Data Localization Laws by Country (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 31 primary sources cited on this page. How we verify our legal content
Data localization laws require that certain personal data be stored on servers within a country's borders. Requirements range from hard localization, such as Russia's Federal Law 242-FZ, which requires the listed processing operations on Russian citizens' personal data to run on in-country databases andbases from leaving Russia, to soft models permitting conditional transfers. Over 60 countries enforce some form of data residency requirement as of 2026.
Data localization laws require organizations to store, process, or maintain copies of certain data on servers physically located within a specific country's territory. These laws have proliferated rapidly since 2015, driven by national security concerns, privacy protection goals, economic development strategies, and geopolitical considerations around digital sovereignty.
The scope and strictness of localization requirements vary dramatically. Some countries mandate that all personal data about their residents remain within national borders. Others apply localization only to specific sectors like banking, healthcare, or telecommunications. Several countries take a middle ground, requiring a local copy while permitting transfers abroad under certain conditions.
This guide provides a country-by-country overview of data localization requirements as of 2026, explains the distinction between hard and soft localization, covers sector-specific rules, examines the EU position, surveys the economic debate, and outlines practical compliance strategies.
Hard Localization vs. Soft Localization
Understanding the difference between hard and soft localization is critical for compliance planning.
Hard Localization
Hard localization prohibits certain data from leaving the country entirely. The data must be collected, stored, and processed exclusively on local servers. No copies may be transferred abroad, regardless of safeguards. Russia's rule that the listed processing operations must run on in-country databases, and certain categories under China's data protection framework, are the closest examples, although Russian law still allows copies abroad once the domestic database holds the primary record.
Soft Localization
Soft localization requires that a copy of the data be maintained on local servers, but permits transfers of copies to other countries, usually subject to conditions such as government approval, consent, or contractual safeguards. India's approach to certain categories of data and Indonesia's regulations represent soft localization.
Conditional Transfer Models
Some countries do not require local storage but impose conditions on cross-border transfers that function as practical localization. For instance, requiring government approval for each transfer, mandating security assessments before export, or limiting transfers to countries with "adequate" protection. These conditional models can be as burdensome as formal localization requirements.
Country-by-Country Data Localization Requirements
The map below shows how each jurisdiction covered in this guide treats data localization. Click any highlighted country for its full data privacy guide.
Coloured countries are the jurisdictions this guide analyses against a primary source. Grey means this guide does not assess that country, not that the country has no requirements. A country shown as having no storage mandate can still impose sector rules, such as health or government data residency.
The following table summarizes data localization requirements across major jurisdictions. Detailed analysis of key countries follows below.
| Country | Type | Scope | Key Law |
|---|---|---|---|
| China | Hard/Conditional | Personal information, important data, CII data | PIPL, DSL, CSL (amended Jan 2026) |
| Russia | Hard | Personal data of Russian citizens | Federal Law 242-FZ, 266-FZ |
| India | Soft/Sector | Payment data (hard); other data conditional | DPDP Act 2023 s. 16, DPDP Rules 2025, RBI directions |
| Indonesia | Soft | Public electronic system data | GR 71/2019, PDP Law (Oct 2024) |
| Vietnam | Soft/Conditional | User data held by in-scope service providers; personal data transfers | Law 91/2025/QH15, Law 116/2025/QH15 |
| Nigeria | Soft/Sector | Government data, critical infrastructure data | NDPA 2023, GAID 2025, NITDA Act |
| Turkey | Conditional | Personal data | Law 6698 (KVKK) art. 9, as replaced by Law 7499 (in force 1 June 2024) |
| Saudi Arabia | Conditional/Sector | Personal data, financial, government data | PDPL (enforced Sept 2024) |
| Brazil | None (conditional) | No localization; conditional transfer rules | LGPD |
| South Korea | Conditional | Personal information | PIPA |
| Australia | Sector | Limited sectoral localization: My Health Record system records must stay in Australia; APP 8 accountability for other transfers | Privacy Act 1988, My Health Records Act 2012 s. 77 |
| Kazakhstan | Soft | Personal data of citizens | Law 94-V art. 12(2) (amended through 2026) |
| UAE | Sector | Financial, health, government data | Various sector regulators |
| Thailand | Conditional | Personal data | PDPA |
| South Africa | Conditional | Personal information | POPIA |
| Japan | Conditional | Personal information | APPI (amended 2022) |
China: The Most Complex Localization Regime
China operates one of the world's most comprehensive data localization frameworks, built on three interconnected laws: the Cybersecurity Law (CSL) of 2017, the Data Security Law (DSL) of 2021, and the Personal Information Protection Law (PIPL) of 2021.
Critical Information Infrastructure (CII) Operators
CII operators must store personal information and "important data" collected and generated in China within the country. Transfers abroad require a government security assessment conducted by the Cyberspace Administration of China (CAC). CII sectors include energy, transportation, finance, public services, e-government, defense, and technology.
CSL Amendment Effective January 1, 2026
The Standing Committee of the National People's Congress passed amendments to the CSL on October 28, 2025, effective January 1, 2026. The January 2026 amendments do not alter the core data localization requirement for CII operators under Article 39 but significantly change the enforcement landscape:
- Maximum penalties for CII operators whose violations cause especially grave consequences now reach RMB 10 million (approximately USD 1.4 million).
- The CSL's extraterritorial reach expanded beyond activities harming domestic critical infrastructure to cover any overseas organization or individual engaging in activities that harm China's cybersecurity broadly.
- AI governance obligations are now explicitly integrated into the CSL framework, including state support for AI innovation, training data resource development, and AI risk assessment and security governance.
- Penalties for selling uncertified network security equipment include fines of up to ten times the purchase amount.
