{"id":388668,"date":"2026-06-27T13:00:08","date_gmt":"2026-06-27T07:30:08","guid":{"rendered":"https:\/\/www.scconline.com\/blog\/?p=388668"},"modified":"2026-06-26T17:18:54","modified_gmt":"2026-06-26T11:48:54","slug":"india-data-sovereignty-us-cloud-act-analysis","status":"publish","type":"post","link":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/","title":{"rendered":"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws"},"content":{"rendered":"<div style=\"text-align: justify; line-height: 150%;\">\n<p style=\"margin-bottom: 3%; font-style: italic; text-align: center;\">RBI established data localisation requirements which force financial services organisations to undergo the most difficult evaluation tests for sovereignty assessment.<\/p>\n<p style=\"margin-bottom: 3%; font-style: italic;\">This article is one of the winning entries (Ranked 5<span style=\"vertical-align: super;\">th<\/span>) of Lexathon organised by NLU, Odisha, a technology law conclave on AI, data protection, and innovation which took place in April, 2026.<\/p>\n<p style=\"font-weight: bold;\">Introduction<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The digital shift and the sovereignty paradox<\/p>\n<p style=\"margin-bottom: 3%;\">Indian financial institutions &#8212; <span style=\"color: #34495f;\">Housing Development Finance Corporation (<\/span>HDFC Bank), State Bank of India, <span style=\"background-color: #ffffff; color: #202122;\">Industrial Credit and Investment Corporation of India (<\/span>ICICI Bank) and various fintech startups have transitioned their major business functions to hyperscale the cloud services which are offered by Amazon Web Services (AWS) and Microsoft Azure and Google Cloud.<a id=\"fnref1\" href=\"#fn1\" title=\"1. Asian Development Bank, Cloud Computing as a Key Enabler for Digital Government across Asia and the Pacific (2021) Chs. 2-3.\"><sup>1<\/sup><\/a> The system provides organisations with the ability to grow their operations, and it offers improved disaster recovery capabilities while decreasing their financial costs. The technological progress originates from a basic conflict situation which occurs when financial institutions keep personal data on Mumbai servers while American companies based in Seattle handle the data management process.<\/p>\n<p style=\"margin-bottom: 3%;\">India has established thorough data protection through the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023 (DPDP Act<\/a>)<a id=\"fnref2\" href=\"#fn2\" title=\"2. Digital Personal Data Protection Act, 2023.\"><sup>2<\/sup><\/a> and Reserve Bank of India&#8217;s (RBI&#8217;s) stringent data localisation regulations that govern payment systems. The two instruments establish that all data which exists within India&#8217;s territorial boundaries must follow Indian jurisdictional laws<\/span><\/span><span class=\"annotation&nbsp;reference\"><span style=\"\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><span style=\"\"><!-- LE to check relevance of n.1 and see article as it cannot be verified. --><\/span><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- removed --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> The territorial principle conflicts with the<\/span> US<\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the relevance --><\/span><\/span> of 2018<\/span><\/span> because this law establishes US A<\/span><a id=\"fnref3\" href=\"#fn3\" title=\"3. Justin Hemmings, Sreenidhi Srinivasan and Peter Swire, &#8221;Defining the Scope of &#8216;Possession, Custody, or Control&#8217; for Privacy Issues and the CLOUD Act&#8221; (2020) 10, 631, available at &lt;https:\/\/nationalsecurity.law.georgetown.edu\/wp-content\/uploads\/2020\/05\/Defining-the-Scope-of-Possession-Custody-or-Control.pdf&gt;.\"><sup>3<\/sup><\/a><\/span><span class=\"annotation&nbsp;reference\"><span style=\"\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><span style=\"\"><!-- LE to check relevance --><\/span><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- Cite Peter Swire \"Defining the Scope of &#8216;Possession, Custody, or Control&#8217; for Privacy Issues and the CLOUD Act\" chrome-extension:\/\/efaidnbmnnnibpcajpcglclefindmkaj\/https:\/\/nationalsecurity.law.georgetown.edu\/wp-content\/uploads\/2020\/05\/Defining-the-Scope-of-Possession-Custody-or-Control.pdf --><\/span> US courts can use the CLOUD Act standard for &#8220;possession custody or control&#8221; to compel American Cloud Service Providers (<\/span><a id=\"fnref4\" href=\"#fn4\" title=\"4. 18 USC S. 2713; Theodore Christakis, &#8220;Extraterritorial Enforcement Jurisdiction in Cyberspace: Normative Shifts&#8221; (2023) Leiden Journal of International Law.\"><sup>4<\/sup><\/a><\/span><span class=\"annotation&nbsp;reference\"><span style=\"\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><span style=\"\"><!