
25 May 2026
Picture this: your cloud sales representative has just given you a very polished presentation. Your data, they assure you, lives in AWS Mumbai or Azure India.
Picture this: your cloud sales representative has just given you a very polished presentation. Your data, they assure you, lives in AWS Mumbai or Azure India. It never leaves India. They point to the MeitY empanelment certificate as the final proof that everything is compliant, secure, and fully within Indian legal jurisdiction. You nod. You sign the contract.
What they did not tell you, and what this article will, is that a United States federal law signed in 2018 gives American law enforcement the legal authority to compel that same cloud provider to hand over your data, regardless of which country it is physically stored in, without requiring the consent or even the knowledge of the Indian government or your own organisation.
That law is called the Clarifying Lawful Overseas Use of Data Act. The world knows it as the CLOUD Act. And if your organisation stores data with any US-headquartered cloud provider, whether on servers in Mumbai, Hyderabad, or the moon, you need to understand what it means for you.
The CLOUD Act (Public Law 115-141, Division V) was signed into law by President Trump on 23 March 2018, attached to an omnibus spending bill. It was not debated on its own merits. There was no standalone committee hearing. It was passed as part of the Consolidated Appropriations Act, 2018.
The law primarily amends the Stored Communications Act (SCA) of 1986. Before the CLOUD Act, there was genuine legal uncertainty about whether US law enforcement could compel a US company to produce data stored on servers outside America. A major case, United States vs. Microsoft Corporation, was heading to the Supreme Court to settle exactly this question, involving data that Microsoft held on a server in Ireland. The CLOUD Act rendered that case moot by settling the question in statute.
Read that phrase carefully: "regardless of whether... located within or outside of the United States." Not "stored in the US". Not "subject to Indian approval". Regardless of location. The only question that matters under the CLOUD Act is whether the provider is subject to US jurisdiction.
AWS, Microsoft Azure, Google Cloud, and IBM Cloud all are, because they are US companies or have substantial US operations.
The official full text of the CLOUD Act is available on the US Department of Justice website, which has created a public resource page for the law and all related materials:
The Congressional Research Service, which provides non-partisan analysis to the US Congress, has also published a detailed analysis of the CLOUD Act and its implications:
https://www.congress.gov/crs-product/R45173The CLOUD Act at least requires a judicially authorised warrant based on probable cause. Law enforcement must identify a specific crime and obtain court approval before demanding specific data. That is a meaningful safeguard, even if it does not respect national borders the way Indian organisations might expect.
Section 702 of the Foreign Intelligence Surveillance Act (FISA) is a different and substantially broader authority. Enacted in 2008 as part of the FISA Amendments Act, and most recently reauthorised in April 2024 under the Reforming Intelligence and Securing America Act (RISAA), Section 702 allows the US Attorney General and the Director of National Intelligence to jointly authorise surveillance targeting persons who are not US persons and who are reasonably believed to be located outside the United States.
Under Section 702, there is no individual warrant requirement. The surveillance is authorised programmatically, meaning the government gets blanket authorisation to collect entire categories of communications, not specific accounts or specific individuals. The authorisation is reviewed annually by the Foreign Intelligence Surveillance Court, but companies receive programme-level orders, not individual account-level judicial approvals.
Edward Snowden's 2013 revelations exposed the two major programmes operating under FISA 702 authority: PRISM, which compels major US technology companies to provide direct access to user data on their servers, and UPSTREAM, which collects data directly from internet backbone infrastructure. Google, Microsoft and Apple were all named in those disclosures. The legal basis for those programmes was Section 702.
The Ministry of Electronics and Information Technology (MeitY) empanelment is a legitimate and important credential. It confirms that a cloud service provider has met the technical, security, and operational standards prescribed by the Indian government for use by public sector organisations, government agencies, PSUs, nationalised banks, and financial institutions.
What MeitY empanelment does not do is exempt a US company from US federal law.
