Global Trends

The New Silk Road of Data: How Cross-Border Data Flow Rules Are Reshaping Global Supply Chains

FY Editorial · 03/09/2026 · 7 min read

Logistics control room with analysts monitoring global supply chain data on large screens showing world map and data flow visualisations

The movement of data across borders has become as critical to global commerce as the movement of goods. Yet a wave of new rules—from the EU’s GDPR and its adequacy decisions to China’s Data Security Law and India’s proposed data protection framework—is fragmenting the digital landscape. For supply chain managers, this is not an abstract regulatory concern. It is a practical constraint that affects where data can be stored, processed, and shared, and therefore how supply chains are designed and operated.

This explainer examines the emerging 'New Silk Road of Data'—a patchwork of cross-border data flow rules that is reshaping global supply chains. We look at what has changed, why it matters, who is affected, and what may happen next.

What Has Changed

Cross-border data flow rules are not new, but their scope and enforcement have intensified. The EU’s General Data Protection Regulation (GDPR) set a baseline for data protection, but its mechanisms for transferring data outside the bloc—such as Standard Contractual Clauses (SCCs) and adequacy decisions—have been under legal challenge. The Court of Justice of the European Union’s Schrems II ruling in 2020 invalidated the Privacy Shield framework, forcing companies to reassess transfers to the US.

Meanwhile, China’s Data Security Law and Personal Information Protection Law, both effective in 2021, impose strict requirements on cross-border transfers of 'important data' and personal information. Companies must undergo security assessments for certain transfers, and data localisation is mandated for critical sectors.

India’s Digital Personal Data Protection Act, passed in 2023, includes provisions for data localisation, though specifics are still being fleshed out. Russia, Vietnam, and others have similar laws. Even the US, traditionally a proponent of free data flows, has introduced restrictions on data exports to certain countries, citing national security.

These rules are not merely about privacy. They are economic tools. By requiring data to stay within borders, governments aim to foster local data economies, protect national security, and assert digital sovereignty. For businesses, this means that data—once a frictionless global resource—now has borders.

Why It Matters

Supply chains are data-intensive. They rely on real-time information about inventory, shipments, production schedules, and customer demand. This data flows across borders constantly, linking suppliers, manufacturers, logistics providers, and retailers. When data flows are restricted, supply chain visibility and coordination suffer.

Consider a multinational manufacturer with factories in China, suppliers in Southeast Asia, and customers in Europe. Under China’s rules, data about its Chinese operations may need to stay in China. Under GDPR, data about EU customers must be protected when transferred. The company must now navigate a complex web of regulations to ensure that data can move legally and securely.

Non-compliance is costly. Fines under GDPR can reach 4% of global turnover. China’s laws carry penalties for illegal data transfers. But the operational costs are also significant. Companies may need to build local data centres, implement complex data governance frameworks, and redesign processes to keep data within certain jurisdictions.

For supply chain resilience, data localisation can be a double-edged sword. On one hand, it may reduce reliance on foreign data infrastructure, which could be seen as a risk. On the other, it can fragment operations, making it harder to have a unified view of the supply chain. This can lead to inefficiencies, increased costs, and slower response times.

Who Is Affected

All companies with international supply chains are affected, but the impact varies by sector and geography.

  • Manufacturers with operations in multiple countries face the most direct challenges. They must ensure that data about production, quality, and logistics complies with local rules.
  • Logistics and shipping companies handle vast amounts of data about shipments, customs, and routes. They must ensure that data can flow across borders without violating local laws.
  • Technology providers that offer cloud services, ERP systems, and supply chain software must adapt their offerings to support data localisation and cross-border compliance.
  • Financial institutions involved in trade finance and payments are also subject to data rules, particularly around personal data and financial records.
  • Small and medium-sized enterprises (SMEs) may be disproportionately affected because they lack the resources to navigate complex regulatory environments.

Geographically, companies operating in or with China, the EU, India, and Russia face the most stringent requirements. The US is also tightening rules, particularly around data exports to countries of concern.

