
27 Jul 2026
If your cloud provider tells you “your data stays in India” and stops there, you have been told the easy half of the answer. Data residency means your data is physically stored in India.
If your cloud provider tells you “your data stays in India” and stops there, you have been told the easy half of the answer. Data residency means your data is physically stored in India. Data sovereignty means it is beyond the legal reach of any government other than India's. A provider can give you the first without being able to give you the second, and the difference is not academic. It is the difference between a compliance checkbox and an actual answer to the question your board is asking.
This is the distinction that gets flattened in most vendor conversations, because flattening it is commercially convenient for anyone whose ownership structure cannot survive the scrutiny.
The Digital Personal Data Protection Act, 2023 sat largely dormant until the Digital Personal Data Protection Rules, 2025 were notified in November 2025, giving the Act operational force and formally constituting the Data Protection Board of India.
Here is what surprises people: India did not mandate blanket data localisation. Cross-border transfer works on a negative-list model. Personal data can leave India unless the government specifically names a restricted country or category. If you have been told Indian law requires all data to stay in the country, that is not accurate for most personal data under the DPDP framework itself. What is accurate is that a separate government power exists to reserve specific categories, and that several sector regulators have already exercised something similar in their own domains, which is where the real hard edges sit.
The framework carries real teeth regardless: penalties running into hundreds of crores for serious failures such as inadequate security safeguards, mandatory breach notification, defined retention and erasure timelines, and enhanced obligations, including impact assessments and audits, for organisations classified as Significant Data Fiduciaries.
The genuine mandates are narrower than the DPDP Act and sit in sector regulation.
Payment data. The Reserve Bank of India requires payment-system data to be stored only within India. This is among the strictest localisation rules in the country and applies directly to fintech and banking workloads touching payment information.
Regulated financial entities. SEBI's Framework for Adoption of Cloud Services by Regulated Entities requires that data reside and be processed within India, that the regulated entity retain ownership of its own data, encryption keys, and logs, and that deployments be monitored through security operations centres.
Identity data. UIDAI guidance requires that Aadhaar data vaults be hosted specifically on MeitY-empanelled cloud environments, drawing identity infrastructure into the empanelled, audited perimeter by name.
If your workload does not touch payments, SEBI-regulated activity, or Aadhaar data, the DPDP Act's own transfer rules are less restrictive than most people assume. If it touches any of those three, the rules are considerably stricter than a general reading of the Act would suggest. Sovereignty planning has to be done workload by workload, not once for the whole organisation.
Here is the question residency alone cannot answer: who can compel your provider to hand over your data, and under whose law?
The US CLOUD Act, enacted in 2018, lets American authorities compel any provider under US jurisdiction to produce data in its possession or control, regardless of where that data is physically stored. The test is corporate control, not server location. A US-incorporated company, or a subsidiary a US parent controls, falls within reach even if every server it operates sits in Mumbai. Section 702 of the US Foreign Intelligence Surveillance Act adds a further layer, permitting surveillance of non-US persons' data under national security authorities, sometimes without the ability to notify the person affected.
The same structural exposure applies wherever a US-controlled provider operates, India included. Encryption only closes this gap if the provider genuinely cannot read your data, meaning you hold the keys. If the provider holds them, and most managed encryption services mean the provider holds them, that provider can be compelled to produce readable data regardless of where the disks physically sit.
MeitY's empanelment process, run through the STQC Directorate, audits providers against recognised standards including ISO 27001, ISO 27017, ISO 27018, and ISO 20000-1 before they can sell into government tenders. It is a genuine and useful security and operational qualification.
It is not a sovereignty certification. All three global hyperscalers are MeitY empanelled alongside Indian providers. Empanelment tells you a provider passed a security and process audit. It tells you nothing about which government can compel that provider to disclose your data. Treating empanelment as proof of sovereignty is the same error as treating residency as proof of sovereignty, just wearing a government stamp instead of a marketing claim.
A sovereignty claim is verifiable, so verify it. Ask your provider, in writing, four questions:
Under which country's law is the provider, and its ultimate parent company, incorporated and controlled?
Can you, the customer, hold your own encryption keys such that the provider is technically unable to produce plaintext data even if compelled?
Are the people with administrative access to your environment located in India, and is that access logged and auditable by you?
Does the arrangement satisfy the specific sector rule that applies to your data: RBI, SEBI, or UIDAI, as relevant?
A provider strong only on the first question, where your data is stored, is offering you residency. A provider that can answer all four in writing is offering you something closer to sovereignty.
Does Indian law require my data to stay in India?
Not in general. The DPDP framework uses a negative-list model: personal data can leave India unless the government restricts a specific destination or category. Hard localisation is sector-specific: RBI payment data, SEBI-regulated entities, and UIDAI's Aadhaar data vault rule.
If my data is stored in an Indian data centre, is it automatically sovereign?
No. If the provider is controlled from another country, that country's legal process can, in principle, still reach the data. The US CLOUD Act applies based on corporate control, not server location.
What is the US CLOUD Act and why does it matter for an Indian company using a US cloud provider?
It is a 2018 US law allowing American authorities to compel a provider under US jurisdiction to produce data it controls, wherever that data is stored. It matters because it makes physical location in India insufficient protection on its own.
Does MeitY empanelment mean a provider is sovereign?
No. Empanelment is a security and operational audit against ISO standards, run by STQC. All three global hyperscalers hold it alongside Indian providers. It answers a security question, not a jurisdiction question.
What is the single most useful question to ask a cloud provider about sovereignty?
Ask who is legally able to compel them to hand over your data, and get the answer in writing. Everything else, residency, encryption, empanelment, is a supporting detail to that one question.
ZeaCloud Services Private Limited operates a sovereign private cloud platform from Tier III data centres in India, built on Indian ownership and Indian jurisdiction. This article is part of ZeaCloud's ongoing coverage of data sovereignty and compliance in India.