Data localisation refers to regulatory requirements imposed by a country that mandates foreign and domestic organisations to store and process certain types of data, particularly sensitive or personal information, within that country’s national borders, specifically in the jurisdiction where the data was originally collected. The Organisation of Economic Cooperation Development (OECD) in a paper titled “The Nature, Evolution and Potential Implications of Data Localisation Measures,” defined data localisation as an explicit requirement that data be stored and/or processed within the domestic territory. In another paper by the OECD titled “Data Localisation Trends and Challenges Considerations for the Review of the Privacy Guidelines”, adopted the following definition of data localisation :
‘Data localisation’ refers to a mandatory legal or administrative requirement directly or indirectly stipulating that data be stored or processed, exclusively or non-exclusively, within a specified jurisdiction
Richard D. Taylor (2020) discussed that phenomena of data localisation come from two distinct policy models, namely Data Sovereignty and Trans-Border Data Flows. Data Sovereignty originates from complete control of the state within its geographical boundaries and Trans-Border Data Flows policies aims to protect personal data and privacy. Further, David Medine (2024) defined it as an umbrella that covers various requirements and restrictions by the Government on cross border data flow, processing, and storage. The study further categorized data localisation into ‘hard localisation’ that prohibits any form of cross border data form, mirroring which mandates a local copy of the data being transferred across borders, and finally a setup where Government regulators have access to data irrespective of where it is stored.
The OECD (2022) further classifies data localisation into three main categories. First, storage-only measures require that certain data be stored domestically but still allow cross-border transfer. Second, storage and flow conditional measures permit data transfers only if specific conditions are met, such as security requirements or regulatory approval. Third, storage and flow prohibition measures are the strictest, requiring data to be stored domestically while restricting or banning cross-border transfers.
Source: Cross-border data flows, OECD
Global restrictive measures on data localisation expanded rapidly after 2010, with storage and flow prohibition measures rising sharply from 9 in 2010 to 71 in 2022. In contrast, conditional flow measures remain limited, increasing only marginally to 2 by 2022. This trend indicates a growing inclination among countries toward stricter control over data flows, reflecting rising concerns around security, sovereignty, and digital governance.