-- LE to check footnote, highlighted text not found --><\/span><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- checked --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"><\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Scope and significance<\/p>\n<p style=\"margin-bottom: 3%;\">The research maintains a research focus through its use of specific analytical methods. The research focuses on financial services data banking payment systems and insurance because these sectors represent the highest economic and strategic risks.<\/span><a id=\"fnref5\" href=\"#fn5\" title=\"5. PwC India, &#8220;On-Soil Storage of Payments Data&#8221; (2018).\"><sup>5<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for Reserve Bank of India (n 2) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> RBI established data localisation requirements which force financial services organisations to undergo the most difficult evaluation tests for sovereignty assessment.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">The geographic corridor primarily examines the India-United States jurisdictional nexus, which shows that AWS and Microsoft Azure and Google Cloud hold most cloud services in India because their market share exceeds 60 per cent.<\/span><a id=\"fnref6\" href=\"#fn6\" title=\"6. Amazon Web Services, MeitY (Ministry of Electronics and Information Technology) Empanelment (2026).\"><sup>6<\/sup><\/a> The US CLOUD Act functions as the most advanced extraterritorial data-access system which enables US Authorities to access data stored outside the United States while European and Chinese cloud services create similar sovereignty problems through General Data Protection Regulation (GDPR) and Chinese cybersecurity law.<\/span><a id=\"fnref7\" href=\"#fn7\" title=\"7. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), (2016) OJ L119\/1; Cybersecurity Law of the People's Republic of China (adopted 7 November 2016, effective 1 June 2017) Art. 37.\"><sup>7<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- XML to hyperlink Regulation (EU) 2016\/679 of the European Parliament and of the Council<br \/>http:\/\/www.scconline.com\/DocumentLink\/eV0B8E6X; LE to check the act mentioned below and XML to hyperlink if needed - Cybersecurity Law of the People's Republic of China (adopted 7 November 2016, effective 1 June 2017) Art. 37. --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- checked --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> The analysis establishes its time-frame by using current regulations that exist in early 2025 which follows the<\/span> <span style=\"Opan sans&quot;;\"><a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">DPDP Act<\/a><\/span><span style=\"Opan sans&quot;;\">&#8216;<\/span>s implementation and the period before all delegated regulations are completed.<\/span> <\/span><\/p>\n<p style=\"font-weight: bold;\">The conceptual framework<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Deconstructing the cloud<\/p>\n<p style=\"margin-bottom: 3%;\">The cloud functions as a network which operates through physical servers located inside concrete buildings.<\/span><a id=\"fnref8\" href=\"#fn8\" title=\"8. David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84.\"><sup>8<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the authors are David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence. 84.pdf. Please also check relevance for 64. Same query for fn. 13-14-15 and 31 --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- update as per https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=2369660 --><\/span> Indian banks store their data &#8220;in the cloud&#8221; which means that their data exists on hard drives located in designated facilities. The AWS Mumbai region consists of actual data centres which operate from locations throughout Maharashtra. The control system contains various elements which go beyond physical location as its only aspect. The essential understanding shows that physical data storage does not limit legal access to information.<\/span><a id=\"fnref9\" href=\"#fn9\" title=\"9. Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.\"><sup>9<\/sup><\/a> A server may exist as a fixed installation in India but the US-based corporation which controls the encryption keys and administrative access will create legal jurisdiction through its operations in the United States.<\/span> <\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The Triad: Residency, localisation, and sovereignty<\/p>\n<p style=\"margin-bottom: 3%;\">Data residency refers to physical storage location, a purely geographical concept. The process of data localisation creates a legal duty to maintain data within national borders by transforming data residency into a binding requirement.<\/span><a id=\"fnref10\" href=\"#fn10\" title=\"10. David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84.\"><sup>10<\/sup><\/a> Data sovereignty represents the apex: supreme authority to govern data, which includes access rights, and the power to choose who can access the data and under what conditions.<\/span><a id=\"fnref11\" href=\"#fn11\" title=\"11. David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84, 12&#8212;15.