Skip to content

Geographic Data Strategy for Ukrainian Businesses: Local or Global Multiregional Cloud?

Ensuring business continuity and resilience against external threats is a priority for Ukrainian enterprises, especially in the current geopolitical instability. The choice of a geographic strategy for hosting critical data and applications is becoming one of the most important strategic decisions. Should preference be given to local cloud providers offering compliance with Ukrainian legislation and low latency, or is it better to opt for global multiregional architectures that guarantee enhanced fault tolerance, scalability, and global availability?

Local Cloud in Ukraine: Advantages and Risks

Hosting data and applications in local cloud environments in Ukraine offers several attractive advantages. Firstly, it simplifies compliance with Ukrainian legislation, particularly the requirements of the State Service of Special Communications and Information Protection of Ukraine (SSSCIP) and the National Bank of Ukraine (NBU) regarding data sovereignty and protection. Ukrainian cloud providers such as GigaCloud, De Novo, Kyivstar Cloud, VoliaCLOUD, and UCloud are actively working to obtain relevant certifications (ISO/IEC 27001, PCI DSS, КСЗІ, NIST), confirming their ability to ensure a high level of security and compliance.

Secondly, local hosting provides minimal latency for users in Ukraine, which is critical for applications sensitive to response speed. Thirdly, many executives feel a greater sense of control over data when it is physically located within the country. However, a local cloud is not without its risks. The main drawback is the potential single point of failure. In wartime conditions, local data centers can be vulnerable to physical attacks, power outages, or network failures, which can lead to business downtime. Although Ukrainian providers often have multiple data centers, including some in the EU, complete isolation from regional risks within Ukraine remains a challenge.

Global Multiregional Cloud: Architectural Capabilities for Resilience

Global multiregional cloud architectures offered by hyperscalers (e.g., AWS, Microsoft Azure, Google Cloud Platform) provide the highest level of fault tolerance and business continuity. Key advantages include:

  • Enhanced Fault Tolerance: Distributing data and applications across multiple geographically distant regions and availability zones ensures that a failure in one region does not lead to a complete system outage.
  • Scalability and Flexibility: Global clouds allow for easy scaling of resources up or down according to business needs, paying only for the capacity actually used (pay-as-you-go).
  • Global Availability: Applications and data are accessible from anywhere in the world, which is important for companies with international operations or remote teams.
  • Advanced Disaster Recovery Strategies (DRaaS): Multiregional architectures support complex disaster recovery scenarios, including active-active configurations, which provide near-zero Recovery Time Objective (RTO) and minimal Recovery Point Objective (RPO).

However, using global cloud providers requires careful consideration of data sovereignty issues. Although the NBU allows banks to use cloud services with infrastructure located in the EU, UK, USA, and Canada during martial law and for two years after its cancellation, for other sectors, questions may arise regarding compliance with Ukrainian legislation, especially concerning personal data and state information resources.

Ukrainian Legislative Requirements and Compliance

Ukrainian legislation, particularly the Law of Ukraine "On Cloud Services" and NBU Resolution No. 99, sets clear requirements for the use of cloud technologies, especially for the financial sector and government agencies. Financial institutions are obligated to inform the NBU about the conclusion, amendment, or termination of cloud service agreements, as well as to conduct risk assessments and control the processing of restricted-access information. It is important to verify that there are no discrepancies in the processing of restricted-access information between Ukrainian legislation and the legislation of the country where the cloud service provider is registered.

The SSSCIP has also clarified that creating protection systems using foreign cloud platforms is not prohibited if the licensed company conducts an expert audit of the system's protection profiles and obtains a positive conclusion. For government agencies and critical infrastructure operators, an official registry of cloud service providers is being introduced, and providers must provide certificates of compliance with security standards and an SBU conclusion.

Key Selection Criteria: Comparative Analysis

The choice between a local and a global multiregional cloud strategy requires a comprehensive approach that considers the unique needs and risks of Ukrainian businesses. To make an informed decision, a comparative checklist is recommended:

  • Legal Compliance: How well does the solution comply with the requirements of the SSSCIP, NBU, the Law "On Cloud Services," and the Law "On Personal Data Protection"? Are additional audits and certifications required?
  • Service Level Agreement (SLA): What guarantees of uninterrupted operation does the provider offer? Does it meet the critical needs of the business?
  • Disaster Recovery Strategies (DRaaS): What recovery capabilities does the provider offer? What RTO (Recovery Time Objective) and RPO (Recovery Point Objective) can the chosen architecture achieve?
  • Cost: Comparison of total cost of ownership (TCO), including capital and operational expenses, licenses, support, and traffic costs.
  • Latency: How critical is low latency for your applications and users? How will it affect performance?
  • Management Complexity: How difficult will it be to manage and monitor the chosen infrastructure? Is there sufficient in-house expertise, or are external specialists needed?
  • Resilience to Regional Failures/Attacks: How well is the chosen solution protected against local incidents (physical attacks, power outages, network failures) and cyberattacks?
  • Scalability: Does the solution allow for easy scaling of resources in the future according to business growth?
  • Security: What security measures (encryption, monitoring, DDoS protection) does the provider offer? What certifications does it hold?
  • Data Localization: Are there requirements for the physical location of data within Ukraine? How does this affect the choice of provider and architecture?

Choosing the optimal geographic strategy for data and application hosting is key to ensuring the resilience of Ukrainian businesses. Balancing the advantages of local hosting (legal compliance, low latency) with the enhanced fault tolerance, scalability, and global availability of multiregional cloud architectures requires deep analysis. In the face of heightened risks, hybrid and multi-cloud strategies that combine local resources with global ones may become the optimal solution, allowing companies to meet regulatory requirements while simultaneously ensuring a high level of resilience and business continuity.

Sources

  1. 01chambers.comPeculiarities of cloud service operations in Ukraine | Article | Chambers and Partners
  2. 02escd.com.uaLegal Regulation of the Cloud Services Market of Ukraine - European Center of Sustainable Development
  3. 03sud.uaCloud services are set to be regulated in a new way: maintaining the list of providers may be transferred to the Ministry of Digital Transformation - sud.ua
  4. 04cms-lawnow.comAI laws and regulations in Ukraine | CMS Expert Guide

Does any of this match your situation?

Tell us where you are now — we will suggest a practical route for infrastructure, cloud or security.

Discuss a project