Logo
Blog

25 May 2026 

The CLOUD Act and Your Data in India: What Your Hyperscaler's Sales Team Never Told You

Picture this: your cloud sales representative has just given you a very polished presentation. Your data, they assure you, lives in AWS Mumbai or Azure India.

Picture this: your cloud sales representative has just given you a very polished presentation. Your data, they assure you, lives in AWS Mumbai or Azure India. It never leaves India. They point to the MeitY empanelment certificate as the final proof that everything is compliant, secure, and fully within Indian legal jurisdiction. You nod. You sign the contract.

What they did not tell you, and what this article will, is that a United States federal law signed in 2018 gives American law enforcement the legal authority to compel that same cloud provider to hand over your data, regardless of which country it is physically stored in, without requiring the consent or even the knowledge of the Indian government or your own organisation.

That law is called the Clarifying Lawful Overseas Use of Data Act. The world knows it as the CLOUD Act. And if your organisation stores data with any US-headquartered cloud provider, whether on servers in Mumbai, Hyderabad, or the moon, you need to understand what it means for you.

Why this matter right now
In July 2025, Microsoft abruptly suspended access to all its services for Nayara Energy, India's second-largest private oil refiner handling 8% of the country's refining capacity. The suspension, triggered unilaterally by Microsoft based on EU sanctions, happened without a court order, without prior notice to the company, and without any involvement of Indian regulatory or judicial authority.

Nayara Energy had to go to court to regain access to its own data and systems. This was not a data extraction event, but it demonstrated, graphically, what it means to depend on a US company for your business-critical infrastructure: that company can act on foreign legal and political pressure at any time, and India may have no immediate remedy.

What the CLOUD Act Actually Says

 

The CLOUD Act (Public Law 115-141, Division V) was signed into law by President Trump on 23 March 2018, attached to an omnibus spending bill. It was not debated on its own merits. There was no standalone committee hearing. It was passed as part of the Consolidated Appropriations Act, 2018.

The law primarily amends the Stored Communications Act (SCA) of 1986. Before the CLOUD Act, there was genuine legal uncertainty about whether US law enforcement could compel a US company to produce data stored on servers outside America. A major case, United States vs. Microsoft Corporation, was heading to the Supreme Court to settle exactly this question, involving data that Microsoft held on a server in Ireland. The CLOUD Act rendered that case moot by settling the question in statute.

In the CLOUD Act (18 U.S.C. § 2713) states:
The requirement to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.

Read that phrase carefully: "regardless of whether... located within or outside of the United States." Not "stored in the US". Not "subject to Indian approval". Regardless of location. The only question that matters under the CLOUD Act is whether the provider is subject to US jurisdiction.

AWS, Microsoft Azure, Google Cloud, and IBM Cloud all are, because they are US companies or have substantial US operations.

The official full text of the CLOUD Act is available on the US Department of Justice website, which has created a public resource page for the law and all related materials:

US Department of Justice CLOUD Act Resource Page: https://www.justice.gov/criminal/cloud-act
Full Text of the CLOUD Act (PDF): https://www.congress.gov/bill/115th-congress/1st-session/house-bill/1625/text
Legislative Entry: https://www.congress.gov/bill/115th-congress/1st-session/house-bill/1625
Congressional Research Service Report: https://crsreports.congress.gov/product/pdf/R/R45173

The Congressional Research Service, which provides non-partisan analysis to the US Congress, has also published a detailed analysis of the CLOUD Act and its implications:

https://www.congress.gov/crs-product/R45173

FISA Section 702 - The Wider Surveillance Risk Nobody Talks About

 

The CLOUD Act at least requires a judicially authorised warrant based on probable cause. Law enforcement must identify a specific crime and obtain court approval before demanding specific data. That is a meaningful safeguard, even if it does not respect national borders the way Indian organisations might expect.

Section 702 of the Foreign Intelligence Surveillance Act (FISA) is a different and substantially broader authority. Enacted in 2008 as part of the FISA Amendments Act, and most recently reauthorised in April 2024 under the Reforming Intelligence and Securing America Act (RISAA), Section 702 allows the US Attorney General and the Director of National Intelligence to jointly authorise surveillance targeting persons who are not US persons and who are reasonably believed to be located outside the United States.

FISA Section 702 requires:
The Attorney General and the Director of National Intelligence may direct, in writing, an electronic communication service provider to immediately provide the Government with all information, facilities, or assistance necessary to accomplish the acquisition.

