At the India Mobile Congress (IMC) 2026, held in New Delhi, the discourse surrounding digital infrastructure took a sharp, assertive turn. While India has spent the better part of the last decade tightening laws around where data is stored, industry leaders are now arguing that "data residency"—the mere act of keeping servers on Indian soil—is no longer sufficient to guarantee true sovereignty.
Abhishek Biswal, Chief Business Officer at Airtel, set the tone for this shift on October 7, 2026. "When we talk about data sovereignty, we go beyond data storage," Biswal told a panel of experts. For India’s digital giants, the real challenge lies in "operational sovereignty"—the absolute ability of an organization to access its own data when needed, free from the threat of a foreign government’s "kill switch."
The Evolving Landscape of Data Localisation
For years, Indian regulatory frameworks have focused primarily on the physical location of data. The Reserve Bank of India (RBI) led the charge in 2018, mandating that all payment system data be stored exclusively within India. Similarly, the Indian Computer Emergency Response Team (CERT-In) issued directives in 2022 requiring entities to maintain system logs within Indian jurisdiction for 180 days, though later modifications allowed for overseas storage provided the data could be "produced promptly on demand."
However, the upcoming implementation of the Digital Personal Data Protection (DPDP) Act, 2023—specifically Section 16, which is slated to go into effect on May 13, 2027—will grant the government the power to restrict data transfers to specific foreign countries. Despite these legislative milestones, experts argue that legal compliance is only half the battle.
The primary concern is no longer just about where data sits; it is about who holds the "keys" to the infrastructure.
A Chronology of the "Kill Switch" Threat
The urgency of this debate is not merely academic; it is driven by high-profile corporate disruptions that have rattled Indian boardrooms.
- July 2025: Microsoft abruptly suspended Outlook and Teams services for Nayara Energy, a refiner partially owned by Russian firm Rosneft. Microsoft cited European Union (EU) sanctions as the reason for the sudden blackout. The services were only restored following intense legal pressure, mere days before a Delhi High Court hearing.
- September 2026: In a related move, the Delhi High Court directed SAP India to restore software support for Nayara Energy. The court observed that the suspension of services—again linked to foreign sanctions—was prima facie a breach of contract, highlighting the vulnerability of Indian enterprises relying on foreign-controlled software stacks.
- August 2025: Recognizing the market void, Bharti Airtel launched "Airtel Cloud" through its digital arm, Xtelify. During the launch, Gopal Vittal, Vice Chairman and MD of Bharti Airtel, emphasized that the platform was designed as a sovereign cloud where all controls reside "strictly within the country."
These incidents have underscored a reality: global tech giants, bound by the laws of their home countries, can inadvertently turn off critical infrastructure for Indian businesses, regardless of where the servers are physically located.
Defining the Layers of Sovereignty
Airtel’s Biswal articulated a three-tier framework for achieving true sovereignty. The first layer is basic data residency. The second involves control over the underlying technology throughout its entire lifecycle. The third, and most critical, is "operational sovereignty."
Operational sovereignty implies that an enterprise must have absolute authority over its physical infrastructure, including the logs, telemetry, and access rights. Biswal explicitly highlighted the risk posed by the U.S. CLOUD Act of 2018, which allows American authorities to compel providers under U.S. jurisdiction to disclose data in their possession or control, regardless of where that data is physically hosted. This extraterritorial reach puts Indian companies using foreign cloud providers in a position of perpetual risk.
Ajai Garg, a Consulting Specialist at Koan Advisory, noted that the era of a seamlessly interconnected, open internet—a byproduct of WTO-era policies—is fracturing. "This new giant called AI came up around 2016," Garg explained, "and economies began to split into blocs." According to Garg, nations are now realizing they have lost control over their intangible assets, from compute power to data, and are scrambling to reclaim it through strategic partnerships and localized infrastructure.
Supporting Data: The Cost of Security
Is the Indian market prepared to pay for this shift? According to Pablo Iacopino of GSMA Intelligence, the research arm of the global mobile operators’ association, the appetite for sovereignty is significant.
GSMA Intelligence research indicates that 75% of Indian enterprises now view technological sovereignty as a top-tier priority for their digital transformation. Perhaps most surprisingly, these businesses are willing to pay an average premium of 13% to 15% for "sovereign-grade" technology.
"Cybersecurity is the objective enterprises rank highest," Iacopino noted. The willingness to pay is particularly high in the financial technology (fintech) sector, where data integrity is the lifeblood of the industry. However, Vivan Sharan, a Partner at Koan Advisory and moderator of the IMC panel, offered a note of caution. He pointed out that Indian fintech operates on razor-thin margins, particularly given that UPI transactions do not carry a Merchant Discount Rate (MDR). For these companies, a 15% premium is a heavy burden, even if the security benefits are clear.
The European Cautionary Tale
During the panel, a provocative point was raised regarding the European Union’s approach to digital regulation. Sharan suggested that Europe attempted to solve the sovereignty question through heavy-handed regulation, only to find that it stifled innovation and investment.
Garg echoed this sentiment, arguing that the EU’s recent digital laws have created an "over-regulated space." He warned that "regulating ahead of the market kills a market." The consensus among the panel was that India must find a middle path—one that ensures national security and operational control without building a "walled garden" that discourages technological advancement.
"We need to find a path between the two things," Iacopino added, emphasizing the delicate balance between robust regulatory frameworks and the need for capital-intensive investment in domestic infrastructure.
Implications for the Future
The debate leaves several critical questions unanswered. Who has the authority to certify a cloud as "sovereign"? Does sovereignty require total indigenous control, or is it about the legal architecture of the provider?
For Airtel and other providers, the challenge is clear: they must convince the market that their sovereign cloud offerings provide not just a patriotic alternative, but a technically superior and more resilient one. As Biswal noted, "Wherever you can solve the customer problem, we can invest decisively."
The implications of this movement are far-reaching. If India successfully mandates or incentivizes the shift toward sovereign infrastructure, it could change the power dynamics between global software giants and domestic enterprises. It also suggests that the next phase of the digital revolution will be defined by "data nationalism," where the value of data is measured not just by its utility, but by the security of the jurisdiction that governs it.
As of the conclusion of the IMC 2026, the industry awaits further clarity from the government on how Section 16 of the DPDP Act will be operationalized. Until then, the scramble to build "sovereign-ready" digital infrastructure will likely remain the defining theme of India’s corporate tech strategy, as companies prepare for a future where access to data is no longer guaranteed, but must be built, guarded, and controlled from within.
