India’s data fortress is a maze of conflicts
What are the incentives behind India’s efforts to localize its data?
Our goal with The Daily Brief is to simplify the biggest stories in the Indian markets and help you understand what they mean. We won’t just tell you what happened; we’ll tell you why and how too. We do this show in both formats: video and audio. This piece curates the stories that we talk about.
You can listen to the podcast on Spotify, Apple Podcasts, or wherever you get your podcasts and watch the videos on YouTube. You can also watch The Daily Brief in Hindi.
In today’s edition of The Daily Brief:
Story: India’s data fortress is a maze of conflicts:
India is tightening data localisation to strengthen digital sovereignty, but the rules are creating geopolitical friction and a domestic divide between large firms that benefit from local infrastructure and businesses that depend on free cross-border data flows.
Chart: Why are so few Indian women in the workforce?
India’s female workforce participation is improving but remains low, as limited suitable jobs, low wages, childcare costs, unsafe commutes, and unpaid household work continue to make employment difficult for many women.
We’re trying out something new. With each episode, instead of two stories, we’re trying one longer story. Along with that, we will have one chart created by our team, and some extra tidbits. We’d love to hear feedback and suggestions from you on what you feel about this format.
India’s data fortress is a maze of conflicts
Three weeks ago, the Department of Telecommunications notified a set of new rules.
According to them, every entity operating communication infrastructure in India — be it mobile tower companies, cloud-based telecom network providers, internet exchange points, or satellite gateways — must now store all their data exclusively within the country. No copies of that data can ever be routed, shared, or made available outside.
The rules are certainly very sweeping, but they haven’t come out of thin air. While this law is just about telecom data, India has been steadily expanding the categories of information that must stay within its borders, be it payment data, insurance records, or even social media data.
Yes, each mandate has had its own logic. But each mandate also creates winners and losers. When we dove into India’s data localization journey, we found debates not just between different sectors of India, but also within the same industry association.
The reason given for data localization is, of course, national sovereignty: protecting our data from foreign interference of any kind, while also making access by our own law enforcement easier. But they often overlap with the commercial interests of some of India’s largest firms.
We covered the DPDP Act last year, which was a major step forward in Indian data localization. However, much of that story was focused on the consequences of the law that were primarily applicable within India itself. This time, we wanted to go beyond, and look into the economics, the geopolitics, and the fierce domestic lobbying battles that have shaped India’s data localization regime.
That starts with a little bit of history.
Data didn’t always have borders
India hasn’t always had strict data localization rules. The earliest version of them was restricted to just government records, which couldn’t be transferred outside the country. Old telecom regulations also barred the overseas transfer of subscriber accounting information specifically. These were very narrow rules, and nobody was thinking about “data sovereignty“ as a grand national project.
The first real extension to the private sector only came in the 2010s.
In 2011, the government notified the IT SPDI Rules. This established baseline consent and security practices for companies handling sensitive personal data, like passwords, financial information, biometrics, and medical records. This was still a rule-set that was primarily confined to the data of everyday citizens. However, the first big case of business data being particularly subject to such a mandate came in 2015, when IRDAI required insurers to keep core insurance records strictly within Indian territory.
Then, around 2018, everything changed. Two separate events happened that turned data localization from a bureaucratic afterthought into a national priority.
One was the scandal of Cambridge Analytica, a political consultancy that had illicitly harvested the personal data of millions of Facebook users’ to target them with political advertising across over 100 election campaigns globally. That was a global wake-up call where data misuse graduated from being a consumer-rights issue to a threat to national integrity. It speeded up the momentum for more comprehensive data legislation everywhere.
The other event came from our own Supreme Court. In August 2017, the court made a first-of-its-kind ruling which declared privacy a fundamental right as per our Constitution. That ruling commanded the government to establish a comprehensive data protection regime. Directly inspired from this ruling, in 2018, the committee of Justice B.N. Srikrishna released a landmark report alongside a draft Personal Data Protection Bill.
The bill proposed India’s first economy-wide framework. One of its key mandates was that at least one live copy of all personal and sensitive data had to be stored on a data server inside India. It also contained rules for the cross-border transfer of other non-critical personal data.
However, the bigger bombshell on data localization came not from our judiciary, but our banking system. That same year, the RBI mandated all payment system operators to store transaction and financial data exclusively in systems located within India. Companies had six months to comply. This was the first major sector-wide localization rule with global economic consequences.
From that point, the trajectory was set.