Under Section 702, there is no individual warrant requirement. The surveillance is authorised programmatically, meaning the government gets blanket authorisation to collect entire categories of communications, not specific accounts or specific individuals. The authorisation is reviewed annually by the Foreign Intelligence Surveillance Court, but companies receive programme-level orders, not individual account-level judicial approvals.

Edward Snowden's 2013 revelations exposed the two major programmes operating under FISA 702 authority: PRISM, which compels major US technology companies to provide direct access to user data on their servers, and UPSTREAM, which collects data directly from internet backbone infrastructure. Google, Microsoft and Apple were all named in those disclosures. The legal basis for those programmes was Section 702.

The critical distinction for Indian enterprises
CLOUD Act: Targeted, warrant-based, law enforcement focused. You might eventually learn it happened. FISA Section 702: Programmatic, intelligence-agency directed, no individual warrant, no notification obligation to affected parties. Orders are classified and companies cannot even acknowledge they received one in most cases. When your cloud service says "we haven't disclosed your data under the CLOUD Act", that statement says nothing whatsoever about what may have happened under FISA 702.

What MeitY Empanelment Actually Guarantees

 

The Ministry of Electronics and Information Technology (MeitY) empanelment is a legitimate and important credential. It confirms that a cloud service provider has met the technical, security, and operational standards prescribed by the Indian government for use by public sector organisations, government agencies, PSUs, nationalised banks, and financial institutions.

What MeitY empanelment does not do is exempt a US company from US federal law.

The STQC audit conducted as part of the MeitY empanelment process checks whether cloud services are hosted within India, whether technical security standards are met, and whether the provider complies with global certifications such as ISO 27001, ISO 27017, and ISO 27018. It does not, and cannot, assess or override the legal obligations that US companies carry under the Stored Communications Act, the CLOUD Act, and FISA.

What MeitY empanelment actually covers (from MeitY's own framework)
MeitY empanelment confirms: technical hosting within India; compliance with global security standards such as ISO 27001, 27017, 27018, and ISO 20000; quality, availability, and security benchmarks as per STQC; and eligibility for government procurement. MeitY empanelment does NOT confirm exemption from US federal law, protection from CLOUD Act warrants, protection from FISA Section 702 surveillance programmes, or guaranteed refusal to comply with US government data demands.

To be absolutely clear: AWS has MeitY empanelment for its Mumbai and Hyderabad regions. Microsoft Azure has MeitY empanelment. IBM Cloud has MeitY empanelment for its Chennai data centre. All three of these are US companies. All three are subject to the CLOUD Act and FISA 702. MeitY empanelment and the CLOUD Act jurisdiction coexist. One does not cancel the other.

What Hyperscalers Say and What They Leave Unsaid

 

The major hyperscalers have published their positions on the CLOUD Act. Let us examine them carefully, because there is a significant difference between what is said and what it means.

AWS's Official Position

On its official CLOUD Act compliance page (https://aws.amazon.com/compliance/cloud-act/), Amazon Web Services states the following:

AWS states on its public CLOUD Act page:
Has resulted in zero disclosures of AWS enterprise or government customer stored outside the U.S. to the U.S. government, since we started reporting the statistic in 2020.
Does not give the U.S. government or any government unfettered or automatic access to data, including data stored in the cloud.
Does not limit technical measures and operational controls AWS offers to customers to prevent access to customer data.

These statements deserve careful reading. The first point says zero disclosures since 2020. What it does not say is that zero records has occurred under FISA Section 702, which is a classified programme. AWS cannot legally disclose FISA requests at all. The absence of a CLOUD Act disclosure is not the same as the absence of any U.S. government access.

The second point is technically correct. The CLOUD Act does not give automatic access. It requires a warrant. But that warrant, once issued by a U.S. federal judge, must be complied with, and Indian courts and Indian law have no standing in that proceeding.

The third point is the most carefully worded. AWS says the CLOUD Act does not limit its technical measures to prevent access. This is true. But if AWS is compelled by a lawful U.S. warrant to produce data, and AWS has the technical ability to do so, it must do so. AWS's own page acknowledges this: "If AWS remains compelled to disclose customer data after exhausting these steps, and we have the technical ability to do so, we disclose only the minimum necessary to satisfy the request." The technical controls are meaningful but not absolute.

