Trust, Ethics & Regulation · established evidence

The Splinternet: Data Localization and the Price of Digital Borders

Last reviewed 2026-08-11. Written by Chandranshu Kumar, Founder, Raveneye Global. · 10 min read

For the internet's first two decades, data moved the way a wire transfer moves money: instantly, and mostly without asking where it landed. That free flow built the global data economy, the modern cloud, and platforms that served a billion users from a handful of data centers. Since the mid-2010s, governments have reversed that assumption. Dozens of countries now require that data about their own citizens be stored and processed inside national borders, treating data the way earlier states treated currency or spectrum: a resource whose movement a state has the right to control. Russia's 2015 localization law forced LinkedIn offline nationally within a day of a court ruling. The European Union's 2023 record fine against Meta showed that a single privacy ruling can move over a billion euros. Together the two cases mark a turn: the open, borderless internet that carried the world's data traffic for a generation has fractured into a patchwork of national data markets, often called the splinternet, in which the physical location of a server is now a matter of state power.

The open internet's original bargain

The commercial internet of the 1990s and 2000s was built on an assumption that now looks almost naive: that data, once digitized, did not really belong anywhere. A company in California could store a customer record on a server in Virginia, process it in Ireland, and serve an answer to a user in Mumbai, and for most of two decades almost no law asked it to do otherwise. That single assumption, the frictionless movement of data across borders, is what let a handful of American and later Chinese platforms scale to billions of users at a marginal cost per additional customer that kept falling toward zero. Cloud computing, global advertising markets, and cross-border e-commerce all depend on the same premise: that a byte generated in one country can be stored, analyzed, and monetized in another.

That premise was never universal. Authoritarian states worried from early on about a communications system they did not control running through infrastructure owned by foreign companies. But for most of the internet's commercial history, the economics of open data flow won the argument. A 2014 law out of Moscow, and a series of rulings out of Luxembourg and Dublin a decade later, are the moment the argument reopened, and the moment a state's claim to data generated within its borders started to carry real financial and legal weight.

The term now used for the result, the splinternet, describes an internet that still functions as a single technical network but no longer functions as a single economic or legal one. Data localization law is the primary instrument doing the splintering. It rests on a related but distinct idea, data sovereignty: the principle that data is subject to the laws of the nation in which it was collected, according to the general legal literature on the subject. Localization goes a step further than sovereignty by specifying where the servers themselves must physically sit, typically requiring that initial collection, processing, and storage occur inside the country before any international transfer is permitted.

By the early 2010s the economics built on that free flow were substantial in scale, even if a single aggregate figure for them remains disputed among analysts. Global cloud computing, transnational advertising exchanges, and cross-border payment processing were all built assuming a company could site its infrastructure wherever electricity, connectivity, and labor were cheapest, then serve every market from that one location. Data-localization law does more than add a compliance line item to that model. It removes the assumption the model was built on, requiring separate infrastructure, separate legal review, and in some cases a separate corporate entity for every jurisdiction that draws its own line.

Russia draws the first hard line

The law that is usually cited as the opening move of the localization era is Russian Federal Law No. 242 FZ. President Vladimir Putin signed it on 21 July 2014, and it took effect on 1 September 2015, requiring every company that processes the personal data of Russian citizens to store and process that data on servers physically located inside Russia, according to Stanford's World Intermediary Liability Map. The law gave Russia's media and communications regulator, Roskomnadzor, direct authority to block online access to any company found in breach.

The law sat mostly unenforced against major foreign platforms for a year, until Roskomnadzor turned it on LinkedIn. A Moscow court ruled in November 2016 that LinkedIn had failed to comply with the localization requirement, and Roskomnadzor blocked the platform nationwide within 24 hours of that ruling, according to reporting from the National Law Review. It was the first time Russia had blocked a foreign online business specifically for violating the data-localization law, and it was not a minor platform: LinkedIn had more than 5 million registered users in Russia at the time. A company built to connect professional networks across borders was, in a single regulatory action, made unreachable inside one of the world's largest national markets.

