Industry Odisha Bureau, Jul 24: For years, the question of where a country’s telecom traffic physically lives was largely an engineering detail, settled by whichever data centre offered the best latency and price. India has now made it a matter of law.
Under rules notified by the Department of Telecommunications on July 20, every newly authorised telecom entity must keep the systems that constitute its network — along with the associated data, logs and information those systems generate — inside the country. The notification is explicit that no copies may be routed, shared or otherwise made available beyond India’s borders.
The wording matters more than it might appear. This is not the familiar debate over where a consumer’s photographs or a bank’s customer records are stored. Telecom network data is a different category: the signalling records, routing tables, configuration files and event logs that describe how a national communications system actually operates. Aggregated, that material reveals traffic patterns, network topology, points of failure and the movement of subscribers. It is the raw material of network management and cybersecurity — and, in the hands of an adversary, of reconnaissance.
A regime change, not just a rule
The localisation mandate arrives as part of a broader architectural shift. India is moving away from the licensing regime that governed telecom for decades toward a lighter-touch authorisation framework built under the Telecommunications Act, 2023 — legislation intended to replace a colonial-era statutory foundation with something designed for a market where connectivity is delivered as much by software and satellites as by copper and towers.
The new framework reaches across six categories: infrastructure providers, digital connectivity infrastructure providers, internet exchange point operators, satellite earth station gateway providers, cloud-hosted telecommunication network providers and mobile number portability providers.
That list is worth reading closely. It captures the entities that sit beneath the consumer-facing operators — the passive tower companies, the exchange points where networks meet, the gateways that link orbital constellations to terrestrial infrastructure. These have historically occupied an ambiguous regulatory space. They no longer do.
The cloud category is the tell
The most consequential entry may be the newest one. By creating a distinct authorisation for cloud-hosted telecommunication network providers, the government has formally acknowledged what network architecture has been trending toward for a decade: telecom functions once embedded in proprietary hardware now run as virtualised software, capable of being hosted anywhere a data centre exists.
Anupam Shrivastava, who heads Submer India and previously served as chairman and managing director of BSNL, called the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026 a transformative milestone for the country’s digital infrastructure. Having led traditional telecom infrastructure and now working in sustainable data centre solutions, he described the framework as a bold step toward a greener, highly secure and cloud-integrated future.
His read on the commercial consequence is direct. Requiring telecom network systems, data and logs to remain exclusively within the country will, he said, trigger a substantial surge in domestic data centre demand. The cloud-hosted category itself carries a deliberately low barrier — a ₹10 lakh entry fee and no annual authorisation charge — which Shrivastava argued will integrate cloud data centres with telecom networks and democratise access to infrastructure.
The economics follow logically. If a virtualised network function serving Indian subscribers must run on Indian soil, and its logs must never leave, then capacity has to be built here. That is a demand signal for hyperscale operators, for the domestic colocation industry, and for the power and cooling supply chains behind them.
Inspection powers, and their limits
Enforcement has teeth. The Centre may inspect telecom infrastructure sites — including installations located inside a user’s premises — and audit the compliance processes and systems of authorised entities. Where immediate action is judged necessary in the public interest, inspections may proceed without prior notice.
The government may also appoint a designated agency to carry out compliance audits. The notification builds in a countervailing safeguard: that agency is not to collect or demand disclosure of information capable of damaging the competitive position of any user or authorised entity.
It is a familiar regulatory balance — supervisory access on one side, commercial confidentiality on the other — and one whose durability will be tested in practice rather than on paper. Auditors examining network configurations are, almost by definition, looking at material that competitors would find valuable.
Where the risk lands
One provision assigns risk with unusual bluntness. Infrastructure providers bear sole responsibility for securing the permissions required to roll out networks, and the rules state that unavailability of right of way, or delays in obtaining it, cannot be invoked as grounds for non-compliance with any obligation.
Right of way has been among the most persistent frictions in Indian network deployment, involving municipal authorities, state governments, highway agencies and private landowners, each with distinct processes. The framework places that coordination burden squarely on the operator and declines to accept it as an excuse.
The unfinished business of spectrum
The most substantive gap concerns satellite gateways. Bharat Bhatia, president of the ITU-APT Foundation of India, welcomed the detail in the authorisation guidelines but flagged an omission that could hollow out one of the six categories.
The notification, he noted, does not permit authorised entities to apply for spectrum — which is essential to operating a gateway at all. At present, gateways are run by ISRO, which holds the necessary gateway spectrum, leaving private players at a disadvantage. Bhatia said TRAI is consulting on the question and expressed hope it would be settled in the regulator’s next set of recommendations.
The asymmetry is straightforward: an authorisation to build a satellite earth station gateway is of limited use without the frequencies to run it. As satellite broadband constellations expand their commercial footprint in India, the gateway is the chokepoint where orbital capacity meets terrestrial fibre — and the entity that controls gateway spectrum controls the terms of entry.
What it adds up to
Taken together, the rules describe a government that has decided telecom infrastructure is national infrastructure, subject to the same sovereignty logic applied to defence supply chains and payments systems. India has pursued localisation in other sectors before; extending it to network operations data is a narrower but more strategically pointed step.
For international cloud providers, the implication is that serving Indian telecom workloads will require in-country footprint rather than regional capacity in Singapore or the Gulf. For operators and enterprise customers, it means a period of architectural review — mapping which logs flow where, and re-engineering the ones that cross a border they no longer may.
Regulatory certainty tends to attract investment, and a framework with clear entry fees and defined categories offers more of it than the discretionary licensing world it replaces. Whether that certainty survives implementation will depend on how the inspection powers are exercised, how the confidentiality safeguard holds, and whether the spectrum question is answered before the satellite category becomes a licence to do nothingsatelit

