- Jurisdictions requiring data to stay onshore rose from 35 to 62 between 2017 and 2021, with the underlying restrictions nearly doubling, per the Information Technology and Innovation Foundation. Compliance trackers count at least 34 dedicated national laws in force by 2026.
- Jamaica's Data Protection Act is no longer theoretical. Fines reach JMD 5 million and up to 10 years in prison for individuals on indictment, and up to 4% of global turnover for companies, enforced by the Office of the Information Commissioner.
- Cloud Carib put US$7 million into Caribbean data centres across 2025 and 2026, building sovereign pods in Bermuda, Curaçao, and Guyana because regional banks and governments are asking to keep data onshore.
- The Inter-American Development Bank estimates closing the Caribbean's digital infrastructure gap could add 6 to 12% to regional GDP over the medium term, a return many times the cost of building it.
- A localized server does not mean localized intelligence. Most credit scoring, fraud detection, and claims automation running inside Caribbean regulated entities still depends on foreign-trained models and foreign-hosted inference, which is the actual exposure sitting under every localization headline.
Data Localization Went From Fringe Rule to Default Setting
In 2017, thirty-five countries had some form of data localization control on the books. By 2021, that had climbed to sixty-two, and the number of individual restrictions those countries imposed had roughly doubled, from 67 to 144, according to research from the Information Technology and Innovation Foundation. Industry compliance trackers now count at least 34 dedicated national data localization laws in force worldwide in 2026, on top of the broader data protection statutes that already touch cross-border transfer. Financial services and health data face the tightest versions of the rule in almost every jurisdiction that has one, because regulators treat those categories as the ones a foreign court order or a foreign vendor outage can do the most damage to.
None of this started as an AI story. Most of these laws predate the current wave of AI deployment by years and were written to answer a narrower question: who can compel access to a citizen's financial or health record, and under which country's law. AI changes what the rule actually requires in practice, because a credit model or a fraud engine does not just store data, it moves data, repeatedly, every time it runs an inference call. A regulator asking "where does this data live" in 2020 was asking about a database. The same question in 2026 is asking about every API call a bank's AI vendor makes on its behalf, several thousand times a day.
Jamaica's Data Protection Act Has Teeth Now
Jamaica's Data Protection Act sets out a tiered penalty structure that regulated entities in the country can no longer treat as background reading. Processing personal data without registering as a data controller with the Office of the Information Commissioner carries a fine of up to JMD 2 million and up to six months in prison. Failing to meet the Act's eight data-handling standards carries a fine of up to JMD 5 million and up to seven years. Serious violations tried on indictment carry the same JMD 5 million ceiling and up to ten years' imprisonment for individuals. Corporate bodies face a separate ceiling entirely: fines of up to 4% of annual global gross turnover, the same figure regulators use under the EU's GDPR.
The Office of the Information Commissioner had not brought formal enforcement action against a data controller as of early 2026. Treat that as a starting gun, not an all-clear. Registration has been mandatory since 2024, the penalty tiers are already written into law, and every regulator in a young enforcement regime eventually picks a case to make an example of. Jamaica is the most tested example in the region, but it is not unusual. Most CARICOM member states have passed or drafted comparable data protection legislation, which means a bank operating across Jamaica, Trinidad and Tobago, and Barbados is already carrying three separate registration and enforcement regimes, on top of whatever regional AI-specific guidance eventually lands from bodies such as the Caribbean Telecommunications Union's AI Task Force.
The Caribbean's AI Stack Still Runs Offshore
Cloud Carib is the clearest regional answer to the localization pressure. The company put more than US$7 million into its Caribbean expansion across 2025, backed by Silicon Valley growth financing from Partners for Growth, and is building Sovereign Data Center Pods in Bermuda, Curaçao, and Guyana to join an existing footprint across the Bahamas, Jamaica, Barbados, and Panama. Its own framing of the investment is explicit: onshoring sensitive data so Caribbean institutions are not subject to a foreign court's reach. That is a real, useful, and increasingly necessary piece of infrastructure.
It is also only half the compliance question. Storage location tells a regulator where the data sits at rest. It says nothing about where that data goes the moment an AI system touches it. A bank can host its core database in a Cloud Carib facility in Kingston and still send every loan application through a foreign-hosted model API for underwriting, which moves that applicant's data across the exact border the localization rule exists to police. Building the sovereign data centre and stopping there is a half-finished compliance project that looks finished from the outside, which is worse than an obviously unfinished one, because nobody goes looking for the gap until an auditor does.
"Everyone building a data centre in the region calls it sovereignty, and the concrete really is sovereign. What runs on top of it usually is not. The model was trained somewhere else, on somebody else's population, and every inference call still has to phone home to wherever that model actually lives."
Adrian Dunkley, Founder, StarApple AI
What This Costs a Compliance Officer Who Waits
Run the numbers on a mid-sized regional bank with, say, US$40 million in annual turnover. A corporate fine at the 4% ceiling under Jamaica's Data Protection Act would run to roughly US$1.6 million, before legal costs, before the regulatory remediation plan a first enforcement action typically forces on an institution, and before the reputational cost of being the case a young regulator chose to make an example of. Set against that, the cost of mapping a vendor's data flows properly is close to nothing.
The practical work is unglamorous and specific. List every point where customer or claims data leaves the organisation's own systems: every AI vendor, every cloud model API, every third-party analytics tool. For each one, establish the physical location where processing actually happens, the legal basis for any transfer across a border, and whether the vendor contract includes a data processing addendum that would hold up if a regulator asked to see it. In our diligence work at Maestro AI Labs, the exposure almost never sits in the core banking system a compliance officer already audits. It sits in the AI vendor relationship nobody has mapped, because it was signed by a business unit that called it a productivity tool rather than a data processor.
The Data Layer That Actually Complies
The honest fix is not another data centre. It is building the AI itself from data that never had to cross a border in the first place. Maestro AI Labs' Data Archaeology product collects and structures training data directly inside the Caribbean, from government archives, cooperative and SUSU financial records, and regional climate data, so the credit models and risk tools built on it are not depending on a foreign dataset or a foreign vendor's pipeline that the institution cannot audit. Harmonics, the agent framework built on that data, logs every decision with a human override in place, which is the audit trail a data protection regulator asks for the moment it opens a file.
None of this is a quarter's work. Collecting and structuring records that were never digitised in the first place takes years of relationship-building with the archives, cooperatives, and government offices that hold them, not a procurement cycle. It will not close the gap between now and a compliance officer's next audit. What it does is stop the gap from reopening every time the institution renews a vendor contract. That is also the wider case StarApple AI, the first AI company established in the Caribbean, has been building since Adrian Dunkley founded it in Jamaica in 2023. Compliance-minded institutions do not have to choose between using AI and staying inside their own jurisdiction's law. They have to choose which data infrastructure they build that decision on top of. The Caribbean AI Risk Management Council has been doing parallel work on the governance side, building the frameworks regulated boards need to evaluate exactly this kind of vendor exposure before a regulator does it for them.
Sixty-two countries now require data to stay home. Jamaica's regulator has the penalty tiers written and the registration list filled, and has simply not picked its first case yet. Whichever institution it picks will not be the one that built a data centre. It will be the one that never checked where its AI vendor actually sent the data.