Xplore Publications
* Volume 3 of Transformations in Management is open for submissions until 30 August 2026. *

Chapter 89

Sovereignty in the Age of Servers Rethinking Power in Global Data Governance, PAPER Bhavya S

ISBN
978-81-992602-2-0
Published
21 July 2026
Accesses
2 views · 0 downloads
Reading time
~26 min

Full text

Sovereignty in the Age of Servers: Rethinking Power in Global Data Governance

AUTHOR: BHAVYA SRIVATSAN

CO AUTHOR: AAHANA RANKA

STUDENTS PURSUING BBA LLB AT SYMBIOSIS LAW SCHOOL HYDERABAD

Abstract

One of the key tensions in the domain of data governance is between digital sovereignty and globalization. With nation-states establishing data sovereignty through data localization measures, data protection laws, and internet sovereignty regulations, they create a major challenge to the very idea of a globally connected digital economy. This paper critically analyzes the concept of this tension, as well as its legal and political implications. By drawing on the literature on international law, domestic legislation, and judicial decision-making across different countries, this paper provides an overview of the evolving landscape of data governance. In doing so, it questions how different regulatory frameworks—illustrated by the EU's rights-centric approach, China's data localization regime, and India's Personal Data Protection law—can be viewed as products of competing ideologies of digital governance. The paper also considers the implications of such tensions for human rights, especially freedom of expression and the right to privacy, and for equity in access to digital information. It is argued that the tension between digital sovereignty and globalization cannot be resolved by advocating for either one of these two competing concepts. Rather, it calls for a hybrid solution based on interoperability, mutual recognition, and multilateralism.

Keywords: Digital Sovereignty, Data Governance, Globalization, Data Localization, Internet Fragmentation

1. Introduction

The digital revolution has changed the way of exercising state power. Once bounded by the physical limits of territory, information now travels a crossing the globe in milliseconds, defying traditional legal jurisdictions and complicating the sovereign prerogative to regulate. Thus, digital sovereignty as a legal principle and geopolitical strategy that represents the claim by a state to enforce authority over digital information generated, processed, or stored in a jurisdiction under its authority is a concept that has arisen in this new context.

Data the free movement of has therefore been incentivized by globalization at the same time. Multinational corporations need data to flow across borders to coordinate supply chains, financial services, and the running of digital platforms. Academic institutions and civil society organizations depend on unimpeded flows of information for research and advocacy. To these actors, ‘digital sovereignty’ claims are obstacles to an interconnected and efficient world.

The conflict between these two imperatives is not an issue of theory only. It takes the form of the Schrems litigation over transatlantic data transfers, China’s Great Firewall, Russian data localization laws, and Indian disputes over the Personal Data Protection Bill. States have asserted control over data by invoking sovereignty resulting in friction with the flow of information in the global space. In other words, freedom of movement of data has thus become necessary because of globalization as well. International businesses require the movement of data across international borders to synchronize their logistics operations, finances, and even their digital platforms. Research organizations and civil-society groups rely on the movement of information freely in order to conduct research work and activism. For these organizations, the notion of 'digital sovereignty' gets in the way of creating a connected world.

However, the tension that exists between these two goals is not merely theoretical in nature. It exists in real life through such legal disputes as the Schrems litigation involving cross-border movement of data, the Chinese firewall, Russian legislation on data localization, and Indian disagreements regarding the Personal Data Protection Bill. The concept of digital sovereignty by states has caused friction with the movement of information across international borders.A critical analysis of this conflict is conducted in this research paper. Next, theories are examined in order to provide deeper insights into the conflict between digital sovereignty and globalization. Following this, the topic of data governance is examined in order to identify the laws and policies involved in this issue, as well as to examine the effect of this conflict on human rights and equality on an international level.

