Will In-Space Data Centers Take Privacy Laws Beyond Earth?

  • Print Page

Washington Lawyer September/October 2026
By Francesca Giannoni-Crystal

Space satellite

With data center projects facing local opposition due to land use issues, environmental impact, and infrastructure strain, as well as regulatory and political risks, space may be the final frontier.

Influential tech entrepreneurs have proposed an alternative: the development of large-scale data centers in space. Google has concrete plans to deploy a network of solar-powered satellites carrying tensor processing units. Lonestar Data Holdings — which already deployed a payload to the Moon in early 2025 with a prototype of a data center — has partnered with Sidus Space to build the first StarVault payload, targeted for launch in October. And NASA's Artemis program, within its broader lunar infrastructure planning, is contemplating data center architectures.

The debate over the technical feasibility and advantages of in-space data centers is ongoing. Some experts point to significant obstacles, including maintenance and repair challenges, exposure to radiation and micrometeoroids, signal delay (specific to the Moon) limiting real-time applications, and broader doubts about launch costs and scalability. Conversely, other experts emphasize significant advantages for both lunar and orbital data centers: lower cooling needs, abundant solar energy, resilience against terrestrial disruptions, reduced climate interference, and modular scalability that may cut costs compared to Earth-based systems.

However, beyond engineering and economics issues are important questions of legal exposure regarding privacy. This article focuses on the application of multiple privacy regimes — U.S. state laws and the European Union General Data Protection Regulation (GDPR) — to in-space data centers.

Privacy in Space

Serving as a starting point, Article II of the Outer Space Treaty (OST) states that "[o]uter space, including the moon and other celestial bodies, is not subject to national appropriation by claim of sovereignty, by means of use or occupation, or by any other means." However, the absence of sovereignty still allows the application of legal frameworks that do not depend on territorial control. Several privacy laws, for example, are not predicated on where a company is headquartered, where infrastructure is located, or where data is stored or processed. Instead, they are centered on protecting the residents of the issuing nation. Thus, privacy laws may also apply when processing occurs in orbit or on the Moon.

In the United States, data breach notification obligations are generally triggered by the residence of the affected individuals. For example, New York's Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) requires notification when a business holds the private information of a New York resident and that information is breached. Similarly, California data breach notification statute (Cal. Civ. Code § 1798.82) applies when a breach involves the personal information of California residents, even if the company involved is headquartered elsewhere.

The same reasoning could extend to data processed in outer space. If an in-space data center holds personal information of residents of a U.S. state with a given privacy law and that data is compromised, the breach notification statute of the relevant state could still apply.

Note that some privacy laws impose compliance obligations beyond breach notification, including the duty to maintain reasonable security measures (e.g., Cal. Civ. Code § 1798.81.5(b)). Those obligations may also extend to out-of-state entities, including operators of in-space data centers.

The GDPR governs personal-data processing as such, imposing continuous obligations across the processing lifecycle and asserting extraterritorial reach in every case in which it applies, pursuant to Article 3. Indeed, the GDPR generally requires full compliance with its substantive framework, not merely discrete obligations tied to specific events, including lawful basis (Article 6), transparency (Articles 12–14), data minimization (Article 5(1)(c)), security (Article 32), and accountability (Article 5(2)). Therefore, once the conditions for the application of the GDPR under Article 3 are satisfied, the law may extend to entities operating entirely outside the EU (including, conceivably, in-space data centers) and subject them to a far broader regulatory regime than U.S. state laws.

The GDPR provides four independent bases for determining its applicability. First, the GDPR applies to data processing "in the context of the activities of an establishment" in the EU, regardless of where the processing occurs (Article 3(1)). "Establishment implies the effective and real exercise of activity through stable arrangements," irrespective of legal form, according to GDPR Recital 22. In the landmark 2015 Weltimmo decision, the Court of Justice of the European Union (CJEU) adopted a functional approach, holding that even limited activities in an EU member state may suffice.

Similarly, in a 2014 decision against Google Spain, the CJEU held that processing by a U.S. company fell within EU data protection law because it was sufficiently intertwined economically with the activities of its Spanish subsidiary. European Data Protection Board (EDPB) Guidelines 3/2018 on the Territorial Scope of the GDPR confirm this broad interpretation. Accordingly, the GDPR may apply to a company operating a lunar data center if it maintains even a minimal but stable EU connection, including through EU-based infrastructure, partnerships, or promotional activities.

