Sovereign Cloud in India: Why Enterprises Are Moving Off Global Hyperscalers
Let’s discard the lazy explanation first. Indian enterprises are not moving workloads off global hyperscalers out of protectionism, and this is not an anti-cloud story. The hyperscalers are excellent platforms, and for plenty of workloads they remain the right answer. What is actually happening is more precise, and more interesting: after a decade of pricing jurisdictional risk at roughly zero, enterprises are repricing it. The law changed. The geopolitics changed. And AI changed what a cloud region holds — no longer just your systems, but your models, your training data and every prompt your organisation types. At L&T Vyoma, we watch this from the receiving end, and the pattern is consistent: the hyperscaler isn’t being fired. It is being re-scoped. The regulated core and the AI layer are coming home to sovereign cloud in India, and this piece explains the forces doing the pulling.
Force One: The Law Grew Teeth
India’s regulatory floor has hardened from guidance into statute. The DPDP Act 2023 governs personal data with penalties that reach ₹250 crore for violations, and its cross-border transfer regime works on a government-controlled negative list — lawful today is not guaranteed lawful tomorrow, which turns every offshore dependency into a standing migration risk. Underneath the Act sit the sector mandates with longer histories: RBI’s requirement that payment data be stored in India, SEBI’s 2023 framework binding cloud adoption for regulated entities to MeitY-prescribed data centers, ABDM shaping how health data moves. A compliance officer reading that stack reaches an uncomfortable conclusion about shared foreign infrastructure: you can be contractually assured on it, but you cannot be architecturally certain.
The DPDP Act and the Real Source of Localization Pressure
Precision matters here, because the DPDP Act is widely misread. The Act does not impose blanket data localization. Earlier drafts — the 2019 and 2021 bills — did propose hard localization, a mandatory local copy of sensitive data and tight limits on sending critical data abroad. The version that became law in 2023 walked away from that. Under Section 16, and the DPDP Rules notified through 2025, cross-border transfer is permitted by default and restricted only to destinations the government specifically names on a negative list. On paper, that is permissive.
So why do Indian enterprises feel localization pressure anyway? Because the real weight sits beside the Act, not inside it. Three forces combine. First, the sector regulators, which localize hard and predate the DPDP Act: RBI’s 2018 circular requires payment-system data to be stored only in India, and SEBI, IRDAI and the health-data frameworks carry their own residency and reporting rules that apply in full regardless of what Section 16 allows. A broker cannot process trading data offshore because a permissive privacy law says it may; the market regulator says it may not. Second, the DPDP Act’s own reserve powers: for Significant Data Fiduciaries — the large processors most enterprises now qualify as — the Rules let the government bar offshore transfer of specified categories of personal data outright, and can impose functional localization on critical-infrastructure and public-sector data. Third, and most corrosive to a foreign-cloud strategy, the negative list is executive and dynamic: a destination that is open today can be restricted by notification tomorrow, on grounds of national security or diplomacy, with no legislative delay. You cannot architect a decade of data flows around a list that can change with a gazette entry.
Put together, the picture is sharper than “the law says keep data in India,” because the law does not quite say that. It says something more demanding for anyone planning infrastructure: your obligations are set by whichever of the DPDP Act, your sector regulator, and a revisable negative list is strictest, and that answer can move. Sovereign infrastructure is how an enterprise stops chasing that moving target. When the data, the operator and the jurisdiction are all Indian, you are compliant with the localization rules that exist and insulated from the ones that might, and you never have to re-plan a migration because a country moved onto a list. That is why, for regulated Indian enterprises, sovereignty reads less like a privacy preference and more like risk management.
Force Two: Jurisdiction Stopped Being Theoretical
The second force is the one contracts cannot fix. A hyperscaler’s Indian region is physically in India and legally tethered to a parent that answers to its home government — including laws with extraterritorial reach that can compel access to data held abroad. For years this stayed a hypothetical in vendor questionnaires. Rising geopolitical tension moved it onto risk registers, and it now tops the list: IDC’s 2025 Worldwide Digital Sovereignty Survey found that Europe’s leading driver for sovereign cloud is protection against extra-territorial data requests, displacing compliance and marking a shift in emphasis toward autonomy (IDC). The market response is measurable too: Gartner forecasts sovereign cloud IaaS spending of USD 80 billion in 2026, up 35.6% in a year, and expects around 20% of workloads to shift from global to local providers as organisations repatriate what matters (Gartner). Governments are the biggest buyers, followed by exactly the industries you’d predict: finance, critical infrastructure, telecom.
