Subscribe to our newsletter!

Submit

Thank you for signing up for our newsletter!

We’re excited to have you with us and will keep you updated with the latest news, insights, and updates straight to your inbox.
Oops! Something went wrong while submitting the form.
Back to Blog
July 30, 2020
|
Read time {time} min

Data Residency: Meaning, Laws, & Requirements

Written by
Permission
Stay in the loop

Get the latest insights, product updates, and news from Permission — shaping the future of user-owned data and AI innovation.

Subscribe

Have you heard about data residency?

If you haven’t, it’s a concept that determines where different organizations store your data.

Some nations have stricter data protection laws, while others have implemented only minor measures.

As you don’t want your data to fall into the wrong hands, the location of your personal information is crucial.

In this article, we will discuss what data residency means and how it differs from data localization and data sovereignty. We’ll also explore the measures different nations use.

What Does Data Residency Mean?

Data residency is where an organization – government body, industrial body, or business – specifies the geographical location of their choice for where they store their data.

There are various reasons why an organization would do this:

  1. Tax benefits. In this case, a nation’s government may offer a beneficial tax environment for a business. However, in exchange, the company would ensure that a significant part of its operations stays within the country’s borders. As data storage is an important component of business operations, it may choose to host its data in the country.
  2. The business could also include data residency in its company policy to make it transparent for its customers where their data is stored.
  3. The company may also choose to host its data in a specific country due to financial (e.g., it’s cheaper to set up a data center or use a local data service provider’s services) or regulatory (e.g., the government has beneficial data protection laws) reasons.

Data Residency vs. Data Localization vs. Data Sovereignty

Have you heard of data localization and data sovereignty?

These terms are often used interchangeably with data residency frequently being used in the wrong way.

While data residency, data localization, and data sovereignty are closely related, they refer to concepts with different meanings, which could create some confusion amongst both consumers and businesses.

Let’s resolve the confusion and get things clear now.

Data Residency

The first and least restrictive concept is data residency, where a government body, industrial body, or business simply specifies the geographical location where it stores its data.

As illustrated in the last section’s examples, with data residency, the organization has a choice as to where it wishes to store its data.

Data Sovereignty

On the other hand, data sovereignty is a more restrictive concept. It represents the idea that data is subject to the nation’s laws where it is collected, processed, and stored.

Therefore, businesses have to comply with local data protection laws to avoid getting fined by the government.

Data Localization

Data localization is the most restrictive concept of the three.

While data residency gives organizations a choice to specify the geographical location where its data is stored, data localization refers to keeping the data of businesses within the borders of a country.

The concept almost always refers to the storage and creation of the data, and some nations that have implemented data localization laws require organizations to keep only the copy of the data within the country.

If there’s a valid reason, such data localization laws allow the government to audit its citizens’ data without requiring the nation’s authorities to interact with other governments.

On the other hand, some nations have implemented very restrictive data localization laws, prohibiting the data from crossing the country’s borders.

For example, Russia’s On Personal Data Law (OPD-Law) requires organizations to store, retrieve, and update data exclusively in data centers within the nation’s borders.

While stating that their goal is to protect their citizens’ data, these nations often implement strict data localization measures to secure a market advantage for local data centers that align with their data protectionism-related goals.

By doing so, such laws restrict the international flow of data. Therefore, critics argue that it prevents organizations from realizing the full potential of their data while contributing to “digital factionalism” and the “splinternet.”

Data Residency and the GDPR

The General Data Protection Regulation (GDPR) is among the world’s most popular data privacy laws.

As per the GDPR, companies that interact with the personal information of European Union citizens – both within and outside the EU – have to comply with strict data privacy laws.

While EU authorities can impose fines up to 20 million EUR on businesses or acquire 4% of their total global turnover as a penalty for non-compliance, there are no data residency laws in the GDPR.

Therefore, as per the EU data residency laws, organizations are free to choose where they host the data of European Union citizens.