What AWS Is Doing In Europe That It Is Not Doing In India

Here is something instructive. In January 2025, AWS launched the AWS European Sovereign Cloud, a separate cloud infrastructure investment of €7.8 billion euros designed specifically to address CLOUD Act concerns among European customers. AWS Germany's CTO specifically told Reuters that this service is designed to keep data protected even if the US bars software exports, and to keep it running even if the EU is cut off from the wider internet.

Europe has leverage. It has GDPR, a binding adequacy framework, and institutional muscle to push back. AWS built a separate sovereign infrastructure in response.

India does not yet have a comparable infrastructure offering from AWS. Indian customers get the standard commercial cloud with the standard legal exposure.

Microsoft's Position

Microsoft has been more candid than most. In July 2025, Microsoft was forced to acknowledge in testimony before French legislators that it cannot guarantee data sovereignty for customers using its services. The Register, reporting on this, quoted a security industry response: "Microsoft has openly admitted what many have long known: under laws like the CLOUD Act, US authorities can compel access to data held by American cloud providers, regardless of where that data physically resides. UK or EU servers make no difference from jurisdictional files elsewhere."

Following the Nayara Energy crisis in August 2025, Microsoft did announce a new governance framework for India's public sector, including a commitment to inform customers of foreign government orders. But this framework came as a damage-control response after a major crisis, not as a proactive protection. And commitments made in a press release are not the same as commitments that override a US federal warrant.

The 'Data Residency' Claim

All three major hyperscalers prominently advertise data residency for Indian customers. Microsoft talks about data-at-rest staying within India. AWS talks about its India regions being isolated. Google and IBM make similar representations.

Data residency means the physical storage location of your data. It says nothing about who can legally compel its production.

Data storage within Indian borders alone may not provide enough security. India must adopt a more strategic, sovereign-conscious approach to cloud policy and procurement.
An Indian company using a cloud service provided by a US firm, even if its datacentres are in Mumbai, could find itself under the thumb of US judicial mandates.

A recent Microsoft Q&A forum post by an enterprise user evaluating Azure for an Indian insurance company revealed this remarkable disclosure from the platform's own community: most AI data residency programs offered in India cover only the data storage layer, while the actual model inference, compute often remains global. That is, enterprise content prompts, files, logs may be stored in India, but LLM execution may still occur in global clusters. This was not a Zscaler representative writing this. This came from Microsoft's own community forum at learn.microsoft.com.

The Nayara Energy Case - When Theory Becomes Reality

The Nayara Energy case, which unfolded in July and August 2025, is the most important real-world demonstration of what it means for Indian companies to depend on US cloud providers, and it must be understood accurately.

On 22 July 2025, Microsoft suspended access to all its services for Nayara Energy, India's second-largest private oil refiner with approximately 8% of India's total refining capacity. This included Outlook, Microsoft Teams, and cloud data storage. The suspension brought the company's communications and operations to a halt.

The reason was EU sanctions on Rosneft, which holds a 49.13% stake in Nayara Energy. Microsoft acted on its own interpretation of EU directives. Neither Indian law nor US law required Microsoft to enforce these specific sanctions against an Indian company operating lawfully in India. But Microsoft did it anyway, without prior notice, without a court order, and without any involvement of Indian regulatory or judicial authority.

Nayara Energy had to seek judicial intervention to regain access to its own data and operational systems.

The sovereignty implication
The Nayara Energy case was not a data extraction event under the CLOUD Act. It was something in some ways more alarming: a US technology company deciding, on its own authority, to deny an Indian enterprise access to its own data based on geopolitical pressure from a third jurisdiction (the EU), with no Indian court involved, no Indian regulator involved, and no prior notice. If a US company can do this voluntarily, in response to foreign sanctions, imagine the obligation it carries when served with a lawful US federal warrant under the CLOUD Act or a classified court order under FISA. The question is not whether your data can be accessed. The question is whether you have any meaningful recourse if it is.

India42, reporting on the aftermath, noted: "The RISAA empowers the US government to access any data that is stored with US-based cloud services and data centres. Now the government needs to do a risk assessment on how much of their data is stored with Microsoft or other US-based cloud service providers and move their contracts to Indian alternatives as quickly as possible." This was not said by a ZeaCloud marketing executive. It was said by an Indian technology industry commentator quoted in a mainstream Indian tech publication.

