Here is a fact that surprises most Hong Kong business owners: Hong Kong has no law that stops your company data from leaving the city. Section 33 of the Personal Data (Privacy) Ordinance was written to restrict cross-border transfers, and it has never been brought into force. Not in 1996. Not today.
So when you paste a customer list into an AI tool, nothing legally stops that data from landing on a server in Oregon. The question is not whether you are allowed to send it. The question is whether you know where it went, and whether you would be comfortable explaining that to your biggest client.
That question has a name. It is called data residency.
What is data residency?
Data residency means the physical country where your data is stored. If your AI vendor keeps your files on servers in Singapore, your data residency is Singapore. It is a question about geography, not about permission.
Three related terms get mixed up constantly, so here is the difference in plain language.
Data residency is where the data physically sits. A location on a map.
Data sovereignty is which country's laws apply to that data once it sits there. A legal question.
Data localisation is a government rule that forces data to stay inside a border. A compliance obligation.
Hong Kong has no data localisation rule for ordinary commercial data. Mainland China does. The European Union does not have a blanket one but restricts transfers heavily. Understanding which of the three someone is talking about saves a great deal of confused vendor conversation.
Why does data residency suddenly matter in 2026?
Two things changed. Regulators started asking where AI data goes, and vendors started selling the answer as a paid feature. What used to be an infrastructure footnote is now a line item on procurement checklists.
The EU AI Act became fully applicable in August 2026, bringing transparency and traceability obligations for AI systems. Any Hong Kong company selling into Europe now sits inside somebody else's paperwork.
The commercial signal is louder than the regulatory one. Research published in 2026 found that 77% of enterprises now factor a vendor's country of origin into AI purchasing decisions, and 58% build their AI stack primarily with local vendors. If you supply a European brand, a Japanese distributor or a mainland state-linked buyer, somebody in their procurement team is going to ask you this question. Probably this year.
For a Hong Kong SME, that is the practical stake. Data residency is rarely a legal problem here. It is increasingly a sales problem.
Where do the major AI tools actually store your data?
Most consumer AI tools default to storing data in the United States. Enterprise tiers let you choose a region, but the list of available regions is shorter than most buyers assume, and Hong Kong is not on it.
OpenAI offers data residency to eligible business customers across Europe, the United Kingdom, the United States, Canada, Japan, South Korea, Singapore, India, Australia and the United Arab Emirates. Hong Kong is not one of the options. For an HK company, the nearest realistic choice is Singapore or Japan.
There is a second detail that trips people up. OpenAI's residency covers data at rest, meaning stored conversations, uploaded files and generated artifacts. In-region GPU inference, meaning the actual processing, was extended to the US and Europe for eligible enterprise plans from January 2026. For everyone else, the processing still happens where the vendor decides. Storage and processing are two different questions, and vendors answer the first one much more loudly than the second.
Anthropic's Claude hosts production data on US infrastructure by default. Regional options exist, but they come from routing the model through a cloud provider such as AWS Bedrock, Google Vertex AI or Microsoft Foundry in a chosen region, rather than from Anthropic directly. That is a meaningfully different purchase from ticking a box on a subscription page.
The lesson is not that any of these vendors are careless. It is that the answer is never on the pricing page. You have to ask.
Does storing data in Asia mean it is safe from foreign law?
No. This is the single most expensive misunderstanding in the whole topic. Legal control follows the company, not the server. A provider headquartered in one country can be compelled by that country's courts even when the hard drive sits somewhere else entirely.
Two worked cases make it concrete.
A US-headquartered AI vendor storing your data in Singapore is still a US company subject to US legal process. Choosing the Singapore region reduces latency and satisfies some contract clauses. It does not place the data outside American jurisdiction.
A mainland-China-rooted provider storing data in Singapore remains subject to PRC law through its parent company, including the Personal Information Protection Law and national security legislation. The server address in Singapore does not change the corporate structure above it.
So the useful question is not only where is my data. It is who can be ordered to hand it over. Two questions, two different answers, and buyers routinely ask only the first.
How does this apply to a Hong Kong SME?
For most Hong Kong SMEs, data residency is not a compliance requirement. It is a tender question and a customer-trust question. The work is small if you do it before someone asks, and painful if you do it after.
Consider a 14-person Kwun Tong electronics exporter selling to buyers in Germany and Japan. The team uses a general AI assistant to draft quotations, an AI notetaker in supplier calls and a cloud CRM holding roughly 2,000 contacts. Three tools, three separate data locations, and nobody in the company has ever written down what those locations are.