The STQC audit conducted as part of the MeitY empanelment process checks whether cloud services are hosted within India, whether technical security standards are met, and whether the provider complies with global certifications such as ISO 27001, ISO 27017, and ISO 27018. It does not, and cannot, assess or override the legal obligations that US companies carry under the Stored Communications Act, the CLOUD Act, and FISA.
To be absolutely clear: AWS has MeitY empanelment for its Mumbai and Hyderabad regions. Microsoft Azure has MeitY empanelment. IBM Cloud has MeitY empanelment for its Chennai data centre. All three of these are US companies. All three are subject to the CLOUD Act and FISA 702. MeitY empanelment and the CLOUD Act jurisdiction coexist. One does not cancel the other.
The major hyperscalers have published their positions on the CLOUD Act. Let us examine them carefully, because there is a significant difference between what is said and what it means.
On its official CLOUD Act compliance page (https://aws.amazon.com/compliance/cloud-act/), Amazon Web Services states the following:
These statements deserve careful reading. The first point says zero disclosures since 2020. What it does not say is that zero records has occurred under FISA Section 702, which is a classified programme. AWS cannot legally disclose FISA requests at all. The absence of a CLOUD Act disclosure is not the same as the absence of any U.S. government access.
The second point is technically correct. The CLOUD Act does not give automatic access. It requires a warrant. But that warrant, once issued by a U.S. federal judge, must be complied with, and Indian courts and Indian law have no standing in that proceeding.
The third point is the most carefully worded. AWS says the CLOUD Act does not limit its technical measures to prevent access. This is true. But if AWS is compelled by a lawful U.S. warrant to produce data, and AWS has the technical ability to do so, it must do so. AWS's own page acknowledges this: "If AWS remains compelled to disclose customer data after exhausting these steps, and we have the technical ability to do so, we disclose only the minimum necessary to satisfy the request." The technical controls are meaningful but not absolute.
Here is something instructive. In January 2025, AWS launched the AWS European Sovereign Cloud, a separate cloud infrastructure investment of €7.8 billion euros designed specifically to address CLOUD Act concerns among European customers. AWS Germany's CTO specifically told Reuters that this service is designed to keep data protected even if the US bars software exports, and to keep it running even if the EU is cut off from the wider internet.
Europe has leverage. It has GDPR, a binding adequacy framework, and institutional muscle to push back. AWS built a separate sovereign infrastructure in response.
India does not yet have a comparable infrastructure offering from AWS. Indian customers get the standard commercial cloud with the standard legal exposure.
Microsoft has been more candid than most. In July 2025, Microsoft was forced to acknowledge in testimony before French legislators that it cannot guarantee data sovereignty for customers using its services. The Register, reporting on this, quoted a security industry response: "Microsoft has openly admitted what many have long known: under laws like the CLOUD Act, US authorities can compel access to data held by American cloud providers, regardless of where that data physically resides. UK or EU servers make no difference from jurisdictional files elsewhere."
Following the Nayara Energy crisis in August 2025, Microsoft did announce a new governance framework for India's public sector, including a commitment to inform customers of foreign government orders. But this framework came as a damage-control response after a major crisis, not as a proactive protection. And commitments made in a press release are not the same as commitments that override a US federal warrant.
All three major hyperscalers prominently advertise data residency for Indian customers. Microsoft talks about data-at-rest staying within India. AWS talks about its India regions being isolated. Google and IBM make similar representations.
Data residency means the physical storage location of your data. It says nothing about who can legally compel its production.
A recent Microsoft Q&A forum post by an enterprise user evaluating Azure for an Indian insurance company revealed this remarkable disclosure from the platform's own community: most AI data residency programs offered in India cover only the data storage layer, while the actual model inference, compute often remains global. That is, enterprise content prompts, files, logs may be stored in India, but LLM execution may still occur in global clusters. This was not a Zscaler representative writing this. This came from Microsoft's own community forum at learn.microsoft.com.
