Jurisdiction Privacy Guide

Data sovereignty isn't just about laws—it's about geopolitical alliances, intelligence sharing, and legal friction against foreign demands.

How We Score: Scores reflect legal friction against US/EU data demands. A "Safe Haven" (8+) forces foreign governments through slow MLAT processes. Always pair jurisdiction choice with client-side encryption.

Hong Kong

Safe Haven (8/10)

Distinct legal system under Basic Law Article 27 protecting communications freedom. Separate internet infrastructure, independent IXP routing, and no direct integration with US CLOUD Act/FISA apparatus. While Beijing exerts political pressure, operational data access for US intelligence requires formal diplomatic channels with significant friction. Best available option for non-US jurisdictional isolation.

Legal References

Chile

Moderate Risk (7/10)

Most stable South American jurisdiction. Geographically isolated from Eurasian conflicts. Connected to US/EU via Humboldt cable system.

Legal References

Malaysia

Moderate Risk (7/10)

Ranked above Singapore due to absence of confirmed upstream cable tapping infrastructure. PDPA provides commercial privacy protection with stricter data localization requirements than SG. Non-aligned foreign policy reduces bilateral intelligence pressure. Shinjiru and other offshore hosts operate here with proven resistance to foreign subpoenas. Not Five Eyes-adjacent; no formal SIGINT sharing treaties. Best SEA option for users needing regional latency without Singapore's collection hub risk.

Legal References

South Africa

Moderate Risk (7/10)

POPIA provides GDPR-equivalent commercial privacy protection. Independent judiciary has blocked unlawful state surveillance (e.g., 2021 spyware ruling). Not part of Western intelligence alliances; BRICS membership creates geopolitical counterweight. WACS submarine cable connects directly to Europe/US without transiting hostile regions. Best African option for users needing EMEA latency with meaningful legal friction.

Legal References

Mauritius

Moderate Risk (7/10)

Data Protection Act modeled on GDPR with strong independent commissioner. Stable democracy with independent judiciary. No historical intelligence ties to Western alliances. Emerging datacenter hub with direct submarine cables to Asia/Europe. Small size limits geopolitical leverage but clean intel history makes it viable for DR/backups. Comparable to Chile for physical isolation in Indian Ocean region.

Legal References

Turkey

Moderate Risk (7/10)

NATO member but operates with significant strategic autonomy; frequently refuses US intelligence sharing requests and maintains independent SIGINT capabilities via MIT. Purchased Russian S-400 systems despite NATO objections, proving willingness to defy alliance pressure. No formal Five Eyes/Fourteen Eyes integration; bilateral intel cooperation is transactional, not treaty-based. Strong legal friction against US data demands due to adversarial relationship post-2016 coup attempt. CRITICAL DOMESTIC CAVEAT: Broad anti-terrorism laws enable extensive government surveillance of citizens; not a safe haven for political speech or activism. Excellent infrastructure with low latency to Europe/Middle East/Central Asia; ideal for users needing regional performance without submitting to US dragnet. Usable for commercial/private data; avoid for politically sensitive content.

Legal References

Mongolia

Moderate Risk (7/10)

Unique geopolitical position between Russia and China creates natural buffer against Western intelligence pressure; no Five Eyes/Fourteen Eyes ties. Constitution guarantees communication secrecy with strong judicial enforcement. Minimal internet infrastructure reduces attack surface for upstream collection. Small population limits mass surveillance scale. CRITICAL INFRASTRUCTURE CAVEAT: Limited datacenter capacity and international bandwidth; suitable only for low-bandwidth DR/backups or niche workloads. Not viable for high-traffic commercial hosting. Best-in-class legal friction for landlocked Asian jurisdiction.

Legal References

Brazil

Moderate Risk (6/10)

ABIN conducts domestic surveillance under Intelligence Law. Not part of Western alliances but has bilateral data-sharing agreements with US. LGPD provides commercial privacy protection but intelligence exemptions are broad. Growing domestic pushback against foreign surveillance cooperation.