2. Conceptual Framework

Digital Sovereignty

Sovereignty of any nation-state (or EU member state or the EU as a union) is understood as its ability to possess autonomous control over its digital properties (that may include elements such as bandwidth, hardware, software, data, among others) as well as over its virtual territories (such as individual data owned by organizations). Thus, Digital Sovereignty is seen as an indication of the degree of autonomy that one possesses over his/her digital self (the identity of the person as presented in the digital domain) as well as over the actual physical means used to access the digital realm (data centers, bandwidth, among others). Hence, Digital Sovereignty can be understood from numerous perspectives, including the perspective of legal theories, geography, politics, among others.

The concept entails several distinct but connected concerns: infrastructure sovereignty (control over physical networks and servers), data sovereignty (authority over data production and storage), algorithmic sovereignty (oversight of AI and automated decision-making), and cognitive sovereignty (shielding citizens from foreign informational influence). Drezner and Nocetti have noted the distinction between ‘cyber-sovereignty’, the authoritarian form of cybersovereignty as a means of political control, and ‘data sovereignty’, which is used in the democratic sense in reference to protection of privacy and economic interests.

The European Union has developed a distinctive definition of digital sovereignty based on its ‘technological sovereignty’ approach that stresses regulatory autonomy rather than internet fragmentation. It is meant to maintain internet connectivity, but with the understanding that the EU can determine conditions relating to data access and use. That is in contrast with the more autarkic models promoted by China and Russia.

Globalization

Globalization, in the digital context, is the process by which information, capital, services and infrastructure cross the boundaries of nation states to form an integrated global digital economy. The architecture of the internet (end-to-end connectivity, decentralization and protocol standardization), is globalization incarnate. Since the liberalization of the internet in the 1990s, commercial internet has been based on this minimal regulatory friction and the free flow of data.

Economic globalization is closely involved with data flows. The World Trade Organization’s e-commerce agenda, the OECD’s Guidelines on Multilateral Approaches to Cross-Border Data Flows, and bilateral trade agreements such as the USMCA (which prohibits data localization between its parties) are reflective of a regulatory philosophy that treats data flows as an economic activity that merits trade liberalization norms.

Critics of globalization argue that it’s not a neutral phenomenon, but rather one in which technologically developed countries (and their businesses) benefit from digitally colonizing developing nations through the extraction of data, thereby creating by the design of the global internet through which the process of digital colonization occurs. There is therefore an aspect of global justice involved; in addition to how global governance will be considered with respect to the relationship or impediment that exists between the sovereign state and the process of globalization.

3. Theoretical Perspective

There are a number of theories that help understand the interaction between digital sovereignty and globalization. The realist approach to international relations perceives data governance in terms of power struggles, whereby countries that control digital technology have the upper hand in the areas of intelligence gathering, economic advantage, and the setting of norms. Thus, the demand for data localization may be considered as the manifestation of structural power, meaning attempts by states to preserve the economic value of data domestically.

The liberal institutionalist approach, on the other hand, stresses the possibilities of cooperation in international affairs aimed at overcoming negative consequences of conflicting regulation of internet-related activities. Organizations such as the United Nations, Internet Governance Forum, the ITU, and the WTO serve as the structures where states could negotiate on the rules governing cross-border data flows that would be accepted by all. According to constructivist theory, norms, identity, and discourse matter when considering preferences for data governance. Norms, identity, and discourse are stressed as factors influencing preferences for data governance within constructivist approaches, where Europe’s data governance regime based on the continent’s historical commitment to human dignity and basic human rights differs fundamentally from that of security-based China’s Cybersecurity Law or of market-based United States. Such normative divergences are not a matter of technology, but of different perceptions regarding the relationships among the state, market, and individual.

