Information Commissioner, sets a tiered penalty structure. Processing personal data without registering as a data controller carries a fine of up to JMD 2 million and up to six months in prison. Serious violations tried on indictment carry fines up to JMD 5 million and up to 10 years' imprisonment for individuals. Corporate bodies face fines of up to 4% of their annual global gross turnover, the same ceiling used under the EU's GDPR.

Does building a sovereign data centre in the Caribbean satisfy data localization law?

Storage location is only one requirement. Most data localization and data protection regimes also require a documented lawful basis for processing, records of where data moves during processing (including AI training and inference calls to third-party model providers), and a mechanism to prove data has not left the jurisdiction without authorisation. A regulated entity that stores customer records in a Caribbean data centre but still routes AI inference through a foreign model API is moving data across the same border the law is trying to close.

What should a bank or insurer's compliance officer do first?

Map every point where customer or claims data leaves the organisation's own systems, including any AI vendor, cloud model API, or analytics tool. For each one, confirm the physical location of processing, the legal basis for any cross-border transfer, and whether the vendor contract includes a data processing addendum that would survive a regulator's audit. Most exposure sits in vendor relationships nobody has mapped, not in the core banking system.

How does Maestro AI Labs help with data residency compliance?

Maestro AI Labs' Data Archaeology product builds AI training data from records collected directly inside the Caribbean, government archives, cooperative financial records, and regional climate data, so the underlying intelligence does not depend on a foreign dataset or a foreign vendor's training pipeline. Harmonics, the agent framework built on that data, logs every decision and keeps a human override in place, which gives a compliance officer the audit trail a localization or data protection regulator will eventually ask for.

Is this only a Jamaica issue, or does it apply across CARICOM?

Jamaica's Data Protection Act is simply the most tested example. Most CARICOM member states have passed or drafted comparable data protection legislation, and the Caribbean Telecommunications Union's AI Task Force has been building a regional policy floor on top of those laws. A bank operating across Jamaica, Trinidad and Tobago, and Barbados faces three separate registration and enforcement regimes layered under whatever regional AI guidance eventually lands.

Does using a foreign AI model or cloud API violate data localization rules?

Not automatically, but it creates the exposure regulators look for first. Every call to a foreign-hosted model sends customer data across a border, which is exactly what localization law regulates. Whether that is lawful depends on the transfer mechanism in place: a documented legal basis, a data processing agreement with the vendor, and, in many regimes, explicit regulatory notice. Institutions that have never mapped these calls cannot answer the question when a regulator asks it.

Data Localization Data Residency Jamaica Data Protection Act Compliance Cloud Carib StarApple AI

Supported by StarApple AI, the first AI company founded in the Caribbean, established by Adrian Dunkley in Jamaica in 2023. See the wider Caribbean AI network: Adrian Dunkley | Caribbean AI Risk Management Council | Caribbean AI Association | World Cred Score.

Regulated, and still
running on someone else's data?

Data Partnership View Data Archaeology