Answer first: Microsoft is moving the AI processing behind Microsoft 365 Copilot inside national borders — 15 countries by 2026. It confirms that "data sovereignty" is now mainstream, not just a bank-and-government concern. But "in-country processing" only answers where data is processed; it doesn't answer who controls it. For genuinely sensitive data — and for Vietnam's storage duties under the 2025 Cybersecurity Law (No. 116/2025/QH15) and Decree 333/2026/ND-CP — the highest level of control remains internal / on-premise AI: the model runs inside your own infrastructure and data never leaves your control.
TL;DR
- Anchor event: On 4 Nov 2025, Microsoft announced an expansion of in-country data processing for Microsoft 365 Copilot — Copilot interactions are processed in data centers located within a nation's borders.
- The numbers: 4 countries get it by end of 2025 (Australia, UK, India, Japan) + 11 more in 2026 = 15 total with in-country processing; Microsoft also offers in-country data residency in 27 countries.
- The trend: Gartner forecasts that by 2030, more than 75% of European and Middle Eastern enterprises will "geopatriate" their virtual workloads, up from less than 5% in 2025.
- Vietnam law: Cybersecurity Law No. 116/2025/QH15 (effective 1 Jul 2026, replacing the 2018 Cybersecurity Law), Article 25(3), requires certain user data to be stored in Vietnam; Decree 333/2026/ND-CP (effective 19 Aug 2026) provides the detail.
- NAM Tech angle: "In-country" fixes where, not who controls. When sensitive data must never leave your perimeter, the definitive answer is internal / on-premise AI.
1. What Microsoft announced
On 4 November 2025, Microsoft announced an expansion of in-country data processing for Microsoft 365 Copilot. Per Microsoft, Copilot interactions "are processed, under normal operations, in data centers located within a nation's borders," giving customers more control over their data. In other words: the prompt you send and the model's response are kept and processed in-country.
Microsoft set out the rollout in two phases:
| Phase | Countries | List |
|---|---|---|
| Available by end of 2025 | 4 | Australia, UK, India, Japan |
| Added during 2026 | +11 | Canada, Germany, Italy, Malaysia, Poland, South Africa, Spain, Sweden, Switzerland, UAE, US |
| Total with in-country processing | 15 | — |
| Existing in-country data residency | 27 | — |
Source for Table 1: Microsoft 365 Blog, "Microsoft offers in-country data processing to 15 countries…", 4 Nov 2025.
2. Residency vs. processing
- Data residency means data is stored in-country. Microsoft says it offers this in 27 countries.
- In-country processing means the inference step (prompt → model → response) also stays inside the border, not just storage. This is the new expansion for Copilot, targeting 15 countries.
The key point: both are still run on the provider's infrastructure — not yours. They close the geographic gap, but the data still lives on the vendor's platform.
3. The bigger trend: data sovereignty goes mainstream
The fact that a hyperscaler like Microsoft has to "bring AI home" reflects industry-wide pressure. Gartner forecasts that by 2030, more than 75% of European and Middle Eastern enterprises will "geopatriate" their virtual workloads — moving them to options that reduce geopolitical risk (sovereign cloud, regional providers, or their own data centers) — up from less than 5% in 2025.
| Metric / Milestone | Value | Source |
|---|---|---|
| EU & Middle East enterprises "geopatriating" workloads by 2030 | >75% (vs <5% in 2025) | Gartner |
| Microsoft 365 Copilot — in-country processing (total) | 15 countries | Microsoft |
| Vietnam — Cybersecurity Law 116/2025/QH15 takes effect (replacing the 2018 law) | 1 Jul 2026 | Law 116/2025/QH15 |
| Vietnam — Decree 333/2026/ND-CP implementing the Cybersecurity Law takes effect | 19 Aug 2026 | Decree 333/2026 |
| Vietnam — minimum storage period (counted from when the firm receives a storage request) | 24 months | Decree 333/2026, Article 20 |
| Vietnam — in-scope foreign firms must complete storage and set up a branch/representative office after a decision by the Minister of Public Security | within 12 months | Decree 333/2026, Article 19 |
| Vietnam — AI Law 2025 passed by National Assembly | 10 Dec 2025 | Bao Lam Dong |
| Vietnam — mandatory labeling of AI-generated content | from 1 Mar 2026 | Bao Lam Dong |
Sources: Gartner (Top Strategic Technology Trends 2026, via Help Net Security), Microsoft 365 Blog, Vietnam Government Portal (Law 116/2025/QH15, Decree 333/2026/ND-CP), Bao Lam Dong.
4. The Vietnam angle
Vietnam localized data even before the AI wave:
- Cybersecurity Law No. 116/2025/QH15 (passed 10 Dec 2025, effective 1 Jul 2026) replaces the 2018 Cybersecurity Law and the 2015 Law on Network Information Security (Article 44(2)). Article 25(3) requires domestic and foreign enterprises providing telecom, Internet and value-added cyberspace services in Vietnam that collect, exploit, analyse or process personal-information data, relationship data and data generated by service users in Vietnam to store that data in Vietnam for the period set by the Government; in-scope foreign enterprises must set up a branch or representative office in Vietnam.