Personal Information Handlers and the March 2024 Threshold Changes
Under the PIPL, organizations processing personal information of Chinese residents that need to transfer data abroad must satisfy one of four conditions: pass a CAC security assessment, obtain certification from a recognized institution, enter into a standard contract filed with the CAC, or comply with other applicable conditions.
On March 22, 2024, the CAC issued the Provisions on Promoting and Regulating Cross-Border Data Flows, effective immediately. These provisions significantly relaxed the prior rules:
- Article 7 requires a security assessment, filed through the provincial cyberspace administration, where a critical information infrastructure operator exports personal information or important data, and where any other data processor exports important data or exports, cumulatively since 1 January of the current year, the personal information of 1,000,000 or more people (excluding sensitive personal information) or the sensitive personal information of 10,000 or more people.
- Article 8 puts a processor that is not a CII operator, and that exports cumulatively since 1 January the personal information of 100,000 or more but fewer than 1,000,000 people (excluding sensitive personal information) or sensitive personal information of fewer than 10,000 people, on the standard contract or the certification route.
- Article 5(4) exempts a processor that is not a CII operator and that exports the personal information of fewer than 100,000 people (excluding sensitive personal information) cumulatively since 1 January from all three routes: the security assessment, the standard contract, and certification.
- CAC-approved security assessments are now valid for three years, extended from the prior two-year term, and may be extended by a further three years on application.
- Organizations in designated free trade zones may follow a negative list: under Article 6 the zone draws up the list of data that still needs one of the three routes, and data outside that list may be exported freely. Shanghai's negative list (2024 edition) was published on 8 February 2025 and covered reinsurance, international shipping, and retail, catering and accommodation; a 2025 edition published on 24 April 2026 replaced it with 4 fields, 9 scenarios and 109 data items. The Lin-gang New Area's scenario-based general data lists of May 2024, covering sectors including public funds, are the opposite instrument: they name data that may flow freely, not data that is restricted.
The certification route now has a binding rule of its own. The Measures for Certification of Personal Information Export, issued jointly by the CAC and the State Administration for Market Regulation as Order No. 20 and published on 17 October 2025, took effect on 1 January 2026, the same day as the CSL amendment. Article 5 limits the route to a processor that is not a CII operator and that exports, cumulatively since 1 January of the year, the personal information of 100,000 or more but fewer than 1,000,000 people, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 people, with no important data included. Certificates run for three years.
Important Data
The DSL introduced a separate category of "important data" subject to localization and export restrictions. Sector-specific regulators are tasked with defining what constitutes important data in their domains. The automotive, financial services, and healthcare sectors have issued draft or final important data catalogs.
Practical Impact
China's regime represents the most burdensome localization framework for multinational companies. Organizations operating in China typically maintain entirely separate data infrastructure, with dedicated in-country data centers and Chinese cloud providers (Alibaba Cloud, Tencent Cloud, Huawei Cloud) handling local processing.
Russia: Strict Personal Data Localization
Russia's data localization law, Federal Law No. 242-FZ (amending the Personal Data Law No. 152-FZ), took effect on September 1, 2015. It requires that all databases used to collect, record, systematize, accumulate, store, update, modify, or retrieve the personal data of Russian citizens be located on servers within the Russian Federation.
Scope
The law applies broadly to any operator (Russian or foreign) that collects personal data from Russian citizens. This includes online services, e-commerce platforms, social media companies, and any business that collects employee or customer data from Russian residents.
Cross-Border Transfers and FZ-266 Changes (2023)
Federal Law No. 266-FZ (signed July 14, 2022; principal provisions effective September 1, 2022; cross-border transfer provisions effective March 1, 2023) substantially updated the cross-border transfer framework. Since March 2023, operators must notify Roskomnadzor of their intention to transfer personal data abroad before doing so. Transfers to countries not recognized as providing adequate protection now require explicit permission from Roskomnadzor.
The prior two-tier system (Council of Europe Convention 108 countries vs. others) remains relevant for determining which countries are presumed adequate. However, the pre-transfer notification requirement now applies regardless of destination.
The storage rule itself was tightened in 2025. Article 18(5) of the Personal Data Law was rewritten by Federal Law No. 23-FZ of 28 February 2025, in force 1 July 2025, and now reads as a flat prohibition rather than a duty owed by the operator: where personal data is collected, including over the internet, the recording, systematization, accumulation, storage, updating and retrieval of Russian citizens' personal data using databases located outside the Russian Federation is not permitted.
The exceptions are the grounds in Article 6(1) items 2, 3, 4 and 8 of the same law: processing required by an international treaty or by statute and for functions imposed on the operator, processing connected with a person's participation in court proceedings, processing needed for the powers of state bodies and the delivery of state and municipal services, and processing for journalism, the lawful activity of a mass medium, or scientific, literary and other creative work where the data subject's rights are not infringed.
Copies may still go abroad under the cross-border transfer rules above, but the operations named in Article 18(5) have to run on databases inside Russia.
Enforcement
Russia's data protection authority, Roskomnadzor, has enforced the localization requirement through blocking actions. LinkedIn was blocked in Russia in 2016 for failing to comply with the localization requirement.
Fines sit in Article 13.11 of the Code of Administrative Offences. Part 8 covers failure to hold Russian citizens' personal data in databases located in Russia and sets fines of RUB 30,000 to RUB 50,000 for individuals, RUB 100,000 to RUB 200,000 for officials, and RUB 1,000,000 to RUB 6,000,000 for legal entities. Part 9 covers a repeat offence and raises those bands to RUB 50,000 to RUB 100,000, RUB 500,000 to RUB 800,000, and RUB 6,000,000 to RUB 18,000,000. Repeated violations can also lead to website blocking.
India: Evolving Localization Landscape
India's data localization framework has shifted considerably. The Digital Personal Data Protection Act (DPDP Act) of 2023 replaced the earlier Personal Data Protection Bill, which had included strict localization provisions.
