Concept

Data as strategic terrain

Data becomes strategic terrain when states use law, infrastructure control, access rights, standards or procurement to shape who may collect, process, transfer, combine or exploit specified data for security, economic or intelligence objectives. The terrain metaphor is analytical. Data is not territory in law. Controls on content, metadata, access, copies, infrastructure and processing have different effects and should not be treated as interchangeable.

The layers of control

Analysis should identify six layers. Data content is the substantive material recorded. Metadata describes records, transactions or communications. Access rights determine who can view, use or disclose material. Storage and processing concern where and how data is held or computed. Cross-border transfer concerns movement between jurisdictions or persons. Physical carriage concerns telecommunications networks, data centres and submarine cables.

Data is often non-rival and copyable. Restricting a future transfer does not erase copies already held or eliminate substitute sources. Local storage does not necessarily prevent remote access. Control of a cable, platform or cloud service can create visibility or leverage, but market position does not prove government access or exploitation. A legal, technical and institutional chain must connect authority to the claimed effect.

Henry Farrell and Abraham L. Newman's weaponised-interdependence framework explains how asymmetric networks can create panopticon and chokepoint effects. Network topology identifies potential leverage. It does not establish a specific state operation, purpose or outcome.

United States data controls

Executive Order 14117 directed restrictions on specified transactions involving Americans' bulk sensitive personal data and United States government-related data where countries of concern or covered persons could gain access. The Department of Justice implemented the Data Security Program in 28 C.F.R. Part 202. The programme took effect on 8 April 2025 and uses defined data classes, thresholds, transactions, countries of concern and covered persons.

The programme is not a blanket prohibition on all data transfers or all foreign recipients. Each application must identify the operative authority, data category, threshold, actor and transaction. Executive Order 14117 established the direction and authority, while the later final rule and guidance created the operational regime. The distinction between announcement and implementation is material.

China and the European Union

China's 2021 Data Security Law establishes security, classification, national-security review, export-control and cross-border provisions. It does not make all civilian data presumptively available to the party-state. The March 2024 provisions on cross-border data flows introduced exemptions and thresholds intended to facilitate compliant transfers. Regulations on Network Data Security Management took effect on 1 January 2025 and add processor obligations within the wider regime.

China's framework combines state control, security, personal rights and facilitation. It is not one blanket localisation rule. Analysis should specify the data class, processor, threshold and applicable security assessment, standard contract, certification or exemption.

The European Union Data Act is principally an access and use framework. Regulation (EU) 2023/2854 covers access to connected-product data, business-to-government access in exceptional need, cloud switching and safeguards against unlawful third-country government access. It generally applied from 12 September 2025. These provisions can have strategic effects, but the Act is not chiefly a coercive national-security export control.

Intermediaries, infrastructure and limits

States enact access, transfer, security and infrastructure rules. Data controllers, processors, brokers, cloud providers, telecommunications firms, platforms and regulated professional services implement them. The concept's state nexus is therefore regulated intermediation. Declared national-security and economic-security measures belong in the main sequence, while any broader intelligence or industrial motive requires separate evidence.

Submarine cables carry the physical traffic beneath data governance. The International Telecommunication Union treats resilience, repair and cooperation as distinct policy problems. Accidental human activity and natural hazards cause many faults. A cable incident is not sabotage, and an abnormal data flow is not state direction, without case-level evidence of actor, method and legal status.

Data governance must account for privacy, due process, research, development, commercial burden and lawful-access safeguards. The OECD declaration on government access sets common principles for trust in cross-border flows, while UNCTAD and Susan Ariel Aaronson show why data cannot be governed as an ordinary traded good. Current law in the United States, China and European Union must be rechecked at publication.

See also

Weaponised interdependence · Data localisation · Data Security Program (United States) · Cross-border data flows · Submarine telecommunications cables

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Data as strategic terrain.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/data-as-strategic-terrain/.

Suggest an edit