\"><sup>11<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to confirm if 12-15 is page reference --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- yes --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> India has achieved residency and localisation, yet may lack complete sovereignty if foreign jurisdictions can compel access by targeting corporate entities controlling those servers.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The control test<\/p>\n<p style=\"margin-bottom: 3%;\">The fundamental rule states that whoever possesses encryption keys and administrative access rights will control everything, regardless of where the hardware exists.<\/span><a id=\"fnref12\" href=\"#fn12\" title=\"12. David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84, 12&#8212;15; Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.\"><sup>12<\/sup><\/a> AWS can decrypt customer data because it uses AWS Key Management Service to handle its encryption keys. Indian banks can maintain exclusive decryption rights when they use Bring Your Own Key (BYOK) solutions because AWS does not access their plaintext keys. The CLOUD Act establishes a control standard that permits law enforcement agencies to issue warrants which require providers to release data that exists within the provider&#8217;s possession and control.<\/span><a id=\"fnref13\" href=\"#fn13\" title=\"13. 18 USC S. 2713.\"><sup>13<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to confirm if this will be hyperlinked and XML to follow as per LE --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- no --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> The system enables remote control through three main components: digital administrative interfaces, encryption key hierarchies, and corporate command structures which operate beyond physical geographic limits.<\/span><\/p>\n<p style=\"font-weight: bold;\">India&#8217;s data shield<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">DPDP Act<\/a><\/p>\n<p style=\"margin-bottom: 3%;\"><span style=\"Opan sans&quot;;\">The <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">DPDP Act<\/a> distinguishes between data fiduciaries [entities determining processing purposes and means banks, non-banking financial companies (NBFCs), fintech] and data processors (entities processing data on behalf of fiduciaries cloud service providers).<a id=\"fnref14\" href=\"#fn14\" title=\"14. Digital Personal Data Protection Act, 2023, Ss. 8 and 10.\"><sup>14<\/sup><\/a><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for n. 1 --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n 1 --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Opan sans&quot;;\"> Fiduciaries remain responsible for processors&#8217; activities, with potential fines up to Rs 250 crores for severe violations.<a id=\"fnref15\" href=\"#fn15\" title=\"15. Digital Personal Data Protection Act, 2023,S. 33; Aastha Kaul, &#8220;The Digital Personal Data Protection Act, 2023: Strengthening Privacy in the Digital Age&#8221; (2024) International Journal of Law Review and Analysis (forthcoming).\"><sup>15<\/sup><\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593456\">Section 16<\/a> adopts a permissive &#8220;negative list&#8221; approach to cross-border transfers, currently allowing transfers to any destination absent specific government blacklisting.<a id=\"fnref16\" href=\"#fn16\" title=\"16. Digital Personal Data Protection Act, 2023, S. 16.\"><sup>16<\/sup><\/a> Critically, the DPDP Act<\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to specify &#8220;the Act&#8221; as it is not used in any above given Acts --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- DPDP Act --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- Noted --><\/span><span style=\"Opan sans&quot;; font-size: 12.5pt;\">focuses on voluntary transfers initiated by fiduciaries or processors but provides no clear guidance on resisting involuntary extraterritorial access demands a gaping hole when analysing conflicts with the CLOUD Act.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">RBI payment data localisation<\/p>\n<p style=\"margin-bottom: 3%;\">RBI issued a mandate in April 2018 which requires all payment system operators in India to store their complete payment records within Indian territory.<\/span><a id=\"fnref17\" href=\"#fn17\" title=\"17. Reserve Bank of India, Storage of Payment System Data.\"><sup>17<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for (n 2) on fn 20-21 --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n2 --><\/span> The localisation requirement was sweeping complete data must always be stored in India, with no exclusive foreign storage permitted.<\/span><a id=\"fnref18\" href=\"#fn18\" title=\"18. Reserve Bank of India, Storage of Payment System Data.\"><sup>18<\/sup><\/a> RBI aimed to achieve its mission by enabling regulators to access all the data without any limitations.<\/span><a id=\"fnref19\" href=\"#fn19\" title=\"19. PwC India, &#8220;On-Soil Storage of Payments Data&#8221; (2018).