Force Three: AI Raised the Stakes
The third force is the newest and, we’d argue, the decisive one. Enterprise AI concentrates an organisation’s most sensitive material in one place. Training corpora distilled from customer records. Fine-tuned weights that are the company’s judgement, encoded. Inference logs and prompts that capture, in plain text, what the business is thinking about right now. Send that layer to a foreign-controlled region and the exposure is no longer one database among hundreds; it is the organisation’s accumulated intelligence. Buyers have noticed, and public-sector buyers first: 53% of EMEA governments plan to increase their use of sovereign cloud specifically for AI solutions (IDC). India’s calculus runs the same way, with the DPDP stack layered on top.
What Actually Moves, and What Stays
Honest sovereignty strategy is triage, not exodus. Global-facing, stateless workloads — content delivery, international products, commodity web tiers — often stay exactly where they are, and should. What moves is the regulated core and the AI layer: payment and KYC data, health records, citizen-facing services, and the training, fine-tuning and inference built on all of it. This is why we’re wary of vendors selling sovereignty as an all-or-nothing migration. The enterprises doing this well run a two-estate model: global platforms for global work, sovereign infrastructure for the workloads where jurisdiction is the risk. The skill is in drawing the line deliberately instead of discovering it during an audit.
What They Move To
A credible sovereign destination has to clear four bars, and “a data center in India” clears only the first. Residency: the data stays in-country. Operator: an Indian entity runs the infrastructure, so no foreign parent’s obligations reach into the hall — ours are L&T-operated campuses in Mumbai and Chennai, Tier III certified, DPDP-aligned by architecture. Capability: sovereignty must not cost you the modern stack, which is why the AI Factory runs current NVIDIA Blackwell, Hopper and RTX fleets in liquid-cooled halls built for beyond 100 kW per rack — the same class of compute the global platforms offer, on Indian soil. And breadth: public cloud, colocation and managed services, so the two-estate model has somewhere real to land. The Cloud Calculator prices the sovereign estate before you commit to it.
The Decision, Criterion by Criterion
|
Decision Criterion |
Global Hyperscaler Region |
Sovereign Cloud (L&T Vyoma) |
|
Legal jurisdiction |
Parent answers to foreign law |
Indian operator, Indian law, end to end |
|
DPDP posture |
Contractual assurances on shared infrastructure |
Compliance by architecture |
|
Sector mandates (RBI, SEBI, ABDM) |
Case-by-case, audit-heavy |
Localisation is the default state |
|
AI workloads |
Weights, prompts and logs follow the platform |
Model layer stays on Indian soil |
|
Cost exposure |
Dollar-denominated, egress-laden |
Indian pricing, modelled up front |
|
Support & escalation |
Global queue |
Local team, same jurisdiction as you |
|
Best kept for |
Global-facing, stateless workloads |
Regulated data and the AI layer |
Repricing Risk, on Purpose
The move to sovereign cloud in India is what it looks like when a market stops treating jurisdiction as a footnote. The law grew teeth, geopolitics made the hypothetical concrete, and AI gathered the crown jewels into one workload class. None of that argues for abandoning global platforms. It argues for knowing exactly which workloads can never sit under someone else’s law, and giving them infrastructure built for that fact. That is what we operate. Talk to our team about drawing your line, or start with the AI Factory and see what the sovereign estate looks like.
Sources: Gartner (sovereign cloud IaaS spending 2026, workload repatriation); IDC, Worldwide Digital Sovereignty Survey 2025 (Europe’s leading sovereign cloud driver) — idc.com/resource-center/blog/digital-sovereignty-in-europe-in-2025-whats-plan-b/; IDC (EMEA government demand for sovereign cloud for AI) — idc.com/resource-center/blog/digital-sovereignty-across-emea-what-it-means-for-telcos/. Regulatory references: DPDP Act 2023 (Section 16, cross-border transfer / negative-list model) and DPDP Rules 2025; RBI payment-data localisation circular (2018); SEBI cloud adoption framework (2023); IRDAI and ABDM sector frameworks.

