Instrument
Data-localisation and cross-border-data restriction
Data-localisation and cross-border-data restriction covers rules governing where data is stored, when it may cross a border and who may receive it. The category includes distinct mechanisms: local storage, security assessment, certification, standard contracts, outbound review, sectoral retention, restricted transactions and prohibitions. These rules make Data as strategic terrain, but privacy, prudential or security regulation is not automatically economic coercion.
Current regimes
China's cross-border framework combines the Data Security Law (China, 2021) with other laws and transfer mechanisms. March 2024 provisions clarified or relaxed several thresholds. Analysis must name the data class, operator, volume threshold and applicable route rather than describe all Chinese data as localised.
India's Reserve Bank direction concerns payment-system data. It requires specified payment data to be stored in India and permits tightly framed processing arrangements. It is sector-specific, not a general prohibition on all data transfers.
The United States Data Security Program, implementing Executive Order 14117 (2024), began operating on 8 April 2025. It governs specified transactions involving bulk sensitive personal data and government-related data with countries of concern and covered persons. Certain affirmative obligations took effect in October 2025. It is a transaction-control regime, not a general domestic-storage mandate.
Statecraft effects
Restrictions can raise compliance costs, alter cloud architecture, preserve regulatory access or reduce exposure to foreign jurisdiction. They may also fragment networks associated with Weaponised interdependence. Effect depends on covered data, thresholds, enforcement and available infrastructure. Strategic-intent claims require evidence beyond commercial cost or localisation alone.
Compliance analysis should use the law in force on the transaction date and record any exemption, approval or transition period.
Sources
- United States Department of Justice, Data Security Program (accessed 30 July 2026).
- Executive Order 14117, 28 February 2024.
- State Council of the People's Republic of China, Provisions on promoting and regulating cross-border data flows, March 2024.
- Reserve Bank of India, Storage of Payment System Data, 6 April 2018.
Recommended citation
Cite this entry
Tennant, James J., ed. 'Data-localisation and cross-border-data restriction.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/data-localisation-and-cross-border-data-restriction/.
Suggest an edit