Data Localisation
Data localisation is the practice or legal requirement of keeping data within the borders of a particular country or region. In most cases it means that organisations must collect, store, and/or process certain data on servers located inside a specific geographic area, rather than sending it overseas. The exact obligations vary depending on the country and the type of data involved.
Data localisation refers to legal, regulatory, or administrative requirements that mandate, directly or indirectly, that specified categories of data be collected, stored, and/or processed within a defined national or regional jurisdiction. Such measures typically restrict cross-border transfers by requiring in-country storage or processing, and are often framed in terms of data sovereignty over the data of a country's citizens or residents. The scope, triggering data categories, and degree of restriction differ significantly between jurisdictions; the term 'data residency' is frequently used synonymously, though practitioners should verify the precise obligations under the applicable national law, as these requirements evolve and are not defined uniformly across regimes. Note that data localisation obligations are distinct from, and may operate alongside, cross-border transfer mechanisms under data protection frameworks such as the GDPR.
Why it matters
Data localisation shapes where organisations may physically hold and process data, and it can operate independently of the transfer mechanisms found in data protection frameworks such as the GDPR. Where a jurisdiction mandates that data about its citizens or residents be collected, stored, and/or processed in-country, an organisation may need local infrastructure or arrangements even where a valid cross-border transfer tool would otherwise be available. In most cases the two regimes must be assessed together rather than treated as alternatives, because satisfying one does not automatically satisfy the other.
The practical significance lies in cost, architecture, and compliance risk. Localisation obligations can require duplicated storage, regional processing, or restrictions on routing data overseas, which affects cloud strategy, vendor selection, and product design. Because the triggering data categories and degree of restriction differ significantly between jurisdictions, an approach that is compliant in one country may not meet the requirements of another.
These requirements are not defined uniformly across regimes and continue to evolve, so a position taken at one point in time should not be assumed permanent. Organisations should verify the precise obligations under each applicable national law and monitor for change, rather than relying on a general characterisation of localisation as a single global standard.
Who it's relevant to
Inside Data Localisation
Common questions
Answers to the questions practitioners most commonly ask about Data Localisation.