A photograph taken on a phone in one country can be stored on a server in a second, processed by artificial intelligence services run by a company headquartered in a third, and viewed a moment later by someone in a fourth, the entire sequence taking place in less time than it takes to read this sentence. Ask, of that photograph, whose law governs it, and the honest answer is that several laws might reasonably claim to -- an outcome ordinary property law never had to seriously confront, because a physical object sits in exactly one place at a time, and the law of that one place has always had a comparatively straightforward claim to govern it. Data behaves differently. It can be, in every sense that matters legally, simultaneously subject to the jurisdiction of the country whose citizen it describes, the country where the company handling it is headquartered, and the country where the physical server happens to sit, three claims that data's cross-border movement makes all equally plausible and none obviously decisive.
Consider a company headquartered in Country A that stores personal data belonging to a citizen of Country B on a server physically located in Country C. A law-enforcement request from Country A's government, a privacy statute passed by Country B to protect its own citizens, and a data-protection regulation Country C applies to any server sitting within its own territory can each, entirely in good faith, claim to govern access to the identical data at the identical moment. None of the three claims is obviously wrong on its own terms -- headquarters jurisdiction, citizenship jurisdiction, and physical-location jurisdiction are all genuine, recognised bases for asserting legal authority -- and the conflict between them has no built-in resolution the way a dispute over a single physical object, sitting in a single physical place, generally would.
Data localisation requirements emerged as one government response to exactly this problem. A country that requires data about its own citizens, or data generated within its own territory, to be stored on servers physically located within its own borders is doing something specific: guaranteeing that at least one of the three competing jurisdictional claims -- the physical-location claim -- will always coincide with its own authority. For a government watching its jurisdiction erode as data crosses borders it can neither see nor control, localisation offers something like the clean, single-location simplicity ordinary property law has always taken for granted, reasserted by brute physical requirement rather than recovered by any change in the underlying nature of data itself.
This solution carries real costs. Requiring separate physical infrastructure in every country that mandates localisation considerably increases the expense of running a service that would otherwise operate from a small number of efficient, centralised data centres, and can fragment what was once a single global service into a patchwork of country-specific versions maintained at extra cost. More troublingly, the same compliance mechanics -- data must sit on a server physically within this country's borders -- can serve two entirely opposite underlying purposes depending on who is doing the requiring. In one government's hands, localisation genuinely protects citizens by keeping their data outside a foreign jurisdiction whose privacy protections may be considerably weaker. In another government's hands, the identical requirement guarantees that country's own law enforcement agencies permanent, convenient physical access to data they might otherwise have had to request through a slower, more accountable cross-border legal process. The two purposes look identical from the outside, since the compliance requirement itself does not change, and only the government's own subsequent conduct actually reveals which purpose was really being served.
Data localisation, properly understood, does not really solve the underlying jurisdictional problem so much as relocate it. Data about a citizen of Country B, stored under Country A's localisation mandate on a server within Country A's own borders, has not stopped being data Country B's own citizenship-based privacy law still claims to govern -- it has simply added a fourth, physically enforced claim on top of the three that already existed, rather than resolving the conflict between any of them. The recurring pattern across every proposed solution is the same: sovereignty, and the law built on top of it, was designed for a world of located physical objects, and data, which has no honest single location in the sense that matters for jurisdiction, keeps forcing the law to choose which of several genuinely competing claims to treat as controlling, localisation included.