HomeSpecialsWhy India's Data Centres must answer to Indian law, not Washington's

Why India’s Data Centres must answer to Indian law, not Washington’s

Indian policies governing Data Centre industry, which include cross-border data flows, infrastructure funding, sustainability, and data protection, are still under development

As this series’ preceding articles have demonstrated, a data centre is more than just a structure housing computers. It is a vital component of the country’s infrastructure, perhaps more strategically important than a power grid or a highway because the data that passes through it affects everything from a citizen’s credit score to the government’s capacity to provide welfare payments in real time. However, such infrastructure cannot establish itself in an appropriate way. It demands a policy framework that is futuristic enough to place a nation in a competitive position within a world where digital supremacy is quickly emerging as a new benchmark of national strength, sufficient to safeguard citizens and the natural environment, and compelling enough to draw significant investment.

In that policy approach, India is currently at a turning point. Global technology companies are increasingly preferring Indian cities over rivals in Southeast Asia and the Middle East, India’s data centre capacity has nearly tripled since 2020, and pledged investment reached nearly USD 95 billion between 2019 and 2025. However, the policies governing this industry, which include cross-border data flows, infrastructure funding, sustainability, and data protection, are still under development. The success of this policy framework is critical to the goals of Digital India, the IndiaAI Mission, and the larger Viksit Bharat 2047 vision. 

How leading nations are governing Data centres

Europe: The world’s most rigorous framework

The European Union has done more than anywhere else to outline what serious data centre governance looks like, and studying its framework in detail offers India the most useful insight because Europe has had to solve challenges that India will face at scale this decade, such as managing grid pressure while meeting climate targets, bringing in investment while safeguarding citizens, and balancing economic growth with sustainable development.  

The General Data Protection Regulation, or GDPR for short, is the cornerstone of the current era of data regulation at the EU level. It came into effect in 2018. Individuals have meaningful rights over their personal data, including the right to know what is collected, the right to request deletion, and the right to object to particular categories of processing, according to the GDPR. It imposed these requirements not only on European corporations, but on any entity across the globe that handles the personal data of EU citizens. The practical impact on data centres was significant: companies essentially had to prove that every data centre holding the personal data of European citizens adhered to GDPR-compliant security and accountability standards. As a result, reliable, regulated data centre infrastructure became more valuable, and considerable investment in high-compliance facilities became the norm throughout Europe. 

The 2023 revision to the EU’s Energy Efficiency Directive went one step further. Data centres larger than a given size were required to report on their energy consumption, water usage effectiveness, waste heat reuse, greenhouse gas emissions, and power usage effectiveness, which is a measure of how well a facility uses electricity and is calculated as total facility power divided by IT equipment power. 

The European Commission is setting up a ranking system that will publicly categorise data centres based on their energy and water performance. Imagine it as a star rating system for data centres, like to energy labels on refrigerators, which will enable citizens, investors, and governments to compare the operational efficiency of various facilities. The approach taken by Germany is based on the idea that data centres should actively participate in the larger energy system of the nearby areas rather than being isolated consumers of public infrastructure.

The story of Ireland’s experience with data centres is unique yet equally interesting. Dublin’s favourable corporate tax rates and English language advantage within the EU helped it become one of Europe’s most significant data centre hub in the 2010s, drawing companies like Microsoft, Google, Meta, and Amazon. However, by 2021, data centres were using about 14% of Ireland’s total electricity, a percentage that the Irish grid operator warned might increase to 30% by 2030 at the current trajectory due to the rapid growth of data centre capacity. In response, the Commission for Regulation of Utilities effectively halted new grid connections for data centres in the Dublin region, mandating that before they could connect to the national grid, new facilities must supply a sizeable portion of their own power through on-site renewable generation and battery storage. 

India urgently needs to learn from this moratorium and its conditional lifting. A data centre boom that exceeds grid capacity not only creates energy risk but also political risk due to the potential for severe and long-lasting public backlash against a clear preference of corporate infrastructure over household electricity supply.