However, businesses still have to comply with the EU’s (mostly data sovereignty-related) laws that require companies to fulfill specific requirements when transferring data outside of the European Union.

For example, a business could only transfer data to a third country if that nation has similarly adequate data safeguards as the EU or the company has a valid legal reason.

As of today, the EU has issued 13 adequacy decisions.

This means that European Union authorities (at least partially) consider these nations to have satisfactory data safeguards, allowing companies to transfer the personal information of EU citizens to these locations.

Data Residency Requirements by Country

Australia

According to the Personally Controlled Health Records Act of 2012, all personal medical information in Australia has to be stored in local servers.

While the law ensures that foreign governments are unable to access Australian citizens’ personal health records, the Oceanic nation’s data residency law prevents medical service providers, such as IBM Watson Health, from offering solutions to the nation’s citizens and organizations.

Canada

In Canada, two provinces (British Columbia and Nova Scotia) require public bodies (e.g. schools, public agencies, hospitals) to store their personal data within the nation’s borders where the data can only be accessed from the country.

China

China has one of the strictest data residency and localization laws on the globe.

In addition to restricting access to certain websites as part of the Golden Shield Program (also referred to as “the Great Firewall of China”), organizations have to comply with a wide range of data residency measures.

For example, companies offering e-banking services in China have to locate their data servers in the Asian nation. At the same time, Chinese personal financial information can only be analyzed, stored, and processed locally.

Also, the data of internet-based mapping services, as well as medical and health records, have to be kept in China.

Certain companies also have to comply with a cybersecurity law that prohibits personal information and important business data from leaving the country.

France

In France, data produced by local and national public administrations have to be stored with cloud services that are within the country’s borders.

It is also illegal in the European country to move information that is connected to legal proceedings outside of the nation.

Germany

Germany has similar views on data residency as France, advocating the idea of national clouds where personal information can be stored locally within its borders.

While data residency laws can vary by state, all organizations within Germany have to store accounting data in the European country.

Furthermore, organizations and individuals liable for taxes in Germany have to keep their accounting records within the country’s borders (with some exceptions).

Russia

Similarly to China, Russia has implemented strict data residency and localization laws.

As per the 2015 Personal Data Law, the data operators that collect personal information from Russian citizens are required to do all their data-related operations using databases that are physically located in the nation.

In addition to requiring companies to store all telecommunications data in the country for six months, the Russian government could impose a fine or shut down the services of businesses that refuse or fail to comply with the nation’s data residency laws.

Data Residency: An Important Concept Influencing Where Your Data Is Stored

As organizations specify the geographical location to store data, data residency has a great influence on where businesses keep your personal information.

Since data residency laws vary by country – for example, there are strict requirements in China and Russia while minimal regulation in Canada and the EU (GDPR) – it’s important to know where the services you use are storing your data.

If that nation has data sovereignty laws, businesses have to comply with them, which means that the government may access your personal information for any (valid) reasons.

While proper data sovereignty rules can help consumers protect their personal information, strict data localization laws could do more harm than good (e.g., the government can monitor the data easily while restricting the international flow of information).

Achieve Full Control Over Your Data With Permission

Permission, the advertising platform of the future, uses blockchain technology to achieve true data sovereignty by enabling full control over its users’ personal information.

Consumers are free to choose whether and how advertisers can use their data.

In exchange for sharing their personal information and engaging with advertising campaigns, users are rewarded in ASK, Permission’s native cryptocurrency, which they can spend on the Permission platform, hodl, or exchange.

Sounds great, huh?

Now check out Permission’s official website to learn more about this new blockchain-based advertising model and its innovative Browser Extension! You can also join the discussion via the Permission.io Telegram channel.

Recent articles

Your ASK Wallet, Now Powered by Coinbase

Sep 22nd, 2026
|
{time} read time

We've partnered with Coinbase to bring best-in-class wallet technology to our community.

