A large cloud provider signed a marketing agreement with a startup this year, and the pitch fits in one sentence: your data never leaves your own environment.
It is a genuinely good sentence. It is also doing far more work than it can carry, and the gap between what it says and what people hear is where the trouble sits.
Read the deal, not the announcement
What actually changes is where the thing runs. Databases spin up inside your own cloud rather than somebody else's. Processing happens under your existing controls. The data stays put.
That is residency. Residency is a real property and it is worth having.
It is not governance, and the announcement is very comfortable letting you conflate the two.
Residency is not governance
Residency answers one question: which building is it in.
Governance answers the ones that actually generate risk. Who can see it. Who granted them that. Who is reviewing that list. What happens when somebody leaves. How long is it kept. Can you produce, on demand, a list of everything you hold about one person.
A database sitting inside your own environment with permissions nobody has reviewed in two years is not safer than a hosted one. It is just closer.
In this business the sensitive material is unusually concentrated: financial position, timelines, family circumstances, why somebody is moving. If a divorce is the reason a house is on the market, that fact is somewhere in your systems, in somebody's notes, and residency has nothing whatever to say about who can read it.
Shadow IT with a badge
The second effect is the one I would actually watch.
These tools let somebody who is not technical describe an application and get a working one. Which is marvellous, and it means the number of small systems holding client data is about to increase sharply, built by people with no obligation to tell anybody they built them.
That used to be called shadow IT and it was discouraged. Now it arrives with an official logo on it, which makes it harder to argue with and no less real.
Somebody on your team will build a lovely little tracker for buyer preferences. It will be genuinely useful. It will hold personal information. Nobody will ever review who has access to it.
The lock-in moved down a layer
Worth naming plainly: "it stays in your cloud" is also a very effective way of ensuring you keep buying that cloud. Your data is portable in principle and the thing built around it is not.
That is not sinister. It is just the deal, and you should price it as part of the deal rather than as a safety feature.
The playbook
List where client information actually lives. Including the spreadsheet, the shared drive, the phone, and the tool somebody built last month. You cannot govern an inventory you have not taken.
Review who has access, on a date, in the diary. Once a quarter, fifteen minutes. The most common breach in a small business is a person who left and kept working access.
Decide how long you keep things. Most people keep everything forever by accident. Deciding is cheaper than defending.
Ask the exit question before you sign. Not "can I export my data." Everybody says yes. Ask what specifically you get, in what format, and how long it takes.
Any road up
Data never leaves is a fine property to have and a poor thing to relax about.
Ask the second question. Who can see it, who said so, and when did anybody last check.