In this article

We answer a specific legal question that general Singapore sovereignty content doesn’t: whether US CLOUD Act jurisdiction reaches infrastructure physically hosted in Singapore, how that’s separate from Singapore’s own PDPA framework, and what that means if you’re evaluating a US-owned infrastructure provider for APAC deployment.


If you’re deploying infrastructure in Singapore and your provider is a US company, there’s a specific legal question worth answering plainly: does US law reach your data anyway, regardless of where the servers sit?

This is a narrower question than the general “is Singapore infrastructure sovereign” discussion, and it deserves a direct answer rather than getting folded into broader sovereignty language.

Singapore’s PDPA Doesn’t Require Data Localization

Singapore’s Personal Data Protection Act, in force since 2012, governs how organizations collect, use, and disclose personal data in the private sector. Unlike several of its regional neighbors, including Indonesia, Vietnam, and India, Singapore’s PDPA does not mandate that data physically stay within the country. There’s no blanket data localization requirement in the way GDPR imposes transfer restrictions in the EU.

That means choosing a Singapore data center for data residency is generally a business and performance decision in Singapore’s case, not a strict legal mandate under the PDPA itself. Companies still choose Singapore for real reasons: low latency to Southeast Asian markets, MAS compliance requirements if you’re a regulated financial entity, or your own customers’ contractual expectations around where their data lives. But it’s worth being precise that the legal driver is different from the EU, where GDPR’s transfer rules make residency a more direct compliance requirement.

The Separate Question: Whose Laws Actually Reach the Data

PDPA governs what happens to data processed in Singapore. It says nothing about whether a foreign government can compel your infrastructure provider to produce that data, and that’s a function of the provider’s corporate jurisdiction, not the data center’s location.

If your infrastructure provider is a US company, the US CLOUD Act applies to it. The CLOUD Act gives US law enforcement authority to compel US-based companies to produce data they control, regardless of where that data is physically stored, including in a facility in Singapore. A Singapore data center run by a US-owned company doesn’t sit outside that reach just because the hardware is in Singapore. The legal exposure follows the company’s incorporation and control, not the server rack.

This is the same structural point that applies to any US-owned provider’s EU region, and we’ve written about it directly in that context; see our breakdown of EU data residency versus data sovereignty. The mechanism is identical in Singapore. What changes is the local regulatory backdrop PDPA and MAS create around it, not the underlying jurisdictional fact.

Where OpenMetal Stands, Plainly Stated

OpenMetal operates within a data center in Singapore. Workloads deployed there run in Singapore, and data stored there stays there, in the sense that we don’t replicate or move it to other regions without you architecting that yourself.

We are a US company. Like every US-headquartered infrastructure provider, we’re subject to US legal process, including the CLOUD Act, regardless of which of our data centers a workload runs in. We’re not going to describe our Singapore facility as sitting outside US jurisdictional reach, because it doesn’t.

What we can tell you is what actually limits exposure in practice: you get full root access to dedicated, single-tenant hardware, we don’t hold your encryption keys or maintain standing credentials into your environment, and our infrastructure is built on OpenStack and Ceph, open standards that mean your architecture isn’t locked to us even if your posture on this question changes later. None of that changes our jurisdictional status. It does mean a legal request for data we actually hold or can access is a narrower thing than a request against a fully managed platform where the provider has broader technical access to customer environments by design.

Why This Matters More for Some Buyers Than Others

For a lot of companies choosing Singapore for latency, cost, or general APAC market access, this distinction is background information rather than a deciding factor. Singapore’s PDPA doesn’t force the question the way GDPR’s transfer rules do, so many buyers reasonably prioritize performance and cost over jurisdictional purity.

It matters more directly for two groups:

  • Financial entities subject to MAS requirements often need to document exactly where data sits and who could compel access to it as part of their own regulatory obligations, even though MAS rules and the CLOUD Act are separate legal questions.
  • And any organization with a genuine mandate for infrastructure entirely outside US legal reach needs to know that a Singapore facility under US ownership doesn’t satisfy that mandate, no matter how the marketing is worded. Better to know that before signing a contract than during an audit.

What This Doesn’t Answer

Whether a Singapore deployment under a US-owned provider satisfies your specific MAS obligations, your customers’ contractual data requirements, or your own board’s risk tolerance is a question for your legal and compliance team, not a vendor blog post. What we can confirm is the structural fact: US jurisdiction follows the company, and no infrastructure location changes that on its own.

Getting Started

Current bare metal and hosted private cloud configurations available in Singapore are on our bare metal pricing page and hosted private cloud product page. For the connectivity case for Singapore specifically within APAC, see why Singapore outperforms Tokyo and Sydney for APAC infrastructure. For a deeper look at what actually determines sovereignty at the architecture level, beyond the jurisdictional question this article covers, see The Infrastructure Foundations of Digital Sovereignty.