- Decree 333/2026/ND-CP (issued and effective 19 Aug 2026) provides the detail. Article 19 lists the data to be stored in Vietnam: personal information of service users in Vietnam, and user-generated data (account name, usage time, credit card information, email, most recent login/logout IP address, phone number linked to the account). Domestic enterprises store this data in Vietnam. Foreign enterprises only have to store it and set up a branch/representative office if they operate in a listed sector, their service has been used to violate cybersecurity law without remediation, and the Minister of Public Security issues a decision; they then have 12 months from that decision to comply.
- Article 20 of Decree 333 sets a minimum storage period of 24 months, counted from when the enterprise receives the storage request; system logs for investigation must be kept for at least 12 months. How this counting rule applies to your specific case should be confirmed by a lawyer.
Scope note: this article does NOT advise on avoiding legal obligations or circumventing the 2025 Cybersecurity Law (No. 116/2025/QH15) or Decree 147/2024/ND-CP on the management, provision and use of internet services and online information. The goal is to help enterprises comply better through the right data architecture.
5. When in-country isn't enough — the role of internal / on-premise AI
In-country processing fixes geography, but three questions remain:
- Who controls the keys and access? On a provider's service, ultimate operational control belongs to the provider, wherever the data center sits.
- Does data leave your infrastructure? With a public API, sensitive payloads still have to be sent out to be processed.
- Are you locked to one vendor? Vendor lock-in risk is one reason Gartner named "geopatriation" among its Top Strategic Technology Trends 2026 — trend #10.
For genuinely sensitive data (customer records, IP, data subject to mandatory residency), the definitive control is internal / on-premise AI: deploy an open model in your own data center or server cluster so data never leaves your perimeter. That is the strongest form of data sovereignty — and, by definition, a third party's "in-country" service does not reach it.
6. What Vietnamese enterprises should do
- Classify data first. Not everything needs on-premise. Separate mandatory-residency / sensitive data from the rest.
- Map legal obligations. Cross-check the 2025 Cybersecurity Law (Article 25) and Decree 333/2026 (Articles 19–20) to see which data types must be stored in Vietnam and for how long.
- Pick the right architecture layer. Public cloud for low-sensitivity tasks; in-country for location compliance; on-premise / internal AI for core data.
- Prepare for AI labeling. From 1 Mar 2026, AI-generated/edited content simulating real people or events must carry a clearly recognizable label under the AI Law 2025.
Frequently asked questions
Does Microsoft's "in-country data processing" mean my data never leaves the country?
Not automatically. The feature currently applies to the 15 countries Microsoft announced (Vietnam is not on the list), and even then, data still sits on Microsoft-operated infrastructure "under normal operations." To guarantee data never leaves your own infrastructure, you need internal / on-premise AI.
Are Vietnamese enterprises required to store data domestically?
Some data types, yes. Under Cybersecurity Law No. 116/2025/QH15 (effective 1 Jul 2026, replacing the 2018 law), Article 25(3), enterprises providing telecom or Internet services in Vietnam that process personal information, relationship data and data generated by users in Vietnam must store that data in Vietnam. Decree 333/2026/ND-CP (effective 19 Aug 2026) details the data types and storage period. Consult a lawyer for your specific case.
When does AI-generated content have to be labeled?
From 1 Mar 2026, under the AI Law 2025 (passed by the National Assembly on 10 Dec 2025). Audio/image/video content created or edited by AI to simulate real people or events must carry a clearly recognizable label; film and the arts apply it flexibly.
What is "geopatriation"?
Moving data and applications off the global public cloud toward domestic options (sovereign cloud, regional providers, or your own data center) to reduce geopolitical risk. Gartner forecasts more than 75% of European and Middle Eastern enterprises will do this by 2030.
Is internal AI always the right choice?
No. Classify your data: low-sensitivity tasks can use cloud/in-country for cost efficiency; only core/sensitive/mandatory-residency data really needs on-premise.
Keep data and prompts inside your organization
Namtech deploys internal AI running 100% on-site — the model and data never leave your firewall, keeping data sovereignty at a level a third party's "in-country" service cannot reach.
Book a free consultationThis article is informational, not legal advice. Enterprises should consult experts before making compliance decisions. Compiled from public sources as of 15 July 2026; the Vietnam legal section was updated on 24 September 2026 under Cybersecurity Law 116/2025/QH15 and Decree 333/2026/ND-CP. Subject to change.
- Microsoft 365 Blog — Microsoft offers in-country data processing to 15 countries… Microsoft 365 Copilot (4 Nov 2025)
- Help Net Security citing Gartner — Top Strategic Technology Trends 2026 (23 Oct 2025)
- Vietnam Government Portal — Cybersecurity Law No. 116/2025/QH15 (effective 1 Jul 2026)
- Vietnam Government Portal — Decree 333/2026/ND-CP detailing the Cybersecurity Law (19 Aug 2026)
- Bao Lam Dong — AI Law 2025: mandatory labeling of AI-generated content from March 2026