top of page

Data Sovereignty and Cross-Border Cloud Computing Regulation

  • sonalimukhia2002
  • Jul 11
  • 13 min read

Author: Richa, IIMT College of Law



ABSTRACT

The rapid expansion of cloud computing has made easy availability of data by enabling organisations to store processed data across multiple judicial restrictions. Cloud computing provides stability, privacy and also it has to deal with various legal questions related to data sovereignty, jurisdiction, privacy, security and complaints. Data sovereignty works on the principle in which data remains subject to laws of the country by which it has to be stored, regulated or processed as data increasingly moves across national border through cloud interface. The government maintains the security and privacy of the data and also protects the data from the leakage or from the hackers. This research article analyses a major framework which includes general data protection regulation, Indian Digital Personal Data Protection Act. This makes the balance between the regulatory harmonization essential for both protection and digital innovation, including the sovereignty interest.

Key Words

Data Sovereignty, Cross-Border Data Transfer, Cloud Computing Regulations, GDPR.


INTRODUCTION

Cross-border cloud computing has become the backbone of the modern digital economy, allowing data generated in one country to be stored, processed, and transmitted through servers located in entirely different jurisdictions. Major cloud service providers such as Amazon Web Services, Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure, and IBM Cloud operate data centers not merely within India but across the United States, Singapore, Germany, and numerous other nations, reflecting the genuinely transnational character of cloud infrastructure today. While this arrangement has enabled cost-effective data storage, promoted innovation, and connected global markets, it has simultaneously raised serious concerns regarding data privacy, security, and the question of which nation's laws ultimately govern data once it leaves its country of origin. Data sovereignty addresses precisely this concern. It holds that, data even when physically stored in another country, remains subject to the laws and regulatory authority of the country in which it was generated. Many nations have responded by promoting data localization, requiring that certain categories of data be stored within domestic borders so as to reduce cross-border risk, strengthen security, and preserve public trust in digital services. However, this approach exists in tension with the operational logic of cloud computing, which depends on distributed networks and flexible cross-border data flows to function efficiently. At the international level, the General Data Protection Regulation governs data transfers from the European Union through a structured framework under Articles 44 to 48, prioritizing individual privacy rights and permitting transfers only where an adequacy decision exists or appropriate safeguards are in place. The United States, through the CLOUD Act, takes a markedly different approach, prioritizing investigative access and flexibility for law enforcement over destination-based restrictions. India has sought to balance economic development with digital sovereignty through the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000, supplemented by sector-specific measures such as the Reserve Bank of India's 2018 circular mandating localization of payment system data. These divergent frameworks generate significant legal challenges. Jurisdictional conflict illustrated starkly by the Schrems II judgment, which invalidated the EU-US data transfer arrangement on the ground that US surveillance practices failed to meet EU privacy standards raises unresolved questions about which country's courts hold authority over cross-border data disputes. Government access to data stored abroad, as seen in the Microsoft Ireland litigation, further complicates the picture, while inconsistent localization requirements impose compliance burdens on global providers. Emerging technologies such as artificial intelligence, multi-cloud environments, and the Internet of Things compound these difficulties, exposing the limitations of existing legal frameworks.

These divergent frameworks generate significant legal challenges. Jurisdictional conflict illustrated starkly by the Schrems II judgment, which invalidated the EU-US data transfer arrangement on the ground that US surveillance practices failed to meet EU privacy standards raises unresolved questions about which country's courts hold authority over cross-border data disputes. Government access to data stored abroad, as seen in the Microsoft Ireland litigation, further complicates the picture, while inconsistent localization requirements impose compliance burdens on global providers. Emerging technologies such as artificial intelligence, multi-cloud environments, and the Internet of Things compound these difficulties, exposing the limitations of existing legal frameworks. Given this fragmented regulatory landscape, there is a pressing need to examine whether a harmonized, globally coordinated framework for cross-border data transfer can reconcile the competing imperatives of data sovereignty, privacy protection, and the operational realities of cloud-based digital infrastructure.


LITERATURE REVIEW

Data sovereignty means data stored and secured under the country laws and regulations where it was generated. Data sovereignty aims to protect privacy, national security. In today's digital era, cloud computing services, where data is stored, processed and transferred in other countries, raise legal challenges related to privacy, security and jurisdiction complexity. These challenges are discussed under the concept of data sovereignty and cross border.

In the favour of data sovereignty Christopher Kuner stated that the legal system is based on a traditional system but the cloud computing ideas break this tradition because data is transferred and stored in multiple countries. It creates major problems for the government in the application of their laws.