It's Critical approaches highlight the imbalance of power in global data governance. Unequal distribution of server capacity, platform control, and standard setting, with most power held in the Global North, permits the extraction of data from the Global South without reciprocity. In this light, sovereignty assertions by developing nations can be interpreted as resistance against inequality as opposed to narrow nationalism

4. Data Governance

Broadly, data governance covers the frameworks, institutions, and processes of decision-making and enforcement concerning the collection, processing, storage, accessing, and transferring of data. Its levels of operation include: international (through treaties, intergovernmental organizations, and industry standards); regional (through supranational regulatory bodies such as the European Data Protection Board); national (through domestic legislation and regulatory agencies); and corporate (through internal data management policies and contractual arrangements).

The field has grown substantially in complexity over the past decade, driven by the datafication of economic and social life, the rise of artificial intelligence, and increasing awareness of the strategic and commercial value of data. From a regulatory standpoint, data governance covers decisions on what data may be collected and under which conditions, how it may be processed and by whom, where it should be stored, and how it may flow across jurisdictions.

Its governance is especially a contested matter. The rights-based model represented by GDPR, which requires a satisfactory level of rights in the receiving jurisdictions, the security-based model represented by China and Russia laws, which emphasize state access and national control, and the market-based model associated with the US mainly based on industry self-regulation, with sectoral regulations. Each model prioritises different values and produces different governance outcomes.

This includes adequacy decisions and standard contractual clauses that are fragile, as evidenced by the invalidation of successive EU-US data transfer frameworks on the Schrems.

5. The Conflict between Digital Sovereignty and Globalization

The relationship between digital sovereignty and globalization is a structural conflict rather than an accidental one. It results because the basic assumptions of each paradigms are mutually incompatible in some important ways. Sovereignty presupposes territorial authority, legal persons and the capacity to enforce obligations within a bounded jurisdiction. Globalization assumes the irrelevance of territorial boundaries in respect of information flows, networks that cannot be centralized, and transnational economic relations.

Data localization requirements are a good example of such structural conflict. Paragraph Context:

“Data localization requirements are a classic example of such a structural conflict – when the state imposes requirements that data relating to its citizens or data creation processes within its geographical boundaries are required to be stored within national boundaries, it imposes substantial compliance costs on multinational enterprises whose operating models rely on centralised or cloud-based data infrastructure.” (ibid). This is seen in the draft India’s Personal

Data Protection Bill at various stages of its development has proposed local storage of sensitive personal data – a provision that led to huge resistance from technology companies and their home states. Russia’s Federal Law No. 242-FZ also mandates that the personal data of Russian citizens must be stored within Russian territory.

Conflicts also occur in relation to government access demands. State authorities routinely demand that companies operating within their jurisdictions grant access to data that is stored abroad, hence creating extraterritorially enforcement tensions. The United States’ CLOUD Act attempts to address such conflicts through executive agreements but has been panned by civil liberties groups and foreign governments alike as an assertion of US extraterritorial jurisdiction over global data.

6. Legal and Policy Frameworks

International

Currently, there are no universal treaties that govern cross-border data flows. This area of international law is primarily composed of several interrelated, but conflicting, legal instruments. The OECD guidelines on the protection of privacy and transborder flows of personal data established a set of principles (1980, and revised 2013), including: limitation of data collection; quality of data; specification of purpose; security of personal data; and the participation by individuals according to these principles; however, they have no binding legal effect.

The Council of Europe’s Convention 108 (and its 2018 modernization, Convention 108+) is the only binding international treaty on data protection, but its jurisdiction applies only to its membership. The United Nations has legislated data governance through the work of Special Rapporteur on Privacy and General Assembly resolutions affirming the right to privacy in the digital age, but not binding norms on data flows.

Within the World Trade Organization, the General Agreement on Trade in Services (GATS) and its schedules provide a partial framework of e-commerce and data flows, with significant uncertainty on the extent to which data localization measures are disciplined by WTO rules. The Joint Statement Initiative on e-commerce in the WTO has not yet finalized an agreement on digital trade rules.

Regional frameworks in this regard, with the most notable examples being the USMCA’s digital trade chapter as well as the ASEAN Framework on Digital Data Governance, represent relatively advanced attempts at actualizing principles of data flow liberalization at the interregional level, albeit with somewhat contingent application on the member states’ implementation.

