Skip to main content

Cloud is not one thing

Cloud describes several different operating models, not one sovereignty position. ArcGIS Online, a managed PostGIS database, a virtual server in an Aotearoa New Zealand region and a provider-hosted application can have very different data locations, responsibilities, exit options and levels of organisational control.

From a te ao Māori perspective, infrastructure is also not a neutral container sitting outside the kaupapa. It shapes who can exercise rangatiratanga, who carries kaitiakitanga, whose capability grows, what relationships become dependent on a supplier, and whether the knowledge can still be cared for when people, funding or technology change.

The cloud question is therefore wider than where does the data live? Ask who holds the keys, who can make decisions, who benefits, who carries responsibility, what whakapapa and context travel with the data, and whether the arrangement can be changed without losing control.

Common models

ModelWho runs most infrastructure?Typical Māori GIS use
SaaSsoftware vendorArcGIS Online, hosted web apps
Managed databasecloud/providerPostGIS without running the database server yourself
IaaSorganisation/provider splitvirtual servers, storage, networks
NZ managed hostinglocal or international providerapplication and database hosted for client
Māori-owned distributed storageMāori infrastructure operator and participating locationsgoverned storage or repository layer integrated with applications
Private cloud / co-locationorganisation/provider splitcontrolled enterprise environment
On-premisesorganisationlocal ArcGIS Enterprise, PostGIS, file servers
Offlineuser or organisationQGIS + GeoPackage, disconnected archive
Hybridseveralrestricted local data plus managed operational/public services

The cloud decision redistributes relationships and risk

Cloud can reduce some risks while increasing others. It can also shift capability and dependency between an iwi or hapū and the organisations that provide infrastructure.

Potential benefits

  • low initial infrastructure cost
  • professional data-centre security
  • resilient storage
  • managed hardware
  • easier remote access
  • scalable compute and storage
  • easier collaboration
  • managed backup options
  • faster deployment
  • reduced need to maintain physical servers

Potential concerns

  • subscription dependence
  • jurisdiction and provider domicile
  • unclear processing or backup locations
  • provider and identity lock-in
  • account suspension or non-payment
  • changing product terms
  • data-egress and migration work
  • subprocessors
  • internet dependence
  • service-specific AI use
  • loss of internal technical understanding
  • whānau or hapū becoming dependent on a relationship they cannot readily change

Neither list decides the answer by itself.

New Zealand cloud choices have expanded

The infrastructure picture changed materially in 2025. AWS opened its Asia Pacific (New Zealand) Region in September 2025 with three Availability Zones. Microsoft operates its New Zealand North region in Auckland with availability-zone support, and the Government Chief Digital Office has certified Microsoft New Zealand public-cloud data-centre facilities and areas under its Public Cloud Data Centre Certification scheme. New Zealand providers also appear in the certified list.

These developments make New Zealand residency more practical for many workloads. They do not make residency identical to Māori Data Sovereignty.

See Data residency is not data sovereignty.

Māori-owned infrastructure is now a live option

Te Kāhui Raraunga launched Te Pā Tūwatawata in May 2026 as a decentralised, iwi-designed, Māori-owned data storage network. Te Kāhui Raraunga says its pilot established seven Points of Presence across Aotearoa, including marae, iwi Māori enterprises and sustainable data-centre locations. It describes the service as S3-compatible, encrypted in transit and at rest, New Zealand-owned, and able to let customers select storage locations according to their own tikanga and kawa.

That is an important change in the practical landscape. Māori organisations are no longer choosing only between global cloud providers, conventional New Zealand hosting and self-managed local servers.

It also changes the nature of the conversation. A Māori-owned infrastructure option can bring ownership, relationships and decision-making closer to Māori communities rather than treating sovereignty solely as a contractual condition negotiated with an overseas platform.

It should still be assessed as infrastructure. Ask the same operational questions about security assurance, backup design, performance, service levels, costs, portability, support, independent recovery and what happens if the service or organisation changes. Māori ownership is significant, but it does not remove the practical obligations of kaitiakitanga and good engineering.

Te Kāhui Raraunga's 2026 Relational Infrastructures for Sovereign Data Storage work also argues that infrastructure should be understood through relationships and Indigenous values rather than treated as a neutral technical container. That provides a Māori-led reason to ask more than where is the server? while still examining the engineering details.

Cloud security can exceed local capability

A small hapū may be unable to reproduce the physical security, redundant power, monitoring and hardware resilience of a major data centre. A managed service can therefore reduce real operational risk.

But the service still needs:

  • hapū- or organisation-owned accounts
  • MFA
  • appropriate permissions
  • documented data locations
  • backup and recovery understanding
  • export capability
  • contract review
  • more than one internal kaitiaki or custodian
  • an exit path

Cloud is managed infrastructure, not managed rangatiratanga.

Local custody can be strong and fragile at the same time

A server in an office or marae can provide direct physical custody and offline operation. It can also be exposed to:

  • fire
  • theft
  • disk failure
  • weak patching
  • ransomware
  • one-person administration
  • no off-site backup
  • obsolete hardware

Physical proximity should not be mistaken for resilience. Nor should a server being physically close to the people automatically be treated as proof that the wider kaupapa, tikanga and succession arrangements are sound.

Hybrid is often the realistic answer

Different data classes can use different environments.

Conceptual flow

The governance layer should span all three, but so should the kaupapa, provenance and relationships that explain why the information is held in the first place.

Questions to ask before choosing cloud

  1. What kaupapa and benefit is the service supporting?
  2. Who holds authority over each data class, and can they still exercise it in this arrangement?
  3. Who owns the tenant and billing account?
  4. Where is the data stored and processed?
  5. Where are backups and disaster-recovery copies?
  6. Which corporate entity provides the service?
  7. What other jurisdictions may apply?
  8. Which subprocessors are involved?
  9. Who can administer or support the environment?
  10. Can the organisation obtain all data, metadata, attachments and provenance?
  11. What happens on non-payment or termination?
  12. Is customer content used for AI training or unrelated service improvement?
  13. What is the cost of leaving?
  14. Can two organisational people recover the service?
  15. Will the arrangement leave the iwi or hapū more capable, or more dependent, over time?

Government guidance is useful but not an iwi decision rule

The current New Zealand Government Cloud First policy requires agencies to assess public cloud case by case and consider te ao Māori perspectives for Māori data. GCDO jurisdictional guidance also states that Māori data-sovereignty interests apply regardless of where data is stored or processed.

That guidance is relevant evidence. It does not decide what a hapū or iwi should do with its own information. The decision belongs within the appropriate Māori authority and kaupapa, informed by technical evidence rather than replaced by it.

Sources

Last verified: 16 August 2026