Is your data truly yours? India's sovereignty struggle with foreign cloud providers and AI
Indian enterprises now prioritize data sovereignty over cost and scale in cloud procurement. New regulations and geopolitical shifts highlight the importance of data control. Data residency does not guarantee jurisdictional independence from for...

His answer was: 'No, I cannot guarantee that, but, again, it has never happened before.' Not surprisingly, the second part of his response revealed more than it hid. It makes one ponder, is that where vendors will retreat.
Also read: India AI policy: Pragmatism before sovereignty
The fact is that a guarantee cannot be given. A dataset can live in a data centre near you and still be reachable, in principle, by a foreign government. The location of your data and the law that governs it are not the same thing. Residency is not sovereignty. Everything else follows from that distinction.
For most of the cloud era, Indian enterprises optimised for cost, scale & reliability. Three forces have dragged sovereignty into ordinary procurement:
Regulation: With Digital Personal Data Protection Act and DPDP Rules notified in November 2025, a decade of debate became a compliance obligation, one carrying penalties up to ₹250 cr for security failures and ₹200 cr for breach-notification lapses, phasing to full enforcement by mid-2027. Boards need to start asking where regulated data sits and who can be compelled to disclose it.
Geopolitical: Governments have stopped treating cloud and AI compute as commodity utilities and started treating them as strategic infrastructure. GoI's 'Aatmanirbhar Bharat' and IndiaAI Mission reflect a view that dependence on foreign-controlled infrastructure is a national risk, not merely a commercial one.
AI compute race: This concentrates enormous value in a handful of providers and chips, determining where inference and training run and under whose law, resulting in a sovereignty question of its own.
The most common error in Indian procurement is to treat 'our data is in Mumbai' as though it answered the sovereignty question. It answers the residency question and leaves the two that matter - 'Who controls the provider?' and 'Who can lawfully compel it?'- untouched.
A related myth is worth clearing up. India did not mandate blanket data localisation. Under DPDP framework, personal data may leave the country, unless GoI restricts a destination or category. This is a negative-list model, with hard localisation confined to sector-specific rules, such as RBI's payment-data directive, Sebi cloud framework and UIDAI's Aadhaar vaults.
The CLOUD (Clarifying Lawful Overseas Use of Data) Act, 2018, allows US authorities to compel any provider under US jurisdiction to produce data in its possession, custody or control, irrespective of where it is stored. The test is control, not location. FISA's (Foreign Intelligence Surveillance Act) Section 702 adds a surveillance authority over non-US persons' data with limited transparency.
This is not an accusation against a provider's integrity or engineering. Hyperscalers have committed tens of billions of dollars to Indian infrastructure. Their limitation on strict sovereignty is not about effort or features. It is structural, not a gap that clever drafting can close. A US-controlled company remains subject to US jurisdiction, however excellent its Indian region.
Also read: When the cloud gets thirsty: Should India make AI pay back its water debt?
Nowhere is the gap between rhetoric and architecture wider than in AI. Despite India's ambition for sovereign AI and putting real money behind it - more than 38,000 subsidised GPUs empanelled across domestic providers and a stated goal of 1 lakh by end-2026 - much of India's DPI and emerging AI stack still runs on foreign-controlled cloud. The real questions for an AI workload are who controls the compute, model weights and training data, and under whose law.
Choosing Indian-controlled providers costs something. A narrower catalogue, fewer managed services, a less developed third-party ecosystem. Buyers must weigh jurisdictional independence against functional capability. For government, defence and critical-infrastructure workloads, sovereignty outweighs the catalogue gap.
The economics help. Indian-native providers commonly price 30-60% below hyperscaler list rates for comparable steady-state workloads, often with lower or zero egress fees reshaping total cost of ownership and widening the range of deployments where the sovereign choice is viable.
India certifies cloud providers through MeitY's STQC (Standardisation Testing and Quality Certification)-audited empanelment. Since 2026, a cloud-selection framework directs ministries to match workloads to deployment options by sensitivity. This empanelment attests to security, quality and data localisation, but not jurisdictional control. US-headquartered hyperscalers are empanelled, too.
What India lacks is a certification that grades sovereignty itself. Until it has one, procurement teams must do their own diligence and score it rather than accept a label. The discipline is to rate every shortlisted provider, incumbent hyperscaler and domestic challenger alike on the same axes, each from 0 to 3:
0: Property is absent or rests entirely with a foreign-jurisdiction entity.
1: It rests on a vendor promise that can be withdrawn.
2: It's enforced in practice but incomplete.
3: Architecture, ownership or law puts it beyond the reach of any single party or foreign demand
Policymakers need to define sovereignty formally. A certification, distinct from security empanelment, would make claims comparable. Sovereignty is maturing from a slogan into a set of verifiable jurisdiction, key control, in-country operations, ownership of logs and a clean exit. Buyers and providers who treat it that way will be the ones left holding a defensible position.
Agrawal is MD-CEO, Esconet Technologies. Chugh is an independent adviser
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.