In orbit: the legal implications of data centres in space

Wednesday 15 July 2026

João Lupi
Associated Partner & Co-Head of Space & Satellites, Abreu Advogados, Lisbon
joao.lupi@abreuadvogados.com

Leonor de Sá e Frade
Associate, Abreu Advogados, Lisbon
leonor.s.frade@abreuadvogados.com

Introduction: data centres in space

In-orbit data centres have emerged as a next frontier for space infrastructure and the data economy.

Backed by a global data-centre market expected to reach €535bn by 2030, and the European Space Policy Institute describing the ability to process information directly in space via satellites as the 'backbone' of the second digital age, the commercial logic is clear.

By moving processing, filtering and decision-making closer to the data source, satellite operators can reduce latency, limit the volume of raw data transmitted to Earth and take advantage of solar energy and naturally low temperatures in orbit.

Yet with opportunity comes complexity. Once data is collected, processed or stored in orbit, issues of jurisdiction, applicable law, cybersecurity, data protection, liability and licensing must be addressed in an environment designed around state-led space activity rather than commercial digital services.

Where artificial intelligence is used in orbit, regulations such as the European Union Artificial Intelligence Act (the ‘AI Act’) may also become relevant.

As an additional piece to this puzzle, and despite the current uncertainty of its final layout, the proposed EU Space Act will likely not regulate data centres in space specifically, but it does address space activities, space services and the first processing of space-based data.

This article maps the main legal issues that operators, investors and advisers should monitor.

Legal and regulatory framework for in-orbit data centres

Data centres are facilities used to store, manage and process large volumes of digital data. In orbit, they may be embedded in satellites or satellite constellations, especially in low Earth orbit, and connected to ground segment and communications infrastructure.

The orbital environment can offer advantages that are difficult to replicate on Earth: continuous or near-continuous solar power, passive cooling, wide network coverage and proximity to space-generated data. It may also reduce pressure from land constraints, grid capacity and local opposition to terrestrial data centres.

Market activity is already visible. SpaceX’s Starlink constellation integrates in-orbit data cleaning and labelling with intelligent traffic rerouting and intersatellite laser links, and most recently, SpaceX’s May 2026 S-1 filing for its initial public offering (IPO) disclosed plans to deploy solar-powered orbital data centres as early as 2028, with pilot testing of on-orbit compute nodes on Starlink V3 hardware scheduled for 2026.

In turn, and among others worth mentioning, Adaspace announced in 2025 that 12 satellites could enable data transmission at speeds of 100 Gb/second, while Google announced in May 2026 a partnership with SpaceX to ‘launch data centers in orbit’.[1]

For operators, however, the opportunity is tied to compliance. Space, data protection, cybersecurity, telecoms, environmental and AI rules may all be relevant, and risk allocation should be addressed across launch, satellite operation, ground monitoring, processing, storage and downstream customer contracts.

Existing legal framework and distribution of risk

In-orbit data centres operate in the physical vacuum of outer space, but not in a regulatory vacuum.

The applicable framework is multilayered, combining international treaties, national licensing regimes and sector-specific regulation.

Before launching or using these services, operators should map whether they qualify as space operators, primary providers of space-based data, processors, controllers, electronic communications providers or critical ICT providers.

They should also identify whether the relevant hardware, software and ground systems form a space object, hybrid infrastructure or supporting service.

Where so, jurisdiction begins with the State of Registry. Under Article VIII of the Outer Space Treaty, read with the Registration Convention, the state in whose registry a space object is recorded retains jurisdiction and control over that object and its personnel. Registry hence determines the first layer of applicable rules for licensing, supervision, data protection, cybersecurity, environmental duties and sanctions.

In constellations built through cross-border supply chains, operators should expect overlapping or competing claims of regulatory authority.

To provide a practical example, if personal data of EU residents is processed in orbit on a satellite registered in a third country, it must be considered whether that processing amounts to an international transfer under Chapter V of the General Data Protection Regulation (GDPR). If it does, safeguards under Articles 46 or 49 of the GDPR may be required: a potentially difficult fit for real-time, automated in-orbit processing.