Today we're updating the technology that powers your ASK wallet. Here's what's changing, what it means for you, and what stays exactly the same.

What's changing

We've moved your Permission wallet to Coinbase's platform. What that means in plain language is this: starting today, you are in full control of your ASK. When you click to send, redeem, or manage your balance, the transaction happens from your account, signed by your login. We no longer hold your wallet keys. Coinbase does, on your behalf, under your authority.

We chose Coinbase's embedded wallet specifically because it brings institutional-grade security to our users without requiring you to manage anything yourself. The infrastructure is Coinbase's. The wallet is yours.

Beyond the custody change, our users now have a wallet that can go wherever they go: exportable, cross-chain ready, and backed by a platform that serves millions of people around the world. We're proud to bring that to our community.

What it means to control your own keys

As Permission has grown, we felt strongly that your funds should be held by a platform built specifically for that purpose, with the security standards and regulatory rigor that come with it. Moving to Coinbase's embedded wallet reflects that commitment.

With today's change, Coinbase secures your private key inside their systems, and only your Permission login can authorize transactions. When you click to send or redeem ASK, the transaction is authorized by you, through your login. We are no longer part of that process.

What this means practically: your wallet operates on its own, independent of Permission. Treat your Permission login like you would a bank password. It is now the key to your wallet. If you ever want to take your wallet entirely outside of Permission, Coinbase supports key export and that option is yours.

What Coinbase sees

Because Coinbase is now part of the infrastructure, your email address, account identifier, and wallet information are shared with them for the purpose of operating the wallet. For details on how Coinbase handles this data, you can review their embedded wallet documentation and their privacy information.

For how Permission handles your data, our Terms of Use and our Privacy Policy govern that relationship, as they always have.

What stays the same

Everything you experience in the app. Earning ASK, redeeming it, transferring it, viewing your balance, managing your family. None of that changes.

And, what does change, we're excited about: key export, cross-chain support, and institutional-grade security. These are capabilities that would have taken years to build in-house and that Coinbase has spent that time perfecting. We chose to partner with the best-in-class, and our product and users will be better for it.

If you have questions, support is always here.

The Permission Team 🤝

What Is Family Friendly AI™?

Sep 9th, 2026
|
{time} read time

Only 15% of people globally say they trust AI systems, and 72% of parents are concerned about AI’s impact on their children.

AI is quickly becoming part of everyday family life, but Big Tech wasn’t built with families in mind. Family Friendly AI is technology intentionally designed for families, giving parents visibility into their children’s digital lives, guidance when they need it, and tools to encourage positive behavior.

5 Things That Make AI Family Friendly

1. Your family owns its data.

‍Your family’s data is never sold. It belongs to your family, and you stay in control of it.

2. Parents know what’s happening online.

‍Family Friendly AI gives parents visibility into their children’s digital lives, helping them fully understand how their children use and interact with technology.

3. It motivates children with rewards and incentives.

‍Parents can set rewards and incentives to encourage positive behaviors and help their children build better habits around technology and beyond.

4. It gives parents coaching and inspiration.

‍Parenting in a digital world comes with challenges that screen-time limits alone can’t help with. Family Friendly AI gives parents personalized AI-insights and guidance to help them navigate what their children are doing online and decide what to do next.

5. It earns families' trust.

‍Technology for families should have a higher bar. The companies building it should stand behind it with an unconditional, no-questions-asked money-back guarantee.

It’s time for AI, crypto, and the technology shaping our children’s lives to meet the family-friendly standard.

Big Tobacco Had Its Reckoning. Now It’s Big Tech’s Turn.

Aug 12th, 2026
|
{time} read time

The floodgates are open.

Thousands of lawsuits are moving forward. States are writing new rules for kids online. And lawmakers are beginning to tell AI companies what they can and cannot do when children use their products.

And you don't have to look far to see it happening...