\"><sup>19<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for (n 12) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n2 --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span> The Master Direction on IT Outsourcing requires contracts with CSPs to incorporate localisation mandates, guarantee RBI supervisory access, and implement strong encryption.<\/span><a id=\"fnref20\" href=\"#fn20\" title=\"20. Khaitan &amp; Co., &#8220;RBI Releases Master Direction to Regulate Outsourcing of IT Services&#8221; (15-5-2023).\"><sup>20<\/sup><\/a> The requirements assume that CSPs will fulfil their Indian contractual obligations which becomes difficult to achieve when foreign courts issue contempt-based orders.<\/span> <\/span><\/p>\n<p style=\"font-weight: bold;\">The foreign sword<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The Microsoft Ireland case<\/p>\n<p style=\"margin-bottom: 3%;\">The CLOUD Act started its development because US law enforcement attempted to obtain emails which Microsoft had stored in Dublin.<\/span><a id=\"fnref21\" href=\"#fn21\" title=\"21. United States v. Microsoft Corpn., 829 F 3d 197 (2d Cir 2016).\"><sup>21<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the case and XML to hyperlink --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- foreign citation- retain as is --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span> Microsoft argued the Stored Communications Act (SCA) applied only domestically; requiring production of Irish-stored data would constitute impermissible extraterritorial application. The Second Circuit reached a 2016 decision which established that the SCA determined data access based on data storage positions instead of business headquarters.<\/span><a id=\"fnref22\" href=\"#fn22\" title=\"22. United States v. Microsoft Corpn., 829 F 3d 197, 222-25 (2d Cir 2016).\"><sup>22<\/sup><\/a><\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the relevance for 222-25. --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- page nos. --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span>The ruling established a system which allowed criminals to protect their communications through international data storage services. The government used its appeal to drive the CLOUD Act development into a legislative solution.<\/span><a id=\"fnref23\" href=\"#fn23\" title=\"23. United States v. Microsoft Corpn., 2018 SCC OnLine US SC 72 : 584 US ___ : 138 S Ct 1186 (2018).\"><sup>23<\/sup><\/a><\/span> <\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The CLOUD Act mechanism<\/p>\n<p style=\"margin-bottom: 3%;\">The CLOUD Act from March 2018 provides law enforcement agencies the authority to obtain data stored outside the United States<\/span><a id=\"fnref24\" href=\"#fn24\" title=\"24. United States v. Microsoft Corpn., 2018 SCC OnLine US SC 72 : 584 US ___ : 138 S Ct 1186 (2018).\"><sup>24<\/sup><\/a> establishes that providers must comply &#8220;regardless of whether such communication, record, or other information is located within or outside of the United States&#8221;. The statute establishes a control-based jurisdictional test based on three overlapping bases: possession (physical holding), custody (legal responsibility), and control (practical ability to retrieve).<\/span><a id=\"fnref25\" href=\"#fn25\" title=\"25. Justin Hemmings, Sreenidhi Srinivasan and Peter Swire, &#8221;Defining the Scope of &#8216;Possession, Custody, or Control&#8217; for Privacy Issues and the CLOUD Act&#8221; (2020) 10, 631, available at &lt;https:\/\/nationalsecurity.law.georgetown.edu\/wp-content\/uploads\/2020\/05\/Defining-the-Scope-of-Possession-Custody-or-Control.pdf&gt;.\"><sup>25<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- Same as fn. 3 --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> Control is the most expansive, encompassing technical capabilities (encryption keys, administrative credentials) and organisational authority (corporate structures that enable US parents to command foreign subsidiaries).<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">For Indian banks that use AWS Mumbai to store data, AWS India Pvt. Ltd. acts as the legal custodian according to Indian law, but Amazon Web Services Inc. (US parent) maintains control through its global administrative consoles and encryption key management systems located in Virginia. The control established through this process enables US Authorities to exercise jurisdiction over the case. The Act includes a comity mechanism that permits providers to challenge orders that conflict with foreign privacy laws, but in the absence of<\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check &#8212; &#8220;in the absence of&#8221; or &#8220;absence of an&#8221; --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- retain as it is --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span>an executive agreement this protection becomes discretionary and limited.<\/span><a id=\"fnref26\" href=\"#fn26\" title=\"26. 18 USC S. 2523.