National

At the national level, data governance frameworks differ widely in terms of substantive content, enforcement mechanisms, and territorial scope. The European Union’s General Data Protection Regulation (GDPR), which came into effect in May 2018, is the most robust personal data regulatory framework. Given its extraterritorial reach over data management enterprises outside the EU community involving EU residents, it has become the global default data governance framework, with extensive regulatory spillovers.

Essentially, India's laws regarding the protection of private information were in flux until K.S. Data Protection Act, presently in effect, was enacted. The law, which has taken four years to draft and successfully pass through the legislature, creates the legal obligations of Data Fiducians and establishes the Data Protection Board to oversee them. Critics have noted many exemptions for Government Agencies' use of Data, during the aforementioned period when there was no Data Protection Law, along with limited enforcement capabilities.

In the world of Data Governance, China is arguably the most aggressive. The three laws: Cyber Security Law of 2017; Data Security Law of 2021; Personal Information Protection Law of 2021 provide a comprehensive framework for governance and access to state-owned or federally controlled data, with a significant emphasis on National Security and data localization. The Cyber Space Administration of China has an extensive mandate to supervise Data Governance, while Critical Data transported outside of China will be subject to assessment for security before being transferred.

The United States, having no all-encompassing federal privacy law, depends on a sectoral approach (HIPAA for health data, GLBA for financial data, COPPA for data on children) supplemented by state legislations, predominantly the California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA). This reflects the US historically market-oriented regulatory philosophy, although rising concerns about national security and control of Chinese technology platforms have created legislative pressure for more aggressive data sovereignty policies.

7. Case Laws

Numerous judicial and quasi – judicial decisions regarding data governance conflict have produced a substantial list of cases that exemplify the difficulties involved with managing digital sovereignty as a result of globalization. Several of these landmark decision warrant close scrutiny.

The first landmark decision was issued in Maximillian Schrems v. Data Protection Commissioner, when the court of justice of the European Union invalidated the EU-US Safe Harbour framework determining that US requirements for surveillance did not afford sufficient data protection to citizens living in Europe. As part of this ruling, the court clarified that a judgement as to whether a country offered adequate data protection must reflect the actual protection provided in that country as opposed to just verification the country provided formal protection through law.

Subsequently, in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems, the court invalidated the successor to the Safe Harbour framework called the Privacy Shield framework because the US intelligence agencies had too much access to data that was sent to the US and that there was not sufficient judicial supervision over these agencies regarding their use of the data. These two rulings above have brought unstable environment for data exchange across the Atlantic, resulting in the development of the EU-US Data Privacy Framework (2023), which is now facing its own legal challenges.

In the case referred to as Google Spain SL and Google Inc. v.Agencia Española de Protección de Datos, Mario Costeja González, the Court of Justice of the European Union (CJEI) recognized the right to de-index (often referred to as the right to be forgotten) as part of EU data protection law. This decision raised a number of key issues regarding how far the territorial reach for data protection obligations is. These territorial questions were addressed at a later point by the court in Google LLC v. Commission nationale de l'informatique et des libertés (CNIL), when the court concluded that EU law does not require global de-referencing but it also does not prohibit it thereby leaving remaining room for there to be broader application of the territorial reach of data protection.

In the U.S., the case of United States v. Microsoft Corporation (2018) presented the issue of whether US law enforcement agencies can compel an American corporation to produce data that is on a server in Ireland. Although the case was rendered moot after the enforcement of the CLOUD Act, it served as an impetus for discussion among the international community regarding the ability of governments to access data that is located around the world and the limitations placed by state law over globally distributed data.

