Skip to content
DopeSwagYolo

Sovereign AI

What is data localization?

Data localization is a legal requirement that certain data be stored or processed inside a particular country or region. The strictest versions also prohibit sending that data abroad.

Also known as: data localisation, data localization requirement

Researched and fact-checked by AI, with no human review. 10 sources listed below. How we verify

Last updated

How it works

In EU law, Regulation (EU) 2018/1807 defines a data localization requirement. It is any obligation, prohibition, condition or limit in a member state's laws or administrative practice that requires data processing in a specific member state or hinders processing in another.

A November 2023 OECD study counted 100 such measures in 40 countries by early 2023. More than two-thirds combined local storage with a ban on sending the data abroad. The study calls that the most restrictive form.

China's Cybersecurity Law, in effect since June 1, 2017, requires operators of critical information infrastructure to store personal information and important data gathered in mainland China there. They must undergo a security assessment before providing it abroad. Both requirements remain in the text as amended in October 2025. China's Personal Information Protection Law, in effect since November 1, 2021, applies a similar storage rule to organizations handling personal information above volumes set by the regulator. A Reserve Bank of India directive dated April 6, 2018, told payment system providers to store their payment data only on systems in India.

Why it matters

The OECD study drew on businesses in e-payments, cloud computing and air travel. It reported localization raises operating costs and can increase exposure to fraud and cybersecurity risks.

Some trade and single-market rules restrict the practice. Article 19.12 of the United States-Mexico-Canada Agreement is one. It bars each party from requiring covered investors and service suppliers to use or locate computing facilities in its territory as a condition of doing business there. The EU regulation, which covers non-personal data, prohibits localization requirements unless justified on public security grounds.

Where things stand in 2026

The 2023 OECD study described localization measures as growing and increasingly restrictive. The European Commission has proposed a Cloud and AI Development Act with four sovereignty assurance levels for public sector bodies. The first level covers data processed and stored on infrastructure in the EU. The European Parliament's legislative tracker dates the proposal to June 3, 2026. As of September 20, 2026, it listed the file as awaiting committee decisions, so it is not law.

A September 2026 briefing paper from the World Economic Forum's Global Future Council on Data Frontiers argued localization alone does not deliver sovereignty. Storing data inside a country can help, it said, but is no substitute for technical control, auditability and enforceable governance.

Sources

Articles on Sovereign AI