\"><sup>26<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the case and XL to hyperlink accordingly --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- retain as is --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span> US courts have historically favoured law enforcement through their balancing tests which particularly benefit national security cases. The absence of a CLOUD Act executive agreement in India creates a disadvantage for Indian data compared to UK and Australian data.<\/span><a id=\"fnref27\" href=\"#fn27\" title=\"27. Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221; (Cross-Border Data Forum, 19 April 2020)\"><sup>27<\/sup><\/a><\/span> <\/span><\/p>\n<p style=\"font-weight: bold;\">The collision<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The Mumbai server fallacy<\/p>\n<p style=\"margin-bottom: 3%;\">The common belief that international legal authorities cannot access the data which exists on Indian soil creates a complete misunderstanding of this matter. The &#8220;Mumbai Server Fallacy&#8221; creates confusion because it links residency with the concept of sovereignty.<\/span><a id=\"fnref28\" href=\"#fn28\" title=\"28. David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-64; Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.\"><sup>28<\/sup><\/a> The standard AWS Mumbai architecture which Indian banks use stores customer data on Maharashtra servers to meet RBI data localisation requirements. Banks use AWS Identity and Access Management (IAM) as their data access method through a control system that operates from Virginia. Data objects remain in Mumbai while authentication systems and encryption key hierarchies operate across AWS global network. Amazon Web Services Inc. provides services through its legal entity which exists as a Delaware corporation. The CLOUD Act receives jurisdictional authority because of this corporate structure.<\/span><a id=\"fnref29\" href=\"#fn29\" title=\"29. Amazon Web Services, Clarifying Lawful Overseas Use of Data (CLOUD) Act (AWS Compliance Centre, updated 8-2-2026).\"><sup>29<\/sup><\/a><\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The legal void<\/p>\n<p style=\"margin-bottom: 3%;\">The Indian and US legal systems both fail to provide solutions for resolving jurisdictional disputes between their countries. The <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">DPDP Act<\/a> governs the voluntary transfer of data, yet it does not control the mandatory data transfer requirements established by foreign legal systems.<\/span><a id=\"fnref30\" href=\"#fn30\" title=\"30. Digital Personal Data Protection Act, 2023, S. 16.\"><sup>30<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for (n 1) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n1 --><\/span> Section 16 definition of cross-border transfer in Microsoft relationship to a CLOUD Act warrant compliance requires assessment. The Act provides no mechanism for preventing foreign compulsion targeting foreign processors.<\/span><a id=\"fnref31\" href=\"#fn31\" title=\"31. Digital Personal Data Protection Act, 2023, S. 16.\"><sup>31<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for (n 1) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n 1 --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span> Cloud service agreements include conflicting obligations because RBI requires Indian law compliance while CSPs maintain their right to follow the laws of their own jurisdictions. The existing legal provisions create an unresolvable situation because the laws establish conflicting requirements. The resolution of disputes between sovereign States exists outside the jurisdiction of private contractual agreements.<\/span><a id=\"fnref32\" href=\"#fn32\" title=\"32. Reserve Bank of India, Master Direction on Outsourcing of Information Technology Services, RBI\/2023-24\/102 (Issued on 10-4-2023).\"><sup>32<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- http:\/\/www.scconline.com\/DocumentLink\/cgxV9WgrXML to hyperlink <br \/>and LE to check relevance for (n 2) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- delete n2 --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"><\/span><\/p>\n<p style=\"margin-bottom: 3%;\">The CLOUD Act enables direct company service and gag orders to bypass government notifications. India cannot escalate conflicts it does not know exist. India lacks a treaty-based right to challenge US data requests because there is no existing CLOUD Act executive agreement. The absence of this system creates non-equal power dynamics because the US possesses complete legal systems which US courts enforce while India has only domestic regulations that control local businesses yet cannot stop foreign companies from accessing Indian data.<\/span><a id=\"fnref33\" href=\"#fn33\" title=\"33. Jukka Ruohonen, &#8220;Recent Trends in Cross-Border Data Access by Law Enforcement Agencies&#8221; (2021) Springer, available at &lt;https:\/\/arxiv.org\/pdf\/2302.09942&gt;.