Data Localization Laws by Country (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 31 primary sources cited on this page. How we verify our legal content

Data Localization Laws by Country (2026)

Frequently Asked Questions

What is data localization?

Data localization refers to legal requirements that personal data or other categories of data be stored, processed, or maintained on servers physically located within a specific country's borders. These laws may require all data about a country's residents to remain in-country (hard localization), require a local copy while permitting transfers abroad (soft localization), or impose conditions on cross-border transfers that function as practical localization.

Which countries have the strictest data localization laws?

China, Russia, and Vietnam maintain the most comprehensive localization regimes as of 2026. China requires CII operators to store personal information and important data locally, with government security assessments required before any cross-border transfer. The CSL amendments effective January 1, 2026 raised maximum penalties to RMB 10 million and expanded the law's extraterritorial reach. Russia prohibits the recording, storage, updating and retrieval of Russian citizens' personal data in databases located outside Russia, a rule recast by Federal Law 23-FZ with effect from 1 July 2025, and since March 2023 operators must also notify Roskomnadzor before any cross-border transfer. Vietnam's Law 116/2025/QH15, in force since 1 July 2026, requires in-scope domestic and foreign providers to store user data in Vietnam and requires foreign providers to open a branch or representative office there.

Does the GDPR require data localization within the EU?

The GDPR does not require data localization within the EU or EEA. Instead, it permits cross-border transfers to countries with adequate protection or through approved transfer mechanisms such as Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. However, the EUCS cloud certification debate and certain EU member states' sector-specific rules for health and government data go beyond the GDPR baseline.

What is the difference between hard and soft data localization?

Hard localization prohibits certain data from leaving the country entirely. The data must be stored and processed exclusively on local servers with no copies transferred abroad. Soft localization requires a copy of the data to be maintained on local servers but permits transfers of copies to other countries, usually subject to conditions such as government approval, consent, or contractual safeguards. Russia's personal data law represents hard localization, while Indonesia's framework represents soft localization.

Does India require data localization?

India does not impose blanket localization. The negative-list power sits in section 16(1) of the DPDP Act 2023, which lets the Central Government restrict transfers to a notified country or territory, and no such notification had been issued as of 10 September 2026. Rule 15 of the Digital Personal Data Protection Rules, published on 13 November 2025, adds a different condition: a Data Fiduciary must meet whatever requirements the Central Government specifies by general or special order about making transferred data available to a foreign State or its agencies. Most of the Rules, including Rule 15, take effect eighteen months after publication, on 13 May 2027. The Reserve Bank of India separately requires all payment system data to be stored exclusively in India, one of the strictest sector-specific localization mandates globally.

What changed in China's data localization rules in 2024 and 2026?

Three changes matter. In March 2024, the CAC issued new cross-border data flow provisions that relaxed the thresholds: a security assessment is required where a critical information infrastructure operator exports personal information or important data, and where any other data processor exports important data or exports, cumulatively since 1 January of the year, the personal information of 1,000,000 or more people or the sensitive personal information of 10,000 or more people. A processor that is not a CII operator and that exports the personal information of fewer than 100,000 people cumulatively is exempt from all three routes, not only from the standard contract. In January 2026, the Cybersecurity Law amendments took effect, raising maximum penalties to RMB 10 million, expanding extraterritorial reach to cover any activity harming China's cybersecurity, and integrating AI governance into the CSL framework. On the same day, the Measures for Certification of Personal Information Export took effect and fixed the eligibility band for the certification route.

How do multinational companies comply with different localization requirements?

Common strategies include deploying regional data centers or using cloud providers with jurisdiction-specific data residency options (including sovereign cloud products like Google Sovereign Cloud and Microsoft EU Data Boundary), implementing data classification frameworks that tag data by country and category, maintaining hybrid architectures with local storage for compliance and centralized processing for analytics, layering transfer mechanisms like SCCs for soft-localization jurisdictions, and establishing quarterly regulatory monitoring processes to track changes across all operating countries.

What sectors face the most data localization requirements?