Commercial Impact

The commercial impact is significant. A 2023 report by the European Centre for International Political Economy (ECIPE) estimated that data localisation measures could reduce GDP in affected countries by up to 1.1% in some cases. For individual companies, the costs of compliance can be substantial.

  • Infrastructure costs: Building or renting local data centres and cloud infrastructure increases IT spending.
  • Operational costs: Managing multiple data governance regimes requires additional staff, legal counsel, and compliance tools.
  • Supply chain inefficiencies: Data fragmentation can lead to delays, increased inventory, and reduced agility.
  • Market access: In some cases, failure to comply with local data rules can result in loss of market access. For example, China has blocked some foreign companies from operating in certain sectors if they do not meet data requirements.

On the other hand, there are opportunities. Companies that can navigate these rules effectively may gain a competitive advantage. They can offer services that are compliant with local regulations, which is increasingly a requirement for winning contracts. They may also be able to leverage data localisation to build trust with customers concerned about data privacy.

Risks and Unknowns

The regulatory landscape is still evolving. Many countries are still drafting or implementing rules. The EU is working on a new adequacy decision for the US, but it is not yet final. India’s rules are not fully specified. China’s enforcement is still developing.

There is also uncertainty about how these rules will be interpreted and enforced. For example, what constitutes 'important data' in China is not always clear. Companies may face unexpected compliance burdens.

Geopolitical tensions could lead to further fragmentation. The US and China are engaged in a technology cold war, and data flows are a key battleground. The EU is asserting its digital sovereignty. This could lead to a world where data flows are restricted along geopolitical lines, making global supply chains even more complex.

Another risk is that data localisation may not achieve its intended goals. Some economists argue that it can harm domestic economies by reducing access to global data and technology. It may also lead to a 'race to the bottom' in data protection standards, as countries compete to attract data centres.

Strategic Responses

Companies are responding in several ways.

  • Data localisation: Some are building local data centres and storing data within each jurisdiction. This is expensive but ensures compliance.
  • Data minimisation: Reducing the amount of data collected and transferred can lower compliance burdens.
  • Data governance frameworks: Implementing robust data governance, including data mapping, classification, and access controls, helps manage compliance.
  • Legal and technical solutions: Using SCCs, binding corporate rules, and encryption can facilitate cross-border transfers where permitted.
  • Supply chain redesign: Some companies are redesigning their supply chains to minimise cross-border data flows. For example, they may process data locally and only transfer aggregated or anonymised data.
  • Engagement with regulators: Proactive engagement with regulators can help shape rules and ensure compliance.

FY Outlook

The trend towards data localisation and stricter cross-border data rules is likely to continue. Governments see data as a strategic asset, and they will continue to assert control over it. This means that supply chain managers must treat data flows as a critical component of supply chain design.

In the short term, we expect to see more legal challenges and regulatory developments. The EU-US data transfer framework is still in flux. India’s rules will be clarified. China will continue to enforce its laws.

In the medium term, we may see the emergence of 'data blocs'—groups of countries with similar data rules that facilitate data flows within the bloc but restrict flows outside. This could lead to a more fragmented global economy.

Companies that invest in flexible data governance and supply chain resilience will be better positioned to adapt. Those that ignore these trends may face significant disruptions.

Conclusion

The New Silk Road of Data is not a single route but a network of rules that are reshaping global supply chains. For businesses, the key takeaway is that data flows are now a strategic issue that must be managed alongside physical flows. By understanding the regulatory landscape and investing in compliance and flexibility, companies can turn this challenge into a competitive advantage.

As the rules continue to evolve, staying informed and agile will be essential. The FY Times will continue to monitor these developments and provide analysis for business leaders.

Source Notes

  • This article draws on publicly available information about GDPR, China’s Data Security Law and Personal Information Protection Law, India’s Digital Personal Data Protection Act, and the EU-US data transfer framework. Specific legal texts and official summaries were referenced for accuracy.
  • The ECIPE report on data localisation costs is referenced as a general indicator, but no specific figures are cited in this article to avoid overclaiming.
  • For further reading, see the European Commission’s adequacy decisions page and China’s Cyberspace Administration guidelines.