\"><sup>33<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check author name not found of the article --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- Please cite as chrome- extension:\/\/efaidnbmnnnibpcajpcglclefindmkaj\/https:\/\/arxiv.org\/pdf\/2302.09942 --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- Not accesssible --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"><\/span><\/p>\n<p style=\"font-weight: bold;\">Mitigation strategies<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Technical solutions: Customer-controlled encryption<\/p>\n<p style=\"margin-bottom: 3%;\">If data is encrypted with keys held exclusively by Indian institutions, cloud providers cannot produce intelligible data in response to legal compulsion. Hold Your Own Key (HYOK) models represent the gold standard: encryption keys never leave customer infrastructure. When CSPs need to encrypt\/decrypt data, they make Application Programming Interface (API) calls to the customer&#8217;s external key management system, which performs operations without exposing keys. RBI could mandate that systemically important financial institutions use HYOK with keys managed exclusively on Indian-located, Indian-certified Hardware Security Modules (HSMs).<\/span><a id=\"fnref34\" href=\"#fn34\" title=\"34. Intel, &#8220;Intel&reg; Software Guard Extensions (Intel&reg; SGX)&#8221;, Product Documentation (16-10-2024).\"><sup>34<\/sup><\/a> This would effectively neutralise the CLOUD Act&#8217;s reach even if US authorities obtain warrants; encrypted data would be useless without keys perpetually in India under Indian control.<\/span><a id=\"fnref35\" href=\"#fn35\" title=\"35. Wikipedia, Trusted Execution Environment, available at &lt;https:\/\/en.wikipedia.org\/wiki\/Trusted_execution_environment&gt;.\"><sup>35<\/sup><\/a><\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Confidential computing addresses vulnerabilities during processing through hardware-based Trusted Execution Environments (TEEs). Technologies like<\/span> <span style=\"Opan sans&quot;;\"><span style=\"background-color: #ffffff;\">Intel Software Guard Extensions<\/span><\/span> (Intel SGX) create isolated enclaves where code and data are encrypted during processing and remain inaccessible to hypervisors or administrators. Combined with HYOK, confidential computing provides end-to-end sovereignty: keys in India, data encrypted everywhere, including during processing, and CSPs unable to access intelligible information under any circumstances.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Diplomatic solutions: India-US executive agreement<\/p>\n<p style=\"\">The signing of a bilateral CLOUD Act executive agreement between two countries will establish unified systems which enable both countries to share their data resources. India would gain two critical benefits:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">1. Indian law enforcement would obtain the ability to deliver orders directly to US-based CSPs without needing to use MLAT procedures<\/span>,<a id=\"fnref36\" href=\"#fn36\" title=\"36. 18 USC S. 2523.\"><sup>36<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the case and xml to hyperlink accordingly --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- foreign citation, retain as is --><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- noted --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> and<\/span><\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt; margin-bottom: 3%;\">2. India would obtain formal ways to challenge US requests for data about Indian citizens.<\/span><a id=\"fnref37\" href=\"#fn37\" title=\"37. Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221;, Cross-Border Data Forum (19-4-2020); Reed Smith, &#8220;Does the UK-US Agreement under the US CLOUD Act Affect UK's Adequacy under the GDPR? approach to data access?&#8221;, Technology Law Dispatch (12-10-2022).\"><sup>37<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check highlighted text of fn 40 not found --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- retain --><\/span> The US-UK agreement prohibits intentional targeting of persons in the partner jurisdiction without consent.<\/span><a id=\"fnref38\" href=\"#fn38\" title=\"38. Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221;, Cross-Border Data Forum (19-4-2020).\"><sup>38<\/sup><\/a><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check relevance for (n 34) --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- all n# to be removed --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\"> Indian objections require political costs which prevent complete power to override them.