Legal References

India

Moderate Risk (6/10)

NTRO/R&AW operate extensive surveillance under IT Rules 2021. Non-aligned but maintains pragmatic intelligence cooperation with multiple powers including US. PDPB proposed but not enacted; current framework allows broad government access without warrants. Major global data center hub.

Legal References

Thailand

Moderate Risk (6/10)

PDPC enforces data protection but military junta history creates unpredictable enforcement. Computer Crime Act allows broad government access without warrant. Not part of Western intelligence alliances but maintains pragmatic bilateral cooperation. Growing datacenter market in Bangkok offers competitive latency to SEA. Acceptable for non-sensitive workloads; avoid for high-risk privacy needs.

Legal References

Indonesia

Moderate Risk (6/10)

PDP Law enacted 2022 provides baseline privacy framework but implementation remains inconsistent. Strategic location hosts major submarine cables but no confirmed upstream tapping agreements. Non-aligned stance reduces alliance pressure. Large domestic market drives local datacenter investment. Suitable for regional content delivery; legal unpredictability limits use for sensitive data.

Legal References

Kenya

Moderate Risk (6/10)

Data Protection Act 2019 establishes framework but enforcement capacity limited. Strategic location hosts TEAMS/LIONSEA cables connecting Asia-Europe. Non-aligned but maintains pragmatic US/UK security cooperation. Growing tech ecosystem offers competitive pricing. Suitable for regional content delivery; avoid for sensitive data due to institutional weakness.

Legal References

Cambodia

Moderate Risk (6/10)

No formal intelligence sharing treaties with Five Eyes/Fourteen Eyes; Chinese-aligned foreign policy creates natural barrier to US data demands. Minimal submarine cable infrastructure reduces upstream tapping risk compared to Singapore/Malaysia. CRITICAL DOMESTIC CAVEAT: Authoritarian regime with pervasive surveillance of political dissent; Cybercrime Law enables warrantless data access for "national security." Suitable ONLY for non-political commercial workloads requiring SEA latency without US dragnet exposure. Never host activist, journalistic, or opposition content.

Legal References

Sri Lanka

Moderate Risk (6/10)

Non-aligned foreign policy with no formal Western intelligence alliances. Strategic Indian Ocean location hosts key submarine cables connecting Asia-Africa-Europe without transiting Five Eyes hubs. Personal Data Protection Act No. 9 of 2022 establishes GDPR-equivalent framework with independent commissioner. Economic crisis has increased reliance on Chinese investment but not formal intelligence integration. Viable for DR/backups and regional content delivery; institutional capacity remains developing.

Legal References

Switzerland

Moderate Risk (5/10)

One notch above Germany solely due to MLAT legal friction; NOT a safe haven. Crypto AG scandal proved Swiss NDB jointly operated backdoored encryption with CIA/BND for decades. Ongoing SIGINT cooperation with German intelligence continues under new Intelligence Act. FADP provides procedural hurdles via MLATs that EU members lack (GDPR intel exemptions nullify GDPR), but operational resistance capacity is minimal. Small nation cannot credibly refuse high-priority Five Eyes requests. Acceptable only for non-sensitive workloads requiring EU proximity; never for private data without client-side encryption.

Legal References

Iceland

Moderate Risk (5/10)

Strong MMI laws but tiny population/economy limits geopolitical leverage. NATO member since 1949 with integrated air defense and SIGINT sharing with US/UK. Cannot realistically refuse high-priority Five Eyes requests without severe diplomatic/economic consequences. Legal protections exist but operational resistance capacity is minimal.

Legal References

Singapore

Moderate Risk (5/10)

Non-Five Eyes but hosts critical undersea cable infrastructure tapped by NSA/GCHQ via "State Room" program. Singaporean intelligence (SID) maintains close operational ties with Western allies. Strong commercial data protection but strategic location makes it a collection point rather than a true sanctuary. Better than US/EU but not immune to upstream interception.

