A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Chief Privacy Officer at Franklin Templeton
Eric Bedell
Will Data Localization Create New Borders?


Data localization refers to the concept of storing data on any device that is present within the physical or political borders of the country, where personal data is collected, processed, and/or stored, prior to being transferred to another country. This concept can automatically create challenges where data is stored on “borderless” clouds.
The goal of data localization laws is to benefit an individual’s (referred to as a data subject) privacy rights by enforcing restrictions on how their (sensitive) data is transferred internationally.
At a minimum, data localization should be a consideration when selecting new vendors, building any new international process, or opening a new office in another country. Organizations should contemplate data localization requirements in the same gravitas as cost reduction in terms of globalized solutions.
Governments are readily sharing some of their goals in relation to data localization, with the touted aim of protecting citizens. However, some covert goals are naturally a part of the agenda. These veiled goals usually include competitive advantage of the country’s industry against their neighbours, or even clandestine operations, such as performing mass surveillance on their own population.
The push for increased data localization started after the 2013 Edward Snowden case, alleging the United States’ counter-terrorism surveillance. Since then, various governments considered draft laws and some have proceeded to implement them, to control the flow of residents' data through technology.
In implementing data localization, governments have taken various stances, such as a moderate one (e.g., in the European Union, Australia or California), a bit less moderate (the recent Indian privacy law draft), or very strict (China and Russia).
Sometimes, the requirements do not come from the regulators and lawmakers, but from the business’s own customers who may expect companies not to share their data with a specific country or may request that their data remains within their country of origin. This trend is rapidly increasing, as the public’s awareness on privacy continues to deepen, demand for the number of privacy laws passed is growing. As the population equipped with some privacy education expands, it is natural they will request such limits.
Consider the globalization of privacy laws as a consequence of the introduction of EU GDPR. This new normal will probably require most organizations to rethink their technology model. After decades of globalization, primarily focused on cost reduction goals, companies’ technology models may require alteration by either creating logical digital boundaries in their network or completely rebuilding their physical infrastructure to comply with data localization demands.
This will doubtlessly impact the organization’s selection of third parties. Some suppliers are yet to offer data localization possibilities, potentially placing them at a market disadvantage. Other vendors will surely use this trend as a market differentiator. (For example, Microsoft offers data storage locale controls in their cloud services.)
Lastly, it may be a best practice, in accordance with risk appetite, for organizations to appoint a “border control” team, who would determine and control data transfer limits. Currently, most countries’ guidance is to control data transfers risks through assessment (for instance, the EU’s Transfer Impact Assessment introduced after the Schrems II decision by the EU Court of Justice). The organization’s privacy office, obviously, will have a role to play, but will require support from other business functions and teams such as data governance, procurement, vendor management, compliance teams, etc.
I would strongly recommend building data localization requirements into your company’s policies and processes. At a minimum, data localization should be a consideration when selecting new vendors, building any new international process, or opening a new office in another country. Organizations should contemplate data localization requirements in the same gravitas as cost reduction in terms of globalized solutions. In conclusion, data localization is a trend that is, without any doubt, here to stay.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