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">India needs to fulfil America&#8217;s<\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- The American&#8217;s ? --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- No --><\/span> requirements, which demand it to establish strong privacy protection measures and judicial authorisation for monitoring as well as complete transparency of operations and mechanisms to address rights violations. The Information Technology Act<\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- Information Technology Act, 2000<br \/>LE to confirm and XML to hyperlink accordingly --><\/span><\/span>of India gives security agencies extensive powers to conduct interception activities which law enforcement agencies can use with minimal court oversight<\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check if this will be deleted --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- yes --><\/span><span style=\"Open Sans&quot;; font-size: 12.5pt;\">, leading to US security concerns. The qualifying process demands legal changes which will enhance judicial authorisation standards and create operational transparency, thus increasing protection for civil liberties through improvements to domestic rights safeguards. The parties have been negotiating since 2019, yet they have not reached a resolution because civil liberties protection needs require political dedication at the highest level.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Blocking statutes and regulatory innovation<\/p>\n<p style=\"margin-bottom: 3%;\">India could create specific blocking laws which would stop companies operating in India from fulfilling international legal requests that India considers to be illegal<\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check if this will be deleted --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- yes --><\/span>. The EU&#8217;s blocking regulation<\/span> <span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><\/span><!-- LE to check the regulation relevance --><\/span><\/span><\/span><span class=\"annotation&nbsp;reference\"><span class=\"upcast-ANNOTATIONNUMBER\"><\/span><!-- relevant --><\/span>provides a template. The proposed legislation would establish complete bans against international data request compliance which would need to be fulfilled through official MLAT procedures<\/span><a id=\"fnref39\" href=\"#fn39\" title=\"39. Erwan Guerineau, &#8220;The European Union's Blocking Statute against Extraterritorial Legislation: An Effective Instrument for Protecting the EU's Economic Interests?&#8221;, Custax &amp; Legal (31-7-2023).\"><sup>39<\/sup><\/a> while all foreign data requests must be reported to Indian Authorities under the new requirements. The regulations would impose heavy fines and licence suspension on CSPs that violate these provisions while Indian entities who face harm from unauthorised disclosure can pursue monetary compensation through legal actions which do not depend on international legal obligations<\/span><a id=\"fnref40\" href=\"#fn40\" title=\"40. Norton Rose Fulbright, &#8220;Potential Impacts of the EU Blocking Statute&#8221;, Regulation Tomorrow (10-12-2018).\"><sup>40<\/sup><\/a>. A blocking statute creates legal dilemmas for CSPs who must choose between two options which require them to either follow US CLOUD Act regulations and face Indian criminal or civil penalties or they must follow Indian laws which will lead to US contempt penalties. The need to resolve this conflict between two different legal systems drives CSPs to support bilateral treaties which will settle their operational disputes<\/span><a id=\"fnref41\" href=\"#fn41\" title=\"41. Sidley Austin, &#8220;EU Blocking Statute: Toward Enhanced Enforcement?&#8221;, Sidley (3-2-2022).\"><sup>41<\/sup><\/a>. The implementation of blocking statutes presents a risk which will discourage CSPs from establishing operations in India because it will create two negative effects. The internet will undergo fragmentation while service providers will need to create their own expensive systems. The United States will respond with protective measures which will extend into wider economic battles. The system&#8217;s success depends on both its enforcement reliability and the actual prosecution of all criminal activities, and the imposition of penalties against leading global businesses. Blocking statutes lose their power as sovereignty defences because they turn into mere symbolic actions which lack trustworthy enforcement capabilities.<\/span><a id=\"fnref42\" href=\"#fn42\" title=\"42. Mayer Brown, &#8220;EU Top Court Issues First-Ever Judgment on the EU Blocking Statute Against US Sanctions&#8221; (21-12-2021).\"><sup>42<\/sup><\/a><\/span> <\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Structural reform: Sovereign cloud infrastructure<\/p>\n<p style=\"margin-bottom: 3%;\">The technological self-sufficiency solution establishes complete sovereignty through the creation of an indigenous cloud infrastructure which enables organisations to handle essential workloads without relying on international cloud service providers. The government cloud project Ministry of Electronics and Information Technology (MeitY) MeghRaj and the proposed national cloud platforms which State-run enterprises will manage offer reliable sovereignty solutions. RBI can require payment systems which have systemic importance to operate on sovereign cloud services that meet four conditions: Indian majority ownership, an Indian-headquartered corporate structure, Indian nationals controlling encryption keys and administrative systems, and contractual commitments never to disclose data to foreign authorities except through MLAT processes.