Legal References

Canada

Moderate Risk (5/10)

Charter Section 8 requires warrants for subscriber data. BUT core Five Eyes member. CSE shares raw intelligence with NSA. CLOUD Act applies to US subsidiaries.

Legal References

Spain

Moderate Risk (5/10)

CNI conducts mass surveillance under National Intelligence Center Act. Not formally Fourteen Eyes but shares intelligence with NSA via bilateral agreements. Hosts key Mediterranean submarine cable hubs. GDPR applies commercially but not to intelligence operations. WAR RISK: Supplies weapons to Ukraine via Mediterranean logistics corridors. Spanish datacenters host EU naval command systems. Russian threats include "logistics support infrastructure" which encompasses commercial cloud facilities supporting military transport. WAR RISK: Supplies weapons to Ukraine via Mediterranean logistics corridors. Spanish datacenters host EU naval command systems. Russian threats include "logistics support infrastructure" which encompasses commercial cloud facilities supporting military transport.

Legal References

Italy

Moderate Risk (5/10)

AISE/AISI operate extensive domestic and foreign surveillance. Participates in informal EU-US intelligence sharing. Hosts critical trans-Mediterranean cable infrastructure. Constitutional privacy protections frequently overridden by national security decrees. WAR RISK: Hosts US/NATO air bases used for Ukraine arms transit. Italian datacenters co-located with military logistics nodes. Russian doctrine explicitly targets "dual-use infrastructure" including commercial facilities supporting alliance operations. WAR RISK: Hosts US/NATO air bases used for Ukraine arms transit. Italian datacenters co-located with military logistics nodes. Russian doctrine explicitly targets "dual-use infrastructure" including commercial facilities supporting alliance operations.

Legal References

Poland

Moderate Risk (5/10)

ABW/Agencja Wywiadu conduct bulk collection under Counterintelligence Act. NATO eastern flank host with deep US intelligence integration. Hosts major Central European data centers. Limited judicial review for foreign intelligence requests. WAR RISK: Primary NATO eastern flank hub; hosts US permanent garrison and Ukrainian arms transit centers. Multiple stray missile/drone incidents on Polish territory. Datacenters face highest kinetic risk in EU due to proximity to conflict zone and explicit Russian targeting of "NATO decision centers". WAR RISK: Primary NATO eastern flank hub; hosts US permanent garrison and Ukrainian arms transit centers. Multiple stray missile/drone incidents on Polish territory. Datacenters face highest kinetic risk in EU due to proximity to conflict zone and explicit Russian targeting of "NATO decision centers".

Legal References

Japan

Moderate Risk (5/10)

Not Five Eyes but operates CABINET INTELLIGENCE AND RESEARCH OFFICE with extensive NSA cooperation. Hosts critical Pacific submarine cables. Act on Protection of Specially Designated Secrets enables warrantless data access for national security. Key US ally in Asia-Pacific SIGINT.

Legal References

South Korea

Moderate Risk (5/10)

NIS conducts broad surveillance under National Intelligence Service Act. Extensive informal data-sharing with NSA despite no formal alliance treaty. Hosts major Asian internet exchange points. Democratic safeguards frequently suspended for "national security" investigations.

Legal References

United Arab Emirates

Moderate Risk (5/10)

State Security Department conducts pervasive surveillance. Not Western-aligned but hosts major regional data centers and cloud infrastructure. No meaningful privacy legislation; all data subject to state access. Critical Middle East hosting location with zero legal friction for government requests.

Legal References

Georgia

Moderate Risk (5/10)

SISG conducts signals intelligence under State Security Service Law. NATO aspirant with growing US/EU intelligence cooperation. Hosts emerging Caucasus data center infrastructure. Democratic institutions provide some oversight but national security exceptions remain broad.