Financial services and banking face the strictest and most widespread sector-specific localization rules, with regulators in India (RBI), Indonesia (OJK), Nigeria (CBN), Saudi Arabia (SAMA), and China all requiring local data storage. Healthcare data faces localization in multiple jurisdictions. Telecommunications metadata is frequently localized for national security reasons. Government and public sector data is subject to localization requirements in nearly every country that has data residency laws. AI training data is an emerging localization category, particularly in China.

Are data localization requirements increasing or decreasing globally?

The global trend is toward more localization. The number of countries with some form of localization mandate has grown significantly since 2015. ITIF's July 2021 study identified 154 localization measures in effect in 66 countries, 144 of which it counted as trade barriers across 62 countries, up from 67 barriers in 35 countries in 2017. Drivers include national security concerns, economic development strategies to build domestic cloud industries, geopolitical tensions around digital sovereignty, and law enforcement access requirements. Some countries (notably India with its DPDP Rules) have adopted more permissive frameworks than earlier drafts proposed, but the broader trend is expansion, not contraction.

Updates

Rebuilt the Vietnam entry on Law 91/2025 and Law 116/2025 and removed the pre-transfer registration certificate claim, replaced a misquoted version of India's Rule 15 with the notified text and moved the negative-list power to section 16(1) of the DPDP Act, restated Turkey's article 9 as amended by Law 7499 and Saudi Arabia's article 29 transfer purposes, corrected China's cross-border thresholds and the Shanghai free-trade-zone lists, corrected the Russian localization penalties and added the 2025 rewrite of article 18(5), recorded Australia's My Health Records Act section 77 in the comparison table, added Regulation (EU) 2018/1807 and Nigeria's GAID 2025, and replaced nine dead or unofficial source links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major expansion: added H2 sections on the EU and data sovereignty, the economic and trade-policy debate, and a dedicated recent-developments section (2024-2026). Updated China section with CSL January 2026 amendment (RMB 10 million penalty cap, extraterritorial expansion, AI governance integration) and March 2024 CAC cross-border provisions (revised thresholds, FTZ negative lists). Corrected Indonesia PP 17/2025 claim (that regulation concerns child protection, not data transfer). Updated India DPDP Rules to reflect final November 2025 publication and May 2027 compliance deadline. Added Nigeria NDPA 2023 (statutory upgrade from NDPR) and 2024 CNII designation. Updated Russia with FZ-266 cross-border notification requirement (effective March 2023). Added Saudi Arabia PDPL enforcement timeline. Fixed malformed Turkey internal link. Word count expanded from 2,490 to approximately 4,700 words.