Then the German buyer's procurement team sends a 40-question vendor security questionnaire. Question 12 asks where personal data of EU residents is processed and stored. The exporter now has to email three vendors, wait for support replies and interpret three different privacy policies, all while a purchase order sits unsigned.
Writing that down in advance takes about 90 minutes: list every tool that touches customer data, find the region setting or ask support, and record the answer in one spreadsheet. Doing it under tender pressure takes a week of chasing and puts a live deal at risk. The task is identical. Only the timing changes the cost.
There is a second, quieter benefit. Once you have that list, you usually discover two or three tools holding customer data that nobody remembered signing up for.
What do people get wrong about data residency?
Four misconceptions cause most of the wasted effort and money in this area. Each one is common enough to be worth naming directly.
Misconception 1: Hong Kong law requires my data to stay in Hong Kong. It does not. Section 33 of the PDPO has never come into force, so there is currently no statutory ban on transferring personal data out of Hong Kong. The PCPD's Recommended Model Contractual Clauses, published in 2022, are best practice rather than law. Reform proposals under consultation in 2026 include possibly activating Section 33, so this may change. This is general information and not legal advice.
Misconception 2: A local server means a local law. Covered above, and worth repeating because it is the mistake that costs real money. Jurisdiction follows the corporate entity.
Misconception 3: Free and paid tiers behave the same way. They generally do not. Consumer and free tiers commonly use inputs to improve models by default. Business and API tiers from major Western vendors are typically contractually no-training by default. The difference matters more than the region setting for a small company, because the biggest exposure is usually not geography but training.
Misconception 4: This is an IT problem. It is a procurement and sales problem wearing an IT costume. The person who needs the answer is the one filling in the customer's questionnaire, not the one configuring the laptop.
How do I check where my data is stored?
You can complete a usable data residency register in one afternoon without technical help. The output is a single spreadsheet you can attach to any future tender response.
Work through these six steps in order.
Step 1. List every tool where staff type or upload customer information. Include the AI assistant, the CRM, the notetaker, the accounting system, the chat platform and the file storage. Most SMEs find between six and twelve.
Step 2. For each one, note the plan you are on. Free, business or enterprise. This single column predicts most of the risk.
Step 3. Find the storage region in the account settings, or email support with one sentence: in which country is our data stored at rest, and in which country is it processed.
Step 4. Note the vendor's headquarters country. This is your jurisdiction answer, and it is usually different from your storage answer.
Step 5. Confirm in writing whether your inputs are used for model training. Screenshot the policy page with the date.
Step 6. Decide which two or three tools genuinely need a stricter setting, and leave the rest alone. Not every tool holding a lunch order needs enterprise-grade residency.
Frequently asked questions about data residency
These are the questions Hong Kong business owners ask most often once they start looking into this properly.
Can I get data residency in Hong Kong itself?
Not from the major global AI vendors. None currently lists Hong Kong as a residency region. Options are local hosting with a Hong Kong provider, self-hosting an open-weight model, or accepting Singapore or Japan as the nearest regional choice.
Does data residency cost extra?
Usually yes, indirectly. Region selection is normally gated behind business or enterprise plans rather than sold as a separate add-on. In practice you are upgrading a tier to get a setting.
Is my data used to train the model?
It depends entirely on the tier. Free and consumer tiers commonly do use inputs by default. Business, enterprise and API tiers from major vendors are typically no-training by default. Check and keep the evidence.
What should I tell a customer who asks where their data is held?
Name the storage country, the vendor's home jurisdiction and your training status, in that order. A specific three-line answer builds more confidence than a vague reassurance ever will.
Do I need a lawyer for this?
Not to build the register. You may want one before signing a contract that makes binding promises about data handling to a customer, especially in Europe.
The takeaway for Hong Kong business owners
Data residency is where your data physically sits. Data sovereignty is whose law can reach it. For a Hong Kong SME in 2026, the second one is usually the more important answer and almost nobody asks for it.
You do not need a legal department to handle this. You need one spreadsheet, six columns and one afternoon, prepared before a customer asks rather than after. That is the entire project.
Technology questions like this one feel intimidating mostly because nobody explains them in ordinary language. That is the part we think should change. We understand AI. UD stands with you.
Reviewed by the UD AI team, Hong Kong. Last updated 10 August 2026.
Not sure which of your tools hold customer data?
Most Hong Kong SMEs have more AI touching their customer data than they realise. A free AI Ready Check maps what you are running today and where the gaps are, and we will walk you through every step of reading the results.