The Srikrishna Committee bill went through multiple iterations in 2019 and 2021 before finally being passed as the DPDP Act in August 2023. As we’d covered earlier, the draft rules released in January 2025 tightened the screws further. And then came the July 2026 telecom rules.
India versus the world
India’s localization push has created real friction with the world’s two largest regulatory blocs — the United States and the European Union — and with them, the multinational companies that operate across all three jurisdictions.
The US and EU
For the US, India’s data borders, particularly the rules around payment data, are officially a trade barrier. American lobby groups representing Amazon, Microsoft, American Express, and others have pushed hard against the mandates, arguing that forcing companies to build redundant local data centres is economically inefficient and prevents Indian businesses themselves from accessing the best global services.
But America’s objections carry a certain irony: they have their own share of exacting data sovereignty rules.
For instance, in the event of a crime, the US CLOUD Act allows American law enforcement to compel US-regulated companies to hand over data, regardless of where that data is physically stored in the world. So even if an Indian citizen’s personal data sits on a server in Mumbai, the US government can legally access it as long as an American company controls it. In this case, physical localization doesn’t actually stop foreign surveillance if the controlling entity is foreign.
Meanwhile, the US Stored Communications Act runs in the opposite direction. It prohibits American tech firms from sharing user content data with foreign governments. One can read this as being complementary to the CLOUD Act for the purpose of prioritizing American interests.
Europe’s friction with India is less trade-related, though.
Europe’s GDPR is privacy-first rather than geography-first: it allows data to flow freely to any country that meets its “adequacy“ standards, rather than mandating where the physical server must sit. European tech bodies, in fact, argue that India’s obsession with physical residency is an outdated approach, because centralising a nation’s sensitive data within a single geography can create high-value targets for cyberattacks. It’s well-known that Big Tech firms like Google and Amazon have lobbied against GDPR.
There’s also an awkward diplomatic mismatch. During India-EU trade negotiations in the early 2010s, India demanded the EU relax its restrictions on transferring European citizens’ personal data to India. This was to make things easier for the Indian IT industry, which has many European clients. However, pushing for strict domestic data borders at home while lobbying for looser rules abroad is a tough position to maintain.
This friction continued well into 2026, when the landmark India-EU free trade agreement, which was finally signed, deferred the issue of cross-border data flows.
The payments showdown
Nowhere was the clash between India’s localization mandates and foreign commercial interests more dramatic than in the payments sector.
In 2018, when the RBI forced all payment data to stay within India, global card networks were caught off guard. Mastercard, Visa, and American Express, which dominated over 70% of the Indian card network at the time, pushed back hard. They requested deadline extensions. They lobbied for a compromise where they could keep a copy in India while continuing to store and process data globally. They argued that fragmenting their globally optimised infrastructure would be expensive and would weaken, not strengthen, overall security.
But the RBI simply did not budge, and stayed its ground.
Then, the lobbying of Western multinationals took another step by directly involving their host government. A Reuters investigation found that Mastercard had directly lobbied the US Trade Representative to oppose payment rules not just in India, but also in Indonesia, Vietnam, Ukraine and Ghana.
Not that this moved the RBI a single inch, anyway. In fact, in July 2021, the RBI banned Mastercard from onboarding new domestic customers.
The card networks had no choice but to give in. After all, India’s digital payments market (especially with UPI) was growing too fast for them to walk away. Eventually, the card companies spent millions building dedicated local data storage facilities within India. The ban on Mastercard was lifted in June 2022.
Meanwhile, domestic payments companies found this beneficial to their business and joined in on criticizing multinationals. PayTM even officially said that India must not become “mere internet colonies for global companies“, indicating a very unequal data relationship where global companies had all the power. Reliance founder Mukesh Ambani has also used similar language of “data colonization” in the past.
India versus….India?
The international friction is well understood. But the more revealing, more dramatic battle is actually the domestic one.
Take, for instance, the Internet and Mobile Association of India (IAMAI), one of India’s most prominent digital industry bodies. Its membership includes both global internet companies, e-commerce and payments companies, and India’s own telecom giants. In theory, it should speak with one voice. But in practice, on the subject of data localization, it has, quite extraordinarily, been torn apart.
You see, while providing its comments on the DPDP Act in 2023, IAMAI’s submission to the government had to include an unusual disclaimer: certain large members of the association had diametrically opposite views to what was in the report. The industry body representing India’s digital economy couldn’t agree on what to tell the government about the most important question in digital regulation.
Who benefits?
The dissenting members were Jio, Airtel and PayTM, who actually made a separate submission to the government.