There was a similar problem in the Netherlands, and in particular in Amsterdam. The Dutch grid operator, TenneT, was unable to connect newly constructed facilities across multiple zones due to the severe grid congestion caused by data centres centred in the Amsterdam city area. In 2019, the municipal administration of Amsterdam implemented a moratorium that aimed at the most congested neighbourhoods while allowing construction in places with grid capacity. This was combined with financial incentives for facilities that met high sustainability standards. 

France took a different approach, offering generous tax credits for investments in data centre infrastructure, expediting permits for facilities located in areas with easy access to renewable energy, and establishing clear Power Usage Effectiveness and Water Usage Effectiveness requirements that facilities had to fulfil in order to be eligible for state assistance.

North America: The market led alternatives and its limits

No serious look at how the world runs its data centres can skip the United States. It’s not just because Silicon Valley started the modern tech industry. It’s because the American way is, by design, the complete opposite of everything Europe has put in place. Washington has never built a single, comprehensive federal data centre policy. Instead, the whole system has been left, quite deliberately, to market forces, the big tech companies themselves, and the fifty different state governments. The federal government’s role stays mostly limited to national security rules and a few indirect financial incentives.

The result of that hands-off approach is Northern Virginia. Those suburban counties just outside Washington now hold roughly 35 percent of the world’s entire data centre capacity, by far the densest concentration of servers on the planet. Virginia didn’t get there because of some grand plan cooked up in Washington. It got there through an aggressive state level incentive package: wide sales tax breaks on equipment and software, special power rates negotiated straight with the utilities, and permitting processes that can green light big projects in months instead of years. Texas, Georgia, Arizona and Nevada quickly copied the same playbook. What you end up with is a fifty state race for data centre investment that looks a lot like India’s own patchwork of state level policies, the same speed in attracting capital, and the same risks of uneven rules and poor coordination between jurisdictions.

The United States offers one of the clearest cautionary tales of what happens when market led growth runs ahead of infrastructure planning. PJM Interconnection, which manages electricity supply across much of the eastern U.S. including the data centre-heavy corridor in Northern Virginia, had already warned by 2024 that the grid was nearing its limits because of rising data centre demand. Its projections suggested that planned new power additions could be overtaken within a few years by AI infrastructure alone. Last month New York resembled the warning as Governor Hochul ordered a temporary statewide moratorium on new hhyper scaledata centres. It is the first of its kind in the country and pauses permitting while the state figures out how to handle the strain on the grid and local resources.

In many ways, this was Ireland’s warning, only on a much larger scale. The investment came quickly because the U.S. asked few hard questions at the start, the costs showed up later, once the infrastructure strain had become structural.

When the federal government did respond, it did so mostly through indirect tools rather than direct intervention. The Inflation Reduction Act of 2022 offered major clean energy tax credits that data centre operators could use if they paired their facilities with renewable power, creating incentives for greener choices without making them mandatory. More striking was the Stargate initiative, the $500 billion private-public AI infrastructure partnership announced in January 2025. It marked a clear break from the old market-only approach and showed that even the U.S. had begun to accept that AI infrastructure is too strategic to be left entirely to competition alone.

Asia and the Gulf: Stringency and speed

The tale of Singapore, the most prominent Asian standard of excellence, is one of intentional, close to surgical management used to achieve a strategic objective. Due to severe land and water challenges, Singapore’s Info-comm Media Development Authority placed a halt on new data centre approvals in 2019. During this time, it developed a comprehensive sustainability framework with mandatory efficiency standards. In 2022, approvals were conditionally reopened, but only for facilities that showed a commitment to using recycled NEWater for cooling and met specified Power Usage Effectiveness and Water Usage Effectiveness thresholds. As a result, the data centre industry is truly world-class in terms of efficiency, commands premium pricing due to its controlled quality, and has made Singapore the leading reliable data hub for Southeast Asia. 