Legal References

Vietnam

Moderate Risk (5/10)

Cybersecurity Law mandates data localization and government access. Authoritarian regime poses risks for political speech but non-aligned foreign policy prevents formal Western intelligence integration. No Five Eyes/Fourteen Eyes ties. Growing tech sector offers competitive pricing. Only consider for non-political commercial workloads where latency outweighs civil liberty concerns.

Legal References

Nigeria

Moderate Risk (5/10)

NDPR provides baseline privacy rules but enforcement is inconsistent. Major West African internet hub with SAT-3/WASC cables. Political instability and corruption create unpredictable legal environment. No formal Western intelligence alliances but bilateral cooperation exists. Only consider for non-critical workloads where West African latency is essential.

Legal References

Russia

Moderate Risk (5/10)

Strong legal friction against US intelligence demands due to adversarial relationship; no FISA/CLOUD Act applicability. Yarovaya Law mandates domestic data localization and government access, creating internal surveillance risk. CRITICAL CAVEATS: Active war in Ukraine makes Russian-hosted infrastructure a legitimate military target per NATO/Russian doctrine. Western sanctions prohibit most businesses from using Russian services; payment processing, domain registration, and cloud APIs are blocked for US/EU entities. Only viable for users physically located in Russia/CIS with no Western business ties. Never use for DR/backups accessible from sanctioned jurisdictions.

Legal References

Germany

High Risk (4/10)

Strict GDPR enforcement but core Fourteen Eyes member. BND shares raw SIGINT with NSA. Subject to EU data retention directives. WAR RISK: As core NATO member supplying weapons to Ukraine, German datacenters are explicitly named as "legitimate targets" in Russian military doctrine. Kinetic strikes on energy/grid infrastructure have already caused cascading datacenter outages in neighboring Poland/Baltics. GDPR provides zero protection against wartime seizure or destruction. WAR RISK: As core NATO member supplying weapons to Ukraine, German datacenters are explicitly named as "legitimate targets" in Russian military doctrine. Kinetic strikes on energy/grid infrastructure have already caused cascading datacenter outages in neighboring Poland/Baltics. GDPR provides zero protection against wartime seizure or destruction.

Legal References

France

High Risk (4/10)

Fourteen Eyes participant. DGSE conducts bulk collection under Military Programming Law. Not subject to GDPR for intelligence purposes. Hosts major IXPs used for upstream collection. WAR RISK: Major arms supplier to Ukraine; French military logistics hubs co-located with civilian data centers. Russian threats specifically cite "decision-making centers" including digital infrastructure. Energy grid attacks have forced datacenter generator reliance across Northern France. WAR RISK: Major arms supplier to Ukraine; French military logistics hubs co-located with civilian data centers. Russian threats specifically cite "decision-making centers" including digital infrastructure. Energy grid attacks have forced datacenter generator reliance across Northern France.

Legal References

Netherlands

High Risk (4/10)

Fourteen Eyes participant. AIVD/MIVD operate extensive undersea cable tapping at Amsterdam internet exchanges. Wiv law permits bulk data collection with minimal oversight. Key transit hub for European traffic. WAR RISK: Key NATO logistics hub hosting US/EU military command systems adjacent to civilian IXPs. Amsterdam datacenter cluster vulnerable to spillover from Baltic/North Sea escalation. Energy dependency on Russian gas (pre-2022) created latent infrastructure vulnerability now exacerbated by war-time grid strain. WAR RISK: Key NATO logistics hub hosting US/EU military command systems adjacent to civilian IXPs. Amsterdam datacenter cluster vulnerable to spillover from Baltic/North Sea escalation. Energy dependency on Russian gas (pre-2022) created latent infrastructure vulnerability now exacerbated by war-time grid strain.