K.S Puttaswamy (Retd.) and Anr. v. Union of India and Ors, (2017) is a landmark ruling from India’s Supreme Court addressing the constitutional right to data protection and privacy. Privacy right being declared a Fundamental Right under Article 21 of the Indian Constitution through the verdict passed by the nine judges in unison forms the normative foundation for formulating laws in its entirety and will keep dictating the interpretation of state powers to conduct surveillance.

The European Court of Human Rights in Big Brother Watch and Others v. United Kingdom, considered whether the bulk interception of communications across periods of time system used by the UK government is compliant with the rights protected under Article 8 (right to respect for private and family life) and Article 10 (right to freedom of expression) of the European Convention on Human Rights. The European Court’s holding of the human rights implications of the purposes and manner of the UK’s electronic data collection process rests upon the concept of and enforcement of the sovereignty of States under in e-world, which has limitations based on the obligations of States under the European Convention on Human Rights.

8. Impact on Human Rights and Global Equity

Digital sovereignty and globalization will significantly influence how the realization of human rights and the distribution of the digital economy’s benefits occur. The impact of these two poles of this conflict is not evenly distributed but instead impacts disadvantaged groups and developing countries particularly heavily, as well as those living in places with authoritarian governments.

These are risks to human rights associated with both digital sovereignty and unrestricted globalization of data. Claims of sovereignty can be used to justify censorship, mass electronic surveillance and the repression of dissenting political opinion. Examples of this include China’s “Great Firewall”; Russia’s “Sovereignty Internet”; and Iran’s “National Information Network”; each instance, rhetoric about sovereignty has been used to conceal what is effectively a political control agenda disguised as protecting citizen’s rights.

As global data flows increase, technology companies will be able to rapidly accumulate large amounts (also known as extracting) personal data from users. This, combined with a lack of safeguards protecting users in poorly regulated markets, alerts us to a growing concern surrounding data colonialism, where corporations from developed countries collect behavioral, demographical and economic data on people living in less- developed areas. Information collected from less developed areas can raise equity issues; impact the consent given by individuals; and commodify personal.

Privacy is considered one of the fundamental rights of human beings that has been mentioned in several international instructions such as Article 12 of the Universal Declaration of Human Rights and Article 17 of the International Covenant on Civil and Political Rights. It is also included in the constitutions of many nations. Both as assertion of sovereignty through surveillance and unregulated commercial processing of personal information can violate your right to privacy. The UN Special Rapporteur on Privacy noted that mass surveillance can have a “chilling” effect on freedom of expressions and association and has raised serious concerns about the systemic impact of the digitalization of state power on international human rights.

The issue of global equity is at the forefront of discussions about internet governance and the digital divide. As developing countries do not have the technology to govern their digital industries or to participate in rule- making at a level that would result in equitable representation of all countries, they will be hindered from participating fully in a processes designed to establish norms for the global digital order. Rule-making authority over global internet governance has been concentrated among a few actors – primarily US and European actors who are responsible for creating the governing documents used by organizations like ICANN, the Internet Engineering Task Force, and the W3C; therefore, the rules surrounding global internet governance reflect the interests of incumbent powers instead of representing all voices on Earth.

9. Challenges in Balancing Sovereignty and Globalization

One of the most difficult things for government to do today is to find a sustainable balance between digital sovereignty and the forces of globalization. There are many structural and political factors working against achieving this lasting goal.

One of these factors is the continued fragmentation of the internet worldwide. As governments invest their resources into building up their own national digital infrastructure and requiring that their information reside only in their country, they increase the technical and economic costs associated with restoring a unified global internet. Fragmentation also leads to a loss of economic efficiency and to the breakdown of the collaborative norms that constitute the basis of internet governance institutions.

Secondly, as countries develop their own rules concerning data sovereignty, multinational companies are finding it difficult to comply with regulatory requirements because of the differences in national regulations. This leads companies to attempt to avoid meeting certain requirements of different countries strategically utilizing the difference in national laws to their advantage (i.e., regulatory arbitration). Since there are no mutual recognition agreements or harmonized standards between the countries, companies are forced to deal with different regulatory requirements across six continents which leads to companies being incentivized to “forum shop” as opposed to genuinely protecting consumer data.

Thirdly, since laws related to national security are not governed by the same principles or rules as consumer protection laws, it is typically difficult to assess national security justifications for data storage, current removal and government access to data, making it difficult to differentiate between legitimate security requirements and the need to protect a country’s economy or to engage in protectionist pursuits. The lack of transparency in national security laws complicates and inhibits trust-based multilateral negotiations.

Fourthly, the interest of large, established tech companies drive the political context around how data will be governed, as they continuously lobby against localizing data and any legislations that would restrict how companies can generate revenue from user data. The development of industry-led policies that serve to limit government intervention in their operations leads to an outcome that may not ultimately serve the best interests of society (including developing countries, which do not have the same regulatory framework or capability as the EU has).

Fifth, as the pace of technology continues to increase more rapidly than the ability of existing laws and regulations to keep pace, new forms of technology such as artificial intelligence, edge computing, federated data architecture and quantum communications are developing even as existing governance structures for these types of technology are still being finalized. The lag between the legal and regulatory environment and the pace at which these innovations occur is a permanent feature of how data will be governed and must be accounted for by both sovereignty supporters and globalists.

10. The Way Forward

This paper argues that; neither complete digital sovereignty nor unlimited global data transfer can provide a sustainable solution for how we govern the digital space. We must create a principled approach that takes into account both sides of the argument, and build governing rules that eliminate the potential of either side to abuse their power.

A hybrid model of governance based on interoperable systems and mutual recognition is likely to be the best way forward. This will allow countries to maintain their own laws governing the data created within their broader, but provide a way for them to agree on minimum requirements for data privacy, security and access when transferring data across national borders. The EU-US Data Privacy Framework is not only a proposed treaty between the EU and the US; it is an example of how best to put this principle into action. The way it has been drafted offers both good examples and bad lessons for future multilateral agreements.

Multilateral treaties can provide a mechanism for establishing legally binding norms on cross-border data governance, (i.e., under the auspices of the UN or ISO or the WTO). Multilateral treaty negotiations are complex and marred by geopolitical competition. However, the other alternative a permanently fractured global system of data governance, will impose a substantial cost on global welfare. Convention 180+, the Council of Europe’s convention on the protection of individuals with regard to automatic processing of personal data, is an example of a model whereby a right based international instrument could be created and subsequently broadened via additional state members or adapting the instrument to fit the needs of specific groups of countries.

Technical assistance, technology transfer and the inclusion (via national representation) of developing country representatives in international and regional organizations involved in establishing internationally recognized technical standards are all intertwined and critical elements for ensuring that global practices/technology are representative of the global community’s collective interests, not merely those of the dominant members of the international community.

At the national level, states are encouraged to exercise restraint when deploying digital sovereignty rhetoric as a cover for political control. However, for sovereignty claims in cyberspace to be legitimate, they have to be in line with the tenants of human rights, as well as proportional to the interests that involve issues of security and privacy. Independent regulators with proper oversight systems and judicial reviews are essential for ensuring that the issue of sovereignty is not used to exploit others. Private industry also shoulders significant roles in balancing sovereignty with globalization.

Technology companies should move away from a model of regulatory arbitrage and minimal compliance, and genuinely engage with the public interest. Privacy – by – design, strong encryption, data minimization and transparent reporting on government requests for access to information are all concrete steps that can help build trust for effective long term data governance.

11. Conclusion

There is no straightforward answer to the issue of data governance’s clash between digital sovereignty and globalization. The two opposing forces create immense disparities between the state system’s territorial framework and the transnational of the digital network; between what governments require to safeguard their citizen’s rights, protect a country’s privacy and create prosperity; and finally, between what global commercial entities need for improved efficiency and what global justice campaigns advocate for in terms of equal opportunity.

