India’s Data-Sovereignty Debate: Beyond Residency to National Resilience

India’s Data-Sovereignty Debate: Beyond Residency to National Resilience

India’s data-sovereignty debate is entering a more consequential phase. The country is generating vast volumes of data, building digital public infrastructure and developing domestic artificial intelligence models. But much of the infrastructure required to store, process, secure and operate these systems remains connected to global technology providers and supply chains.

That dependence is becoming more significant as geopolitical conflicts begin to affect digital infrastructure directly. Data centres, cloud platforms, connectivity networks and AI systems are no longer merely commercial assets. They are increasingly part of a country’s strategic and economic infrastructure.

This has shifted the concern for India from where its data is stored to whether the country has control over its data and digital systems when foreign laws, sanctions, cyberattacks, supply-chain restrictions, or armed conflict disrupt the technology ecosystem. 

The Cases That Exposed Jurisdictional Risk 

The practical implications of this issue were visible in the Nayara Energy–Microsoft dispute in 2025.

Microsoft restricted Nayara Energy’s access to services including Outlook, Teams and other cloud-based tools after sanctions connected to the company’s ownership structure. The dispute raised questions about whether an Indian company could lose access to its communication and cloud services because of legal or regulatory decisions originating outside India.

Nayara approached the Delhi High Court, after which access was restored. This incident showed that data does not necessarily have to leave India for a sovereignty concern to emerge. A customer may retain physical custody of its data while losing practical access to the systems through which that data is used.

However, the case raises several questions relevant to critical sectors, such as: Can a foreign cloud provider suspend an Indian customer’s access due to external sanctions? How much notice must the customer receive? Can the customer access and export its data during a suspension? Are backups and recovery tools controlled by the customer or the provider? How quickly can the organisation shift to another platform?

In India, the problem is not limited to one company or sector, as all sectors, including banks, manufacturers, hospitals, government departments, and infrastructure operators, rely heavily on cloud-based email, identity, collaboration, security, and application platforms. 

In June 2026, a similar case in the AI sector emerged when the US directed Anthropic to suspend access to its Claude Fable 5 and Mythos 5 models for foreign nationals. Anthropic took both models offline temporarily to comply with the order, affecting users outside the US region even though their data and AI workloads may have been hosted anywhere globally. Later in July 2026, the restrictions were lifted, and access to Fable 5 was restored globally. 

However, this incident highlights that data sovereignty also includes continued access to the software, models, and cloud-based capabilities used to process data. This also raised concerns about government control over frontier AI releases and highlighted the possibility that foreign governments could influence access to critical AI services. 

This raises additional questions for CIOs: Can the organisation continue its AI-enabled operations if a foreign provider restricts model access? Does it have an alternative model, local deployment option, or exportable workflow? And how quickly can it switch without disrupting critical services?

When Data Centers Become Targets

Kanishk Gaur, Founder at India Future Foundation, brings a second dimension to the debate: the physical and operational resilience of digital infrastructure during conflict.

Kanishk Gaur, Founder, India Future Foundation

Gaur points to the Russia–Ukraine war and the conflict involving Iran, the United States and Israel as examples of how modern warfare is affecting digital infrastructure. Military establishments and airports are not the only targets. Data centres, telecom networks and other technology facilities can also become part of the conflict environment.

 

The risks became clear in March 2026, when drone strikes damaged Amazon Web Services facilities in the United Arab Emirates and Bahrain. AWS said two UAE facilities were directly hit, while a nearby strike caused physical damage to infrastructure in Bahrain. The strikes caused structural damage, disrupted power delivery, and led to fire suppression and water damage.

The consequences extended beyond physical facilities. AWS reported disruption to cloud services in the affected regions and advised customers to move accessible resources to other regions or restore inaccessible resources from remote backups. By the end of April, Amazon said recovery of its damaged operations in the UAE and Bahrain could take several months, with 31 services still listed as disrupted. 

This case is significant because customers did not need to be directly attacked to be affected. A disturbance to power, cooling, physical infrastructure, or regional connectivity was sufficient to affect cloud availability.

It also argues against a common assumption about cloud resilience that workloads are automatically safe as they are distributed across multiple availability zones. If multiple zones are sharing the same physical region, power network, connectivity routes, or geopolitical exposure, regional redundancy may not provide enough protection. 

This episode underscores the need for end‑to‑end domestic ownership so India is not left as collateral damage.

When Cloud Resilience Becomes a National Concern 

For India, a similar disruption could affect more than individual companies. Cloud platforms increasingly support digital payments and banking applications, telecom and mobile services, manufacturing and supply-chain systems, healthcare records and hospital applications, energy and utility operations, government portals and public-service delivery, logistics, aviation and transport systems, and retail, e-commerce and customer-service platforms.

Prominent economic disruption can arise even without data being permanently damaged by a cybercrime or physical disturbance. Business disruption, delayed payments, production halts, and a decline in public trust could result from even a brief incapacity to authenticate users, access apps, conduct transactions, or repair systems. 

The impact could also cascade. A cloud outage could affect a bank’s applications; a telecom disruption could affect payment authentication; a power failure could bring down a data centre; and an identity-system compromise could spread across multiple services.

This makes data sovereignty partly an economic-continuity issue. The question is not simply whether data is protected from unauthorised access. It is whether essential digital services remain available during a crisis.

Sovereignty is not a Residency Checkbox

Rahul Vatt, Group CRO and Director–Corporate Affairs at Bharti Airtel, argues that data residency is only the first layer of sovereignty.

Rahul Vatt, Group CRO & Director–Corporate Affairs, Bharti Airtel

Vatt says, “Sovereignty is really about how you are controlling the end-to-end stack of what you are trying to create in an AI,” and identifies four pillars of sovereignty – Data residency: Data generated in India should be stored and protected in India; Digital sovereignty:

 

The systems and control plane managing that data should remain within the sovereign stack; Operational sovereignty: The country should control who operates, administers and secures the infrastructure; and Jurisdictional sovereignty: The data and systems should remain subject to Indian law rather than external legal authority.

He also referred to technological sovereignty as an additional consideration. This includes control over the hardware, software, processors, networking equipment, and other components required to operate the infrastructure.

The variance is crucial as data can be physically stored in India while the systems used to manage, secure, update, or recover it remain controlled by companies incorporated elsewhere.

The Way Forward

CIOs and CISOs should incorporate data sovereignty considerations into their design, rather than viewing it as a compliance requirement. The first step is to begin by tagging every classification of vital citizen data (PII, identity, telemetry, logs, models) with its physical and logical location across cloud, SaaS, or on-prem, then harden their usage via sovereign-by-default region-locked storage, compute, guest i/o, customer-managed keys, and formal data egress restrictions while migrating their high-value workloads into trusted countries or jurisdictions.

Technology leaders must combine that with a sovereign control plane: a single, policy-as-code engine for readability on residency, storage, and access; persistent data lineage and egress monitoring; and contractual and/or technical assurance that AI backfilling, training, inference, and backups cannot leave the jurisdiction, absent not just compliance but explicit approval by the citizen.
 
Finally, stress-test this architecture as a tool against geopolitical risk scenarios (VSP vendor embargo, DMCA cross-border block, export restrictions on compute / ML model training) so that even if a third-party provider enforces restrictions, every core constituent experience, event, or service remains untouched on domestically isolated infrastructure.

 

Share:

Author

Nisha Sharma

Nisha is a Senior Editor at CIONow.in, with over 5 years of experience covering enterprise technology, business, and the CIO community.

Chat with CIONow.in

Sequencing AI, Data and Factory 5.0...