India data localization

India's New Telecom Rules Make Data Localization Absolute, With No Carve-Out for Backup or Disaster Recovery

DoT's 2026 authorisation rules bar all telecom data from leaving India, with no exception even for backups.

India's Absolute Data Localization Mandate People of Internet Research · India Zero Backup/DR exemptions allowed Rule 25(3) carries no proviso for … 141 years Years of licensing regime replaced New rules replace the licensing fr… ₹10 lakh Cloud telecom entry fee Zero annual charges for cloud-host… peopleofinternet.com
India's Absolute Data Localization Man… People of Internet Research · India Zero Backup/DR exemptions allow… 141 years Years of licensing regime… ₹10 lakh Cloud telecom entry fee peopleofinternet.com

Key Takeaways

An Old Regime Ends, A Stricter One Begins

On July 20, 2026, the Department of Telecommunications (DoT) notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, retiring the licensing framework that had governed India's networks since the Indian Telegraph Act of 1885 in favour of an authorisation regime under the Telecommunications Act, 2023 (DoT Authorisation Portal). Buried inside the new framework is Rule 25(3), which requires every system associated with a telecommunications network — plus all related data, logs and information — to be physically located within India. No copy may be routed, shared or made accessible outside the country under any circumstance (Business Standard; The420.in).

The rule's reach is wide. It covers cloud-hosted telecom networks, internet exchange points, mobile tower infrastructure, satellite gateways and national mobile-number-portability providers (Telangana Today). Any entity that needs to access its own network remotely from outside India must first obtain DoT permission, disclosing the purpose, duration, the individual accessing the system, and the specific Indian location involved.

The Case For It

The strongest argument for this rule is not novel, and it deserves to be stated plainly before it is critiqued. Telecom networks carry call detail records, subscriber location data and lawful-intercept logs — the exact categories of information that matter most for national security investigations and the exact categories most vulnerable to foreign subpoenas, state-sponsored intrusion, or simple jurisdictional ambiguity when they sit on servers abroad. India has precedent for localization delivering real capacity: the Reserve Bank of India's 2018 payment-data localization mandate is widely credited with accelerating domestic data-centre investment, and India's data-centre market is now a serious regional hub partly as a result. A government moving communications infrastructure — not just financial data — onto the same footing is a coherent extension of that logic, and cloud-hosted telecom providers get a genuine incentive to comply: a ₹10 lakh entry fee with zero annual authorisation charges, explicitly designed to make local build-out cheap relative to the compliance alternative.

Where the Rule Overreaches

The problem is not the localization principle; it is the absence of any exception. Rule 25(3), as reported, carries no proviso even for routine backup, disaster recovery or cross-border technical support arrangements — the operational scaffolding that global telecom and cloud vendors have relied on for decades to keep networks resilient (The420.in). Compare this to the RBI's 2018 framework, which permitted a foreign mirror copy for cross-border transaction processing, or the EU's GDPR, which allows standard contractual clauses and adequacy findings for exactly the backup and support scenarios India's new rule forecloses entirely. A telecom operator that today routes encrypted backups through a redundant data centre in Singapore or replicates logs to a global SOC for 24/7 incident response has no lawful path to keep doing so — not with consent, not with encryption, not with an audit trail. That is a security regression dressed as a security upgrade: concentrating all copies of network data in a single jurisdiction removes the redundancy that disaster-recovery architecture exists to provide.

The enforcement design compounds the rigidity. Authorities can inspect facilities without prior notice where "immediate action is deemed necessary in the public interest," and the government may appoint outside auditing agencies to examine operator systems, with operators bearing sole responsibility for approvals — regulatory delay is explicitly not accepted as an excuse for non-compliance (The420.in). For multinational cloud and satellite operators already navigating India's separate personal-data-protection rules, this stacks a second, stricter localization regime on top of the first, with compliance timelines that assume domestic infrastructure can simply appear on demand.

The Satellite Gap Nobody Has Resolved

The rule's timing is awkward for India's nascent satellite broadband push. Spectrum allocation for satellite gateway earth stations remains undefined under the new framework, and references to Global Mobile Personal Communications by Satellite (GMPCS) services were reportedly stripped out entirely — a signal of caution toward foreign satellite entrants. Bharat Bhatia, President of the ITU-APT Foundation, has flagged that the notification "does not allow the authorised entities to apply for spectrum," a gap that could leave private satellite gateway operators — the Starlinks and OneWebs eyeing India's market — structurally disadvantaged against ISRO's incumbent gateway operations. Former BSNL chairman Anupam Shrivastava, by contrast, called the framework "a bold step towards a greener, highly secure, and cloud-integrated future" — a fair reflection of the domestic-industry optimism the rule is designed to generate, even if it sits uneasily with the compliance burden facing global entrants.

The Fix Is Narrow, Not Structural

None of this requires abandoning data localization as a policy. It requires DoT to write in what Rule 25(3) currently omits: a defined, auditable exception for encrypted backup and disaster-recovery replication, comparable to the mirroring allowance RBI already uses successfully, plus a fast-track spectrum pathway for satellite gateway authorisation so the rule doesn't become a de facto ban on new entrants by omission. India does not need to choose between sovereignty and resilience. The current draft, as reported, asks operators to choose anyway.

Sources & Citations

  1. DoT Authorisation Portal
  2. PRS India — Legislative Brief, Telecommunications Bill 2023
  3. Deccan Chronicle
  4. The420.in
  5. Telangana Today