The economic logic of the block is the part that outlasted the headline. LinkedIn did not lose a foreign subsidiary or a supply contract. It lost access to a national market of millions of registered users over a decision about where a database physically sat, a cost with nothing to do with the quality of its product or the price of its service. That is the economic thread that runs through every localization law that followed: a state converted control over physical infrastructure into direct power over a company's revenue, without needing to touch the company's balance sheet, ownership, or product at all.

The mechanism generalizes far beyond one platform. Any company that stores Russian user data abroad, and does not build local servers to comply, carries the same exposure LinkedIn discovered in 2016: the difference between operating in a market of tens of millions of internet users and being cut off from it can rest on a single infrastructure decision, enforced by a regulator rather than negotiated by a competitor.

Europe turns privacy into a matter of sovereignty

The European Union took a different legal route to a similar destination. Rather than mandating that data physically stay inside EU borders in every case, EU law permits data to leave the bloc only when the receiving country, or a specific legal mechanism, offers protection judged equivalent to European standards. For years, the mechanism governing data transfers between the EU and the United States was a framework called Privacy Shield.

In July 2020, the Court of Justice of the European Union struck that framework down. The ruling, widely known as Schrems II after the Austrian privacy campaigner Max Schrems who brought the case, invalidated the EU-US Privacy Shield on the grounds that it did not adequately protect Europeans' data from access by US government surveillance programs, according to legal analysis from Faegre Drinker and Hunton Andrews Kurth. The ruling reached well past one invalidated legal document. It forced years of transatlantic negotiation over a legal successor arrangement, and in the interim it left thousands of companies moving personal data across the Atlantic on a legal foundation the EU's highest court had just called unsound. Where a server sat, and whose intelligence agencies could reach it, had become a first order question in relations between two allied economic blocs.

The consequence of that unresolved question landed on Meta in 2023. On 22 May of that year, Ireland's Data Protection Commission, the lead EU regulator for Meta's European operations, fined Meta Ireland 1.2 billion euros for continuing to transfer European users' personal data to the United States in violation of the Schrems II ruling, according to Hunton Andrews Kurth's Privacy and Cybersecurity Law Blog. It was the largest fine in the history of the General Data Protection Regulation, surpassing the previous record of 746 million euros levied against Amazon. The regulator did not stop at the fine. It ordered Meta to suspend the unlawful transfers within five months. A single national regulator, acting under a EU wide law, had moved more than a billion dollars and forced one of the world's largest technology companies to restructure how it moved data across an ocean.

Read together, the Russian and European cases carry the same lesson from opposite political systems. An authoritarian state used localization law to remove a company from its market inside a day. A democratic bloc used privacy law to extract a record fine and force a change in data architecture inside months. Both moves treated the physical and legal location of data as a lever a government could pull, not a technical detail a company could quietly manage.

The pattern spreads beyond Russia and Europe

Neither Russia nor the EU is an outlier any longer. China built its own localization and cross-border transfer regime on top of its 2017 Cybersecurity Law and the 2021 Personal Information Protection Law, generally referred to as PIPL, which requires security assessments before data collected by what the law calls critical information infrastructure operators can be sent outside the country, based on the general comparative record of data-localization law. The category is broad enough to sweep in most large platforms, banks, and telecommunications providers operating in the Chinese market.

India took a lighter-touch route with its own Digital Personal Data Protection Act, passed in 2023. The law stops short of a blanket requirement that data stay inside the country. Instead it gives the central government the power to restrict cross-border transfers to specific countries it designates, a mechanism sometimes described as a blacklist model, based on the general provisions of the DPDPA. It is a narrower instrument than Russia's outright localization mandate or China's assessment regime, but it rests on the same underlying claim: the state that governs the citizens whose data is generated gets a say in where that data is allowed to travel.

