Concept
Data as strategic terrain
Data becomes strategic terrain when states use law, infrastructure control, access rights, standards or procurement to shape who may collect, process, transfer, combine or exploit specified data for security, economic or intelligence objectives. The terrain metaphor is analytical. Data is not territory in law. Controls on content, metadata, access, copies, infrastructure and processing have different effects and should not be treated as interchangeable.
The layers of control
Analysis should identify six layers. Data content is the substantive material recorded. Metadata describes records, transactions or communications. Access rights determine who can view, use or disclose material. Storage and processing concern where and how data is held or computed. Cross-border transfer concerns movement between jurisdictions or persons. Physical carriage concerns telecommunications networks, data centres and submarine cables.
Data is often non-rival and copyable. Restricting a future transfer does not erase copies already held or eliminate substitute sources. Local storage does not necessarily prevent remote access. Control of a cable, platform or cloud service can create visibility or leverage, but market position does not prove government access or exploitation. A legal, technical and institutional chain must connect authority to the claimed effect.
Henry Farrell and Abraham L. Newman's weaponised-interdependence framework explains how asymmetric networks can create panopticon and chokepoint effects. Network topology identifies potential leverage. It does not establish a specific state operation, purpose or outcome.
United States data controls
Executive Order 14117 directed restrictions on specified transactions involving Americans' bulk sensitive personal data and United States government-related data where countries of concern or covered persons could gain access. The Department of Justice implemented the Data Security Program in 28 C.F.R. Part 202. The programme took effect on 8 April 2025 and uses defined data classes, thresholds, transactions, countries of concern and covered persons.
The programme is not a blanket prohibition on all data transfers or all foreign recipients. Each application must identify the operative authority, data category, threshold, actor and transaction. Executive Order 14117 established the direction and authority, while the later final rule and guidance created the operational regime. The distinction between announcement and implementation is material.
China and the European Union
China's 2021 Data Security Law establishes security, classification, national-security review, export-control and cross-border provisions. It does not make all civilian data presumptively available to the party-state. The March 2024 provisions on cross-border data flows introduced exemptions and thresholds intended to facilitate compliant transfers. Regulations on Network Data Security Management took effect on 1 January 2025 and add processor obligations within the wider regime.
China's framework combines state control, security, personal rights and facilitation. It is not one blanket localisation rule. Analysis should specify the data class, processor, threshold and applicable security assessment, standard contract, certification or exemption.
The European Union Data Act is principally an access and use framework. Regulation (EU) 2023/2854 covers access to connected-product data, business-to-government access in exceptional need, cloud switching and safeguards against unlawful third-country government access. It generally applied from 12 September 2025. These provisions can have strategic effects, but the Act is not chiefly a coercive national-security export control.
Intermediaries, infrastructure and limits
States enact access, transfer, security and infrastructure rules. Data controllers, processors, brokers, cloud providers, telecommunications firms, platforms and regulated professional services implement them. The concept's state nexus is therefore regulated intermediation. Declared national-security and economic-security measures belong in the main sequence, while any broader intelligence or industrial motive requires separate evidence.
Submarine cables carry the physical traffic beneath data governance. The International Telecommunication Union treats resilience, repair and cooperation as distinct policy problems. Accidental human activity and natural hazards cause many faults. A cable incident is not sabotage, and an abnormal data flow is not state direction, without case-level evidence of actor, method and legal status.
Data governance must account for privacy, due process, research, development, commercial burden and lawful-access safeguards. The OECD declaration on government access sets common principles for trust in cross-border flows, while UNCTAD and Susan Ariel Aaronson show why data cannot be governed as an ordinary traded good. Current law in the United States, China and European Union must be rechecked at publication.
See also
Weaponised interdependence · Data localisation · Data Security Program (United States) · Cross-border data flows · Submarine telecommunications cables
Sources
- Henry Farrell and Abraham L. Newman, "Weaponized Interdependence: How Global Economic Networks Shape State Coercion", International Security 44, no. 1 (2019): 42-79.
- President of the United States, Executive Order 14117: Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern, 28 February 2024.
- United States Department of Justice, National Security Division, "Data Security", updated 24 September 2025.
- Supreme People's Procuratorate of the People's Republic of China, English translation of the Data Security Law of the People's Republic of China, adopted 10 June 2021 and effective 1 September 2021.
- Cyberspace Administration of China, "Provisions on Promoting and Regulating Cross-Border Data Flows", 22 March 2024.
- State Council of the People's Republic of China, Regulations on Network Data Security Management, effective 1 January 2025.
- European Parliament and Council, Regulation (EU) 2023/2854 on Harmonised Rules on Fair Access to and Use of Data, 13 December 2023.
- Organisation for Economic Co-operation and Development, Declaration on Government Access to Personal Data Held by Private Sector Entities (14 December 2022).
- United Nations Conference on Trade and Development, Digital Economy Report 2021: Cross-border Data Flows and Development (2021).
- International Telecommunication Union, "Submarine Cable Resilience", current portal, checked 29 July 2026.
- International Telecommunication Union, "International Advisory Body Approves Landmark Report to Strengthen Submarine Cable Resilience", 10 July 2026.
- Anu Bradford, Digital Empires: The Global Battle to Regulate Technology (Oxford University Press, 2023).
- Susan Ariel Aaronson, Data Is Different: Why the World Needs a New Approach to Governing Cross-Border Data Flows, CIGI Paper no. 197 (Centre for International Governance Innovation, 2018).
Recommended citation
Cite this entry
Tennant, James J., ed. 'Data as strategic terrain.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/data-as-strategic-terrain/.
Suggest an edit