India Has No CLOUD Act Agreement With the United States

 

The CLOUD Act contains a mechanism that partially addresses cross-border sovereignty concerns: bilateral executive agreements between the US and qualifying foreign governments. These agreements allow law enforcement in both countries to access data held by providers subject to the other country's jurisdiction, subject to procedural safeguards.

The United Kingdom signed such an agreement with the US in October 2019. Australia signed one in December 2021. Negotiations are underway with Canada and the European Union.

India has not signed any such agreement. As of May 2026, there is no bilateral CLOUD Act executive agreement between India and the United States.

Observer Research Foundation (ORF) on India's position:
While the United Kingdom and Australia have concluded agreements with the US and can therefore access data from US service providers, this is not yet the case for India. One reason could be the notion that Indian laws may not be able to meet the requirements set out under the CLOUD Act. For instance, the Fourth Amendment guarantee in the US Constitution requires LEAs to obtain a probable cause warrant before they can conduct searches.

The ORF paper, published by one of India's most respected strategic affairs think tanks, is available at: https://www.orfonline.org/research/india-proposed-data-protection-law

This absence of an agreement has a specific consequence. With the UK-US agreement, there is a bilateral framework: both governments have agreed on procedures, both can challenge requests, and there is at least some reciprocal oversight. With India, there is no such framework.The US government can issue a warrant or FISA order compelling a US cloud provider to produce your data, and India has no formal legal mechanism to challenge or even be informed of that order. A May 2026 analysis published in Bar and Bench, commenting on the Aadhaar-Google Wallet partnership, described the situation plainly: 'India has no operative cross-border data protection framework, no bilateral data access agreement with Washington, and no legally defined concept of digital sovereignty.'

 

The DPDP Act 2023 Does Not Solve This Problem
 

India enacted its Digital Personal Data Protection Act in August 2023, and the implementing rules were notified by MeitY on 13 November 2025. This is a significant step forward for data governance in India. But there are two important things it does not do.

First, the DPDP Act is largely permissive on cross-border transfers. It allows personal data to flow to any country unless the central government specifically restricts that country by notification. No such restriction list has been published yet. The US is not a restricted country under the DPDP Act.

Second, the DPDP Act cannot override US federal law. When a US federal court issues a warrant under the CLOUD Act, the jurisdiction of that order is determined by US law, not Indian law. India's DPDP Act may create obligations for the data fiduciary (your company) and the data processor (the cloud provider) under Indian law. But the cloud provider's obligation to comply with a US warrant is determined under US law, and US courts do not treat the DPDP Act as a blocking statute.

The fundamental conflict
India's DPDP Act requires data fiduciaries (your company) to ensure that data processors (your cloud provider) maintain appropriate security and compliance. But your cloud provider has a separate, prior, and overriding legal obligation under US law to comply with lawful US government orders. These two obligations exist simultaneously, and in a conflict, the US court order takes precedence from the perspective of the US provider. Your company may face obligations under Indian law for which it has no practical remedy because the provider's compliance with US law is outside your control.
What Europe Did and What India Should Learn From It
 

India is not the first country to confront this problem. Europe has been grappling with CLOUD Act and FISA 702 risks since GDPR came into force in 2018. The European Court of Justice invalidated the EU-US Privacy Shield arrangement in 2020 in the landmark Schrems II judgment, precisely because FISA 702 surveillance programmes were found to be incompatible with EU fundamental rights protections.

The European response has been multifaceted. The EU negotiated a new framework with the US, the EU-US Data Privacy Framework, which came into force in 2023. German and French legislators have pushed hyperscalers to establish operationally and legally separate EU-based entities.

GAIA-X initiative was launched to build genuinely European cloud infrastructure. A survey by the German digital association Bitkom found that two-thirds of German companies now consider a European data centre location a decisive factor in choosing a cloud provider.

Europe's efforts have produced real infrastructure changes. AWS's European Sovereign Cloud, launched in 2025, is a direct response to European pressure. Microsoft has established an EU Data Boundary. These initiatives exist because European buyers, regulators, and governments demanded them.

India, with a cloud market expected to reach US$76 billion by 2030, is in a similar position to Europe four years ago. The question is not whether this problem will need to be addressed. It is whether Indian enterprises will wait for a crisis or get ahead of it.

The Questions Your Procurement Team Should Be Asking

 

If your organisation is evaluating cloud providers or reviewing existing cloud contracts, the following questions deserve clear written answers from any US-headquartered provider. If the answers are vague or qualified, treat that as the answer.

