Abstract:Data Localization and privacy protection of cross-border e-commerce are emerging and unresolved issues nowadays in the field of international trade law. Although the two cases, Schrems I and Schrems II as well as United States v. Microsoft Corp., did not directly create data localization regulations, they highlighted the irreconcilably different approaches of US and EU to data privacy, and eliminated effective solutions for cross-border data transfer, thus made data localization the only remaining elastic one. While the future of WTO e-commerce negotiation is unclear, the new RTAs represented by CPTPP e-commerce rules and USMCA Digital Trade rules prohibit Data Localization and forced disclosure of source code, which has potential to form a model of global cross-border E-commerce rules. Cross-border data flows and data localization measures should be effectively regulated based on data types effectively, while legal public policy exceptions being defined in the future model regional E-commerce norms. This is significant regional modernization of rule of law to bridge the fragmentation of cross-border E-commerce rules.