Data sovereignty is now likened to the new oil, yet West Asia primarily produces the raw resource while foreign technology giants handle its refinement.
The hidden map behind servers and the myth of digital borders
On June 10, 2025, two top officials from Microsoft France testified before a French Senate committee investigating public contracts and digital sovereignty. The session maintained a typical reassuring tone until a pivotal question arose: Could the company assure that data belonging to French citizens—even if stored on servers based in France—would never be transferred to a foreign authority without authorization from the French government? Anton Carniaux, the director of public and legal affairs at the subsidiary, answered under oath with a stark six-word response: “No, I cannot guarantee that.”
This admission undermined years of corporate messaging touting “local cloud regions”, “reliable infrastructure”, and “data residency”. Even when servers are on French soil, data created by French citizens, and services paid for by French institutions, ultimate control can still lie beyond France. The committee’s conclusion was clear: Microsoft could not guarantee sovereignty over the hosted data. This exchange highlights a critical fact affecting West Asia: the physical presence of data no longer equals its political sovereignty.
Traditional geopolitics associates sovereignty with territory. Oil is owned by the state beneath which it is buried; ports are governed by the nations along whose coasts they lie; pipelines trace national borders. Power is understood through geographical boundaries. Yet, data operates under a different spatial logic.
A medical document might originate in Riyadh, be saved in Bahrain, processed by algorithms developed in the U.S., and administered through a European branch. Which nation truly holds authority? Conventionally, data belongs to those who create it—individuals, corporations, or governments. However, control over that data outweighs nominal ownership. Real influence belongs to entities that can access, handle, transfer, limit, or legally demand disclosure of the information.
The U.S. Department of Justice makes this clear. Under the CLOUD Act, companies subject to U.S. law can be legally required to provide data “regardless of where the company stores it”. While Washington frames this legislation as a means to obtain electronic evidence, geopolitically it extends U.S. authority globally via corporate reach. Today’s power map includes borders and cables but is also shaped by corporate headquarters, encryption control, legal frameworks, system administrators, and the states able to enforce cooperation.
Governments throughout West Asia are investing substantially in cloud computing, AI, digital identities, smart urban projects, and data-centric public services. Saudi Arabia aspires to lead the data economy; the UAE, Qatar, Bahrain, Oman, and Turkey are building their capabilities in information management and governance. The physical infrastructure is concentrated in regional data hubs: a 2025 World Bank assessment counted thirty-nine data centers in the UAE and thirty-three in Saudi Arabia—numbers below high-income country averages but far exceeding the wider region’s.
The digital transformation is quantifiable. According to the International Telecommunication Union, 70% of people in Arab states accessed the Internet in 2024 versus 68% globally. However, within the region, connectivity varies widely, with an 82-percentage-point difference separating the most and least connected economies. Meanwhile, fixed broadband penetration is less than half the global average. The digital divide is both swift in growth and starkly uneven.
The market for providers is highly concentrated. Research from Synergy Research Group indicates that in Q3 2025, Amazon, Microsoft, and Google commanded 63% of worldwide enterprise spending on cloud infrastructure—a $107 billion market up from $68 billion just two years prior. Nations rapidly developing digital frameworks face an already entrenched dependency. Governments might mandate data remains domestically stored yet simultaneously depend on foreign firms to manage platforms, update software, supply AI models, or control critical system layers. This creates merely an illusion of sovereignty.
Data localization addresses only where data physically resides, leaving critical issues unresolved. Who holds the encryption keys? Who controls software updates? Who can disable services? Which nation’s laws govern providers? Who can demand data disclosure, and who wields the power needed to derive strategic advantage? Storing servers within national borders does not equate to sovereign control.
Palestine and data weaponization
The effects of this invisible geography are most stark in occupied Palestine. Modern conflict increasingly relies on gathering, cross-referencing, and analyzing vast volumes of information. Phone logs, biometric data, intercepted communications, location tracking, and aerial imagery become potent military intelligence through AI and cloud technologies.
The combined deployment of Microsoft and OpenAI tools by the Israeli military soared in March 2024, reaching levels nearly 200 times those before October 7, 2023. By July 2024, data stored on Microsoft’s servers surpassed 13.6 petabytes, doubling in size, with server activity increasing by nearly 66% during the war’s initial two months. Azure was reportedly utilized to gather, transcribe, and translate surveillance information, integrating some data into target-acquisition systems.
