Several countries require certain data to be stored or processed within their borders. The requirement sounds like a filing rule and functions as an infrastructure mandate.
The stated purposes are varied
Governments cite access for law enforcement, protection from foreign surveillance, resilience against external disruption and the development of a domestic technology sector.
These are distinct objectives requiring different rules, and a single localisation requirement is often expected to serve all of them simultaneously.
Because the purposes differ, so does the scope: some rules cover only copies of records, others prohibit any transfer abroad at all.
Architecture is the real cost
Modern services distribute data across regions for redundancy and speed, and confining a dataset to one country removes both advantages.
Providers must run separate infrastructure per jurisdiction, replicate operational tooling and maintain distinct compliance processes, which multiplies fixed costs.
Large providers absorb this. Smaller ones frequently exit the market instead, which reduces competition in exactly the countries the rules were meant to benefit.
Security effects run in both directions
Keeping data locally can reduce exposure to foreign legal access and give domestic regulators clearer oversight of how it is handled.
It can also concentrate data in fewer facilities with less mature security practice, and it removes the geographic redundancy that protects against local disasters.
Which effect dominates depends on the domestic sector's capability, so identical rules produce different security outcomes in different countries.
Enforcement is technically awkward
Verifying where data physically resides is difficult, since services span providers, caches and backups that move automatically according to load.
Regulators generally rely on audits and attestations rather than direct observation, which shifts the burden onto documentation and contractual assurance.
Encryption complicates the picture further, since data stored abroad but decryptable only domestically satisfies some stated purposes while breaching a literal storage requirement.
Rules written before that distinction was common tend to be interpreted case by case, and the resulting uncertainty is itself a cost for firms trying to comply.
The rules interact badly across borders
A company operating in several countries can face requirements that conflict, where one jurisdiction demands local storage and another demands access to the same records.
Resolving these conflicts requires bilateral agreements on cross-border access, which exist for some jurisdictions and not for most.
Until such frameworks are broader, firms manage the conflict by fragmenting their systems, which is the outcome that both sets of regulators were trying to avoid.