- Home
- Digital Sovereignty
- Data Embassies: Towards Digital Sovereignty Beyond Borders?
Data Embassies: Towards Digital Sovereignty Beyond Borders?
Population registers, cadastral records, land registers, business registers and Treasury systems: the data underpinning Estonia’s public administration is duplicated in Luxembourg, in facilities that no Luxembourg official may enter without the consent of an Estonian representative, except in the event of a fire or other emergency.
The principle is straightforward, although its legal classification is less so: one state stores copies of its essential registers on the territory of another while retaining control over them. This approach runs counter to the principle of data localisation. Information is moved outside national territory precisely to protect it and ensure continuity, while the resulting loss of physical control is offset through a legal framework.
In Luxembourg, immunity through treaty
Only two arrangements are based on treaties between states, and both are hosted by the same country. The Estonian agreement, signed on June 20, 2017, by Jüri Ratas and Xavier Bettel, was ratified by the Riigikogu in March 2018, following discussions that began as early as 2014 with Microsoft.
Tallinn selected the Grand Duchy because of its Tier IV-certified public data centres and its commitment to guaranteeing immunity for the systems, according to the explanatory memorandum cited by the Riigikogu. The cost was estimated at €2.2 million over five years, 85% of which was financed by the European Regional Development Fund, according to ERR.
Ten databases are replicated there: the population register, business register, electronic land register, cadastral register, register of taxable persons, identity documents register, Treasury information system, eFile judicial system, pensions register and Official Gazette.
Four years later, Monaco signed its own agreement with Luxembourg in July 2021. It entered into force on June 30, 2023. According to the preamble, the principality was seeking premises abroad, at least 150 kilometres from its territory, to protect its data against both natural disasters and unlawful acts. With a territory of just two square kilometres, geographical redundancy is impossible without crossing a border.
Both agreements state that they were concluded “in the spirit” of the 1961 Vienna Convention, which they consider insufficient, and replicate some of its mechanisms. Under the Estonian agreement, the premises are inviolable (Article 3), the equipment is immune from any form of judicial process (Article 5), and the data is treated as archives of the Republic (Article 6).
Estonia may encrypt its official communications as it sees fit and use diplomatic couriers; these communications may neither be censored nor restricted. If the agreement is terminated, the data may only be handed over to Estonia’s authorised representative. If that representative cannot be found, Luxembourg must protect the data as it would its own archives until a legal representative comes forward (Article 10). The agreement therefore anticipates a scenario in which the authorities of a state are no longer able to respond. Monaco incorporated the same principle into its own agreement (Article 14).
The Monegasque agreement expands the framework in several respects. Article 7 expressly prohibits Luxembourg authorities from accessing the data remotely without Monaco’s prior consent: logical access is therefore covered, rather than only physical intrusion. Article 4 prevents any “foreign” authority from gaining physical access, although the prohibition on remote access applies only to Luxembourg. Article 8 prohibits any interception of communications for administrative or judicial purposes. Article 3 requires Luxembourg to provide six months’ notice of any sale of the premises or change of operator, except in cases of compelling urgency.
Blind spots remain in both arrangements. Immunity protects the premises, machines and data, but not the electricity supply or cooling systems: both treaties require the premises to be provided in working order, without guaranteeing their continuity during a crisis. Luxembourg is only required to provide Tallinn with the same level of protection it affords itself (Article 4).
The Estonian representative, since they are not a member of a diplomatic mission, enjoys no personal immunity, Bartłomiej Sierzputowski noted in 2019 in the International and Comparative Law Quarterly. No live failover under real-world conditions has been made public to date. The Estonian facility remains a backup, although Tallinn ultimately wants to be able to operate it directly.
In Ukraine, registers sent into exile in an emergency
Ukraine is the only documented case of an actual failover, and it took place outside any diplomatic framework and with private-sector operators.
Before 2022, Ukrainian law required certain public data to remain on servers located within the country. The Law “On Cloud Services” No. 2075-IX, adopted on February 17, 2022, one week before the invasion, did not remove this restriction. Signed on March 15 and applicable from September, it instead prohibits state secrets, official information and data from state registers from being processed outside the country, as detailed in an analysis by law firm Sayenko Kharenko.