Current Framework: DPDP Rules (November 2025)
The DPDP Rules were published in the Gazette of India on 13 November 2025 as notification G.S.R. 846(E). The negative-list power itself sits in the Act rather than the Rules. Section 16(1) of the DPDP Act 2023 provides that "the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." Transfers are therefore permitted to every destination unless the government notifies a restriction, and as of 10 September 2026 no country or territory had been notified.
Rule 15 does something different, and it is easy to miss. As published, it provides that personal data processed by a Data Fiduciary under the Act "may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State." That is a live compliance obligation about foreign-State access to transferred data, separate from the negative list.
The Rules commence in stages. Rules 1, 2 and 17 to 21 took effect on publication; rule 4 one year after publication; and rules 3, 5 to 16, 22 and 23 eighteen months after publication, which puts Rule 15 in force on 13 May 2027.
Section 16(2) preserves any Indian law that provides a higher degree of protection or a stricter transfer restriction, which is why the RBI payment-data mandate below is untouched by the DPDP framework. India chose this model over the adequacy-based approach used under the GDPR, and it is notably more permissive than earlier drafts of the Bill, which had proposed strict whitelisting.
Payment Data Localization
The Reserve Bank of India (RBI) issued a directive in April 2018 requiring all payment system data to be stored exclusively in India. This applies to domestic transaction data processed by payment system operators, including card networks, payment aggregators, and wallet providers. The requirement is one of the strictest sector-specific localization mandates globally and forced companies like Visa, Mastercard, and PayPal to establish Indian data centers. This mandate remains fully in force and is not affected by the DPDP framework.
Sector-Specific Requirements
The Securities and Exchange Board of India (SEBI) issued a circular in 2024 imposing data residency requirements on regulated entities using cloud service providers, requiring that regulatory and compliance data remain in India. The Insurance Regulatory and Development Authority of India (IRDAI) imposes conditions on where insurance data may be processed and stored. These sector rules operate independently from the DPDP framework.
Vietnam: Cybersecurity and Data Storage
Vietnam replaced both of the instruments this section used to rest on, so a compliance plan built on Decree 13/2023 or the 2018 Cybersecurity Law is now out of date.
The Law on Personal Data Protection (Law No. 91/2025/QH15) was passed on 26 June 2025 and took effect on 1 January 2026. Decree 356/2025/ND-CP, which details it, took effect the same day and expressly ended Decree 13/2023/ND-CP.
The Law on Cybersecurity (Law No. 116/2025/QH15) was passed on 10 December 2025 and took effect on 1 July 2026. From that date the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber-Information Security ceased to have effect.
Storage inside Vietnam
Article 25(3) of Law 116/2025 states the storage duty in the statute itself. Domestic and foreign enterprises providing services on telecommunications networks, the internet, or value-added services in Vietnam that collect, exploit, analyze or process personal information, data about service users' relationships, or data generated by users in Vietnam must apply the data protection measures required by law and store that data in Vietnam for a period set by the Government. A foreign enterprise covered by that paragraph must establish a branch or a representative office in Vietnam.
Article 25(2)(d) separately requires providers to retain user account names, service usage times, service payment information, access IP addresses and other related data for the period prescribed by law after a user stops using the service.
The storage period and the operating detail are left to Government regulation, and the implementing decrees under the new Law were still at the public consultation stage during 2026. Decree 53/2022/ND-CP, which supplied the old trigger-based mechanism for foreign providers, was made under the repealed 2018 Law.
Cross-border transfer
There is no prior approval and no registration certificate. Article 20 of Law 91/2025 treats three situations as cross-border transfers: moving personal data stored in Vietnam to storage systems outside Vietnam, sending personal data to organizations or individuals abroad, and using a platform outside Vietnam to process personal data collected in Vietnam.
The transferring party must prepare a cross-border transfer impact assessment dossier and send one original to the specialized personal data protection authority within 60 days of the first day of transfer. Decree 356/2025 sets the dossier contents, gives the authority 15 days to record it as satisfactory or not, and allows 30 days to complete a file that is incomplete. The assessment is made once for the life of the organization and updated under Article 22.
Article 20(5) lets the authority order transfers to stop where the data is being used in ways that could harm national defense or national security. Article 20(6) exempts transfers by competent state agencies, an organization holding its own employees' data on a cloud service, a data subject transferring their own data, and further cases set by the Government.
Penalties are turnover-linked. Under Article 8(4) of Law 91/2025, the maximum administrative fine for an organization that breaches the cross-border transfer rules is 5 percent of its revenue for the preceding year, and the general ceiling for other personal data offences is 3 billion Vietnamese dong.
Indonesia: Government Regulation on Electronic Systems
Indonesia's Government Regulation No. 71 of 2019 (GR 71/2019) on Electronic Systems and Transactions requires public electronic system operators to place their data centers and disaster recovery centers in Indonesian territory. Private electronic system operators may locate data outside Indonesia subject to conditions: the offshore location must not diminish government supervision effectiveness, and access must be provided for supervision and law enforcement.
Indonesia's Personal Data Protection Law (Law No. 27 of 2022) was enacted in October 2022. The two-year transition period for compliance ended on October 17, 2024, and organizations are now required to fully comply. The PDP Law allows data controllers to store personal data either in Indonesia or offshore, maintaining consistency with GR 71/2019's approach for private operators.
The financial services sector faces additional requirements from Indonesia's Financial Services Authority (OJK), which requires banks and financial institutions to maintain primary data centers domestically.
Nigeria: NDPR Upgraded to Statutory Law
Nigeria's data localization requirements are now grounded in the Nigeria Data Protection Act (NDPA) of 2023, signed into law in June 2023. The NDPA superseded the 2019 Nigeria Data Protection Regulation (NDPR) and elevated the data protection framework to statutory law. It established the Nigeria Data Protection Commission (NDPC) as a statutory body replacing the earlier regulatory arrangement under NITDA.
