Technology

Data as strategic resource and cross-border data flows

Data becomes a strategic resource when control over its collection, transfer, processing or denial creates intelligence, industrial or coercive advantage. Cross-border data flows connect firms and public services, but also expose sensitive information to foreign legal authority, infrastructure control and platform concentration.

Strategic value

Data differs from a depletable commodity. It can be copied, combined and reused, while value often depends on scale, quality, timeliness and complementary computing capacity. Personal, genomic, geolocation, financial, government and industrial data present different risks. The relevant asset is therefore not data in the abstract, but a defined dataset and the systems that make it usable.

Hyperscale cloud infrastructure concentrates storage and computation in a small number of providers. Platforms can control access to users, advertising and application ecosystems. Governments can compel disclosure, restrict transfers or condition market entry. These dependencies exemplify Weaponised interdependence when a state turns network centrality into surveillance or denial power.

Regulatory controls

China's Data Security Law establishes classification, security duties and controls relating to important data and national-security interests. Other Chinese laws and implementing measures add personal-information and cybersecurity requirements. These instruments should not be collapsed into one general localisation mandate.

The United States created a different architecture through Executive Order 14117 and implementing Department of Justice regulations. It restricts or prohibits specified transactions that could give countries of concern access to bulk sensitive personal data or government-related data. The regime uses transaction classes, thresholds, security requirements and exemptions rather than a general ban on international transfers.

Data-localisation and cross-border-data restriction can improve sovereign control and regulatory access, but it can also fragment services, raise costs and concentrate data inside a target jurisdiction. CISA security requirements show that risk mitigation can operate alongside prohibition.

Statecraft application

Data controls may protect citizens, constrain intelligence collection or deny inputs to foreign artificial-intelligence systems. They may also pressure platforms through divestiture, licensing or access conditions, as in United States forced-divestiture policy towards TikTok (2020-present). Intent and legal authority matter because privacy regulation, national-security action and commercial protection can produce similar technical effects.

As at 30 July 2026, analysis should specify the data category, volume threshold, country nexus, transaction type, operator and control point. A cross-border flow is neither inherently benign nor inherently coercive. Strategic effect follows from who can lawfully access, combine, process or interrupt it.

Measurement and safeguards

Strategic exposure can be tested through data mapping. The operator should know what is collected, where it is stored, which legal entity controls it, who can administer the system, which subprocessors receive it and how quickly access can be revoked. Encryption reduces some risks but does not solve lawful-access, endpoint or metadata exposure by itself.

Policy design must also account for economic spillovers. Blocking a dataset can impair research, fraud detection or global service delivery, while forced localisation may create attractive central targets. Narrow classifications, auditable security controls and appeal routes can protect national-security interests with less disruption than an undifferentiated restriction on all data.

Sources

  1. President of the United States, Executive Order 14117 on access to Americans' bulk sensitive personal data.
  2. US Department of Justice, Data Security Program (accessed 30 July 2026).
  3. US Code of Federal Regulations, 28 CFR Part 202 (accessed 30 July 2026).
  4. Cybersecurity and Infrastructure Security Agency, security requirements for restricted transactions.
  5. National People's Congress of China, Data Security Law.

Recommended citation

Cite this entry

Tennant, James J., ed. 'Data as strategic resource and cross-border data flows.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/data-as-strategic-resource-and-cross-border-data-flows/.

Suggest an edit