The courts: 3,000+ lawsuits get the green light

On August 10, the Ninth Circuit allowed more than 3,000 lawsuits against Meta, Google/YouTube, TikTok and Snap to move forward.

The cases allege that the companies deliberately designed features of their platforms to be addictive, particularly for young users.

The tech companies had argued that Section 230 of the Communications Decency Act protected them from the claims. The court rejected their attempt to use Section 230 to stop the litigation at this stage, finding that it provides a defense rather than immunity from being sued.

At their core, these cases are allegations about the platforms themselves: how they were designed, how they kept people engaged, and what responsibility the companies bear for the consequences.

The companies will still have the opportunity to defend themselves against those allegations.

But with more than 3,000 cases now getting the chance to be heard, this is getting harder to argue away.

New Jersey: families get a way to enforce the rules

One day later, New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act into law.

The law establishes new design and privacy requirements for covered online services likely to be accessed by minors. Among other provisions, it requires high privacy settings by default, restricts certain push notifications, prohibits dark patterns for minors, limits how children's personal data can be used and retained, and places restrictions on targeted advertising.

But one provision in particular changes the accountability equation: a private right of action.

An individual under 18 who is injured by a violation can bring a claim under the law, with statutory damages of $5,000 per violation. Parents may also bring an action on a minor's behalf.

Which is legal language for something pretty simple: families don't have to wait around for a regulator to act. They can take companies to court themselves.

Colorado: AI safety starts becoming a legal requirement

Then there's Colorado.

Earlier this year, Governor Jared Polis signed Colorado HB 26-1263, establishing specific requirements for operators of conversational AI services.

And this one is worth paying attention to because the law doesn't simply tell AI companies to "keep kids safe." It starts defining what that actually means.

Operators must estimate users' ages. When dealing with minors, the law requires recurring disclosures that they are interacting with AI rather than a person and establishes protections around sexually explicit interactions.

It also addresses one of the most unsettling questions surrounding companion-style AI: emotional dependence.

The law requires safeguards designed to prevent conversational AI from producing statements that simulate emotional dependence. It also requires protocols for responding to suicidal ideation and self-harm, privacy and account-management tools for minors and parents or guardians, and reporting requirements intended to help regulators evaluate whether those safeguards are actually working.

The law takes effect January 1, 2027.

For companies building conversational AI, that's a meaningful shift. Child safety is moving beyond a set of voluntary guardrails companies write for themselves. In Colorado, some of those guardrails are becoming law.

It's no coincidence that this is all happening at once.

Big Tobacco didn't wake up one morning and discover the world had changed its mind. The reckoning came piece by piece, until lawsuits became regulation and an industry that had spent decades setting its own standards was finally forced to take responsibility for the harm its products caused.

We're watching that shift happen again.

For years, the responsibility for keeping kids safe online has fallen on parents.

Set the parental controls. Check the privacy settings. Watch the screen time. Know which apps they're using. Figure out who they're talking to. Keep up with every new platform, algorithm and now AI chatbot entering their lives.

All while the technology on the other side of the screen gets more sophisticated by the month.

Now courts and lawmakers are starting to ask the companies building that technology a much more uncomfortable question:

If children are using your products, what are you doing to keep them safe?

For families, that's the shift that matters most.

This isn't another round of false promises to "do better."

This is legislation. These are lawsuits. This is accountability beginning to have teeth.

Parents will always have the role of protecting their children online. We happen to believe they should have far more visibility and control over the technology entering their families' lives, not less.

But parents cannot be the entire safety system.

The law is making clear that the companies designing the products, writing the algorithms and building the AI our kids interact with have a responsibility, too.

And when they fail to meet it, they'll finally be held accountable.

ChatGPTs Births A Parenting Tool That Needs Some Image Repair

Aug 4th, 2026
|
{time} read time

Sam Altman keeps pitching AI as a co-parent. The reason parents aren't buying isn't nostalgia, it's the lawsuits.