The NDPA does not impose blanket localization. Part VIII of the Act governs cross-border transfer, and the operative rulebook is now the NDPC's General Application and Implementation Directive (GAID) 2025, issued on 20 March 2025, whose Article 45 and Schedule 5 deal with transfers.
Schedule 5 names three grounds for transfer: an Adequacy Decision by the Commission, a Cross-Border Data Transfer Instrument approved by the Commission, and other lawful bases recognized under the Act. Article 45(2) says that pending the issuance of any regulatory instrument by the Commission on cross-border transfer, the explanatory note in Schedule 5 is to be used to evaluate countries for adequacy.
That is a framework for future evaluation, not a published list. The Commission has not issued adequacy decisions, for the United States or for any other destination, so a transfer out of Nigeria currently rests on a Commission-approved transfer instrument or another lawful basis rather than on an adequacy finding.
A 2024 government order designated several critical systems as Critical National Information Infrastructure (CNII): the Bank Verification Number (BVN) database, the National Identification Number (NIN) database, and the Nigerian Interbank Settlement System (NIBSS). CNII-designated systems are subject to stricter data handling and localization rules.
Government data faces additional requirements. NITDA guidelines require government data and data processed on behalf of government agencies to be hosted within Nigeria. The Central Bank of Nigeria (CBN) requires financial institutions to maintain local data storage and obtain approval for certain cross-border transfers.
Saudi Arabia: PDPL Now Fully Enforced
Saudi Arabia's Personal Data Protection Law (PDPL) came into force on September 14, 2023, with a one-year grace period for compliance. Full enforcement began September 14, 2024. The PDPL applies extraterritorially: it covers processing of personal data of Saudi residents by entities outside Saudi Arabia.
Article 29(1) of the PDPL fixes the purposes for which a controller may transfer or disclose personal data outside the Kingdom: performing an obligation under an agreement to which the Kingdom is a party, serving the interests of the Kingdom, performing an obligation to which the data subject is a party, or other purposes set out in the Regulations. Consent is not a transfer basis, and there is no controller-invoked public interest basis.
Article 2 of the Transfer Regulation fixes those other purposes as central processing operations needed for the controller's activities, providing a service or benefit to the data subject, and scientific research and studies.
Article 29(2) imposes three conditions on any such transfer. It must not prejudice national security or the vital interests of the Kingdom, the personal data must have a level of protection outside the Kingdom at least equivalent to that guaranteed by the Law and Regulations as assessed by the competent authority, and the transfer must be limited to the minimum personal data needed. Article 29(3) sets those conditions aside only in cases of extreme necessity to preserve the life or vital interests of the data subject, or to prevent, examine or treat disease.
Article 4 of the Transfer Regulation exempts a controller from the adequacy and minimization conditions in defined cases, but only against appropriate safeguards: standard contractual clauses, binding common rules, or a certificate of accreditation from a body licensed by the competent authority.
Article 7 adds a step that is easy to overlook. The controller must carry out a risk assessment before transferring or disclosing personal data outside the Kingdom where it relies on an Article 4 exemption, or where it transfers sensitive data outside the Kingdom on a continuous or widespread basis.
SDAIA did not create this regulation in August 2024. It published version 2.0 of the Regulation on Personal Data Transfer Outside the Kingdom, announced on 1 September 2024, amending the version first issued alongside the Implementing Regulations in September 2023.
SAMA (Saudi Arabian Monetary Authority) regulations require financial institutions to maintain primary data storage in Saudi Arabia. The National Health Information Center imposes additional requirements for health data. The National Cybersecurity Authority (NCA) requires government data to remain on Saudi soil.
Turkey: Conditional Transfer Framework
Turkey's Personal Data Protection Law No. 6698 (KVKK) does not impose strict data localization but creates a conditional transfer framework that can function as practical localization.
Parliament, not the regulator, rewrote the transfer rules. Article 9 of Law 6698 was replaced by article 34 of Law No. 7499, published in the Official Gazette on 12 March 2024 (issue 32487), and the new article 9 entered into force on 1 June 2024.
The order of operations under the amended article is fixed. A transfer may proceed where the Personal Data Protection Board has issued an adequacy decision for the destination country, for a sector within it, or for an international organization, and one of the article 5 or article 6 processing conditions is met.
Failing an adequacy decision, article 9(4) allows a transfer on one of four appropriate safeguards: a non-treaty agreement between public bodies plus Board permission, Board-approved binding corporate rules, the standard contract published by the Board, or a written undertaking plus Board permission. Article 9(5) then requires that a standard contract be notified to the Authority within five business days of signature, and article 18(1)(d) backs that duty with an administrative fine of 50,000 to 1,000,000 Turkish lira.
Only where there is neither an adequacy decision nor an appropriate safeguard may a transfer rely on the article 9(6) derogations, and then only on an incidental basis. The data subject's explicit consent, given after being informed of the risks, is derogation (a) rather than a routine transfer basis. See our Turkey data privacy laws guide for full details.
Kazakhstan: Localization Under a Law Amended Through 2026
Kazakhstan's Law on Personal Data and Its Protection (Law No. 94-V of 21 May 2013) keeps its localization rule in article 12(2): storage of personal data is carried out by the owner, the operator or a third party in a database located in the territory of the Republic of Kazakhstan.
Amendments effective February 11, 2024 (passed December 11, 2023) added breach notification to the Ministry of Digital Development, with that duty effective July 1, 2024, and gave the Ministry authority to conduct unscheduled compliance inspections.
