Data Colonialism Persists as International Privacy Law Fails Global South, Scholars Argue

A growing body of legal scholarship argues that the current international framework for data protection is structurally incapable of addressing the transnational extraction of personal data from the Global South. Scholars describe this phenomenon as "data colonialism"—a modern iteration of historical resource extraction, where raw data generated by users in developing countries is transferred, processed, and monetized by corporations headquartered in wealthy jurisdictions, leaving originating communities with neither control nor meaningful benefit.

The critique targets the patchwork of domestic privacy statutes—including the European Union's General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA), and China's Personal Information Protection Law (PIPL)—which operate within territorial boundaries while the harm they seek to remedy is inherently cross-border. Mechanisms like the GDPR's adequacy decisions function less as neutral safeguards and more as instruments of digital diplomacy, extending a small circle of "trusted" jurisdictions that largely coincide with existing economic power centers.

Historical Parallels and the Data Colonialism Framework

The analytical lens draws heavily from Third World Approaches to International Law (TWAIL), whose scholars have long argued that international law was constructed to facilitate colonial extraction. Writers like Antony Anghie and B.S. Chimni have shown how doctrines justifying nineteenth-century resource extraction persisted through trade agreements and investment treaties that continue to structure unequal North-South relations. The data colonialism framework, developed by Nick Couldry and Ulises Mejías in their book The Costs of Connection , applies this logic to the digital economy: human life becomes an input into industrial production through continuous, largely invisible data capture.

Under this framing, the "digital footprint" is not an incidental byproduct of internet use but the raw material of a new extractive economy. Social media platforms, mobile applications, and cloud services function analogously to the trading companies and extraction concessions of the colonial era. The harm is not merely economic inequality but a relational one—a new social order where the originating community lacks agency over either process or proceeds.

The Legal Architecture: A Patchwork Designed for Data Importers

The GDPR is often held up as a global gold standard, yet its cross-border transfer mechanisms reveal a Northern-centric design. Article 45 allows the European Commission to recognize a third country as offering adequate protection, permitting data flows without additional safeguards. In the absence of such a decision, transfers require Standard Contractual Clauses or Binding Corporate Rules—mechanisms that impose significant compliance costs, disproportionately burdening smaller entities and developing-country data processors.

India's DPDPA, enacted in 2023, represents a genuine advance within its jurisdiction. It regulates how data fiduciaries process personal data of individuals in India and imposes conditions on cross-border transfers. However, it has no mechanism to compel a foreign recipient—such as a cloud provider headquartered in California—to adhere to Indian standards once data has left Indian territory. Enforcement depends heavily on the recipient jurisdiction's willingness to cooperate, which is itself a function of relative bargaining power. This is not a unique flaw; it is an inherent limitation of any domestically legislated privacy framework operating in an international vacuum.

Case Study: India's Scale Without Leverage

India presents a particularly instructive case. The Aadhaar biometric identification system, linked to a vast array of government and private services, has created one of the world's largest centralized repositories of biometric and demographic data. The broader ecosystem—digital payment platforms, fintech applications, data-driven service providers—routes significant volumes of Indian user data through cloud infrastructure operated by foreign technology firms. The DPDPA regulates this processing only up to the point of transfer; beyond that, Indian data subjects have limited practical recourse against a foreign processor's downstream use of their data.

The result is a scale paradox: India generates data volumes rivaling or exceeding any single Western economy, yet lacks the adequacy status, mutual enforcement treaties, or comparable leverage to negotiate the terms of that data's international treatment on equal footing. The same dynamic applies across much of the Global South.

The Global AI Data Labour Supply Chain

A rapidly growing but less visible form of extraction involves the human labor required to make AI systems function. Large AI companies rely on outsourced content moderation and data labeling workforces in Kenya and other low-income countries. These workers interpret, filter, and moderate raw data used to train AI models, frequently for low wages and with significant psychological exposure to disturbing content. The resulting models and the value they generate are owned and monetized entirely by firms headquartered in wealthy jurisdictions.

This case study extends the data colonialism framework beyond personal data to the broader data supply chain supporting the global AI economy. The extraction pattern is not limited to passive data collection from ordinary users; it encompasses the active labor of Global South workers whose contribution to refining and validating data receives a fraction of the value it ultimately creates.

A Binding International Privacy Rule: Lessons from the Nagoya Protocol

International law has confronted a structurally similar problem in a different domain: the extraction of genetic resources and associated traditional knowledge. Historically, pharmaceutical and agricultural companies based in the Global North took such resources from biodiversity-rich developing countries without compensation flowing back to the communities of origin. The Nagoya Protocol to the Convention on Biological Diversity, adopted in 2010, responded by establishing binding principles of access and benefit-sharing. A country providing genetic resources is entitled to a share of the benefits arising from their commercial use, and prior informed consent is required before access is granted.

While genetic resources are limited and physically bounded in a way data is not, the Protocol's underlying legal architecture is transferable. It establishes that resources of significant value to global commerce generate an obligation of benefit-sharing running back to the point of origin. A binding international privacy regime could adopt an analogous structure.

Core Principles for a Proposed Rule

The article outlines three core principles for such a regime:

  1. Affirmative recognition of data sovereignty as a standalone principle of international law—not merely a permitted exception to trade liberalization, but a right co-equal to the free flow of data, requiring the two to be balanced.

  2. Mandatory cross-border data impact assessments , modeled on environmental impact assessment regimes in international environmental law. Entities transferring data out of a lower-capacity jurisdiction would be required to assess and disclose the human rights and developmental implications of that transfer before it occurs.

  3. A benefit-sharing mechanism ensuring that value generated from data or data labor originating in the Global South is not captured entirely by the processing jurisdiction.

Feasibility and the Path Forward

The most obvious objection is political feasibility. The United States and China, the two jurisdictions with the greatest capacity to process global data, have historically resisted binding multilateral data governance instruments that would constrain their domestic technology sectors. Any treaty lacking their participation would address only a fraction of the problem.

However, the same objection could have been raised against early efforts toward the Nagoya Protocol, the Paris Agreement, and other multilateral instruments that were eventually joined, however imperfectly, by major economic powers once a critical mass of developing and middle-power states coalesced around a shared normative framework.

For legal practitioners, the implications are significant. If the data colonialism framework gains traction, it could reshape how cross-border data transfer agreements are drafted, how impact assessments are conducted, and how benefit-sharing obligations are enforced. The conversation is no longer about privacy as a right or a market trust mechanism; it is about correcting a structural imbalance at a civilizational scale. The Global South's digital footprint may finally find its legal standing.