Second, companies with no EU establishment may fall within the GDPR scope if they offer goods or services to individuals in the EU, often referred to as "targeting." This provision is interpreted broadly, with both the EDPB and the CJEU confirming that even minimal engagement may suffice, provided the outreach is intentional. Relevant indicators include the use of an EU language or currency, references to EU users, or the ability to provide services to EU residents.

Orbital and lunar data centers marketing their services to European clients (EU institutions, universities, aerospace firms, or consortia), accepting euro payments, or using EU languages could satisfy the targeting requirement. For example, a lunar data center promoting backup or disaster-recovery services to EU customers or collaborating with EU-based researchers or firms would need to comply with the GDPR.

Third, certain monitoring activities (such as tracking through profiling, location data, or similar tools) may trigger GDPR application where EU residents are involved and when personal data is used to analyze or predict conduct, preferences, or attitudes, according to GDPR Article 3(2)(b). The monitoring extends beyond the internet and turns on whether it seeks to assess or influence behavior. Monitoring must be intentional, not incidental.

Space-based systems, including remote sensing, may fall within this provision. Current Earth observation projects focus on environmental data only indirectly linked to individuals, but missions to support astronauts already involve biometric monitoring. If in-space data centers take part in monitoring EU residents (e.g., predictive analytics on EU-origin information), the GDPR may apply.

Fourth, the GDPR (Article 3(3)) may apply where the law of a member state governs by virtue of public international law, as is the case for embassies and consulates. Although the CJEU has not yet addressed the provision, EDPB Guidelines 3/2018 confirmed that the GDPR encompasses situations where member state law applies, including diplomatic missions, consular posts, and vessels registered in a member state. This reasoning arguably extends to outer space. OST Article VIII assigns jurisdiction and control over a space object to its state of registry. Accordingly, the GDPR would arguably apply to a data center hosted on a payload registered by an EU member state. This approach parallels the 1998 Intergovernmental Agreement on the International Space Station, under which each partner retains jurisdiction and control over its modules and personnel, allowing the GDPR to apply to processing carried out in an EU partner's module.

Effective Enforcement

With reference to privacy laws and nonresident entities, a misalignment often exists between prescriptive jurisdiction (i.e., the authority to regulate) and enforcement jurisdiction (i.e., the ability to enforce). In space, this misalignment may be further compounded.

Take, for example, the SHIELD Act, the enforcement of which is operated by the Office of the New York State Attorney General. In most cases, enforcement of a data breach is feasible because companies processing New York residents' data operate and have assets in New York or at least in the United States — or they maintain commercial contacts that allow regulators to assert jurisdiction. Generally speaking, enforcement is possible against nonresident companies when they serve New York residents or maintain contacts with the state, which provides leverage for cooperation or settlement. And as the 2017 Equifax breach proved, sometimes enforcement is multistate.

Enforcement of the GDPR, which relies on data protection authorities (DPAs) in each EU member state, is not an easy road. As stated in the EDPB's 2024 Report on Extraterritorial Enforcement of GDPR, "the lawfulness of the assertion of this extraterritorial jurisdiction under international law is questionable at best, and practical enforcement of these provisions by the DPAs or courts against entities without any property within the EU's territory seems very difficult, if not impossible." For example, in 2025, when the Italian DPA sought information from and ordered a suspension against the Chinese chatbot service DeepSeek (an uncooperative company with no EU presence), the action stalled. The app was removed from app stores, but the website remained accessible. In its proceeding against OpenAI, the Italian DPA obtained initial voluntary compliance, but the Court of Rome overruled its €15 million fine in March 2026.

These cases illustrate that effective enforcement becomes uncertain when operators lack meaningful contacts with the regulating jurisdiction and refuse to cooperate, a problem likely to be compounded for space processing. That said, at least in the near future, data center operators will not function exclusively from space. Some territorial nexus will exist through ground stations, assets, or market presence in one or more jurisdictions. Privacy enforcement against in-space data centers will be therefore feasible — the key question is simply where.

As space infrastructure matures, particularly if inter-satellite links reduce reliance on ground stations or if other space-to-space solutions emerge, operators may become self-sufficient enough to sever meaningful jurisdictional contacts, at which point enforcement would require new legal tools. In the meantime, it would be prudent for data center projects to incorporate privacy considerations from the outset, treating them as a design constraint rather than an afterthought.

Francesca Giannoni-Crystal of Crystal & Giannoni-Crystal LLC advises law firms and companies across various industries (including aerospace and defense) on privacy, ethics, international, and space law. A portion of this article originally appeared in the Spring 2026 edition of South Carolina Lawyer magazine. Reprinted with permission.

Photo courtesy of Official Intuitive Machines Photos, Creative Commons, CC BY-NC-ND 2.0

Skyline