Data Localization logo

Data Localization

Community
mukul975
data-localization

Guides compliance with country-specific data localization requirements across key jurisdictions including Russia (242-FZ), China (PIPL Art. 40, CAC measures), India (DPDP Act), Turkey, Vietnam, and Indonesia. Covers localization assessment, architecture design, and exemption procedures. Keywords: data localization, data residency, PIPL, 242-FZ, cross-border restrictions.

Overview

Publishermukul975
RepositoryPrivacy-Data-Protection-Skills
Skill namedata-localization
Stars
279
Forks
59
Bundled files
4
LicenseApache-2.0
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 4 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by mukul975 on GitHub. Read the source before you install it.

Installation

Install the Data Localization AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git /tmp/Privacy-Data-Protection-Skills
mkdir -p .claude/skills
cp -r /tmp/Privacy-Data-Protection-Skills/plugins/cross-border-transfers-skills/skills/data-localization .claude/skills/data-localization
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Data Localization in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Data Localization on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Data Localization is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Implementing Data Localization Requirements

Overview

Data localization laws require that personal data of a country's residents be stored, processed, or both within the territory of that country. These requirements exist independently of and in addition to transfer mechanism requirements under the GDPR. Organisations operating globally must map their data localization obligations by jurisdiction, design infrastructure architectures that comply with local storage mandates, and implement exemption procedures where cross-border transfer is permitted subject to conditions.

Country-Specific Requirements

Russia — Federal Law No. 242-FZ (Amendments to Federal Law No. 152-FZ)

Effective: 1 September 2015

Key requirements:

  • Art. 18(5) of Federal Law 152-FZ (as amended by 242-FZ): When collecting personal data, including via the internet, the data operator must ensure that recording, systematisation, accumulation, storage, modification, extraction, and retrieval of personal data of citizens of the Russian Federation are carried out using databases located in the territory of the Russian Federation.
  • The law applies to any organisation collecting personal data of Russian citizens, regardless of the organisation's location.
  • Cross-border transfer is permitted after initial localization — the primary database must be in Russia, but copies may be transferred abroad subject to Federal Law 152-FZ cross-border transfer rules.

Enforcement:

  • Roskomnadzor (Federal Service for Supervision of Communications) is the enforcement authority.
  • Non-compliance can result in website blocking within Russia, fines (up to RUB 18 million for repeated violations under 2023 amendments), and criminal liability for certain violations.
  • LinkedIn was blocked in Russia in 2016 for non-compliance with 242-FZ.

Athena Global Logistics implementation:

  • Primary HR database for Russian employees hosted on servers in Moscow (OVHcloud Russia data centre, Bolshaya Nikitskaya 22).
  • Customer data from Russian-origin shipments stored primarily in Moscow before replication to the Frankfurt analytics platform.
  • Cross-border transfers from Moscow to Frankfurt covered by Russia's cross-border transfer rules (adequate countries list per Roskomnadzor Order No. 274 or consent of the data subject).

China — PIPL Art. 40 and CAC Measures

Personal Information Protection Law (PIPL) — Effective 1 November 2021

Key requirements:

  • Art. 40: Critical Information Infrastructure Operators (CIIOs) and personal information processors handling personal information reaching the volume threshold specified by the Cyberspace Administration of China (CAC) must store personal information collected and generated within the territory of China domestically. Cross-border transfers require a CAC-administered security assessment.
  • CAC Measures on Security Assessment of Outbound Data Transfers (effective 1 September 2022):
    • Security assessment mandatory for: (a) CIIOs; (b) processors handling personal information of over 1 million individuals; (c) processors that have cumulatively transferred personal information of over 100,000 individuals or sensitive personal information of over 10,000 individuals since 1 January of the preceding year.
    • Assessment conducted by the provincial-level CAC and reviewed by the national CAC.
    • Assessment valid for 2 years; must be re-conducted before expiry or upon material change.
  • CAC Standard Contract Measures (effective 1 June 2023): Personal information processors not subject to the mandatory security assessment may use the CAC-published Standard Contract for cross-border transfers, filed with the provincial CAC within 10 working days of execution.
  • PRC Data Security Law (DSL) Art. 31: Important data collected and generated by CIIOs must be stored domestically.

