Comment by michael-bey

15 hours ago

What a nightmare scenario to tabletop. How do you even begin to recover from something like this?

For providers that just act as middlemen, I assume data that doesn't have a residency requirement is stored outside, so probably

a) letting customers in other areas know that their data is backed up to another continent

b) asking the AI model of your choice to translate the following into PR-speak: "Because of the boneheaded data residency requirements in this country, all your data is gone, and we weren't able to do anything about it - here's an empty copy of a re-setup version of whatever infrastructure we provide, glhf setting up everything from scratch, hope you had backups"

For customers who use such a provider or operate primarily in that area: Restore from local backups, or tell whoever depended on you that everything is gone and if you really didn't have backups, probably close up shop.

Backups in a different region?

  • Works unless local laws specifically block you doing that which they do for some classes of data in some countries.

    Multi-cloud in the same country (if that exists in the country and is far enough apart) maybe.

    • I wonder what exactly these laws prohibit. Like, does it apply to a fully encrypted cold-copy on Amazon Glacier? If you don't store the encryption key outside of UAE, I'd say this isn't even the same data that gets transferred to the third party, it's just some random blob. But I have no idea if the authorities of that country would agree and if it's even actually enforced for that matter, or if it's one of those laws that actually cause problems only if you follow them.

    • In this case, a local on-prem backup in your office-that-is-not-an-aws-datacenter would've worked and satisfy the law right?

      (or an AWS Outpost thingy, assuming those things work even if the mothership is down)