Insights · Sovereign & air-gapped AI

Data residency for healthcare AI

Dario Heymann, PhD ·

Data residency means your data is stored in a specified jurisdiction. For healthcare AI that is necessary and it is the weakest of the guarantees on offer, because storing data in a country says nothing about where it is processed, who can access it, or whether it crosses a border transiently during inference.

The distinctions between residency, localisation, processing locality and transfer are frequently blurred in vendor material, and the blurring usually favours the vendor. For the wider picture, see sovereign AI. Regulatory positions described here are current as of August 2026 and change frequently — verify against primary sources before relying on any of it.

Four terms that are not synonyms

Data residency. Where data sits at rest. A system with data resident in Singapore, processed by a model serving from another region, satisfies residency and fails almost everything a sovereignty assessment cares about.

Data localisation. A legal requirement, imposed by statute or regulation, that certain data be stored — and sometimes processed — within national borders. Several ASEAN markets impose localisation requirements on health or government data, varying materially by jurisdiction and category.

Processing locality. Where computation happens when your data is in context. The question to ask precisely: does content leave the facility for any purpose — inference, logging, telemetry, monitoring or abuse detection?

Cross-border transfer. The regulated act of moving personal data between jurisdictions. The point that catches AI deployments: transfer includes transient processing. Sending a document to a model in another region for inference is a transfer, even though nothing was stored there. See PDPA and AI for how this plays out under Singapore's law specifically.

What this means for an AI deployment

Map the data flow before choosing infrastructure. For each workflow: what data enters, where does it come to rest, where is it processed, what leaves, and where does that go — including logs, telemetry, backups and any monitoring pipeline. Deployments fail this analysis at the edges rather than the centre.

De-identification changes the analysis but is not a free pass. De-identified data typically falls outside the strictest transfer restrictions, but re-identification risk rises with aggregation, and an AI system that assembles data across sources is precisely an aggregation engine.

Residency of the evidence base, not just the source data. Embeddings derived from patient records are derived from patient records. Vector stores, indexes and backups all need to sit within the same boundary as the data they came from — routinely missed, since the primary database is carefully located and the vector index is wherever the platform put it.

Where Eclypse sits: the evidence base — including embeddings and indexes derived from it — is deployed inside the same boundary as the source data, not wherever the platform's default happens to place it.

See AI for government health agencies for how residency requirements play out at the strictest end of this spectrum.

FAQ

Common questions about data residency.

What is data residency in AI?

A commitment that data is stored in a specified jurisdiction. It constrains storage location only, not where processing happens or who can access the running system.

Does sending data to an AI model count as a cross-border transfer?

Generally yes, if the model is served in another jurisdiction — transfer rules typically cover transient processing, not just storage.

Does de-identifying data remove residency restrictions?

Often it reduces them substantially, but re-identification risk rises when data is aggregated across sources — assess against the combined dataset, not each field.

Do embeddings and vector indexes inherit data residency requirements?

Yes. Embeddings and indexes derived from restricted data generally carry its restrictions — routinely missed in residency analyses.

Show us your deployment constraints — we'll map where the data actually goes.

Book a working session
ECLYPSE AI

Our proprietary AI orchestration platform for healthcare: one engine, a registry of reusable task modules and domain agents, and a governed knowledge base — deployed inside your walls and run by your team.

© 2026 Eclypse Pte. Ltd. Privacy policy
Singapore