Their position is that they are strongly opposed to any form of cross-border transfer of personal data of Indians. What they want is a “whitelist” approach, where the data stays in Indian servers by default, and the government individually approves each foreign country that can receive it.
All of them have commercial reasons to advocate for this, too.
Airtel, for instance, has been investing ₹1,500 crore annually in its data centre subsidiary Nxtra, targeting an expansion from 120-130 megawatts to 1 gigawatt of capacity over 3-4 years. Its digital arm, Xtelify, has launched a sovereign cloud offering that it is looking to offer to companies in the banking, financial services, and manufacturing sectors.
Jio, meanwhile, is on the road to building some of India’s biggest data centers, including one in Jamnagar that is expected to be the largest in the country by capacity. Jio also has its own cloud service.
Without a legal mandate that keeps data inside India, there wouldn’t be a business case to build domestic data storage infrastructure, and the billions already invested would go to waste. Global tech giants would continue routing data to their cheaper, pre-existing global facilities. Localization would create a guaranteed, captive domestic market for the infrastructure these companies are building.
Besides recent localization efforts, the government has responded in kind to these concerns. The Union Budget of 2026-27 introduced a tax holiday until 2047 for foreign cloud service providers that route their services through Indian data centres.
Who loses?
On the other side, IAMAI’s e-commerce players, SaaS startups, and other internet companies want an open-by-default internet. They pushed for a “blacklist” approach, where data flows freely to any country unless the government explicitly flags a destination as harmful.
They had many qualms with India’s blunt, brute-force approach to data localization.
For one, they argued that the DPDP Act’s definition of personal data was so broad it could capture even data that’s totally anonymized. That would directly threaten the ad-funded business models that keep online content free. Hard localization, in their view, would crush startups that lack the capital to build domestic data fallbacks and couldn’t afford to spend too much on compliance. It could also deter foreign investment, while also harming India’s IT export sector, which relies primarily on exporting to the US and Europe.
Is the fortress enough?
India’s data localization regime has come a long way from the 1990s. What started as a narrow restriction on government files has evolved into an economy-wide system of sectoral mandates, each reinforced by the next. And each mandate was stricter than the previous one.
But, even in its intended goal of data sovereignty, is localization enough as a policy?
For instance, the CLOUD Act means physical localization doesn’t stop a foreign government from compelling a US-controlled company to hand over data sitting on an Indian server. The Data Protection Board that is meant to enforce the DPDP Act’s rules hasn’t been fully operationalised yet, leaving businesses in a state of compliance-related uncertainty.
The economic costs are not evenly distributed, either. Large telcos and payments firms can absorb compliance overheads and profit from the captive market, while startups and smaller firms will likely face a disproportionate burden that makes them less attractive to investors.
These problems become even more glaring in the face of AI. You could have Indian data sit entirely inside India, but sovereignty would be a foregone conclusion if the LLMs, the GPUs, and the semiconductors are all external. Now, the definition of sovereignty need not be restricted to whether India has the domestic capacity for all this. It could be about the choices we have and the control we can exercise.
Many countries in the world have data localization rules, and many of them are justified. But in India’s case, the question is whether the specific form our regime has taken is solving the problems it intends to solve.
Why are so few Indian women in the workforce?
Female labour-force participation measures the share of women aged 15 and above who are either working or actively looking for work. It includes salaried employees, self-employed workers and women working on farms or in family businesses. So, it is broader than simply counting women with office jobs.
India’s rate was around 30% in 1990. It rose to nearly 35% in the mid-2000s, fell to around 26% by 2020 and then recovered to 32.4% in 2025. This recent improvement is welcome, but India still remains far behind China at 59.1%, South Korea at 56.8% and Vietnam at 68.6%.
So, why is the gap still so large?
One way to understand it is to look at the real cost of taking a job. A job may pay ₹15,000 a month, but accepting it could also mean paying for transport and childcare, spending several hours commuting and still handling most of the housework. If the workplace is far away, the journey feels unsafe or the salary is too low, working outside the home may not appear practical even when a woman wants to work.
Education has improved, but suitable jobs have not necessarily grown at the same pace. India has created valuable jobs in technology and services, but many require specific qualifications and are concentrated in large cities. At the other end, women may find informal jobs that are closer to home but offer low wages, little security and few opportunities to grow.
The kinds of jobs an economy creates also matter. Manufacturing expansion in countries such as China and Vietnam brought large numbers of women into factories. India’s growth has leaned more heavily towards services and capital-intensive industries, which have not created accessible jobs on the same scale for women with different levels of education.