Athena Global Logistics implementation:

  • China operations process personal information of approximately 15,000 individuals (below the 1 million threshold for mandatory security assessment).
  • Localization: Chinese customer and employee data stored on Alibaba Cloud servers in the Shanghai region.
  • Cross-border transfers: Athena uses the CAC Standard Contract filed with the Shanghai CAC for transfers of logistics data to the Frankfurt headquarters.
  • Personal Information Impact Assessment (PIIA) completed before cross-border transfer per PIPL Art. 55.

India — Digital Personal Data Protection Act 2023 (DPDP Act)

Effective: Provisions being brought into force in phases from 2024.

Key requirements:

  • Section 16(1): The Central Government may, by notification, restrict the transfer of personal data by a significant data fiduciary to any country or territory outside India.
  • Section 16(2): The Central Government may prescribe conditions for cross-border transfer to specific countries.
  • Blacklist approach: India adopts a "blacklist" model — transfers are permitted to all countries except those specifically restricted by government notification. As of March 2026, no blacklist notifications have been issued.
  • Significant Data Fiduciary (SDF): Designation by the Central Government based on volume of data, sensitivity, risk to data principals, and other factors. SDFs face heightened obligations including mandatory DPO appointment and data protection audit.
  • RBI data localization: The Reserve Bank of India mandates that payment system data be stored exclusively in India (RBI Circular DPSS.CO.OD.No.2785, April 2018). This applies to all payment data processed by payment system operators.

Athena Global Logistics implementation:

  • Indian operations data stored on AWS Mumbai region (ap-south-1).
  • Cross-border transfers permitted (no blacklist notification as of March 2026) but monitored for future restrictions.
  • RBI payment localization: Indian payment transaction data processed through local payment gateways with primary storage in India.

Turkey — Law No. 6698 on the Protection of Personal Data (KVKK)

Key requirements:

  • Art. 9: Personal data may be transferred abroad only with the explicit consent of the data subject, or if one of the conditions in Art. 5(2) or Art. 6(3) is met and: (a) the destination country provides adequate protection (per KVKK Board list); or (b) the data controllers in Turkey and the destination country provide a written undertaking of adequate protection and the KVKK Board grants permission.
  • Data Localization: No explicit data localization mandate in KVKK, but the Board Regulation on Data Transfer Abroad (2024 amendment) introduced a notification-based system requiring data controllers to apply to the Board before transferring data to countries not on the adequate list.
  • Practical localization: Many organisations maintain Turkish data in Turkey due to the complexity of the Board approval process for cross-border transfers.

Vietnam — Decree 13/2023/ND-CP on Personal Data Protection

Effective: 1 July 2023

Key requirements:

  • Art. 25(4): Data controllers and processors transferring personal data abroad must prepare and maintain a transfer impact assessment dossier.
  • Art. 26: The transfer impact assessment dossier must be submitted to the Ministry of Public Security within 60 days of processing.
  • No strict localization: Vietnam does not mandate data localization for most personal data, but the Cybersecurity Law (2018) Art. 26(3) requires storage of certain data in Vietnam for companies providing services on telecommunications networks or the internet where the data relates to national security, social order, or cybersecurity.

Indonesia — Government Regulation No. 71/2019 (GR 71)

Key requirements:

  • Art. 20: Public electronic system operators must place their electronic systems and data in Indonesia for the purpose of supervision, law enforcement, data access protection, and national security.
  • Art. 21: Private electronic system operators may place their systems and data outside Indonesia, provided they grant access for supervision and law enforcement.
  • Practical impact: Government and public sector data must be stored in Indonesia; private sector data may be stored abroad with access provisions.