Similarly, Dan Jerker B. stated that, cross-border data flow created jurisdiction complexity because more then one country claiming authority on the same data.

On the other hands Michael Geist is against excessive restrictions, according to them cloud computing improves effectiveness and reduce costs for businesses but it also raise challenges that which country law will be followed and it becomes a major problem for the companies which are handling data cross border.

For the solution of this major problem countries has introduced data localization laws.

However, Anupam Chander disagrees with data localization law and argues that strict data localization can harm innovation and reduce the benefits in global digital trade. According to him, free flow of data supports economic growth. But on the other hand Christopher Kuner supports data localization law, according to them countries need strong data protection law for privacy and national security.

The European Union General Data Protection (GDPR) is discussed as a strong data regulation. According to Paul Schwartz GDPR has improved data protection because it provides strong privacy rights but it also raises challenges for companies who transfer their data outside Europe.

Schrems II, Data protection Commission v. Facebook Island Ltd. case made this statement strong but Graham Greenleaf favours this case, according to them it increased legal uncertainty but also enhanced principal protection.

Recent Literature of Lyria Bennett suggests a balanced approach, according to her, instead of choosing between strict sovereignty and free data flow, countries should develop a Harmonized Framework.

The literature shows a clear debate between strict sovereignty and the cross-border cloud system. Scholars highlight the gap in global governance. No unified legal framework for cross-border, which shows the uncertainty in regulation.


DISCUSSION

What is Data Sovereignty?

Data Sovereignty means data stored and secured under the country laws and regulations where it was generated. Data Sovereignty aims to provide security and maintain their privacy. When data is stored in another country, by any organization, it must obey that country's laws and regulations related to the data. And we also with the help of Data Localization through laws can store the data in own country, it safeguards the data, provide better regulations and it reduces cross border risks.


Importance of Data Sovereignty?

Data Sovereignty is important for the government, businesses and organisations. Data is an asset, which is used for economic growth. Intellectual protection with the data sovereignty layer of security is created keeping data under other countries' loss and status which increases the security of data with the strong data sovereignty and helpsngain the public trust.


What is Cross Border Cloud Computing?

Cross border cloud computing means transferring data from one country to another country for storage, processing, and transmission through cloud computing services.

According to Diane Coyle & David Nguyen, cross-border cloud computing provides the cloud-based services and mainly infrastructures by which our data can be stored, processed and transferred within the national borders and it also enables digital activities which occur globally through distributed networks and many data centres.


Importance of Cross-border Cloud Computing

Cross-border cloud computing is important for the digital economy. It helps businesses, companies, government agencies, small businesses and other organisations by enabling data storage processing and transmission. It provides easy availability of data globally with cheap cost and also promotes innovation and digital transformation. Moreover, cross - border cloud computing is very easy to use and it connects all the global nations and contributes towards economic growth.

In India Cloud Services majorly provided by Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure, and IBM Cloud. Their centres not only are present in India, but also in other nations like the United States, Singapore, Germany and many more such countries.


LEGAL FRAMEWORK AND REGULATIONS

The rapid growth of Cross-Border Cloud Computing rapid makes transfer and storage of data within multiple countries. However, Data beyond boundaries show concern about protection, data privacy and security. To make their concerns in use, various international and national legal frameworks have been established to protect their citizen’s data from theft and keep it secure and safe.


International Legal Framework

General Data Protection Regulation (GDPR), enacted in the year 2016 and came into force in 2018 for data protection for the European citizens. GDPR mainly makes its dependency on six legal bases: consent, contract, legal obligation, United interest, public task, legitimate interest. Article 44 of GDPR, are general principles for transfer, according to this data transfers outside the country by third parties or any other organisation only if protection is under the same manner. Article 45 of GDPR, allows transfer on the basis of an adequacy decision. In this Article EU commission can grant data transfer to the country which ensure adequate level of data protection. Article 46 of GDPR, is if there is absence of decision present in article 45(3) a controller or processor makes the smooth transfer of data to the third country and provides proper safeguard. Article 48 Of GDPR states, any judgement of court or decision of any authority requiring the processor transfer is only possible, if there is an international agreement present otherwise it won't.