Reviewed and approved by an editor

Sources and References

  1. Personal Information Protection Law of the People's Republic of China (2021), full text published by the Cyberspace Administration of China (arts. 38-40 on cross-border provision and storage)(cac.gov.cn).gov
  2. Data Security Law of the People's Republic of China (2021), full text published by the Cyberspace Administration of China(cac.gov.cn).gov
  3. Cybersecurity Law of the People's Republic of China (2016 text), published by the Cyberspace Administration of China; for the amendment in force 1 January 2026 see the gov.cn notice(cac.gov.cn).gov
  4. China CSL Amendment (October 2025, effective January 2026)(gov.cn).gov
  5. CAC, Provisions on Promoting and Regulating Cross-Border Data Flows (22 March 2024), official text (arts. 5, 6, 7, 8, 9)(cac.gov.cn).gov
  6. CAC Standard Contract for Data Export (2023)(cac.gov.cn).gov
  7. Russia, Federal Law of 21.07.2014 No. 242-FZ, official publication (publication no. 0001201407220042)(publication.pravo.gov.ru).gov
  8. Council of Europe Convention 108(coe.int).gov
  9. India, Digital Personal Data Protection Act 2023 (No. 22 of 2023), MeitY text, section 16 on processing personal data outside India(meity.gov.in).gov
  10. RBI Payment Data Storage Directive(rbi.org.in).gov
  11. Nigeria Data Protection Act 2023, official text from the Nigeria Data Protection Commission(ndpc.gov.ng).gov
  12. Nigeria Data Protection Commission(ndpc.gov.ng).gov
  13. Turkey KVKK Law 6698(mevzuat.gov.tr).gov
  14. Indonesia, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions, JDIH Kementerian Komunikasi dan Digital(jdih.komdigi.go.id).gov
  15. SDAIA, Regulation on Personal Data Transfer Outside the Kingdom of Saudi Arabia, version 2.0 (August 2024), arts. 2, 4 and 7(sdaia.gov.sa).gov
  16. Saudi Arabia ICT Cross-Border Transfer Enforcement (US ITA)(trade.gov).gov
  17. Kazakhstan Data Localization Overview (Morgan Lewis 2024)(morganlewis.com)
  18. ITIF: Barriers to Cross-Border Data Flows(itif.org)
  19. ITIF: EU Cloud Service Restrictions (2025)(itif.org)
  20. Hogan Lovells: EUCS Sovereignty Debate(hoganlovells.com)
  21. Vietnam, Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, in force 1 January 2026), art. 20 on cross-border transfer and art. 8 on penalties(vanban.chinhphu.vn).gov
  22. Vietnam, Decree 356/2025/ND-CP detailing the Law on Personal Data Protection (in force 1 January 2026; ends Decree 13/2023/ND-CP), arts. 17-18 on the cross-border transfer impact assessment dossier(congbao.chinhphu.vn).gov
  23. Vietnam, Law on Cybersecurity No. 116/2025/QH15 (passed 10 December 2025, in force 1 July 2026; replaces Law 24/2018/QH14 and Law 86/2015/QH13), art. 25(3) on storing user data in Vietnam(congbao.chinhphu.vn).gov
  24. India, Digital Personal Data Protection Rules 2025, Gazette notification G.S.R. 846(E) dated 13 November 2025 (rule 1 commencement schedule; rule 15 on transfer outside India)(meity.gov.in).gov
  25. Turkey, Law No. 7499 (Official Gazette 12 March 2024, issue 32487), art. 34 replacing art. 9 of Law 6698 and art. 40 setting entry into force on 1 June 2024(mevzuat.gov.tr).gov
  26. Saudi Arabia, Personal Data Protection Law, SDAIA official English text, art. 29 on transfer and disclosure outside the Kingdom(sdaia.gov.sa).gov
  27. China, Measures for Certification of Personal Information Export (CAC and SAMR Order No. 20, published 17 October 2025, effective 1 January 2026), art. 5 eligibility band(cac.gov.cn).gov
  28. Russia, Federal Law of 28.02.2025 No. 23-FZ amending the Federal Law on Personal Data (official publication; art. 1(2) rewrites art. 18(5), art. 10 sets entry into force 1 July 2025)(publication.pravo.gov.ru).gov
  29. Russia, Code of Administrative Offences art. 13.11, parts 8 and 9 (fines for failing to hold Russian citizens' personal data in databases located in Russia)(consultant.ru)
  30. Regulation (EU) 2018/1807 on a framework for the free flow of non-personal data, art. 4 (data localisation requirements prohibited unless justified on public-security grounds)(eur-lex.europa.eu).gov
  31. Australia, My Health Records Act 2012 (Cth), s. 77 'Requirement not to hold or take records outside Australia', current compilation No. 18 (compilation date 1 July 2026)(legislation.gov.au).gov
  32. Nigeria Data Protection Commission, General Application and Implementation Directive (GAID) 2025, issued 20 March 2025, art. 45 and Schedule 5 on cross-border data transfer(ndpc.gov.ng).gov
  33. Kazakhstan, Law No. 94-V of 21 May 2013 on Personal Data and Its Protection, consolidated text (art. 12(2) storage in Kazakhstan; amendments through 2026 and the pending change under the Law of 24.06.2026 No. 326-VIII)(adilet.zan.kz).gov
  34. ITIF press release, 'Restrictions on International Data Flows Have Doubled in Four Years' (19 July 2021), source of the 154 measures in 66 countries and the 144 barriers in 62 countries figures(itif.org)
  35. ENISA, European cybersecurity certification portal (EUCC published; EUCS still a candidate scheme)(certification.enisa.europa.eu).gov
  36. Shanghai, questions and answers on the data export negative list (2025 edition), published 24 April 2026, replacing the 2024 edition(shhk.gov.cn).gov
  37. Lin-gang New Area, scenario-based general data list for the public fund sector (May 2024), an instrument listing data that may flow freely(jrj.sh.gov.cn).gov
Share: