Data localization laws, which require data to be stored within a country’s physical borders, are often promoted as a means to enhance cybersecurity. But do these laws actually improve cybersecurity outcomes? A new study by SIS Professors and Center for Security, Innovation, and New Technology (CSINT) co-directors William Akoto, Samantha Bradshaw, and Trey Herr compiles a global dataset of data localization laws and policies, using econometric analysis to compare cybersecurity performance between countries with and without such regulations.
Their findings indicate that data localization laws have no discernible effect on reducing the likelihood of cyber breaches. Countries that enforce data localization are just as vulnerable to data theft and disruptive cyberattacks as those that do not. These results have important implications for cybersecurity policy, especially given that data localization laws are frequently criticized for raising costs, hindering innovation, and restricting cross-border data flows without delivering clear security benefits.
Read the article here.