Indian Legal Framework

The Indian legal system tries to frame their own laws for cross-border cloud computing regulation. For the Cross-border regulation, India introduced The Digital Personal Data Protection Act 2023. Under this Act, data can be transferred or processed outside India until the country is restricted by the central government of India. Section 8, talks about the duties. While the Information Technology Act 2000, provides legal framework related to Cyber Laws. Under the Section 43A of IT Act, a government body takes the responsibility of handling any type of sensitive data and if that body somehow fails to maintain security, such body will have to pay compensation. And Section 72A of the IT Act, facilitates, if an individual gets access to someone's personal data and shares the same without any consent of the owner, then the individual gets punished with imprisonment. And for the protection and storage of data which is linked to payment, the Reserve Bank of India (RBI) has passed this circular, 'Storage of Payment System Data' on 6th April 2018. Under this circular, data will be stored or processed within the same country itself. In addition to the growth and development of the country, international organization plays a crucial role in regulating cross-border data flows. The Organization for Economic Co-operation and Development, is an organisation for economic Co-operative and development and was established in the year 1961. Its main purpose is to promote or develop economic growth which increases international co-operation. It simply helps in growth and development and has 38 members. However, India is not part of OECD but follows the guidelines and influences in standards. Nowadays, nations prefer data localization. OECD promotes neutral balance between data protection and free flow of data just to establish a smooth flow. There are many legal frameworks but still there are not particularly globally expected frameworks and because of this we find loop holes. We discover some legal challenges which increase the risks of data theft, cybercrime, online fraud etc. It is clear that it provides security and stores the data. There are stills, so many risks are left.


Legal Challenges

Jurisdiction Conflicts: In terms of Cross-Border Cloud Computing Regulation, different nations have different laws for their data protection like the European Union has GDPR, the United States has CLOUD, and China has PIPL etc. Due to different laws across nations, the stored and processed data is the biggest problem. It creates conflict between countries. This jurisdiction conflict is highlighted in the Schrems ii case, whether the court invalidates the EU-US data transfer because US surveillance laws are not equal to EU privacy standards. These things create the confusion, which country court has authority on dispute related cross-border data transfer.


Data Localization Requirement: Data Localization mainly focuses on public personal data like citizen records, healthcare data etc, which is stored and processed within the country. But for the global cloud provider it becomes expensive and difficult to follow. The RBI circular mandates the data localization for financial data of Indian citizens, in this circular RBI clearly mentioned that the whole data, which is related to payment must be stored in India. And this is how they increase the trend of data localization, which creates the tension between cross-border cloud computing services.


Privacy and Data Protection Compliance: During cross-border data transfer, obeying the different data protection laws is difficult. For the privacy purpose different nations have their different laws like DPDP Act, GDPR, LGPD and CCPA etc and fulfilling these laws requirement is tough still the other providers, organization and nation trying to fulfil the requirement and adopt different privacy data protection frameworks.


Government Access and Surveillance Concerns: Under the Government Access and surveillance concern, states keep an eye on their citizen’s digital activities for the monitoring purpose. For this purpose, any nation's Government can ask for data access, which is stored on cloud servers. The issue was highlighted in the Microsoft Ireland case, where the case emphasizes the conflict, in which nation laws and authorities have power to govern cross-border data access requests.


Data Breaches and Cyber Security risks: During cross-border data transfer the risk of data leakage is very high due to which it comes under cyber security we have not found the exact solution for this problem. In case of data leakage, which jurisdiction and authority are liable for remedy is still not found.

Aside from the existing challenges, rapid growth of technological advancement is creating new challenges for Data Sovereignty in Cross-Border Cloud Computing.


EMERGING TRENDS AND FUTURE CHALLENGES

AI and Cloud Computing: The rapid growth of Artificial Intelligence (AI) in cloud computing increases the risk of privacy and security. Hackers can attack on cloud servers or AI systems by which data may be stolen or lost.

Distributed Cloud: The rise of cloud computing shows new challenges, as data stored and processed in multiple geographical locations creates the problem in jurisdiction and data governance.

Data Governance in Future: The growth of advancement technologies such as AI, Multi-Cloud environment, IOT, is changing the way data is processed and stored. These technologies offer benefits but they also arise new challenges for Data Sovereignty and the existing legal frameworks are insufficient.

For the resolution of these challenges, Therefore, it is necessary to strengthen the data governance and legal framework.


ANALYSIS

The Analysis of existing framework of cross-border data transfer regulation reveal that, General Data Protection Regulation (GDPR), Article 44 to 48 prioritise privacy and individual rights, and Clarifying Lawful Overseas Use of Data (CLOUD) focuses on investigative effectiveness & flexibility and The Digital Personal Data Protection Act & Information Technology Act (IT) considers balancing economic development and digital sovereignty. They provide sufficient protection and security for cross-border data transfer.

The study highlights legal challenges, which arise from legal frameworks. These challenges are jurisdiction conflicts, whether for the data countries create complexity regarding applicable laws. Another important challenge is inconsistent Data Localization requirements, where different jurisdictions impose different laws and requirements, fulfillment of these requirements create burden on providers. In addition to the above, one more key issue is Government access to data creates uncertainty. In this, the Government authority may ask for the data access which is stored and processed in other countries and it creates uncertainty and raises trouble related to privacy protection and transparency.