The cumulative effect is a regulatory map that no longer resembles a single internet. A company operating across Russia, the European Union, China, and India today is not managing one data policy with local variations. It is managing four structurally different legal regimes, each backed by its own enforcement authority, its own definitions of what counts as sensitive data, and its own penalty for getting the location wrong.

For a multinational business, the practical result of four or more independently enforced regimes is duplication. A company already storing data locally in Russia to satisfy 242 FZ, running a separate review for any data leaving China under PIPL, and monitoring India's list of restricted destination countries under the DPDPA, is not applying one privacy policy with local footnotes. It is running parallel infrastructure and separate legal review for each government that asserts a claim over where its citizens' data can travel, a cost that shows up on a balance sheet long before any regulator issues a fine.

What the border buys, and what it costs

Every localization law makes the same trade, and the trade genuinely runs both directions. On one side, forcing data to sit inside a country's borders gives that country's courts, regulators, and law enforcement real jurisdiction over it, jurisdiction that a foreign-hosted database can be difficult or impossible to compel. It also, in principle, narrows the paths by which a foreign intelligence service can reach a citizen's data without going through that citizen's own government first, which was the precise concern the Schrems II court raised about US surveillance access to European data.

On the other side, the same law concentrates power over that data in the hands of whichever government now hosts it. A Russian court that can order LinkedIn blocked in a day can, in principle, order a domestic company's locally stored data disclosed just as fast, without the friction of a cross-border legal request. Data localization protects citizens from a foreign government's reach and simultaneously widens their own government's reach over the same records. The Schrems saga makes the same point from the European side: the ruling protected Europeans from American surveillance, but it also handed the Irish regulator, and by extension EU institutions, sole practical authority over how a company as large as Meta could move data at all.

That double edge is why data localization resists a simple verdict of good policy or bad policy. It liberates a national government from dependence on foreign infrastructure and foreign legal process. It concentrates control over a citizen's digital life inside a single national jurisdiction with less external check than a globally distributed system provided. Both things are true of the same law, often in the same clause.

Businesses have adapted the way markets typically adapt to a fixed cost: by building the local infrastructure the law demands. A local data center satisfies a localization requirement the way a local warehouse once satisfied an import tariff, at the cost of duplicating capacity that a single global facility used to handle for every market at once. A company that builds it converts a legal risk into a fixed cost it can plan around. A company that does not risks the outcome LinkedIn met in 2016: a court date, then a block.

What the evidence does not yet settle

None of this should be read as an argument that localization is uniformly protective or uniformly costly. A hospital network keeping patient records inside the country that regulates its hospitals is a different case from a state blocking a professional network over an unrelated dispute, even though both fall under the same legal category on paper. The evidence gathered here supports the pattern and the mechanism; it does not support treating every localization law as economically or politically equivalent to every other one.

The economic cost of this fracturing at a global scale is genuinely disputed, and it belongs in a different tier from the dated cases above. Industry-funded studies, often produced by cloud providers with a commercial interest in unrestricted data flow, and independent academic estimates of the aggregate cost of localization mandates, counting lost cloud-efficiency gains, duplicated data-center investment, and added compliance overhead, vary widely and are entangled with other regulatory and market changes happening at the same time. No single, agreed figure for the global cost of the splinternet currently exists, and any number presented as settled should be read with that caveat attached.

What is not disputed is the direction of the pattern and the size of the cases that mark it. A law signed in Moscow in 2014 removed a five-million-user platform from a national market within a day of a court order two years later. A ruling from Europe's highest court in 2020 unwound a transatlantic data agreement and, three years on, produced the largest privacy fine in the law's history. China and India have each built their own version of the same instrument since. The question of where a server physically sits, once a detail left to an engineering team, is now decided in courtrooms and carries a price tag with nine or ten figures attached.

That question has not stayed confined to social networks and cloud storage. As AI systems trained and hosted in one jurisdiction are asked to answer questions about businesses and people in another, the same border logic is starting to apply to where a model runs, what data it was trained on, and which national rules govern the answer it gives. A business's visibility to an AI system, like its visibility to a national regulator a decade earlier, increasingly depends on facts about infrastructure the business itself may never have thought to examine.