The framework did not stop there. The consolidated text on the Ministry of Justice database records further amending laws of 19 June 2024, 17 November 2025, and 9 January 2026 (No. 256-VIII, the Digital Code), the last of which swaps the Act's "informatisation objects" vocabulary for "digital objects" six months after its first official publication. The official text also carries a note that article 12(2) itself is subject to a pending change under the Law of 24 June 2026 No. 326-VIII, entering into force sixty calendar days after first publication.
The identity-document rule is narrower than a flat ban. Collecting and processing paper copies of identity documents is prohibited except where there is no integration with the state digital objects, where the person cannot be identified by technological means, or in other cases provided by the laws of Kazakhstan.
Sector-Specific Localization Patterns
Several patterns emerge across jurisdictions where localization applies to specific sectors rather than all data.
Financial Data
Banking regulators worldwide frequently impose the strictest localization rules. India's RBI payment data mandate, Indonesia's OJK requirements, Nigeria's CBN directives, China's banking data rules, and Saudi Arabia's SAMA regulations all require some degree of local storage for financial data. Financial data localization is the most globally consistent sector pattern.
Healthcare Data
Health data localization appears in Australia, Turkey (health data regulations), Saudi Arabia (National Health Information Center requirements), and several EU member states that impose additional restrictions on health data beyond the GDPR baseline.
Australia's rule is a statutory prohibition, not guidance. Section 77 of the My Health Records Act 2012 bars the System Operator, registered repository operators, registered portal operators and registered contracted service providers from holding or taking My Health Record system records outside Australia, from processing or handling the related information outside Australia, and from causing or permitting another person to do either. Contravention is an offence carrying up to five years imprisonment or 300 penalty units, and a civil penalty of 1,500 penalty units. The carve-out in section 77(2) covers only records and information that contain no personal information about a healthcare recipient or participant and no identifying information.
Telecommunications
Telecom metadata and subscriber data face localization requirements in Russia, China, Vietnam, India (through telecom license conditions), and several African countries. These rules often derive from national security and law enforcement access concerns.
Government and Public Sector Data
Almost universally, countries require government data to be stored domestically. This includes Indonesia's GR 71/2019 for public electronic systems, Nigeria's NITDA guidelines, India's government cloud policy, and Saudi Arabia's NCA requirements.
Artificial Intelligence Training Data
China's AI governance regulations, which are now integrated into the CSL framework as of the January 2026 amendments, include localization components for AI training data processed by CII operators. Organizations training AI models on data collected from Chinese users within CII sectors must ensure that training data remains subject to the standard localization and security assessment requirements.
The EU and Data Sovereignty
The GDPR does not require data localization within the EU or EEA. Instead, it permits cross-border transfers to countries with adequate protection or through approved transfer mechanisms such as Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. The GDPR framework is built around transfer conditions, not storage mandates.
However, the EU is not entirely free of data sovereignty pressures.
The European Cybersecurity Certification Scheme for Cloud Services (EUCS), developed by ENISA under the EU Cybersecurity Act, has been the subject of prolonged debate over sovereignty requirements. Earlier EUCS drafts included explicit sovereignty requirements for the highest certification tier (High+): EU headquarters location, EU jurisdictional control, and no legal obligation to disclose data to third-country governments. These requirements would have effectively excluded major US cloud providers from achieving the top certification tier. In September 2024, the EU Council urged ENISA and the European Commission to accelerate the EUCS process and clarify how sovereignty criteria would be incorporated. The 2025 adoption target was not met. As of 10 September 2026 the EUCS is still a candidate scheme, and the EUCC for ICT products, software, components and hardware remains the only adopted European cybersecurity certification scheme.
EU law also regulates localization head-on, which is easy to miss on a page framed around the GDPR. Regulation (EU) 2018/1807 on a framework for the free flow of non-personal data, applicable since 28 May 2019, provides in Article 4(1) that "data localisation requirements shall be prohibited, unless they are justified on grounds of public security in compliance with the principle of proportionality." Member States had to repeal non-compliant localisation requirements by 30 May 2021 and to notify the Commission of any they considered still justified.
Member-state localization rules therefore do not simply sit alongside EU law. For non-personal data they are presumptively prohibited, and any surviving rule has to pass a public-security and proportionality test and be notified to the Commission. Several member states do maintain sector-specific requirements, particularly for health data and for government-related data, and any such rule should be checked against the Commission's record of notified measures before it is relied on.
The Economic and Trade-Policy Debate
Data localization requirements carry measurable economic costs. In its July 2021 study, the Information Technology and Innovation Foundation (ITIF) identified 154 cases of explicit or de facto data-localization regulations in effect in 66 countries, and counted 144 of them as trade barriers across 62 countries, up from 67 barriers in 35 countries in 2017. Using an OECD-derived data-restrictiveness index, ITIF estimates that a 1-point increase in a country's data restrictiveness reduces its gross trade output by 7 percent, slows productivity by 2.9 percent, and increases downstream prices for data-reliant industries by 1.5 percent over five years.
The most data-restrictive countries in that 2021 count are China (29 localization measures), India (12), Russia (9), and Turkey (7).
At the World Trade Organization, digital trade discussions within the Joint Statement Initiative on Electronic Commerce have addressed cross-border data flows. Several WTO members have proposed binding commitments on data flow liberalization, but no binding multilateral agreement on data localization has been concluded.
Proponents of localization argue that it serves legitimate interests: national security (preventing foreign intelligence access to citizen data), law enforcement access (ensuring data is available for investigations within the jurisdiction), economic development (building domestic cloud industries and keeping data-processing jobs local), and privacy protection (keeping citizen data under national law). Critics argue that localization fragments the global internet, raises compliance costs for businesses operating across borders, disadvantages developing countries that lack domestic cloud infrastructure, and duplicates infrastructure at significant economic cost without commensurate security benefits.