With attractive tax rates, quick regulatory approvals, and a strategic location at the meeting point of Europe, Asia, and Africa, the United Arab Emirates has employed an innovative model, the free zone framework, to lure international data centre operators. The UAE has combined economic appeal with clear data sovereignty rules and a drive to guarantee that UAE citizens’ data stays inside UAE jurisdiction, demonstrating that speed and ease of investment are compatible with strategic control.

From a sovereignty point of view, China’s strategy is insightful, even though India cannot immediately adopt its political setting. China restricts the movement of certain types of data overseas without regulatory consent and mandates that any data generated within its borders be retained on servers physically located in China. The fundamental idea that a country’s data is a sovereign asset that should not be casually transferred to foreign jurisdictions is the foundation of policy thinking in Brussels, Singapore, and increasingly New Delhi, even though this level of limitation is incompatible with an open investment environment. 

Why data protection is the invisible architecture

When talking about data centre policy, it is easy to concentrate just on the physical infrastructure, such as the buildings, electrical connections, and cooling systems. However, steel and fibre optic cable are not the most important parts of the infrastructure that sustains a robust data centre ecosystem. It is a trustworthy data protection law for both individuals and companies.

The logic is clear. Sensitive data, such as government records, health information, financial transactions, and private communications, will only be stored in digital systems by people and organisations if they have no doubt that the law will prevent unauthorised use, unauthorised access, and extraction of information by foreign governments. Highly valuable data simply does not enter digital systems at all without that confidence, which prevents the digital economy from reaching its full potential. The EU has built the institutional trust infrastructure necessary to support a major data economy, which is why GDPR had such a significant effect on worldwide data centre investment patterns.

The dangers of doing this in the wrong way can be summarised in what scholars and decision makers commonly refer to as ‘digital colonialism’, a scenario in which data produced by citizens of one nation is processed, analysed, and monetised mainly by corporations with headquarters and regulations in another nation, with the economic value moving outward rather than remaining inside the country. Aadhaar, UPI, ONDC, and the Digi Yatra facial recognition system are examples of India’s digital public infrastructure that produce large amounts of extremely sensitive and valuable citizen data. The risk of such value being taken overseas is not hypothetical in the absence of a robust domestic regulatory framework controlling the use and storage of that data, it’s structural.

India’s own journey: From Srikrishna Committee to the DPDP Act, 2023

India’s journey to modern data protection law has been more lengthy and challenging than that of most similar economies, and comprehending that journey is critical to determining where the country stands today.

When the Supreme Court of India unanimously ruled in Justice K.S. Puttaswamy v. Union of India in 2017 that privacy is a fundamental right under the Indian Constitution, the process officially got underway. In response, the government established a committee led by retired Justice B.N. Srikrishna to suggest a framework for data protection. Though it suggested a framework tailored to Indian conditions, including important provisions for data localisation, the requirement that specific categories of data be stored exclusively within India, the committee’s 2018 report was notable for its academic quality and its explicit engagement with the GDPR model.

The 2019 Personal Data Protection Bill was an important piece of legislation, it was simultaneously criticised from a number of angles. The range of the data localisation measures was protested to by global tech companies and foreign investors, who said that it would increase cost and complexity. Concerns regarding clauses that provided government agencies broad powers to process citizen data without agreement were voiced by civil society organisations and privacy activists. Both startups and domestic IT firms were concerned that the expense of compliance would make it difficult for new businesses to enter the market and favour established ones. The bill was sent to a Joint Parliamentary Committee, which spent two years thoroughly reviewing it. The committee’s recommendations in 2021 made the process of passing the bill even more difficult. The government decided to take a rare option to completely withdraw the Bill in August 2022, announcing its plan to replace it with a more straightforward and targeted law.