The evidence

Key findings, with their sources

  • Russia's Federal Law No. 242 FZ, signed 21 July 2014 and effective 1 September 2015, requires all companies processing the personal data of Russian citizens to store and process it on servers physically located inside Russia.

    established Stanford World Intermediary Liability Map (wilmap), "Federal Law No. 242-FZ."

  • Russia's regulator Roskomnadzor blocked LinkedIn nationwide within 24 hours of a November 2016 Moscow court ruling, the first time Russia blocked a foreign platform specifically for a data-localization violation; LinkedIn had over 5 million registered users in Russia at the time.

    established National Law Review / Zwillgen, "LinkedIn Blocked in Russia Following Breach of Data Localization Laws" (2016-2017).

  • The Court of Justice of the European Union's July 2020 Schrems II ruling invalidated the EU-US Privacy Shield data-transfer framework, citing insufficient protection against US government surveillance access to Europeans' data.

    established Faegre Drinker and Hunton Andrews Kurth legal analyses (2023).

  • On 22 May 2023, Ireland's Data Protection Commission fined Meta Ireland 1.2 billion euros, a record GDPR penalty surpassing the prior record of 746 million euros against Amazon, for unlawful EU-to-US data transfers, and ordered Meta to suspend those transfers within five months.

    established Hunton Andrews Kurth Privacy and Cybersecurity Law Blog, "Irish Regulator Fines Meta 1.2 Billion Euros" (May 2023).

  • Data localization builds on the related but distinct concept of data sovereignty, the principle that data is governed by the laws of the nation in which it was collected, and typically requires initial collection and processing to occur inside national borders before any international transfer.

    established Wikipedia, "Data localization."

  • China operates its own localization and cross-border transfer regime under the 2017 Cybersecurity Law and the 2021 Personal Information Protection Law, requiring security assessments for cross-border transfers of data collected by designated critical information infrastructure operators.

    established General comparative record cited in data-localization legal literature.

  • India's 2023 Digital Personal Data Protection Act stops short of blanket localization but gives the central government the power to restrict cross-border data transfers to specific countries it designates, a lighter-touch variant of the Russian and Chinese models.

    established General provisions of the Digital Personal Data Protection Act, 2023.

  • Estimates of the aggregate global economic cost of data-localization mandates, including lost cloud-efficiency gains and duplicated data-center investment, vary widely between industry and independent academic studies and are not treated as settled.

    contested Divergent cloud-industry and independent-economist estimates (comparative literature).

Calibration

What is proven, what is promising, what is unproven

Evidence tierTacticsWhat the evidence says
establishedThat data-localization law has proliferated since the mid-2010s, and the two dated, sourced cases that mark its arrival: Russia's 242 FZ and the LinkedIn block, and the EU's Schrems II ruling and the record Meta fine.Each event carries a specific date, a named regulator or court, and a figure corroborated by independent legal reporting (Stanford wilmap, National Law Review, Faegre Drinker, Hunton Andrews Kurth).
emergingThat China's and India's newer regimes represent a widening, more varied second wave of localization law rather than a settled global standard.Grounded in the general provisions of PIPL and the DPDPA, but not yet the subject of an independent comparative census tracking enforcement outcomes the way the Russian and EU cases have been tracked.
contestedThe claim that localization carries a specific, quantifiable aggregate cost to the global economy.Industry-funded and independent academic estimates diverge widely and are entangled with other simultaneous regulatory and market shifts, so no single figure is treated as established.