  • Has your company ever received a request from any US government agency, including under FISA Section 702, for data belonging to non-US customers stored outside the United States? (Note: a provider cannot legally confirm FISA requests, which itself tells you something about transparency.)
  • In the event of a CLOUD Act warrant for our data, are you contractually obligated to notify us before complying and, if so, under what circumstances can that notification be withheld?
  • Does your MeitY empanelment status create any legal protection against CLOUD Act compliance obligations? (The correct answer is no.)
  • Where specifically is our data being processed, not just stored, including for AI and analytics workloads?
  • In the event that a foreign government (including the US or EU) directs you to restrict our access to our own data or services, what is your contractual commitment to us and what recourse do we have?
  • Is your India entity a subsidiary of a US entity, and if so, does the parent company maintain the ability to access or produce our data in response to US legal process?

What Genuine Data Sovereignty Requires

 

Data sovereignty is not the same as data residency. True sovereignty over your data requires that the infrastructure you use is controlled by an entity that is not subject to the jurisdiction of a foreign government.

This means, in practical terms, choosing infrastructure providers that are:

  • Incorporated and headquartered in India
  • Not subsidiaries of US or other foreign entities with US operations
  • Not subject to the Stored Communications Act or the CLOUD Act as a matter of US legal jurisdiction
  • Not subject to FISA Section 702 programme orders
  • Operated entirely within Indian legal jurisdiction by Indian entities

This is not impossible. India has a growing set of private cloud and infrastructure providers that meet these criteria. The choice is not between US hyperscalers and unreliable local alternatives. It is between US hyperscalers with genuine CLOUD Act exposure and Indian infrastructure providers that are, as a matter of law, not subject to US government data demands.

For organisations in regulated sectors, government agencies, PSUs, and any enterprise that handles sensitive commercial, strategic, or personal data, the question of legal jurisdiction over their cloud provider is not a compliance checkbox. It is a fundamental risk management decision.

How ZeaCloud Addresses This

 

ZeaCloud Services Private Limited is incorporated in India and is a wholly owned subsidiary of Esconet Technologies Limited, an Indian company. ZeaCloud has no US parent, no US subsidiary, and no operations in the United States. ZeaCloud is not subject to the CLOUD Act, the Stored Communications Act, or FISA Section 702.

When you store data on ZeaStack, ZeaCloud's private cloud platform, in our Tier III facility in Noida, that data is held by an Indian entity under Indian law. A US federal court has no jurisdiction over ZeaCloud. A FISA order cannot be served on ZeaCloud. Your data cannot be compelled by US law enforcement through ZeaCloud because ZeaCloud has no US legal presence.

This is not a marketing claim. It is a legal fact that follows from the corporate structure of the company and the absence of US operations. If you would like documentation of our corporate structure for your compliance or procurement processes, we are happy to provide it.

We are also pursuing ISO 27001 certification, with ISO 27017 (cloud security) and ISO 27018 (personal data in cloud) planned as a next phase, aligned with MeitY empanelment requirements. Our compliance roadmap is built around the actual requirements that Indian regulated enterprises and government organisations face, including the DPDP Act 2023 and CERT-In directives.

Conclusion: The Salesperson's Pitch vs. the Law

 

There is a significant distance between what a hyperscaler's sales team tells you in a meeting and what the law actually requires of that company. The sales team tells you your data is in India. The law tells that company it must produce your data regardless of where it is, if served with a valid US government demand.

MeitY empanelment is a real and meaningful credential for technical security standards. It is not a shield against US federal law. Data residency means your data is stored in India. It does not mean only Indian law governs who can access it.

The Nayara Energy case showed, in practice, what dependency on a US cloud provider means when geopolitical pressure is applied. CLOUD Act warrants and FISA 702 orders represent a different and potentially more serious category of the same underlying risk: that the infrastructure you depend on is ultimately accountable to a foreign government's legal system, not yours.

India has no bilateral CLOUD Act agreement with the United States. The DPDP Act 2023, while a welcome development, does not override US federal jurisdiction over US companies. The Indian regulatory framework and the US surveillance legal framework exist simultaneously, with no clear resolution mechanism in place.

For Indian enterprises that take data governance seriously, this is not a hypothetical risk to acknowledge and ignore. It is an architectural decision that should be made with eyes open.

We are happy to discuss this with you in detail. Every ZeaCloud engagement begins with an honest conversation about your infrastructure, your risk profile, and whether what we offer is actually the right fit.