The Digital Personal Data Protection Bill 2022 was much shorter and easier to understand when it was made available for public comment. It replaced the complicated layered data localisation requirements of the 2019 Bill with a ‘negative list’ approach, which would allow cross-border data transfers to all nations save those that the government has specifically blacklisted. It also adopted a consent centric model, which requires companies to obtain clear, informed consent from individuals before doing anything with their personal data. This strategy provided businesses with far more regulatory certainty while sacrificing some of the earlier Bill’s stronger sovereignty provisions.

In August 2023, Parliament passed the Digital Personal Data Protection Act 2023, and the President officially signed it into law. The persons whose data is being handled are known as data principals, while the companies processing the data are known as data fiduciaries. The norms that govern the Act’s implementation were laid out in November 2025, with a gradual implementation schedule. Consent manager frameworks were to be functional by late 2026, the entire set of provisions, including processing obligations and penalty frameworks, were to be fully implemented by mid 2027, and the Data Protection Board of India, the Act’s enforcement body, was to be constituted immediately. A careful balancing act between the pressing need for governance and the practicality of building new institutional capacity is reflected in this layered approach.

What still needs to be done

MeitY has played a proactive and, in many ways, innovative role in the development of India’s data centre ecosystem. The first major attempt to develop a comprehensive federal framework for the industry was the Draft National Data Centre Policy, which was published in 2020. Its most important feature, designating data centres as essential infrastructure in 2022, completely changed the financing environment. Because financial and banking institutions categorise loans to important infrastructure differently from loans to regular commercial properties, data centre projects can obtain long-term institutional credit at cheaper interest rates. 

Another noteworthy development is the integration of data centre policy with the IndiaAI Mission, which came into effect in 2024. Leading data centers’ high performance computing infrastructure is directly demanded by the government as a result of the Mission’s objective of increasing domestic computer capacity for AI research. The IndiaAI Mission portrays the state as an active stakeholder in making sure that India has indigenous AI compute capacity under national governance, as opposed to letting foreign technology company’s investment decisions completely influence AI infrastructure.

The Union Budget 2026-27 introduced a landmark fiscal measure. A tax holiday extending to 2047 for eligible foreign cloud providers that use notified Indian data centres to serve their global operations, paired with structured eligibility criteria and safe harbour provisions to prevent abuse. This measure, by aligning the fiscal incentive horizon with the Viksit Bharat 2047 vision, sends a signal of policy continuity that is particularly valuable for investors making 15 to 20 year infrastructure commitments.

Notable Shortcomings  

India currently lacks a complete, all encompassing national data centre strategy with clearly defined implementation plans, quantifiable goals, and established accountability frameworks for both state and central bodies. Large investors, especially those making multi-state commitments, find it challenging to negotiate the regulatory inconsistencies caused by the lack of coordination between the central framework and the numerous state-level policies. Operators are left to decide themselves on measures that other nations have previously made necessary due to the lack of explicit national sustainability requirements for energy and water use within data centre facilities. Additionally, the DPDP Act’s full regulatory assurance won’t materialise until the phased implementation is finished, which means that current investment decisions are still being made in a somewhat unclear legal environment.

States as competing laboratories

The federal structure of India has resulted in a mixture of state level data centre rules that collectively reflect the nation’s coordination issues as well as its investment energy.   Knowledge of this type of setting is important since state governments make the majority of the decisions that directly impact the location of a data centre, including land purchase, electricity connections, and municipal approvals.

One of the most dynamic states is Maharashtra, which is home to the largest data centre hub in India, located in and around Mumbai. Through the Maharashtra Industrial Development Corporation, the data centre policy provides single window clearance, dedicated power feeders with guaranteed supply requirements, and capital subsidies. Submarine cable landing stations, a major pool of technical talent, and a logistics network that supports complicated supply chains of building large facilities are all part of the state’s current ecosystem. 

With policies meant for attracting facilities focused on AI and cloud native workloads, Karnataka, which has its headquarters in Bengaluru, offers a complimentary profile. It is stronger on technology workforce depth and startup ecosystem integration. 