Localization Architecture Design

Pattern 1: Primary Local Storage with Replication

┌───────────────────┐     Replication     ┌──────────────────┐
│ Local Data Centre  │ ─────────────────→  │ Central EU DC    │
│ (Country Required) │    (encrypted,      │ (Frankfurt)      │
│ Primary database   │     compliant       │ Analytics,       │
│ All CRUD operations│     transfer)       │ Reporting        │
└───────────────────┘                      └──────────────────┘

Use case: Russia (242-FZ), China (PIPL Art. 40 for CIIOs) Implementation: All create, read, update, delete operations occur on the local database. Encrypted replication to central EU systems for analytics and group reporting, subject to local cross-border transfer rules.

Pattern 2: Local Processing with Central Analytics

┌───────────────────┐     Aggregated/     ┌──────────────────┐
│ Local Instance     │     Anonymised     │ Central EU DC    │
│ Full processing    │ ─────────────────→ │ Only aggregated  │
│ in-country         │                    │ or anonymised    │
└───────────────────┘                     │ data received    │
                                          └──────────────────┘

Use case: Strict localization without cross-border transfer approval (pre-CAC filing in China) Implementation: All personal data processing occurs locally; only aggregated or anonymised data (not personal data) is transferred centrally.

Pattern 3: Hybrid Cloud with Data Residency Controls

┌───────────────────┐
│ Cloud Provider     │
│ Local Region       │ ← Data residency policy enforced
│ (e.g., AWS Mumbai) │   via cloud service configuration
│ Personal data      │
│ stored here only   │
└───────────────────┘
     │ (API access from EU for administration; no data egress)
┌───────────────────┐
│ Central EU DC      │
│ Application logic  │
│ No local PD stored │
└───────────────────┘

Use case: India (DPDP Act), Indonesia (GR 71 private sector) Implementation: Cloud provider's local region stores personal data; application logic may run centrally but personal data does not leave the local region.

Localization Compliance Checklist

JurisdictionStorage RequirementTransfer ConditionsFiling/ApprovalEnforcement Authority
RussiaPrimary DB in RussiaPermitted after localization; subject to 152-FZ transfer rulesNo filing required for localizationRoskomnadzor
China (CIIO/threshold)Domestic storageCAC security assessment or Standard ContractSecurity assessment filed with CAC; Standard Contract filed within 10 daysCAC
IndiaNo localization (yet)Permitted except to blacklisted countriesNo filing (monitor for future requirements)Data Protection Board of India
India (RBI)Payment data in IndiaNot permitted for payment dataRBI compliance reportingReserve Bank of India
TurkeyNo explicit localizationBoard approval or adequate country listBoard application for non-adequate countriesKVKK Board
VietnamCertain data in VietnamImpact assessment requiredDossier to Ministry of Public Security within 60 daysMinistry of Public Security
Indonesia (public)In IndonesiaLimited exceptionsNo specific filingMinistry of Communication
Indonesia (private)May be abroadAccess for supervision requiredNo specific filingMinistry of Communication

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Data Localization AI skill do?

Guides compliance with country-specific data localization requirements across key jurisdictions including Russia (242-FZ), China (PIPL Art. 40, CAC measures), India (DPDP Act), Turkey, Vietnam, and Indonesia. Covers localization assessment, architecture design, and exemption procedures. Keywords: data localization, data residency, PIPL, 242-FZ, cross-border restrictions.

Why use Data Localization on TypingMind?

Because you install it once and use it with any model. Data Localization is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Data Localization in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/cross-border-transfers-skills/skills/data-localization. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Data Localization?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Data Localization?

As many as you like. As long as a model supports skills, you can use Data Localization with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Data Localization AI skill free?

Yes. It is published on GitHub by mukul975 under the Apache-2.0 license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