The balance between these interests is not resolved. The global trend is toward more localization, not less, even as some countries (notably India with the DPDP Act) have moved toward more permissive baseline frameworks than their earlier drafts proposed.
Recent Developments (2024-2026)
The developments below have taken effect since this page was first written, with the position stated as of 10 September 2026:
China. The CSL amendments took effect January 1, 2026, increasing maximum penalties to RMB 10 million, expanding extraterritorial reach, and integrating AI governance. The March 2024 CAC cross-border provisions relaxed transfer thresholds and introduced FTZ negative lists, representing the most significant easing of China's cross-border rules to date.
India. The DPDP Rules were published in the Gazette on 13 November 2025 as G.S.R. 846(E). The negative-list power is in section 16(1) of the DPDP Act 2023; Rule 15 adds a separate condition about making transferred data available to a foreign State and takes effect on 13 May 2027. No country has been notified as restricted.
Saudi Arabia. The PDPL grace period ended September 14, 2024. SDAIA published version 2.0 of the Regulation on Personal Data Transfer Outside the Kingdom in August 2024, announced on 1 September 2024, amending the version issued in September 2023. Saudi Arabia's data protection regime is now fully operative and enforceable.
Nigeria. The NDPA, signed June 2023, replaced the NDPR as the statutory basis for data protection. The 2024 CNII designation of BVN, NIN, and NIBSS added new critical infrastructure localization obligations.
Indonesia. The PDP Law's two-year transition period ended October 17, 2024. All organizations were required to achieve full compliance as of that date.
Russia. The FZ-266 cross-border transfer notification requirement (effective March 2023) added a mandatory pre-transfer notification step to Roskomnadzor for any cross-border personal data transfer. Federal Law 23-FZ of 28 February 2025, in force 1 July 2025, then rewrote Article 18(5) of the Personal Data Law as a prohibition on using databases located outside Russia for the recording, systematization, accumulation, storage, updating and retrieval of Russian citizens' personal data.
Kazakhstan. February 2024 amendments introduced breach notification obligations (effective July 2024) and restricted the collection of paper identity-document copies. Several further amending laws followed through 2026, including the Digital Code (Law of 9 January 2026 No. 256-VIII), and a change to the localization provision itself is pending under the Law of 24 June 2026 No. 326-VIII.
Vietnam. Law 91/2025/QH15 on personal data protection and Decree 356/2025/ND-CP took effect on 1 January 2026 and ended Decree 13/2023. Law 116/2025/QH15 on cybersecurity took effect on 1 July 2026, replacing the 2018 Cybersecurity Law and the 2015 Law on Cyber-Information Security, and states the in-country storage duty in Article 25(3).
Turkey. Article 9 of Law 6698, as replaced by Law 7499, has applied since 1 June 2024. Turkey moved from a consent-or-adequacy model to adequacy first, then listed safeguards, with explicit consent left as an incidental derogation.
China (certification). The Measures for Certification of Personal Information Export, published on 17 October 2025, took effect on 1 January 2026, the same day as the CSL amendment, and set the eligibility band for the certification route.
Nigeria (implementation). The NDPC issued the General Application and Implementation Directive 2025 on 20 March 2025. Its Article 45 and Schedule 5 govern cross-border transfer evaluation, and no adequacy decisions have been issued.
Compliance Strategies for Multinational Organizations
Organizations operating across multiple jurisdictions with different localization requirements can adopt several strategies.
Regional Data Center Architecture
Deploying data centers (or contracting with cloud providers) in key jurisdictions ensures local storage compliance. Major cloud providers like AWS, Microsoft Azure, and Google Cloud offer region-specific data residency options. Organizations can configure data residency policies to ensure that data from specific countries remains within designated regions. Major providers have also introduced sovereign cloud offerings: Google's Sovereign Cloud, Microsoft's EU Data Boundary, and comparable products allow organizations to contractually commit that certain data never leaves a defined geographic zone, which can satisfy soft localization requirements without the capital expense of dedicated infrastructure.
Data Segregation and Classification
Implementing data classification frameworks that tag data by jurisdiction and category allows organizations to apply localization rules selectively. Not all data from a given country requires localization; often only specific categories (financial, health, government) are subject to local storage requirements.
Hybrid Architectures
Some organizations maintain local "hot" storage for compliance purposes while processing or analyzing data centrally. This approach satisfies localization requirements while preserving the efficiency of centralized analytics. The key is ensuring the local copy meets the "primary storage" requirement where applicable.
Transfer Mechanism Layering
In soft localization jurisdictions, organizations can maintain local storage while using transfer mechanisms (SCCs, adequacy decisions, consent, or contractual clauses) to export copies of data for global operations.
Regulatory Monitoring
Localization laws change frequently. Organizations need a systematic process for tracking legislative and regulatory developments in every country where they operate. The 2024-2026 period saw significant changes in India, Saudi Arabia, Indonesia, Nigeria, Kazakhstan, Turkey, Vietnam, and China. Quarterly compliance reviews are a minimum for organizations with significant presences in these markets.
This is general legal information, not legal advice. Organizations navigating data localization requirements across multiple jurisdictions should consult an attorney licensed in the relevant jurisdiction for advice specific to their situation. This page reflects information available as of 10 September 2026.
Frequently Asked Questions
What is data localization?
Data localization refers to legal requirements that personal data or other categories of data be stored, processed, or maintained on servers physically located within a specific country's borders. These laws may require all data about a country's residents to remain in-country (hard localization), require a local copy while permitting transfers abroad (soft localization), or impose conditions on cross-border transfers that function as practical localization.
Which countries have the strictest data localization laws?