Contact ZeaCloud: santosh@zeacloud.com  |  Website: zeacloud.com

References and Source Documents

 

All claims in this article are sourced from official government documents, publicly available corporate disclosures, and credible press and research publications. Key references are provided below.

SourceDescription and URL
US DOJ CLOUD Act ResourcesOfficial US Department of Justice CLOUD Act resource page including full text of the law
https://www.justice.gov/criminal/cloud-act-resources
CLOUD Act Full Text (PDF)Full text of the Clarifying Lawful Overseas Use of Data Act, hosted by DOJ
https://www.justice.gov/criminal/media/fff391/dl?inline
DOJ CLOUD Act White PaperUS DOJ white paper: Promoting Public Safety, Privacy, and the Rule of Law Around the World (April 2019)
https://www.justice.gov/criminal/media/fff601/dl?inline
Congress.gov CLOUD Act EntryOfficial legislative record of the CLOUD Act (S.2383, 115th Congress)
https://www.congress.gov/bill/115th-congress/senate-bill/2383/text
CRS CLOUD Act AnalysisCongressional Research Service non-partisan analysis of the CLOUD Act (R45173)
https://www.congress.gov/crs-product/R45173
AWS CLOUD Act PageAmazon Web Services official position on the CLOUD Act
https://aws.amazon.com/compliance/cloud-act/
AWS MeitY EmpanelmentAWS official page on MeitY empanelment status for Mumbai and Hyderabad
https://aws.amazon.com/compliance/MeitY/
Microsoft MeitY ComplianceMicrosoft's description of its MeitY empanelment
https://learn.microsoft.com/en-us/compliance/regulatory/offering-meity-india
IBM Cloud MeitYIBM Cloud's MeitY empanelment page
https://www.ibm.com/products/cloud/compliance/meity
ORF - India and CLOUD ActObserver Research Foundation: India's Proposed Data Protection Law and an India-US Executive Agreement Under the CLOUD Act
https://www.orfonline.org/research/indias-proposed-data-protection-law
BW BusinessworldThe Cloud Conundrum: How US CLOUD Act and FISA Shape India's Digital Future
https://www.businessworld.in/article/the-cloud-conundrum-how-us-cloud-act-and-fisa-shape-indias-digital-future-553297
Inc42 - Nayara EnergyMicrosoft-Nayara Energy Case Exposes India Inc's Cloud Risk (August 2025)
https://inc42.com/buzz/microsoft-nayara-energy-case-exposes-india-incs-cloud-vulnerability/
Medianama - NayaraMicrosoft Blocks Nayara Energy Data Access in India
https://www.medianama.com/2025/08/223-microsoft-blocks-nayara-data-india/
The RegisterMicrosoft admits it cannot guarantee data sovereignty (July 2025)
https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/
Bar and BenchAadhaar in Google Wallet: India's Sovereignty Under the US CLOUD Act Framework (May 2026)
https://www.barandbench.com/columns/aadhaar-in-google-wallet-indias-sovereignty-under-the-us-cloud-act-framework
archTIS AnalysisUnderstanding the US Cloud Act: Impact on Compliance, Agreement, and Data Protection
https://www.archtis.com/understanding-the-us-cloud-act/
FISA 702 ResourcesAmerican Bar Association FISA Section 702 resources page
https://www.americanbar.org/groups/law_national_security/resources/fisa-section-702/
CRS FISA 702 ReportCongressional Research Service: FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act
https://www.congress.gov/crs_external_products/R/PDF/R48592/R48592.pdf
Hogan Lovells - DPDPIndia's Digital Personal Data Protection Act 2023 brought into force (November 2025)
https://www.hoganlovells.com/en/publications/indias-digital-data-protection-act-2023-brought-into-force
Reuters - AWS EU CloudAmazon launches Europe-based cloud service to address data sovereignty concerns (January 2025)
https://www.aol.com/articles/amazon-launches-europe-based-cloud-070227602.html
Disclaimer
This article is published for informational and awareness purposes by ZeaCloud Services Private Limited. It represents ZeaCloud's interpretation and analysis of publicy available information, official government documents, and published research. It does not constitute legal advice. Organizations concerned about their legal exposure under the CLOUD Act, FISA, or the DPDP Act should seek qualified legal counsel. All viewpoints quoted are drawn from publicly available official sources cited above.
Is Your Data Really Safe in India? The CLOUD Act Explained