The development comes at a time when cost advantages, supportive policies, and data localisation are positioning India as a regional data centre hub
| Photo Credit:
The Government of India is expected to announce a unified cloud sovereignty framework in the coming days, aimed at ensuring that all government entities retain control over the country’s mission-critical data, sources told businessline.Following consultations with local cloud service providers (CSPs) and industry stakeholders, the Ministry of Electronics and Information Technology (MeitY) has drawn up a list of parameters for government entities to consider when working with cloud and network service providers. These parameters include the deployment of air-gapping solutions within the adopted cloud infrastructure, particularly in the case of international CSPs.Isolated systemsIn an air-gapped setup, critical systems are isolated from external networks, allowing them to continue operating independently even if connectivity with a cloud provider’s overseas infrastructure is disrupted. Such a solution physically separates information networks to protect India’s sensitive data, even when hosted on foreign hyperscaler platforms. It can be thought of as a security measure beyond localised datasets, where the information is isolated even from cloud or Wi-Fi networks.“Today, you have virtual private clouds, private clouds, and government-certified clouds. None of these incorporates the concept of an air-gapped environment. For example, if a hyperscaler’s connectivity with its home country is cut off, the system in India would continue operating because it is air-gapped. That demonstrates resilience in running cloud infrastructure,” a source told businessline.The overarching intention is to understand sovereignty and develop possible strategic resilience checks, particularly for government bodies that currently use a mix of cloud offerings. Different government bodies across India utilise various cloud solutions, ranging from the Meghraj cloud, managed by the National Informatics Centre (NIC), to private cloud services. According to Communications Minister Jyotiraditya Scindia, the government currently has about 14 cloud partners.Data SovereigntyThe proposed framework would require government entities to assess factors such as the origin of cloud platforms, whether Indian or foreign, their operational independence from parent companies, compliance with Indian data protection laws and regulations, exposure to foreign legislation such as the US CLOUD Act and the Patriot Act, server locations, and kill-switch mechanisms.“The idea is to develop a practical definition of sovereignty. During consultations, all CSPs spoke about control and improvement. Ultimately, the objective is to differentiate between local and international players and strengthen control mechanisms,” said a source familiar with the discussions.The development comes at a time when cost advantages, supportive policies, and data localisation are positioning India as a regional data centre hub. Last Friday, Finance Minister Nirmala Sitharaman, at the Global Fintech Fest, also called for a soft-touch regulatory approach to agentic AI, suggesting that the government is increasingly moving towards a more structured governance framework for emerging technologies, underpinned by a stronger emphasis on digital sovereignty.Published on September 13, 2026