Apart from these challenges, new emerging trends like Artificial Intelligence (AI), Multi-Cloud Environment, Internet of Things (IOT) create future challenges. These new technologies offer benefits but they also increase the risk of data leakage and cyberattacks. Hackers may attack cloud services and AI systems by which citizen’s data may be stolen or lost.

The study highlights that for the reduction of these challenges policy reforms should be focused on a harmonized framework for cross-border data transfer. A harmonized framework should focus on data transfer processed and stored with strong security and privacy. A new framework must be working on a global level, which maintains peace and provides for punishment and remedy, e.g., United Nation, which resolves disputes between countries and maintains peace. With a harmonized framework the challenges, jurisdiction complexity, Government access uncertainty, Localization requirements and other emerging challenges may be resolved.

Before the introduction of new frameworks, the Government should regulate their data transfer on the behalf of agreement. An agreement-based data transfer provides legal clarity, fast processing and reduces the burden of providers.


CONCLUSION

This study examined the legal framework and challenges related to cross border data transfer in cloud computing. The analysis highlighted that, the rapid growth of digital technologies like AI, IOT and Cloud-based services needs development and Harmonized International Legal framework. Each country has their own laws for cross border data transfer in cloud computing regulation. This paper analyses major legal frameworks, international laws such as the GDPR, national laws such as Digital Personal Data Protection Act, Information Technology Act for the data protection and other circular explains the importance of regulatory laws, while legal frameworks aim to provide privacy and security. Hence, the absence of uniformity creates conflicts and complications for organisations. In addition, the research identified some critical challenges including jurisdiction conflicts, inconsistent data localisation requirements and uncertainty regarding government access to data stored and processed across borders. These challenges create complexity regarding applicable loss and increase burden on international organisations and providers. The different regulatory laws such as CLOUD, CGPD and other laws get complicated beyond the territory. Overall finding indicates the lack of unified global frameworks for cross- border data transfer in cloud computing regulation. This absence affects the legal certainty and citizens' trust in cross-border data transfer and the importance of framework development for citizens' privacy and data security on an international level.

In conclusion there is a clear need for a Harmonized Framework for Cross-border data governance on a global level. The Harmonized framework should aim to balance the data transfer to provide national security in the free flow of data. Even before the introduction of the Harmonized framework, governments should regulate their data on the agreement bases. An agreement may reduce the complexity, uncertainty and risk related to data transfer in cloud computing regulation. A Harmonized framework may resolve the challenges of jurisdiction complexity, government access uncertainty and localization requirements and apart emerging trends challenges.


REFERENCES
  • Christopher Kuner, Data Protection Law and International Jurisdiction on the Internet (Part 2), 18 International Journal of Law and Information Technology 227 (2010).

  • Christopher Kuner, Transborder Data Flows and Data Privacy Law 3–15 (Oxford University Press 2013).

  • Dan Jerker B. Svantesson, Solving the Internet Jurisdiction Puzzle 1–25 (Oxford University Press 2017).

  • Diane Coyle & David Nguyen, Cloud Computing, Cross-Border Data Flows and New Challenges for Measurement in Economics, 249 National Institute Economic Review R30–R38 (2019).

  • Digital Personal Data Protection Act, 2023, § 8 (India).

  • Information Technology Act, 2000, § 72A (India).

  • Lyria Bennett Moses, Why Have a Theory of Law and Technological Change?, 8 Minnesota Journal of Law, Science & Technology 589 (2007).

  • Michael Geist, Law, Privacy and Surveillance in Canada in the Post-Snowden Era, 4 International Data Privacy Law 73 (2014).

  • Organisation for Economic Co-operation and Development (OECD), Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (2013).

  • Organisation for Economic Co-operation and Development (OECD), OECD Principles on Artificial Intelligence (May 22, 2019).

  • Paul M. Schwartz, Global Data Privacy: The EU Way, 94 New York University Law Review 771 (2019).

  • Regulation (EU) 2016/679, General Data Protection Regulation (GDPR), art. 44, 2016 O.J. (L 119) 1 (EU).

  • Data Protection Commissioner v. Facebook Ireland Ltd. & Maximillian Schrems (Schrems II), Case C-311/18, Judgment, ECLI:EU:C:2020:559 (Court of Justice of the European Union, July 16, 2020).

  • United Nations Conference on Trade and Development (UNCTAD), Digital Economy Report 2021: Cross-Border Data Flows and Development (2021).










Comments


bottom of page