From an EU cybersecurity standpoint, the Network and Information Security 2 (NIS2) Directive and its national transpositions apply to space and digital infrastructure, as well as to electronic communications providers, while the Digital Operational Resilience Act (DORA) may become relevant where EU financial entities rely on in-orbit data centres as critical information and communication technology (ICT) third-party providers.

The EU AI Act may add further obligations where in-orbit systems perform high-risk AI functions.

Liability is also fragmented. Under the Outer Space Treaty and the Liability Convention, launching states may be liable for damage caused by space objects, with strict liability for damage on Earth and fault-based liability for damage in outer space.

Those instruments were designed for physical damage, not for the losses most likely to arise in data centre operations, such as data breaches, service interruption or loss of stored data.

Contractual risk allocation is therefore central. Launch agreements, satellite-operation contracts, cloud or edge-processing terms, customer agreements and insurance arrangements should address liability caps, indemnities, service levels, cybersecurity incidents, data loss, audit rights and rights of recourse across the value chain.

Data centres in the upcoming EU Space Act

The proposed EU Space Act seeks to regulate space activities around safety, resilience and sustainability. It also recognises outer space as part of the data economy, referring in Recital 22 to space data services ‘for the benefit of the entire economy and citizens’.

For in-orbit data centres, the key concept is the ‘primary provider of space-based data’. As it currently stands, the overall stabilised definition captures operators that perform the first processing of space-based data to enable subsequent downstream provision, while ‘space-based data’ appears broadly defined as data received from outer space.

This definition may cover operators that collect, store and first-process data through satellite networks, while eventually affecting telecoms or digital infrastructure groups that use satellite facilities or operate satellites directly, since the same entity may qualify both as space operator and primary data provider.

Article 27 is particularly important for market access. Primary providers may provide space-based data in the Union only where the data has been generated by space objects registered in the Union registry. They must also respond to alerts or complaints concerning potentially unregistered or non-compliant sources and inform suppliers or competent authorities where appropriate.

Material coordination problems are likely to arise from the EU Space Act in the currently proposed designs. Indeed, radio spectrum allocation and authorisation is excluded through Recital 22, leaving operators to align EU Space Act obligations with telecoms regulation and International Telecommunication Union Radio Regulations on frequencies, inter-satellite links and orbital coordination.

This means that an operator fully compliant with the EU Space Act may still face separate licensing and coordination requirements for the radio frequencies on which its data centre constellation depends, creating a risk of regulatory gaps or conflicting timelines.

Other EU digital legislation will need to be considered in parallel.

The Data Act may be relevant for access and usage purposes of data generated by connected products and related services, while GDPR, NIS2, DORA and the AI Act may apply depending on the role of the operator and the customers served.

Operators will often face cumulative obligations under several of these different regimes. As such, early regulatory mapping and cross-functional compliance planning will be of the essence.

Conclusion: impacts and challenges for the data market

The EU Space Act legislative process remains dynamic.

The analysis above is based on careful consideration of the several versions of the EU Space Act, while its detailed content remains uncertain. Subsequent versions and in particular the trilogue stage may adjust definitions, registry requirements or the scope of obligations for primary providers.

Operators should closely monitor developments as the proposal moves through the ordinary legislative procedure.

In-orbit data centres promise energy efficiency, lower latency and new forms of data autonomy, while also exposing gaps in the legal architecture: the Liability Convention does not address purely economic losses; GDPR treatment of in-orbit processing remains uncertain; and the interaction between space, telecoms, cybersecurity, AI and data-sharing rules is still largely untested.

For practitioners, the immediate task is practical rather than theoretical. Operators and advisers should:

  • identify the State of Registry and licensing perimeter;
  • map roles under space, data, cybersecurity, telecoms, AI and financial-sector rules;
  • build contractual protections for data loss, outages and third-party claims;
  • align insurance with operational risk; and
  • monitor the EU Space Act as it moves through the legislative process.

Until international frameworks catch up with commercial innovation, contract and foresight remain the practitioner's strongest tools. As in-orbit data centres move from science fiction to commercial reality, the legal architecture must evolve to match.


[1] Wall Street Journal, ‘SpaceX and Google Are in Talks to Launch Data Centers in Orbit’: see www.wsj.com/tech/spacex-google-in-talks-to-explore-data-centers-in-orbit-7b7799e2