The Nayara Energy case, which unfolded in July and August 2025, is the most important real-world demonstration of what it means for Indian companies to depend on US cloud providers, and it must be understood accurately.
On 22 July 2025, Microsoft suspended access to all its services for Nayara Energy, India's second-largest private oil refiner with approximately 8% of India's total refining capacity. This included Outlook, Microsoft Teams, and cloud data storage. The suspension brought the company's communications and operations to a halt.
The reason was EU sanctions on Rosneft, which holds a 49.13% stake in Nayara Energy. Microsoft acted on its own interpretation of EU directives. Neither Indian law nor US law required Microsoft to enforce these specific sanctions against an Indian company operating lawfully in India. But Microsoft did it anyway, without prior notice, without a court order, and without any involvement of Indian regulatory or judicial authority.
Nayara Energy had to seek judicial intervention to regain access to its own data and operational systems.
India42, reporting on the aftermath, noted: "The RISAA empowers the US government to access any data that is stored with US-based cloud services and data centres. Now the government needs to do a risk assessment on how much of their data is stored with Microsoft or other US-based cloud service providers and move their contracts to Indian alternatives as quickly as possible." This was not said by a ZeaCloud marketing executive. It was said by an Indian technology industry commentator quoted in a mainstream Indian tech publication.
The CLOUD Act contains a mechanism that partially addresses cross-border sovereignty concerns: bilateral executive agreements between the US and qualifying foreign governments. These agreements allow law enforcement in both countries to access data held by providers subject to the other country's jurisdiction, subject to procedural safeguards.
The United Kingdom signed such an agreement with the US in October 2019. Australia signed one in December 2021. Negotiations are underway with Canada and the European Union.
India has not signed any such agreement. As of May 2026, there is no bilateral CLOUD Act executive agreement between India and the United States.
The ORF paper, published by one of India's most respected strategic affairs think tanks, is available at: https://www.orfonline.org/research/india-proposed-data-protection-law
This absence of an agreement has a specific consequence. With the UK-US agreement, there is a bilateral framework: both governments have agreed on procedures, both can challenge requests, and there is at least some reciprocal oversight. With India, there is no such framework.The US government can issue a warrant or FISA order compelling a US cloud provider to produce your data, and India has no formal legal mechanism to challenge or even be informed of that order. A May 2026 analysis published in Bar and Bench, commenting on the Aadhaar-Google Wallet partnership, described the situation plainly: 'India has no operative cross-border data protection framework, no bilateral data access agreement with Washington, and no legally defined concept of digital sovereignty.'
India enacted its Digital Personal Data Protection Act in August 2023, and the implementing rules were notified by MeitY on 13 November 2025. This is a significant step forward for data governance in India. But there are two important things it does not do.
First, the DPDP Act is largely permissive on cross-border transfers. It allows personal data to flow to any country unless the central government specifically restricts that country by notification. No such restriction list has been published yet. The US is not a restricted country under the DPDP Act.
Second, the DPDP Act cannot override US federal law. When a US federal court issues a warrant under the CLOUD Act, the jurisdiction of that order is determined by US law, not Indian law. India's DPDP Act may create obligations for the data fiduciary (your company) and the data processor (the cloud provider) under Indian law. But the cloud provider's obligation to comply with a US warrant is determined under US law, and US courts do not treat the DPDP Act as a blocking statute.
India is not the first country to confront this problem. Europe has been grappling with CLOUD Act and FISA 702 risks since GDPR came into force in 2018. The European Court of Justice invalidated the EU-US Privacy Shield arrangement in 2020 in the landmark Schrems II judgment, precisely because FISA 702 surveillance programmes were found to be incompatible with EU fundamental rights protections.
The European response has been multifaceted. The EU negotiated a new framework with the US, the EU-US Data Privacy Framework, which came into force in 2023. German and French legislators have pushed hyperscalers to establish operationally and legally separate EU-based entities.