Tamil Nadu has taken advantage of its submarine cable infrastructure and affordable power rates, establishing Chennai as the second-largest hub in India. Recent policy modifications have included particular incentives for green data centre certification.

By using the Telangana State Industrial Project Approval and Self-Certification System, or TSIPASS, to deliver exceptionally quick approval timelines, sometimes within 15 days for data centre projects meeting specified criteria, Telangana has been particularly active in positioning Hyderabad as a data centre hub. 

By merging the policy incentive framework with the port city’s advantageous location on the Bay of Bengal, Andhra Pradesh is using Visakhapatnam as the focal point of its data centre ambitions. 

With its 2025 data centre policy, Rajasthan has adopted what may be the most environmental friendly policy, requiring recycling of wastewater and, for some types of facilities, zero liquid discharge obligations, which require treated water to be used again within the facility instead of being discharged. 

Recently, Gujarat, Uttar Pradesh, and a few of other states have also started implementing data centre policies, acknowledging that this industry is one of the most lucrative industrial investments accessible to a state government actively striving for foreign direct investment.

One advantage of these frameworks’ diversity is that it encourages competition, which leads to improved incentives and the emergence of novel policies. However, it also makes it challenging for investors to make multi state, multi phase commitments, and it means that investor safeguards, approval procedures, and sustainability requirements differ greatly between states. This would be resolved without compromising the competitiveness that state level policy competition has produced by a more solid central coordination system that establishes minimum uniform requirements and a common reporting structure rather than removing state discretion.

The strategic and geopolitical case for keeping Indian data in India

Data centre governance is more than just a domestic economic and environmental issue. India’s strategic significance in a world that is quickly reorganising around digital power will be shaped by its policy choices in this domain, which is situated at the crossover of some of the most significant geopolitical factors of today’s world. 

Introduced in 2018, the United States Clarifying Lawful Overseas Use of Data Act, also referred to as the CLOUD Act, gives US law enforcement agencies the authority to require American technology companies to provide data kept on their servers, regardless of the location of those servers. Practically speaking, this means that US authorities may be able to access data belonging to Indian citizens or Indian government agencies that is stored on the infrastructure of US based cloud service providers, such as Amazon Web Services, Microsoft Azure, and Google Cloud, under domestic US law, without being required to inform the Indian government or obtain authorisation through Indian legal procedures. Every Indian policymaker involved in digital sovereignty should have a thorough understanding of this structural aspect of the existing global data architecture.

Since 2020, there has been significant speeding up of the US-China technology decoupling, which has had an important strategic advantage for India. Global tech giants that formerly concentrated their infrastructure in China are actively diversifying their operations, and India is becoming a more attractive option due to a number of factors, including a sizeable domestic data market that generates large volumes, competitive costs for construction and operation at true scale, a sizeable technical talent pool that speaks English, democratic governance, and an independent foreign policy that positions India as neither a Chinese customer nor a US reliant nation.

Aadhaar identification, the Unified Payments Interface, the Open Network for Digital Commerce, and the Account Aggregator financial data framework are just a few of the open digital platforms that make up India’s Digital Public Infrastructure arrangement, which produces citizen data in a size and privacy that is unmatched globally. A dataset of exceptional importance and high sensitivity is created when more than a billion people use a single digital architecture to interact with financial systems, government services, and commerce on a daily basis. Therefore, the logical case for ensuring that this data is handled, kept, and regulated within Indian jurisdiction, under Indian law, subject to Indian courts, and made available to Indian authorities by way of proper legal procedures as opposed to through the overseas laws of foreign statutes, is beyond ego or principle. It involves the core security of India’s digital sovereignty at a time when data is becoming the foundation for political power, economic measure, and national security.