The transfer of data abroad relied on emergency law. Cabinet of Ministers Resolution No. 263 of March 12, 2022, authorised public registers and their copies to be hosted in foreign clouds or data centres for the duration of martial law. This exemption was subsequently incorporated into Law No. 2130-IX of March 15, 2022.
Implementation relied on private providers. Three AWS Snowball appliances were transported from Dublin via Poland during the first days of the conflict. According to Liam Maxwell, an AWS executive, 161 state registers and 356 organisations were migrated, representing around 15 petabytes of data.
The current arrangement offers none of the formal immunity associated with an “embassy”, since protection is contractual and relies on the commercial relationship with the hosting provider, encryption and geographic distribution.
Using a US provider introduces another constraint: the CLOUD Act allows US authorities to compel a provider subject to US jurisdiction to disclose data under its control, including when that data is stored outside the United States.
Kyiv also entered into parallel discussions with several countries, including Estonia and France, about protecting essential Ukrainian data outside its national territory, according to the Wall Street Journal on June 14, 2022. No agreement has since been made public.
The Ukrainian government has subsequently strengthened the framework governing the hosting of its data. Resolution No. 154 of February 11, 2025 sets requirements for cloud and data-centre service providers, including compliance with the ISO/IEC 27001 standard.
Towards a market for data asylum?
In the Gulf, hosting arrangements are initially being organised through the law of the host country, while Saudi Arabia plans to complement this approach with state-to-state agreements.
Bahrain’s Legislative Decree No. 56 of 2018 places the content of foreign customers, including businesses, under the jurisdiction of their home state, while requiring the local provider to notify the Attorney General of any injunction. The regime applies only to states and data centres designated by the Council of Ministers. The decree came shortly before AWS opened the Middle East’s first AWS Region in Bahrain in 2019.
Saudi Arabia’s proposed Global AI Hub Law, submitted for consultation in April 2025, distinguishes between three models.
The Private Hub is a data centre reserved for a foreign state, referred to as the “guest country”, and operates under that country’s law within the framework of a bilateral agreement with Riyadh.
The Extended Hub follows the same logic but allows a third-party operator to host its own data or that of its customers under the law of the guest country, again on the basis of an agreement with Saudi Arabia.
The Virtual Hub is operated by a Saudi provider and allows customers’ data to be governed by the law of a “designated foreign state”, without necessarily requiring a bilateral agreement.
In all three cases, the arrangement remains under Saudi control. The Council of Ministers may terminate agreements or arrangements to protect the Kingdom’s security and sovereignty, although the proposed legislation provides for the temporary continuation of certain privileges.
India, meanwhile, has promised since its February 1, 2023 budget to host data embassies in GIFT City, the special economic zone in Gujarat that houses its international financial centre and dedicated regulator, the IFSCA.
In February 2025, an IFSCA official told The Hindu BusinessLine that Singapore was “actively” considering establishing a presence there. No dedicated legislation has been adopted, CMS IndusLaw noted in July 2026. The law firm argues, among other things, that exemptions from Section 69 of the Information Technology Act would be useful, as that provision allows Indian authorities to intercept and decrypt data.
According to the firm, a GIFT City official has discussed ad hoc legislation granting immunity comparable to that enjoyed by embassies, but no such legislation has followed.
The India-UAE joint statement of January 19, 2026 opened another avenue: the two leaders instructed their teams to explore “digital embassies” under mutually recognised sovereignty arrangements. On the same day, Indian Foreign Secretary Vikram Misri described the idea during a briefing as a “relatively new” concept whose regulatory framework had yet to be developed.
The following day, in Davos, Emirati group G42 launched a commercial offering called “Digital Embassies”, backed by state-to-state agreements.
The term “data embassy” therefore currently encompasses initiatives at very different stages of maturity: two bilateral treaties modelled on diplomatic law, an emergency relocation carried out under commercial contracts in Ukraine, and several projects still under consideration without a settled legal framework.
Although no new intergovernmental agreement has been signed since 2021, interest in the concept is widening. Gartner predicts that by 2029, at least 15% of “nations in geopolitically volatile regions” will have established a formal data embassy agreement.
the newsletter
the newsletter