GAIA-X initiative was launched to build genuinely European cloud infrastructure. A survey by the German digital association Bitkom found that two-thirds of German companies now consider a European data centre location a decisive factor in choosing a cloud provider.
Europe's efforts have produced real infrastructure changes. AWS's European Sovereign Cloud, launched in 2025, is a direct response to European pressure. Microsoft has established an EU Data Boundary. These initiatives exist because European buyers, regulators, and governments demanded them.
India, with a cloud market expected to reach US$76 billion by 2030, is in a similar position to Europe four years ago. The question is not whether this problem will need to be addressed. It is whether Indian enterprises will wait for a crisis or get ahead of it.
If your organisation is evaluating cloud providers or reviewing existing cloud contracts, the following questions deserve clear written answers from any US-headquartered provider. If the answers are vague or qualified, treat that as the answer.
Data sovereignty is not the same as data residency. True sovereignty over your data requires that the infrastructure you use is controlled by an entity that is not subject to the jurisdiction of a foreign government.
This means, in practical terms, choosing infrastructure providers that are:
This is not impossible. India has a growing set of private cloud and infrastructure providers that meet these criteria. The choice is not between US hyperscalers and unreliable local alternatives. It is between US hyperscalers with genuine CLOUD Act exposure and Indian infrastructure providers that are, as a matter of law, not subject to US government data demands.
For organisations in regulated sectors, government agencies, PSUs, and any enterprise that handles sensitive commercial, strategic, or personal data, the question of legal jurisdiction over their cloud provider is not a compliance checkbox. It is a fundamental risk management decision.
ZeaCloud Services Private Limited is incorporated in India and is a wholly owned subsidiary of Esconet Technologies Limited, an Indian company. ZeaCloud has no US parent, no US subsidiary, and no operations in the United States. ZeaCloud is not subject to the CLOUD Act, the Stored Communications Act, or FISA Section 702.
When you store data on ZeaStack, ZeaCloud's private cloud platform, in our Tier III facility in Noida, that data is held by an Indian entity under Indian law. A US federal court has no jurisdiction over ZeaCloud. A FISA order cannot be served on ZeaCloud. Your data cannot be compelled by US law enforcement through ZeaCloud because ZeaCloud has no US legal presence.
This is not a marketing claim. It is a legal fact that follows from the corporate structure of the company and the absence of US operations. If you would like documentation of our corporate structure for your compliance or procurement processes, we are happy to provide it.
We are also pursuing ISO 27001 certification, with ISO 27017 (cloud security) and ISO 27018 (personal data in cloud) planned as a next phase, aligned with MeitY empanelment requirements. Our compliance roadmap is built around the actual requirements that Indian regulated enterprises and government organisations face, including the DPDP Act 2023 and CERT-In directives.
There is a significant distance between what a hyperscaler's sales team tells you in a meeting and what the law actually requires of that company. The sales team tells you your data is in India. The law tells that company it must produce your data regardless of where it is, if served with a valid US government demand.
MeitY empanelment is a real and meaningful credential for technical security standards. It is not a shield against US federal law. Data residency means your data is stored in India. It does not mean only Indian law governs who can access it.
The Nayara Energy case showed, in practice, what dependency on a US cloud provider means when geopolitical pressure is applied. CLOUD Act warrants and FISA 702 orders represent a different and potentially more serious category of the same underlying risk: that the infrastructure you depend on is ultimately accountable to a foreign government's legal system, not yours.
India has no bilateral CLOUD Act agreement with the United States. The DPDP Act 2023, while a welcome development, does not override US federal jurisdiction over US companies. The Indian regulatory framework and the US surveillance legal framework exist simultaneously, with no clear resolution mechanism in place.
For Indian enterprises that take data governance seriously, this is not a hypothetical risk to acknowledge and ignore. It is an architectural decision that should be made with eyes open.
We are happy to discuss this with you in detail. Every ZeaCloud engagement begins with an honest conversation about your infrastructure, your risk profile, and whether what we offer is actually the right fit.