Gaps, Synthesis, and what must come next

Significant progress has been made in India’s data centre governance, and this development should be acknowledged rather than subjected to self criticism. The granting of essential infrastructure status, the creation of the DPDP framework following a challenging legislative process, the integration of national compute aspirations by the IndiaAI Mission, and the long term financial certainty of the Budget 2026-2027 tax initiatives all point to a government that acknowledges the sector’s strategic importance and is working carefully to achieve it. The states, especially Rajasthan, Telangana, and Maharashtra, have shown that innovative, competitive state-level policy creation may draw significant foreign investment without compromising regulatory standards.

The architecture must then be completed by a series of actions. 

  1. First and foremost, India requires a completed and holistic national data centre approach with definite rollout dates, concrete objectives, and a clear coordination arrangement between MeitY and state governments. 
  2. Second, in order to guarantee the sector’s sustainable growth and to establish Indian data centres as globally recognised and reliable when seeking for certifications and global companies, a national energy and water efficiency norms, comparable to Europe’s Power Usage Effectiveness and Water Usage Effectiveness thresholds, must be officially defined and implemented. 
  3. Third, instead of being an idealistic outcome, the DPDP implementation schedule needs to be considered a strict deadline because each month of unfinished implementation is a month of uncertainty regarding regulations that costs India investment decisions made by multinational tech companies over several years.
  4. Fourth, in order to capture the job benefits of this capital intensive market domestically instead of foreign labour, India should take steps to nurture its skilled pool, including highly skilled engineers, data centre operations experts, and ecologically conscious administrators, through targeted programs integrated with the current National Skill Development Corporation framework.

Additionally, India is in a great position to take advantage of a completely unexplored opportunity. India is the clearly established leader in setting the standards for what ethical, sovereign, and inclusive data governance looks like for developing economies because it is the most developed democracy in the Global South and has the most extensive and comprehensive digital public infrastructure in the world. Compared to any framework exported from Brussels or Washington, a framework created in New Delhi that draws from the DPI experience and takes into account the unique requirements of developing countries that are digital adopters rather than digital originators would have far greater legitimacy throughout Africa, Southeast Asia, and Latin America. It would also position India as an influential pioneer of the emerging digital order rather than a player in the game in a system created by those in power. 

Conclusion

In the most basic sense, a nation’s data infrastructure is its nervous system for the digital era; it is the legal and physical framework that allows information to be transferred, stored, processed, and safeguarded. It is not appropriate for engineers and regulators to handle the specifics of this architecture. The decisions made today regarding the location of data storage, who controls it, and how effectively the facilities that store it use public resources will develop over decades into either a position of true digital sovereignty or one of fundamental dependency, making it an essential strategic requirement that belongs at the very top of government planning.India is at its closest point to the first result ever. Investments have begun to come in, rules and regulations are developing, and the global environment, the trend to shift away from China and the acknowledgement of India as a reliable third pole in the tech sector, is as favourable as it is going to be for some time. The current challenge is to build a data centre environment that is truly sovereign, sustainable, and reflective of the Viksit Bharat ambition it is intended to serve, as well as fill the remaining policy gaps with the exact same urgency and calibre of thinking that have defined the highest quality of India’s digital governance efforts over the past ten years.

Join OpIndia's official WhatsApp channel

  Support Us  

For likes of 'The Wire' who consider 'nationalism' a bad word, there is never paucity of funds. They have a well-oiled international ecosystem that keeps their business running. We need your support to fight them. Please contribute whatever you can afford

Divyansh Tiwari
Divyansh Tiwari
Transforming legal conundrums and global affairs into riveting prose where scholarly research meets real world significance.

Related Articles

Trending now

From Newslaundry to Javed Akhtar: How the left-liberal ecosystem whitewashed and shielded ‘Tehelka’ rapist Tarun Tejpal

The high and mighty, elite sections of society tried to defend Tejpal by downplaying a serious crime like sexual harassment in the workplace.

The victims that Punjab politics chose to forget

Local memorials, police webpages, press-freedom records and family recollections preserve fragments of those killed, while incomplete archives, political commemorations and cultural narratives continue shaping which victims remain visible and which gradually disappear from public memory.
- Advertisement -