FAQ

Does Singapore’s PDPA require data to stay in Singapore?

No. Unlike GDPR in the EU, or data localization laws in some neighboring countries such as Indonesia and Vietnam, Singapore’s PDPA does not mandate that personal data physically remain in-country. Choosing Singapore infrastructure for residency is generally a business decision rather than a strict PDPA requirement.

Does the US CLOUD Act apply to a Singapore data center?

If the data center is operated by a US company, yes. The CLOUD Act’s reach follows the corporate jurisdiction of the company controlling the data, not the physical location of the servers. A Singapore facility run by a US-owned provider is still subject to US legal process.

Is OpenMetal’s Singapore infrastructure sovereign from US jurisdiction?

No, and we don’t claim otherwise. OpenMetal is a US company, and that status applies to our Singapore data center the same as it does to our US and EU facilities. We provide Singapore data residency and dedicated, single-tenant infrastructure with customer-controlled access, not exemption from US legal process.

Does this affect MAS compliance for financial services companies in Singapore?

MAS requirements and CLOUD Act jurisdiction are separate legal questions. A financial entity’s MAS obligations are worth evaluating independently of, and in addition to, the jurisdictional question this article addresses. Confirm specifics with your compliance and legal team.



Chat With Our Team

We’re available to answer questions and provide information.

Reach Out

Schedule a Consultation

Get a deeper assessment and discuss your unique requirements.

Schedule Consultation

Try It Out

Take a peek under the hood of our cloud platform or launch a trial.

Trial Options

 

 

 Read More on the OpenMetal Blog

Running Confidential Computing Workloads in the EU in Amsterdam

Jul 24, 2026

We explain what Intel TDX confidential computing actually protects, confirm which hardware configuration delivers it in our Amsterdam data center today, and walk through why pairing TDX with EU data residency matters for regulated workloads.

EU Data Residency and Data Sovereignty Are Not the Same Thing

Jul 20, 2026

We break down the real difference between data residency and data sovereignty, why many “sovereign cloud” claims from US-owned providers don’t hold up under scrutiny, and what EU-based infrastructure can and can’t actually guarantee.

Why MEV Block Building Infrastructure Is Moving to TDX Bare Metal

Jul 09, 2026

The operator trust problem in MEV block building has a hardware solution. This article explains why Intel TDX has become the substrate of choice for confidential block building, and what bare metal adds that cloud TDX doesn’t.

Enabling Intel SGX and TDX on OpenMetal v4 and v5 Servers: Hardware Requirements

Jun 11, 2026

Learn how to enable Intel SGX and TDX on OpenMetal’s v4 and v5 servers. This guide covers required memory configurations (full channel allotment and 1TB RAM), hardware prerequisites, and a detailed cost comparison for provisioning SGX/TDX-ready infrastructure.

Running Confidential AI Inference on Bare Metal TDX Servers

Jun 11, 2026

Running AI inference on sensitive data requires hardware-level isolation, not just software controls. This guide covers how to build a confidential inference pipeline on OpenMetal’s XL v5 using Intel TDX, including Trust Domain setup, vLLM deployment, attestation, and storage architecture.

How MSPs Can Win Clients With Compliance and Private Cloud

Apr 30, 2026

Enterprise clients in regulated industries are asking harder infrastructure questions than most MSPs are equipped to answer. This article covers where the Microsoft stack has limits for compliance workloads, what private cloud adds to an MSP’s portfolio, and how to start without overhauling your entire stack.

Is Your AI Infrastructure Ready for the EU AI Act?

Apr 28, 2026

EU AI Act compliance is more than a legal project, but an architecture decision. This article breaks down the four infrastructure requirements high-risk AI systems must meet, where public cloud creates compliance gaps, and how dedicated EU infrastructure with hardware-level isolation changes the picture.

Why Proof-of-Stake Validators Outgrow Their Hosting Provider

Apr 21, 2026

Professional PoS validator operations have specific infrastructure demands that general hosting and public cloud weren’t built for. This guide covers the five requirements that separate adequate from production-grade hosting, where public cloud falls short, and what to verify before signing with a provider.

Evaluating Intel TDX for Production Workloads in 2026

Mar 11, 2026

Intel TDX has matured past the proof-of-concept stage, but “production-ready” means different things depending on your workload and team. This guide covers real performance overhead figures, operational complexity, hardware options on OpenMetal v4 and v5, and when to adopt vs. wait.

Secret Network to Silicon: Building a True Confidential Computing Stack with Intel TDX on Bare Metal

Mar 01, 2026

Secret Network proves encrypted smart contracts work. Intel TDX on bare metal completes the confidential computing stack from application layer to silicon.