This paper examines this conflict by investigating the core concepts involved, the theoretical aspects as identified in the literature, various governing entities legal and policy approached and how this conflict affects human rights and overall global policy equity. The findings suggest that there are multiple issues including an inconsistent and fragmented global governance framework, and an unequal distribution of power among those most at risk especially individuals subject to authoritarian governments or living in countries without access to adequate amounts of data, in trying to find a resolution to this conflict.

The way forward will require political will, creativity in our institutions and the true commitment to sovereignty and solidarity. Digital Sovereignty as most people should know, is not in opposition to global connectivity; it’s a component for building trust and creating sustained global cooperation. Globalization, when governed approximately is not in opposition to Sovereignty; this provides the context in which Sovereign States can work together to address cross-boundary consequences of their digital actions.

The rules governing the digital domain will lay the foundations for the international order for a long period to come. To satisfy this challenge requires developing new frameworks that states, individuals, and the private sector use in negotiating their respective rights and obligations in a digitally integrated world

References

Aaronson, Susan Ariel. 'Data Is Different: Why the World Needs a New Approach to Governing Cross-Border Data Flows.' 12 Digital Policy, Regulation and Governance 159 (2018).

Chander, Anupam, and Uyên P. Lê. 'Data Nationalism.' 64 Emory Law Journal 677 (2015).

Council of Europe. Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data (ETS No. 108), Jan. 28, 1981.

Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Schrems II), Case C-311/18, ECLI:EU:C:2020:559 (CJEU, July 16, 2020).

Drezner, Daniel W. 'The Global Governance of the Internet: Bringing the State Back In.' 119 Political Science Quarterly 477 (2004).

European Parliament and Council Regulation 2016/679 of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data (General Data Protection Regulation) [2016] OJ L 119/1.

Google LLC v. Commission nationale de l'informatique et des libertés (CNIL), Case C-507/17, ECLI:EU:C:2019:772 (CJEU, Sept. 24, 2019).

Google Spain SL, Google Inc. v. Agencia Española de Protección de Datos (AEPD), Mario Costeja González, Case C-131/12, ECLI:EU:C:2014:317 (CJEU, May 13, 2014).

India. Digital Personal Data Protection Act, 2023, No. 22 of 2023.

K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors., (2017) 10 SCC 1 (India).

Kuner, Christopher. Transborder Data Flows and Data Privacy Law. Oxford: Oxford University Press, 2013.

Maximillian Schrems v. Data Protection Commissioner, Case C-362/14, ECLI:EU:C:2015:650 (CJEU, Oct. 6, 2015).

Milanovic, Marko. 'Human Rights Treaties and Foreign Surveillance: Privacy in the Digital Age.' 56 Harvard International Law Journal 81 (2015).

OECD. Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (2013 Revision). Paris: OECD Publishing, 2013.

People's Republic of China. Cybersecurity Law of the People's Republic of China, promulgated Nov. 7, 2016, effective June 1, 2017.

People's Republic of China. Personal Information Protection Law of the People's Republic of China, promulgated Aug. 20, 2021, effective Nov. 1, 2021.

Raustiala, Kal. 'The Geography of Justice.' 73 Fordham Law Review 2501 (2005).

Rozenshtein, Alan Z. 'Surveillance Intermediaries.' 70 Stanford Law Review 99 (2018).

United Nations General Assembly Resolution 68/167, The Right to Privacy in the Digital Age, UN Doc. A/RES/68/167 (Dec. 18, 2013).

United States-Mexico-Canada Agreement (USMCA), Nov. 30, 2018, ch. 19 (Digital Trade).

Woodrow Wilson International Center for Scholars. 'Digital Sovereignty: The Fight Over the Future of the Internet.' Washington, D.C.: Wilson Center, 2020.

Zuboff, Shoshana. The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. New York: PublicAffairs, 2019.

Get an email when we publish new research and open calls for chapters.

Create a free account