Reference

Glossary

Data localization
A legal requirement that data about a country's residents be stored and, in the strictest versions, processed on servers physically located inside that country before any transfer abroad is permitted.
Data sovereignty
The broader principle that data is subject to the laws of the nation in which it was collected, whether or not that nation also requires the data to be physically stored within its borders.
Privacy Shield
The EU-US legal framework that governed transatlantic personal-data transfers until the Court of Justice of the European Union invalidated it in the 2020 Schrems II ruling.
Critical information infrastructure operator
A designation under Chinese law for organizations, including major platforms, banks, and telecommunications providers, whose cross-border data transfers require a government security assessment.
The splinternet
A description of the internet as it now functions: one technical network still connecting the world, but split by law into separate national and regional data markets with different rules for storage, transfer, and access.

Straight answers

Frequently asked questions

What is data localization, and how does it differ from data sovereignty?

Data sovereignty is the principle that data is governed by the laws of the country where it was collected. Data localization is a stricter, more specific requirement built on that principle: that the data must physically be stored and processed inside that country's borders before it can be transferred anywhere else.

Why did Russia block LinkedIn?

Russia's Federal Law No. 242 FZ, effective from 1 September 2015, requires companies to store Russian citizens' personal data inside Russia. LinkedIn did not comply, a Moscow court ruled against it in November 2016, and the regulator Roskomnadzor blocked the platform nationwide within 24 hours of that ruling, removing a service with over 5 million registered Russian users from the market.

What was the Schrems II ruling and why does it matter?

Schrems II was a July 2020 ruling by the Court of Justice of the European Union that invalidated the EU-US Privacy Shield framework, the main legal mechanism for transferring personal data from the EU to the United States, over concerns that US surveillance law did not offer Europeans adequate protection. It forced years of renegotiation and left many transatlantic data transfers on uncertain legal footing.

How large was the EU's fine against Meta, and why was it issued?

Ireland's Data Protection Commission fined Meta Ireland 1.2 billion euros on 22 May 2023, the largest fine in GDPR history, for continuing to transfer EU users' data to the United States after the Schrems II ruling had found the legal basis for those transfers inadequate. The regulator also ordered Meta to suspend the transfers within five months.

Is data localization only a Russian and European issue?

No. China built its own regime under the 2017 Cybersecurity Law and the 2021 Personal Information Protection Law, and India's 2023 Digital Personal Data Protection Act allows the government to restrict transfers to specific designated countries. Dozens of governments now operate some version of a localization or cross-border transfer rule.

Provenance

Sources

  1. Stanford World Intermediary Liability Map (wilmap), "Federal Law No. 242-FZ."wilmap.stanford.edu
  2. National Law Review / Zwillgen, "LinkedIn Blocked in Russia Following Breach of Data Localization Laws" (2016-2017).natlawreview.com
  3. Faegre Drinker, legal analysis of Schrems II and the Meta GDPR fine (2023).faegredrinker.com
  4. Hunton Andrews Kurth Privacy and Cybersecurity Law Blog, "Irish Regulator Fines Meta 1.2 Billion Euros and Orders It to Cease Data Transfers to the U.S." (May 2023).hunton.com
  5. Wikipedia, "Data localization."en.wikipedia.org
  6. Lexology and Inside Privacy, legal analyses of Roskomnadzor's enforcement authority under Federal Law 242-FZ (2016).
  7. General comparative legal record on China's 2017 Cybersecurity Law and 2021 Personal Information Protection Law (PIPL).
  8. General regulatory record on India's Digital Personal Data Protection Act, 2023.
  9. Comparative industry and academic literature on the estimated economic cost of data-localization mandates.

Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.

About this analysis

This is part of Raveneye's research on how the control of information shapes economies and power, from printing presses to AI answer engines. Data localization decided which government could reach a company's servers. The same question of where data sits and who can read it now shapes which AI systems can find, evaluate, and represent a business at all, which is what we measure as machine readiness.

diagnostic Surface Intelligence Audit A measured read of where a business stands across the surfaces buyers and AI systems now use to find, evaluate, and choose it. See how it works

Start with a free Machine-Readiness Score, a specialist-reviewed read of where a business stands across search and AI answers. No guaranteed number, and no obligation.