In September 2025, Microsoft halted certain cloud and AI services to an Israeli military unit after an internal review confirmed their products were used for mass surveillance of Palestinians; the affected data resided in European cloud centers. This sequence is telling: data collected in Palestine, processed by Israeli forces, stored in Europe, and ultimately controlled by a U.S. corporation. Yet, as Hossam Nasr, a former Microsoft employee and advocate of the No Azure for Apartheid campaign, pointed out, most Israeli military contracts remained untouched. Big tech now occupies roles once exclusive to states: providing intelligence capabilities, deciding on client access, investigating abuses, and enforcing cross-border restrictions.
Israel acknowledges the strategic necessity of cloud control. The Nimbus project, awarded to Google and Amazon Web Services, aims to supply Israeli government bodies with comprehensive cloud infrastructure. The $1.2 billion contract called for local infrastructure and was pitched as a way to keep data inside Israeli borders, yet the key providers remain U.S.-based entities embedded in American legal and technological systems.
Nimbus illustrates the core paradox of data sovereignty: governments demand that information stays within national borders while outsourcing storage, computation, and platform management to foreign-based firms. Israel leveraged its influence to mitigate some risks, but most West Asian countries lack its negotiating power, technological integration with the U.S., or the ability to pressure major American corporations. Sovereignty also reflects bargaining strength.
Ultimately, control over data revolves around three strategic rights. First, the right to collect: various actors—including governments, digital platforms, telecoms, banks, and security agencies—gather data on identity, movements, communications, health, consumption, and behavior. Second, the right to process: raw information gains value only when actors have the necessary chips, algorithms, cloud platforms, and skilled staff to analyze it. Third, the right to compel: authorities and courts have the jurisdiction to demand providers disclose, retain, remove, or restrict data.
The economic concentration consolidating these rights is growing. According to UNCTAD, the five largest digital multinationals expanded their share of industry sales from 21% in 2017 to 48% in 2025, with their asset share rising from 17% to 35%. Control over data and computation is advancing more swiftly than infrastructure expansion. A country that only collects data acts as a digital raw material supplier; one that collects and processes data can emerge as a digital power; a player exercising all three rights approaches full digital sovereignty.
The economic stakes escalate rapidly. UNCTAD projects the global AI market will climb from $189 billion in 2023 to $4.8 trillion by 2033—a twenty-five-fold surge in a decade. Regions providing data but lacking computing infrastructure and intellectual property risk capturing minimal benefits. The 20th century’s strategic edge lay not just in extracting oil but refining, transporting, pricing, and financing it. The 21st century applies the same logic to data: West Asia can produce the raw input, but authority resides with the “data refineries”—cloud services, AI frameworks, and computing systems that transform information into profit, intelligence, and geopolitical power.
Moving beyond digital colonialism
The answer is not isolation. No West Asian country can independently build every layer of the global technology stack, and replacing dependence on American providers with total reliance on China or others merely shifts the center of external control. The challenge is to prevent the transition from fossil fuel reliance to digital dependence, where foreign platforms own infrastructure, harness value, and maintain control while local companies generate data. What is required is distributed technological self-reliance.
From this perspective, a set of priorities emerges. Cloud service procurement must be approached as a matter of national security, not routine IT. Contracts should clarify who controls encryption keys, how international legal requests are managed, and whether migration to alternate providers is allowed. Sensitive sectors—health, defense, biometrics, judiciary, civil registries—demand enhanced safeguards. Governments need to invest in interoperable regional cloud infrastructure, open standards, independent audits, and contingency plans to maintain critical services if foreign providers revoke access. Most importantly, data sovereignty must cover the entire lifecycle: collection, classification, processing, access, sharing, and deletion.
For over a century, West Asia’s strategic relevance was charted through oil fields, pipelines, ports, straits, and military bases. These remain vital, but an additional network has spread on top: databases, cloud contracts, legal jurisdictions, identity frameworks, AI models, and covert authorizations. Mastery over data equips states and corporations to map societies, decode behavior, forecast political and economic trends, and take informed action.
Western Asian nations are swiftly constructing the digital backbone for their economies and institutions. Yet, much of the governance over these systems still lies beyond the region. In the 21st century, controlling a territory increasingly hinges on controlling the data that reveals its people, institutions, and resources.
The June 2025 question posed to the French Senate has global resonance: those unable to ensure where their data ends up lack full sovereignty over their domain. And with that data, virtually anything can be achieved.
