India’s data fortress is a maze of conflicts artwork

India’s data fortress is a maze of conflicts

The Daily Brief

August 17, 2026

In today's episode of The Daily Brief, we cover a major story shaping the Indian economy and global markets: 00:04   Intro 00:39   The fight over Indian data 15:12   Tidbits We also send out a crisp and short daily newsletter for The Daily Brief.
Speakers: Akshara

Topics: Investing, Business, News, Business News

**Akshara** (0:04)
In today's episode, we'll break down India's data fortress being a maze of conflicts. Welcome back to The Daily Brief by Zerodha, where we cut through the noise to help you understand what's actually happening in the most important stories from business and markets. I'm your host Akshara, and today is Monday, 17th August. So we're trying out something new. With each episode, instead of two stories, we're trying one longer story. And along with that, we'll have one chart created by our team and some extra tidbits. And we'd love to hear feedback and suggestions from you on what you feel about this format. Coming to the first story.
Three weeks ago, the Department of Telecommunications notified a set of new rules. According to them, every entity operating communication infrastructure in India, be it mobile tower companies, cloud-based telecom network providers, internet exchange points or satellite gateways, must now store all their data exclusively within the country. No copies of that data can ever be routed, shared or made available outside.
Now, the rules are certainly very sweeping, but they haven't come out of thin air. While this law is just about telecom data, India has been steadily expanding the categories of information that must stay within its borders, be it payment data, insurance records or even social media data.
Yes, each mandate has its own logic, but each mandate also creates winners and losers. And when we dove into India's data localization journey, we found debates not just between different sectors of India, but also within the same industry association. Now, the reason given for data localization is, of course, national sovereignty. Protecting our data from foreign interference of any kind, while also making access by our own law enforcement easier. But they often overlap with the commercial interest of some of India's largest firms. Last year, we covered the DPDP Act, which was a major step forward in Indian data localization. However, much of that story was focused on the consequences of the law that were primarily applicable within India itself. But this time, we wanted to go beyond and look into the economics, the geopolitics, and the fierce domestic lobbying battles that have shaped India's data localization regime. And that starts with a little bit of history. So India hasn't always had strict data localization rules. The earliest version of them was restricted to just government records, which couldn't be transferred outside the country. Old telecom regulations also barred the overseas transfer of subscriber accounting information specifically. Now, these were very narrow rules, and nobody was thinking about data sovereignty as a grand national project. And the first real extension to the private sector only came in the 2010s. In 2011, the government notified the ITSBDI rules, and this established baseline consent and security practices for companies handling sensitive personal data, like passwords, financial information, biometrics, and medical records. Now, this was still a rule set that was primarily confined to the data of everyday citizens. However, the first big case of business data being particularly subject to such a mandate came in 2015, when IRDAI required insurers to keep code insurance records strictly within Indian territory.
And then, around 2018, everything changed. Two separate events happened that turned data localization from a bureaucratic afterthought into a national priority.
One was the scandal of Cambridge Analytica, a political consultancy that had illicitly harvested the personal data of millions of Facebook users to target them with political advertising across over 100 election campaigns globally. That was a global wake-up call where data misuse graduated from being a consumer rights issue to a threat to national integrity. And it sped up the momentum for more comprehensive data legislation everywhere. The other event came from our own Supreme Court. In August 2017, the court made a first-of-its-kind ruling which declared privacy a fundamental right as per our constitution.
That ruling commanded the government to establish a comprehensive data protection regime. And directly inspired from this ruling, in 2018, the Committee of Justice B and Srikrishna released a landmark report alongside a draft personal data protection bill. So this bill proposed India's first economy-wide framework. One of its key mandates was that at least one live copy of all personal and sensitive data had to be stored on a data server inside India. It also contained rules for the cross-border transport of other non-critical personal data. But the bigger bombshell on data localization came not from our judiciary, but our banking system.
That same year, the RBI mandated all payment system operators to store transaction and financial data exclusively in systems located within India. And companies had six months to comply.
This was the first major sector-wide localization rule with global economic consequences. And from that point, the trajectory was set. The Srikrishna Committee Bill went through multiple iterations in 2019 and 2021 before finally being passed as the DPDP Act in August 2023 And as we had covered earlier, the draft rules released in January 2025 tightened the screws further. And then came the July 2026 telecom rules. Now, India's localization push has created real friction with the world's two largest regulatory blocs, the United States and the European Union. And with them, the multinational companies that operate across all three jurisdictions. So, for the US, India's data borders, particularly the rules around payment data, are officially a trade barrier. American lobby groups representing Amazon, Microsoft, American Express, and others have pushed hard against the mandates, arguing that forcing companies to build redundant local data centers is economically inefficient and prevents Indian businesses themselves from accessing the best global services. But America's objections carry a certain irony. They have their own share of exacting data sovereignty rules. For instance, in the event of a crime, the US Cloud Act allows American law enforcement to compel US-regulated companies to hand over data regardless of where that data is physically stored in the world.

9 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID