Airtel's Chief Business Officer Abhishek Biswal declared data residency "not enough" for true data sovereignty at IMC 2026. He argues actual data control matters, especially whether a foreign government can cut off access to Indian enterprises. The Delhi High Court in September 2026 already ruled against SAP India for suspending Nayara Energy's software support citing EU sanctions.
How We Got Here
India's data localization mandates, like RBI's 2018 payment data rule and CERT-In's 2022 log requirements, heavily focus on domestic storage. Airtel itself launched its sovereign cloud, Xtelify, in August 2025, with controls promised "strictly within the country."
The Numbers
- Biswal's approach to sovereignty extends beyond storage, covering technology lifecycle control and operational access to physical infrastructure, logs, and telemetry.
- The Digital Personal Data Protection Act's Section 16, which enables the government to restrict data transfers, activates on May 13, 2027.
- Microsoft suspended Outlook and Teams services for Nayara Energy in July 2025 due to EU sanctions, restoring them before a Delhi High Court hearing.
- The US CLOUD Act of 2018 allows American authorities to compel data disclosure from providers under US jurisdiction, regardless of data storage location.
- CERT-In's 2022 directions require entities to keep system logs for 180 days within India, though FAQs later allowed abroad storage if promptly produced.
What Happens Next
🇮🇳 Why This Matters for India
For SaaS founders and enterprise IT leaders in Pune and Hyderabad, this highlights the critical vendor lock-in risk from foreign cloud providers and the need for truly sovereign alternatives.
The Take
Airtel is directly challenging MNC cloud giants like AWS and Azure operating in India, highlighting the glaring gap in current data laws. The underlying tension about foreign judicial reach into Indian enterprise data will force a regulatory reckoning within 18 months, undeniably favoring local providers.
Source:
MediaNama ↗