What the Notification Actually Requires
On July 20, 2026, India's Department of Telecommunications (DoT) issued a notification under the Telecommunications Act, 2023 authorisation framework mandating that "all systems of its telecommunication network and the data, logs and information associated with its telecommunication network shall be stored within India and no copies of such data, logs and information shall be routed, shared or made available outside India" (Deccan Chronicle; The Federal).
The mandate is not confined to telecom operators. It reaches six categories of authorised entity: infrastructure providers, digital connectivity infrastructure providers, internet exchange point (IXP) providers, satellite earth station gateways, cloud-hosted telecommunication network providers, and national-level mobile number portability providers (Daily Excelsior). That is a deliberately wide net — it covers not just the backbone but the cloud and satellite layers that increasingly are the backbone.
The notification operationalises the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, part of a broader overhaul that replaced the license-based regime under the 1885 Telegraph Act with an authorisation system. The principal rules were gazetted on June 23, 2026 (G.S.R. 513(E)), and the Act itself — passed by Parliament in December 2023 — concentrates authorisation, interception and infrastructure-access powers in the central government rather than delegating them to the sector regulator, TRAI (PRS India).
The Case For It
The strongest argument for the rule is straightforward: telecom network logs are not ordinary business records. They can reveal who is communicating with whom, from where, and how often — precisely the metadata that intelligence services covet and that a foreign government could compel a cloud or satellite provider to hand over under its own laws, regardless of where the user sits. India is not inventing this concern. The Reserve Bank of India applied a comparable logic to payment data in its April 6, 2018 directive requiring payment system operators to store transaction data exclusively in India (Digital Policy Alert). For critical infrastructure — IXPs that see the shape of the country's internet traffic, satellite gateways that anchor connectivity in border and coastal regions — a sovereign-storage requirement is a defensible baseline, not a paranoid one.
Where It Overshoots
But the DoT rule goes further than its own precedent. RBI's 2018 directive allowed a copy of the foreign leg of a cross-border payment to be processed abroad; this notification permits no copies anywhere outside India, for any authorised entity, full stop. That's a meaningfully stricter standard than India has applied to financial data, and stricter than the EU's GDPR, which permits cross-border transfer with contractual and adequacy safeguards rather than an outright ban.
The practical cost falls hardest on exactly the entities the government says it wants to attract. The notification creates a new, low-barrier "Cloud-Hosted Telecommunication Network Provider" category — a ₹10 lakh (roughly $12,000) entry fee with zero annual charges, clearly designed to pull networking functions onto Indian soil (Daily Excelsior). But global cloud and satellite operators run security operations — fraud detection, DDoS mitigation, threat correlation — that depend on pooling logs across markets. A zero-copy mandate doesn't just raise their compliance costs; it can degrade the very security monitoring the rule is nominally meant to protect, by severing Indian traffic data from the global signal that catches attacks early. For a satellite gateway operator serving a handful of Indian ground stations alongside dozens of others worldwide, standing up India-only logging infrastructure is a real fixed cost that a low entry fee doesn't offset.
The Spectrum Gap
The notification also leaves an asymmetry unresolved. Bharat Bhatia, president of the ITU-APT Foundation of India, has flagged that the new framework doesn't let private satellite earth station gateway operators apply for the spectrum their gateways need — that allocation currently sits exclusively with ISRO (Deccan Chronicle). So private gateway operators face the full weight of the localization mandate while the spectrum they need to operate remains gated behind the state satellite agency. That's not a data-sovereignty argument at all — it's a market-structure problem the localization rule incidentally exposes.
The Bottom Line
India is entitled to insist that logs from its telecom backbone don't sit on servers a foreign government can subpoena. But a blanket, zero-exception rule applied uniformly across IXPs, cloud-hosted networks and satellite gateways doesn't distinguish between data where sovereign control genuinely matters and routine operational logs where cross-border pooling makes the system safer, not weaker. Anupam Shrivastava, head of Submer India and a former BSNL chairman, called the framework "a bold step toward a greener, highly secure, and cloud-integrated future" (Daily Excelsior) — and it will undoubtedly pull data-centre investment onshore. The more useful test of the rule, though, is whether DoT is willing to calibrate it by data sensitivity in practice, rather than enforcing an absolute standard that a security-conscious regulator like the RBI didn't think necessary even for payments data.