Legal References

Sweden

High Risk (4/10)

Fourteen Eyes participant. FRA operates massive signals intelligence infrastructure. Cable Acts permit unrestricted monitoring of all cross-border communications passing through Swedish territory. WAR RISK: NATO accession (2024) transformed Sweden from neutral to active alliance member. Russian rhetoric explicitly includes Nordic data infrastructure in "counter-force" targeting doctrine. Baltic Sea cable sabotage incidents demonstrate physical vulnerability of regional internet backbone. WAR RISK: NATO accession (2024) transformed Sweden from neutral to active alliance member. Russian rhetoric explicitly includes Nordic data infrastructure in "counter-force" targeting doctrine. Baltic Sea cable sabotage incidents demonstrate physical vulnerability of regional internet backbone.

Legal References

Denmark

High Risk (4/10)

Fourteen Eyes participant. PET conducts signals intelligence under Executive Order 156. Hosts critical undersea cable landing points connecting Nordic traffic to US/UK networks. Shares raw intercepts with NSA via formal agreement. WAR RISK: Hosts critical undersea cable landing points connecting Nordic traffic to US/UK networks. Danish military intelligence integration with NATO makes civilian infrastructure dual-use target. Greenlandic satellite stations used for SIGINT create additional escalation risk. WAR RISK: Hosts critical undersea cable landing points connecting Nordic traffic to US/UK networks. Danish military intelligence integration with NATO makes civilian infrastructure dual-use target. Greenlandic satellite stations used for SIGINT create additional escalation risk.

Legal References

Norway

High Risk (4/10)

NATO member with extensive SIGINT cooperation with NSA/GCHQ. E-tjenesten operates bulk collection at Troms satellite station. Not EU member but participates in EU-US data sharing frameworks. Minimal judicial oversight for foreign intelligence. WAR RISK: Borders Russia directly; hosts NATO air defense and SIGINT facilities integrated with US NORAD. Troms satellite station is high-value target. Civilian datacenters near military sites face collateral damage risk in any Arctic escalation scenario. WAR RISK: Borders Russia directly; hosts NATO air defense and SIGINT facilities integrated with US NORAD. Troms satellite station is high-value target. Civilian datacenters near military sites face collateral damage risk in any Arctic escalation scenario.

Legal References

Belgium

High Risk (4/10)

Fourteen Eyes participant. ADIV/SGRS conduct bulk metadata collection. Hosts major European internet exchange points used for upstream surveillance. Subject to EU data retention directives despite constitutional privacy protections. WAR RISK: HQ of NATO and EU military command structures. Brussels datacenter cluster houses allied command systems making it priority target in Russian strike planning. Energy grid attacks have already impacted Belgian datacenter operations during 2022-2023 winter. WAR RISK: HQ of NATO and EU military command structures. Brussels datacenter cluster houses allied command systems making it priority target in Russian strike planning. Energy grid attacks have already impacted Belgian datacenter operations during 2022-2023 winter.

Legal References

United Kingdom

High Risk (3/10)

Core Five Eyes member. Operates Tempora program for bulk fiber optic interception. Subject to Investigatory Powers Act (Snoopers Charter) requiring ISPs to retain 12 months of browsing history. Deeply integrated with NSA via GCHQ.

Legal References

Australia

High Risk (3/10)

Core Five Eyes member. ASD shares raw SIGINT with NSA. Mandatory data retention laws force telcos to store metadata for 2 years. Assistance and Access Act compels tech companies to build decryption capabilities.

Legal References

New Zealand

High Risk (3/10)

Core Five Eyes member. GCSB operates IRONBARK signals intelligence facility. Shares raw intercepts with NSA. Privacy Act exemptions allow broad intelligence gathering without judicial oversight.

Legal References

Israel

High Risk (3/10)

Unit 8200 conducts world-class SIGINT operations. Extensive informal data-sharing with NSA despite not being formal Five Eyes member. Cybersecurity firms often serve as proxies for intelligence collection.

Legal References

United States

High Risk (2/10)

Subject to Patriot Act NSLs, FISA Section 702 warrantless surveillance, and CLOUD Act. Gag orders prohibit disclosure. Highest mass surveillance risk.

Legal References