An Old Regime Ends, A Stricter One Begins
On July 20, 2026, the Department of Telecommunications (DoT) notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, retiring the licensing framework that had governed India's networks since the Indian Telegraph Act of 1885 in favour of an authorisation regime under the Telecommunications Act, 2023 (DoT Authorisation Portal). Buried inside the new framework is Rule 25(3), which requires every system associated with a telecommunications network — plus all related data, logs and information — to be physically located within India. No copy may be routed, shared or made accessible outside the country under any circumstance (Business Standard; The420.in).
The rule's reach is wide. It covers cloud-hosted telecom networks, internet exchange points, mobile tower infrastructure, satellite gateways and national mobile-number-portability providers (Telangana Today). Any entity that needs to access its own network remotely from outside India must first obtain DoT permission, disclosing the purpose, duration, the individual accessing the system, and the specific Indian location involved.
The Case For It
The strongest argument for this rule is not novel, and it deserves to be stated plainly before it is critiqued. Telecom networks carry call detail records, subscriber location data and lawful-intercept logs — the exact categories of information that matter most for national security investigations and the exact categories most vulnerable to foreign subpoenas, state-sponsored intrusion, or simple jurisdictional ambiguity when they sit on servers abroad. India has precedent for localization delivering real capacity: the Reserve Bank of India's 2018 payment-data localization mandate is widely credited with accelerating domestic data-centre investment, and India's data-centre market is now a serious regional hub partly as a result. A government moving communications infrastructure — not just financial data — onto the same footing is a coherent extension of that logic, and cloud-hosted telecom providers get a genuine incentive to comply: a ₹10 lakh entry fee with zero annual authorisation charges, explicitly designed to make local build-out cheap relative to the compliance alternative.
Where the Rule Overreaches
The problem is not the localization principle; it is the absence of any exception. Rule 25(3), as reported, carries no proviso even for routine backup, disaster recovery or cross-border technical support arrangements — the operational scaffolding that global telecom and cloud vendors have relied on for decades to keep networks resilient (The420.in). Compare this to the RBI's 2018 framework, which permitted a foreign mirror copy for cross-border transaction processing, or the EU's GDPR, which allows standard contractual clauses and adequacy findings for exactly the backup and support scenarios India's new rule forecloses entirely. A telecom operator that today routes encrypted backups through a redundant data centre in Singapore or replicates logs to a global SOC for 24/7 incident response has no lawful path to keep doing so — not with consent, not with encryption, not with an audit trail. That is a security regression dressed as a security upgrade: concentrating all copies of network data in a single jurisdiction removes the redundancy that disaster-recovery architecture exists to provide.
The enforcement design compounds the rigidity. Authorities can inspect facilities without prior notice where "immediate action is deemed necessary in the public interest," and the government may appoint outside auditing agencies to examine operator systems, with operators bearing sole responsibility for approvals — regulatory delay is explicitly not accepted as an excuse for non-compliance (The420.in). For multinational cloud and satellite operators already navigating India's separate personal-data-protection rules, this stacks a second, stricter localization regime on top of the first, with compliance timelines that assume domestic infrastructure can simply appear on demand.
The Satellite Gap Nobody Has Resolved
The rule's timing is awkward for India's nascent satellite broadband push. Spectrum allocation for satellite gateway earth stations remains undefined under the new framework, and references to Global Mobile Personal Communications by Satellite (GMPCS) services were reportedly stripped out entirely — a signal of caution toward foreign satellite entrants. Bharat Bhatia, President of the ITU-APT Foundation, has flagged that the notification "does not allow the authorised entities to apply for spectrum," a gap that could leave private satellite gateway operators — the Starlinks and OneWebs eyeing India's market — structurally disadvantaged against ISRO's incumbent gateway operations. Former BSNL chairman Anupam Shrivastava, by contrast, called the framework "a bold step towards a greener, highly secure, and cloud-integrated future" — a fair reflection of the domestic-industry optimism the rule is designed to generate, even if it sits uneasily with the compliance burden facing global entrants.
The Fix Is Narrow, Not Structural
None of this requires abandoning data localization as a policy. It requires DoT to write in what Rule 25(3) currently omits: a defined, auditable exception for encrypted backup and disaster-recovery replication, comparable to the mirroring allowance RBI already uses successfully, plus a fast-track spectrum pathway for satellite gateway authorisation so the rule doesn't become a de facto ban on new entrants by omission. India does not need to choose between sovereignty and resilience. The current draft, as reported, asks operators to choose anyway.