China, Russia, and Vietnam maintain the most comprehensive localization regimes as of 2026. China requires CII operators to store personal information and important data locally, with government security assessments required before any cross-border transfer. The CSL amendments effective January 1, 2026 raised maximum penalties to RMB 10 million and expanded the law's extraterritorial reach. Russia prohibits the recording, storage, updating and retrieval of Russian citizens' personal data in databases located outside Russia, a rule recast by Federal Law 23-FZ with effect from 1 July 2025, and since March 2023 operators must also notify Roskomnadzor before any cross-border transfer. Vietnam's Law 116/2025/QH15, in force since 1 July 2026, requires in-scope domestic and foreign providers to store user data in Vietnam and requires foreign providers to open a branch or representative office there.
Does the GDPR require data localization within the EU?
The GDPR does not require data localization within the EU or EEA. Instead, it permits cross-border transfers to countries with adequate protection or through approved transfer mechanisms such as Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. However, the EUCS cloud certification debate and certain EU member states' sector-specific rules for health and government data go beyond the GDPR baseline.
What is the difference between hard and soft data localization?
Hard localization prohibits certain data from leaving the country entirely. The data must be stored and processed exclusively on local servers with no copies transferred abroad. Soft localization requires a copy of the data to be maintained on local servers but permits transfers of copies to other countries, usually subject to conditions such as government approval, consent, or contractual safeguards. Russia's personal data law represents hard localization, while Indonesia's framework represents soft localization.
Does India require data localization?
India does not impose blanket localization. The negative-list power sits in section 16(1) of the DPDP Act 2023, which lets the Central Government restrict transfers to a notified country or territory, and no such notification had been issued as of 10 September 2026. Rule 15 of the Digital Personal Data Protection Rules, published on 13 November 2025, adds a different condition: a Data Fiduciary must meet whatever requirements the Central Government specifies by general or special order about making transferred data available to a foreign State or its agencies. Most of the Rules, including Rule 15, take effect eighteen months after publication, on 13 May 2027. The Reserve Bank of India separately requires all payment system data to be stored exclusively in India, one of the strictest sector-specific localization mandates globally.
What changed in China's data localization rules in 2024 and 2026?
Three changes matter. In March 2024, the CAC issued new cross-border data flow provisions that relaxed the thresholds: a security assessment is required where a critical information infrastructure operator exports personal information or important data, and where any other data processor exports important data or exports, cumulatively since 1 January of the year, the personal information of 1,000,000 or more people or the sensitive personal information of 10,000 or more people. A processor that is not a CII operator and that exports the personal information of fewer than 100,000 people cumulatively is exempt from all three routes, not only from the standard contract. In January 2026, the Cybersecurity Law amendments took effect, raising maximum penalties to RMB 10 million, expanding extraterritorial reach to cover any activity harming China's cybersecurity, and integrating AI governance into the CSL framework. On the same day, the Measures for Certification of Personal Information Export took effect and fixed the eligibility band for the certification route.
How do multinational companies comply with different localization requirements?
Common strategies include deploying regional data centers or using cloud providers with jurisdiction-specific data residency options (including sovereign cloud products like Google Sovereign Cloud and Microsoft EU Data Boundary), implementing data classification frameworks that tag data by country and category, maintaining hybrid architectures with local storage for compliance and centralized processing for analytics, layering transfer mechanisms like SCCs for soft-localization jurisdictions, and establishing quarterly regulatory monitoring processes to track changes across all operating countries.
What sectors face the most data localization requirements?
Financial services and banking face the strictest and most widespread sector-specific localization rules, with regulators in India (RBI), Indonesia (OJK), Nigeria (CBN), Saudi Arabia (SAMA), and China all requiring local data storage. Healthcare data faces localization in multiple jurisdictions. Telecommunications metadata is frequently localized for national security reasons. Government and public sector data is subject to localization requirements in nearly every country that has data residency laws. AI training data is an emerging localization category, particularly in China.
Are data localization requirements increasing or decreasing globally?
The global trend is toward more localization. The number of countries with some form of localization mandate has grown significantly since 2015. ITIF's July 2021 study identified 154 localization measures in effect in 66 countries, 144 of which it counted as trade barriers across 62 countries, up from 67 barriers in 35 countries in 2017. Drivers include national security concerns, economic development strategies to build domestic cloud industries, geopolitical tensions around digital sovereignty, and law enforcement access requirements. Some countries (notably India with its DPDP Rules) have adopted more permissive frameworks than earlier drafts proposed, but the broader trend is expansion, not contraction.
Updates
Rebuilt the Vietnam entry on Law 91/2025 and Law 116/2025 and removed the pre-transfer registration certificate claim, replaced a misquoted version of India's Rule 15 with the notified text and moved the negative-list power to section 16(1) of the DPDP Act, restated Turkey's article 9 as amended by Law 7499 and Saudi Arabia's article 29 transfer purposes, corrected China's cross-border thresholds and the Shanghai free-trade-zone lists, corrected the Russian localization penalties and added the 2025 rewrite of article 18(5), recorded Australia's My Health Records Act section 77 in the comparison table, added Regulation (EU) 2018/1807 and Nigeria's GAID 2025, and replaced nine dead or unofficial source links.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Major expansion: added H2 sections on the EU and data sovereignty, the economic and trade-policy debate, and a dedicated recent-developments section (2024-2026). Updated China section with CSL January 2026 amendment (RMB 10 million penalty cap, extraterritorial expansion, AI governance integration) and March 2024 CAC cross-border provisions (revised thresholds, FTZ negative lists). Corrected Indonesia PP 17/2025 claim (that regulation concerns child protection, not data transfer). Updated India DPDP Rules to reflect final November 2025 publication and May 2027 compliance deadline. Added Nigeria NDPA 2023 (statutory upgrade from NDPR) and 2024 CNII designation. Updated Russia with FZ-266 cross-border notification requirement (effective March 2023). Added Saudi Arabia PDPL enforcement timeline. Fixed malformed Turkey internal link. Word count expanded from 2,490 to approximately 4,700 words.