Last Friday, Sam Altman had an idea he was excited about. Hook your family calendar up to ChatGPT, tell it what your kids are into, and every morning on the drive to school it'll produce a little podcast: one kid's soccer game that afternoon, another kid's birthday coming up, maybe some news. He called it a "cool use case."

What should’ve felt really innovative, landed like the opening scene of a bleak dystopian movie. Two kids in the back, one parent up front, and a smooth synthetic voice narrating, to everyone present, the lives of everyone present. "Later today, Maya has soccer." Maya, who has soccer, looks out the window. Nobody says anything, because the podcast is saying it for them.

The internet population caught what we caught. The reply that stuck came from Alex Hirsch, creator of Disney’s Animated series, Gravity Falls. It was seven poignant words: "What if you just talked to your children?" That was the entire rebuttal, and it traveled a great deal further than the thing it was rebutting. Altman's post drew somewhere around 9,600 likes. Hirsch's reply cleared 120,000. On the CEO's own platform, the crowd took a vote, and the crowd chose the small talk.

Now, we want to be fair here, because the easy thing is to dunk and move on. But we’re parents here at Permission and anyone who has done the 7:40 a.m. drive on four hours of sleep, refereeing a backseat dispute about who touched whom first, knows the exact fantasy of a button that handles the morning. That instinct isn't a character flaw. It's a Tuesday.

But this wasn't a one-off. Altman has been quietly auditioning AI for the co-parent role for a while now. On The Tonight Show in December 2025 he said he couldn't imagine having to "raise a newborn without ChatGPT" then added that people had managed the trick for a few hundred thousand years without it. Also, last year, in a podcast hosted by Andrew Mayne, Altman admitted that people might form “problematic parasocial relationships” to a chatbot. (You know, the one-sided kind that we usually reserve for celebrities we've never met.) He sees the hazards clearly. He's pitching the product anyway.

When visibility turns into vulnerability.

The reason parents flinched at the idea of carpooling with a chatbot for school drop off isn't that they're allergic to convenience. It's that the company making the offer is, right now, being sued by multiple families who say its chatbot played a role in their loved ones' spiraling delusions and, in the worst cases, their deaths. OpenAI says it is continually improving how its models handle sensitive conversations, and that work genuinely matters. But you can see the problem. "Let me into your calendar, your commute, and your kids personal details" is a big ask from anyone. It is a much bigger ask from a company currently explaining itself in court.

Trust isn't a feature you ship in the next update. It's something people hand you slowly, and take back all at once.

Here's where we should admit an interest. We build Permission on a belief that sounds boring until you sit with it: your data belongs to you. With Permission your kids’ browsing history doesn’t get shipped out to the open internet. Not to a model, not to a growth chart, not to whoever posts the next cool use case. And the closer AI creeps toward our kids (and it is creeping, because kids are already asking it everything) the more one question starts to outrank all the others:

Where is the line between parenting and outsourcing parenting?

Because "parenting tool" is doing a lot of quiet work in that phrase. A tool is a hammer. It lives in a drawer, it does one honest thing, and it does not ask to read your child's messages or move into the family calendar. When a company calls its chatbot a "parenting tool," it's worth asking, gently, which word they mean. The tool part, or the parenting part.

We happen to think AI can be genuinely, unglamorously useful to families. Not by doing the talking for you, but by handing you the context you'd otherwise miss instead of a thousand panicked notifications, and then getting out of the way so you can make the call. That's a real distinction, and it deserves its own piece.

So take this as Part One: the news, the flinch, and the reason the flinch is earned. In Part Two, we'll make the harder and more hopeful argument that you can let AI help you parent without completely handing over your family secrets. There is a version of this where the grown-ups stay in charge. We think it's the only version worth building.

For now, the seven best words anyone has offered on the whole affair still belong to Hirsch. So we'll give him the last one, too.

What if you just talked to your children?

‍