Help us improve
Share bugs, ideas, or general feedback.
Guides compliance with data localization laws in Russia (242-FZ), China (PIPL Art. 40), India (DPDP Act), Turkey, Vietnam, Indonesia. Covers assessment, architecture design, exemptions.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeHow this skill is triggered — by the user, by Claude, or both
Slash command
/privacy-skills-complete:data-localizationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Data localization laws require that personal data of a country's residents be stored, processed, or both within the territory of that country. These requirements exist independently of and in addition to transfer mechanism requirements under the GDPR. Organisations operating globally must map their data localization obligations by jurisdiction, design infrastructure architectures that comply wi...
Guides compliance with data localization laws in Russia (242-FZ), China (PIPL Art. 40), India (DPDP Act), Turkey, Vietnam, Indonesia. Covers assessment, architecture design, exemptions.
Guides Transfer Impact Assessments for GDPR data transfers to third countries using EDPB Recommendations 01/2020 six-step methodology. Evaluates surveillance laws, essential guarantees, and supplementary measures.
Navigates GDPR and CCPA privacy regulations, reviews DPAs, and handles data subject requests. Useful for compliance assessments, vendor agreements, cross-border transfers, and DSAR responses.
Share bugs, ideas, or general feedback.
Data localization laws require that personal data of a country's residents be stored, processed, or both within the territory of that country. These requirements exist independently of and in addition to transfer mechanism requirements under the GDPR. Organisations operating globally must map their data localization obligations by jurisdiction, design infrastructure architectures that comply with local storage mandates, and implement exemption procedures where cross-border transfer is permitted subject to conditions.
Effective: 1 September 2015
Key requirements:
Enforcement:
Athena Global Logistics implementation:
Personal Information Protection Law (PIPL) — Effective 1 November 2021
Key requirements:
Athena Global Logistics implementation:
Effective: Provisions being brought into force in phases from 2024.
Key requirements:
Athena Global Logistics implementation:
Key requirements:
Effective: 1 July 2023
Key requirements:
Key requirements:
┌───────────────────┐ Replication ┌──────────────────┐
│ Local Data Centre │ ─────────────────→ │ Central EU DC │
│ (Country Required) │ (encrypted, │ (Frankfurt) │
│ Primary database │ compliant │ Analytics, │
│ All CRUD operations│ transfer) │ Reporting │
└───────────────────┘ └──────────────────┘
Use case: Russia (242-FZ), China (PIPL Art. 40 for CIIOs) Implementation: All create, read, update, delete operations occur on the local database. Encrypted replication to central EU systems for analytics and group reporting, subject to local cross-border transfer rules.
┌───────────────────┐ Aggregated/ ┌──────────────────┐
│ Local Instance │ Anonymised │ Central EU DC │
│ Full processing │ ─────────────────→ │ Only aggregated │
│ in-country │ │ or anonymised │
└───────────────────┘ │ data received │
└──────────────────┘
Use case: Strict localization without cross-border transfer approval (pre-CAC filing in China) Implementation: All personal data processing occurs locally; only aggregated or anonymised data (not personal data) is transferred centrally.
┌───────────────────┐
│ Cloud Provider │
│ Local Region │ ← Data residency policy enforced
│ (e.g., AWS Mumbai) │ via cloud service configuration
│ Personal data │
│ stored here only │
└───────────────────┘
│
│ (API access from EU for administration; no data egress)
│
┌───────────────────┐
│ Central EU DC │
│ Application logic │
│ No local PD stored │
└───────────────────┘
Use case: India (DPDP Act), Indonesia (GR 71 private sector) Implementation: Cloud provider's local region stores personal data; application logic may run centrally but personal data does not leave the local region.
| Jurisdiction | Storage Requirement | Transfer Conditions | Filing/Approval | Enforcement Authority |
|---|---|---|---|---|
| Russia | Primary DB in Russia | Permitted after localization; subject to 152-FZ transfer rules | No filing required for localization | Roskomnadzor |
| China (CIIO/threshold) | Domestic storage | CAC security assessment or Standard Contract | Security assessment filed with CAC; Standard Contract filed within 10 days | CAC |
| India | No localization (yet) | Permitted except to blacklisted countries | No filing (monitor for future requirements) | Data Protection Board of India |
| India (RBI) | Payment data in India | Not permitted for payment data | RBI compliance reporting | Reserve Bank of India |
| Turkey | No explicit localization | Board approval or adequate country list | Board application for non-adequate countries | KVKK Board |
| Vietnam | Certain data in Vietnam | Impact assessment required | Dossier to Ministry of Public Security within 60 days | Ministry of Public Security |
| Indonesia (public) | In Indonesia | Limited exceptions | No specific filing | Ministry of Communication |
| Indonesia (private) | May be abroad | Access for supervision required | No specific filing | Ministry of Communication |