Contact ZeaCloud: santosh@zeacloud.com | Website: zeacloud.com
All claims in this article are sourced from official government documents, publicly available corporate disclosures, and credible press and research publications. Key references are provided below.
| Source | Description and URL |
|---|---|
| US DOJ CLOUD Act Resources | Official US Department of Justice CLOUD Act resource page including full text of the law https://www.justice.gov/criminal/cloud-act-resources |
| CLOUD Act Full Text (PDF) | Full text of the Clarifying Lawful Overseas Use of Data Act, hosted by DOJ https://www.justice.gov/criminal/media/fff391/dl?inline |
| DOJ CLOUD Act White Paper | US DOJ white paper: Promoting Public Safety, Privacy, and the Rule of Law Around the World (April 2019) https://www.justice.gov/criminal/media/fff601/dl?inline |
| Congress.gov CLOUD Act Entry | Official legislative record of the CLOUD Act (S.2383, 115th Congress) https://www.congress.gov/bill/115th-congress/senate-bill/2383/text |
| CRS CLOUD Act Analysis | Congressional Research Service non-partisan analysis of the CLOUD Act (R45173) https://www.congress.gov/crs-product/R45173 |
| AWS CLOUD Act Page | Amazon Web Services official position on the CLOUD Act https://aws.amazon.com/compliance/cloud-act/ |
| AWS MeitY Empanelment | AWS official page on MeitY empanelment status for Mumbai and Hyderabad https://aws.amazon.com/compliance/MeitY/ |
| Microsoft MeitY Compliance | Microsoft's description of its MeitY empanelment https://learn.microsoft.com/en-us/compliance/regulatory/offering-meity-india |
| IBM Cloud MeitY | IBM Cloud's MeitY empanelment page https://www.ibm.com/products/cloud/compliance/meity |
| ORF - India and CLOUD Act | Observer Research Foundation: India's Proposed Data Protection Law and an India-US Executive Agreement Under the CLOUD Act https://www.orfonline.org/research/indias-proposed-data-protection-law |
| BW Businessworld | The Cloud Conundrum: How US CLOUD Act and FISA Shape India's Digital Future https://www.businessworld.in/article/the-cloud-conundrum-how-us-cloud-act-and-fisa-shape-indias-digital-future-553297 |
| Inc42 - Nayara Energy | Microsoft-Nayara Energy Case Exposes India Inc's Cloud Risk (August 2025) https://inc42.com/buzz/microsoft-nayara-energy-case-exposes-india-incs-cloud-vulnerability/ |
| Medianama - Nayara | Microsoft Blocks Nayara Energy Data Access in India https://www.medianama.com/2025/08/223-microsoft-blocks-nayara-data-india/ |
| The Register | Microsoft admits it cannot guarantee data sovereignty (July 2025) https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/ |
| Bar and Bench | Aadhaar in Google Wallet: India's Sovereignty Under the US CLOUD Act Framework (May 2026) https://www.barandbench.com/columns/aadhaar-in-google-wallet-indias-sovereignty-under-the-us-cloud-act-framework |
| archTIS Analysis | Understanding the US Cloud Act: Impact on Compliance, Agreement, and Data Protection https://www.archtis.com/understanding-the-us-cloud-act/ |
| FISA 702 Resources | American Bar Association FISA Section 702 resources page https://www.americanbar.org/groups/law_national_security/resources/fisa-section-702/ |
| CRS FISA 702 Report | Congressional Research Service: FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act https://www.congress.gov/crs_external_products/R/PDF/R48592/R48592.pdf |
| Hogan Lovells - DPDP | India's Digital Personal Data Protection Act 2023 brought into force (November 2025) https://www.hoganlovells.com/en/publications/indias-digital-data-protection-act-2023-brought-into-force |
| Reuters - AWS EU Cloud | Amazon launches Europe-based cloud service to address data sovereignty concerns (January 2025) https://www.aol.com/articles/amazon-launches-europe-based-cloud-070227602.html |