There is also a measurement problem. Women may spend hours helping on family farms, caring for livestock or supporting a household business without being paid separately. Some of this activity can be missed or reported as household work, making women’s economic contribution harder to see. At the same time, not every woman outside the labour force is looking for a job.
Raising participation, therefore, is not simply about encouraging more women to work. It requires jobs that pay enough to justify the cost of taking them, safer and more reliable transport, affordable childcare, opportunities closer to home and workplaces that make it easier to return after a career break. Sharing unpaid care work more evenly would also give women more time to remain employed. Lasting progress will depend on creating jobs that women can realistically access and continue doing.
- This edition of the newsletter was written by Manie.
Arpit Tandon on the road ahead for Indian IT
In the latest episode of Subtext, we host Arpit Tandon (Director of AI Strategy, CGI) to break down what AI is actually doing to Indian IT. We cover the shift from headcount billing to outcome-based pricing, why “enterprise context” is becoming the ultimate competitive moat, and how AI is reshaping the roles of middle managers and junior talent.
You can watch or listen to the full episode on YouTube, Spotify, or Apple Podcasts.
Tidbits
[1] Mines Minister G. Kishan Reddy clarified that the MMDR Amendment Bill limits state levies on major minerals while keeping state powers over 49 minor minerals intact. However, several states argue the central restrictions on mineral-bearing land levies still intrude on state powers.
Source: Business Standard
[2] Fintech startup Navi has reportedly tapped banks including JPMorgan and Goldman Sachs for a planned IPO seeking to raise about $315 million through a primary share sale. While targeting a filing by December at a valuation up to $2 billion, discussions remain private and deal terms may change.
Source: Bloomberg
[3] A government panel is weighing health insurance proposals in India, including benchmarked treatment rates and an expanded National Health Claims Exchange. The proposed measures aim to improve pricing transparency and curb fraud amid ~12–14% annual medical inflation.
Source: Reuters
[4] US rules may be extending an existing $4,000 H-1B fee to certain visa extensions are adding millions in potential costs for large employers. The move reinforces Indian IT firms’ ongoing shift toward hiring local US talent and expanding offshore delivery models.
Source: Business Standard
[5] Larsen & Toubro has secured a mega order (touted at ₹10,000–15,000 crore) to deploy 10,000 Nvidia B300 GPUs for Together AI at its Chennai campus. The facility will be India’s largest single-cluster AI infrastructure within a gigawatt-scale data center site.
Source: The Economic Times
[6] India’s edible oil imports fell by 8% year-on-year to 14.81 lakh tonnes in July, with crude edible oils rising to 96% of the import basket. The shift was primarily driven by higher crude palm oil imports as refined oil imports dropped significantly.
Source: The Economic Times
[7] Defence PSU India Optel Limited has officially entered the commercial market with its indigenous GARUD high-resolution binoculars, which are weather-resistant and offer 8x magnification. The company has leveraged its defence-grade optical expertise for civilian outdoor use.
Source: CNBC
[8] Motilal Oswal Group has committed ₹1,500 crore via compulsorily convertible debentures to Inox Clean Energy, with ₹1,000 crore already deployed. The funding will support inorganic expansion and strategic acquisitions across INOXGFL Group’s renewable platform.
Source: Business Standard
Beyond Today’s Brief
There’s always more happening at Markets by Zerodha.
The Chatter: Why is the RBI Governor calling AI a structural shift on par with 1990s liberalisation? How is Canara Bank using foreign currency swaps to replace high-cost bulk deposits? And why did low-margin catering compress IRCTC’s overall profitability despite strong top-line growth?
What We’re Reading: Everything from how equity market institutions transformed Indian finance to whether AI data center build-outs pose a real credit risk to why Deepseek is chasing AGI at one-twentieth the cost.
Points & Figures: Why does Tamil Nadu lead India in factory jobs while Gujarat leads in gross output and Maharashtra in value creation? And what does state-level capital intensity reveal about how different regions build industrial ecosystems?
Join us on WhatsApp, where we share interesting soundbites from concalls, articles, and everything else we come across throughout the day. You’ll also get notified the moment a new video or article drops so that you can read or watch it right away.
Thank you for reading. Do share this with your friends and make them as smart as you are 😉











Reading/following one (more detailed/deeper study) story per day is definitely better than two per day. I had requested for this change in one of my comments earlier in the year. Thanks 🙏
In my opinion the charts need not be included. But if they do, the accompanying explanation can be done away completely and replaced by 1 more chart, asking readers for their comments on charts leading towards your next story 👍