Reviewed and approved by an editor
Sources and References
- Personal Information Protection Law of the People's Republic of China (2021), full text published by the Cyberspace Administration of China (arts. 38-40 on cross-border provision and storage)(cac.gov.cn).gov
- Data Security Law of the People's Republic of China (2021), full text published by the Cyberspace Administration of China(cac.gov.cn).gov
- Cybersecurity Law of the People's Republic of China (2016 text), published by the Cyberspace Administration of China; for the amendment in force 1 January 2026 see the gov.cn notice(cac.gov.cn).gov
- China CSL Amendment (October 2025, effective January 2026)(gov.cn).gov
- CAC, Provisions on Promoting and Regulating Cross-Border Data Flows (22 March 2024), official text (arts. 5, 6, 7, 8, 9)(cac.gov.cn).gov
- CAC Standard Contract for Data Export (2023)(cac.gov.cn).gov
- Russia, Federal Law of 21.07.2014 No. 242-FZ, official publication (publication no. 0001201407220042)(publication.pravo.gov.ru).gov
- Council of Europe Convention 108(coe.int).gov
- India, Digital Personal Data Protection Act 2023 (No. 22 of 2023), MeitY text, section 16 on processing personal data outside India(meity.gov.in).gov
- RBI Payment Data Storage Directive(rbi.org.in).gov
- Nigeria Data Protection Act 2023, official text from the Nigeria Data Protection Commission(ndpc.gov.ng).gov
- Nigeria Data Protection Commission(ndpc.gov.ng).gov
- Turkey KVKK Law 6698(mevzuat.gov.tr).gov
- Indonesia, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions, JDIH Kementerian Komunikasi dan Digital(jdih.komdigi.go.id).gov
- SDAIA, Regulation on Personal Data Transfer Outside the Kingdom of Saudi Arabia, version 2.0 (August 2024), arts. 2, 4 and 7(sdaia.gov.sa).gov
- Saudi Arabia ICT Cross-Border Transfer Enforcement (US ITA)(trade.gov).gov
- Kazakhstan Data Localization Overview (Morgan Lewis 2024)(morganlewis.com)
- ITIF: Barriers to Cross-Border Data Flows(itif.org)
- ITIF: EU Cloud Service Restrictions (2025)(itif.org)
- Hogan Lovells: EUCS Sovereignty Debate(hoganlovells.com)
- Vietnam, Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, in force 1 January 2026), art. 20 on cross-border transfer and art. 8 on penalties(vanban.chinhphu.vn).gov
- Vietnam, Decree 356/2025/ND-CP detailing the Law on Personal Data Protection (in force 1 January 2026; ends Decree 13/2023/ND-CP), arts. 17-18 on the cross-border transfer impact assessment dossier(congbao.chinhphu.vn).gov
- Vietnam, Law on Cybersecurity No. 116/2025/QH15 (passed 10 December 2025, in force 1 July 2026; replaces Law 24/2018/QH14 and Law 86/2015/QH13), art. 25(3) on storing user data in Vietnam(congbao.chinhphu.vn).gov
- India, Digital Personal Data Protection Rules 2025, Gazette notification G.S.R. 846(E) dated 13 November 2025 (rule 1 commencement schedule; rule 15 on transfer outside India)(meity.gov.in).gov
- Turkey, Law No. 7499 (Official Gazette 12 March 2024, issue 32487), art. 34 replacing art. 9 of Law 6698 and art. 40 setting entry into force on 1 June 2024(mevzuat.gov.tr).gov
- Saudi Arabia, Personal Data Protection Law, SDAIA official English text, art. 29 on transfer and disclosure outside the Kingdom(sdaia.gov.sa).gov
- China, Measures for Certification of Personal Information Export (CAC and SAMR Order No. 20, published 17 October 2025, effective 1 January 2026), art. 5 eligibility band(cac.gov.cn).gov
- Russia, Federal Law of 28.02.2025 No. 23-FZ amending the Federal Law on Personal Data (official publication; art. 1(2) rewrites art. 18(5), art. 10 sets entry into force 1 July 2025)(publication.pravo.gov.ru).gov
- Russia, Code of Administrative Offences art. 13.11, parts 8 and 9 (fines for failing to hold Russian citizens' personal data in databases located in Russia)(consultant.ru)
- Regulation (EU) 2018/1807 on a framework for the free flow of non-personal data, art. 4 (data localisation requirements prohibited unless justified on public-security grounds)(eur-lex.europa.eu).gov
- Australia, My Health Records Act 2012 (Cth), s. 77 'Requirement not to hold or take records outside Australia', current compilation No. 18 (compilation date 1 July 2026)(legislation.gov.au).gov
- Nigeria Data Protection Commission, General Application and Implementation Directive (GAID) 2025, issued 20 March 2025, art. 45 and Schedule 5 on cross-border data transfer(ndpc.gov.ng).gov
- Kazakhstan, Law No. 94-V of 21 May 2013 on Personal Data and Its Protection, consolidated text (art. 12(2) storage in Kazakhstan; amendments through 2026 and the pending change under the Law of 24.06.2026 No. 326-VIII)(adilet.zan.kz).gov
- ITIF press release, 'Restrictions on International Data Flows Have Doubled in Four Years' (19 July 2021), source of the 154 measures in 66 countries and the 144 barriers in 62 countries figures(itif.org)
- ENISA, European cybersecurity certification portal (EUCC published; EUCS still a candidate scheme)(certification.enisa.europa.eu).gov
- Shanghai, questions and answers on the data export negative list (2025 edition), published 24 April 2026, replacing the 2024 edition(shhk.gov.cn).gov
- Lin-gang New Area, scenario-based general data list for the public fund sector (May 2024), an instrument listing data that may flow freely(jrj.sh.gov.cn).gov