<\/p>\n<p style=\"margin-bottom: 3%;\">This strategy encounters three main obstacles because it needs extensive financial resources while its operations do not match hyperscale providers and it risks cutting India off from worldwide technological progress. The government and defence sectors together with financial infrastructure should have their sovereignty needs met through strategic sovereignty whereas commercial workloads should be open to competition which enables organisations to choose their sovereignty requirements and costs and capabilities based on their risk assessment.<\/p>\n<p style=\"font-weight: bold;\">Conclusion<\/p>\n<p style=\"background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\"><span style=\"font-style: italic;\">Answering the research question<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">The <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">DPDP Act<\/a>, and RBI&#8217;s data localisation framework mark a strong statement of India&#8217;s authority over financial data. These measures provide solid privacy protections. They require payment and financial data to be stored physically within Indian territory and ensure that Indian law oversees routine processing and supervisory access. This framework successfully improves domestic regulatory capability and decreases reliance on foreign legal systems for accessing data.<\/p>\n<p style=\"margin-bottom: 3%;\">However, an operational limitation remains. The framework cannot stop foreign authorities from forcing access to data through legal mechanisms directed at multinational cloud service providers. The US CLOUD Act allows American law enforcement to demand that US-based cloud providers hand over data within their &#8220;possession, custody, or control,&#8221; no matter where it is stored. Because of this, data kept in India may still be legally accessible to foreign authorities without involving Indian judicial processes. This creates an alternative access channel that exists outside India&#8217;s legal protections.<\/p>\n<p style=\"background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\"><span style=\"font-style: italic;\">Broader implications: Rethinking digital sovereignty<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">This situation shows a wider change in the concept of sovereignty in the digital age. The traditional model believed that legal authority directly related to physical location. Cloud computing challenges this idea by separating where data is stored from who controls and manages it. Authority can now come from control over infrastructure, encryption systems, and companies, not just territorial ownership.<\/p>\n<p style=\"margin-bottom: 3%;\">Thus, data localisation ensures residency but does not guarantee full sovereign control. Real sovereignty needs control over encryption keys, administrative power, and the legal responsibilities of service providers. Laws like the CLOUD Act show that jurisdiction is increasingly based on the nationality of a company and its operational capacity, rather than just its location. Therefore, digital sovereignty needs to be seen as depending on both territorial regulation and technological control.<\/p>\n<p style=\"background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\"><span style=\"font-style: italic;\">The path forward<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">This research shows that localisation alone is not enough to achieve full digital sovereignty. Sovereignty in the cloud era needs a layered approach that combines territorial regulation with technical, legal, and institutional protections. Technical options, like customer-controlled encryption and local key management, can lessen the reach of foreign legal demands. Regulatory and contractual arrangements can improve transparency and strengthen local legal authority. Diplomatic work and institutional coordination can also help reduce jurisdictional conflicts.<\/p>\n<p style=\"margin-bottom: 3%;\">In the end, sovereignty in the digital realm does not just depend on where data is kept but on who exercises real control over it. India&#8217;s current framework lays a crucial foundation by ensuring territorial storage and regulatory power. However, to achieve true and lasting digital sovereignty, it will be necessary to extend that control to the technical and legal frameworks governing access. Only by connecting territorial localisation with operational and cryptographic control can India fully achieve the sovereign goals behind its data protection strategy.<\/p>\n<\/div>\n<hr\/>\n<p style=\"margin-left: 18pt; text-indent: -18pt; font-family: ED Garamond;\"><strong><span style=\"color: #000080;\">*National Forensic Sciences University, Gandhinagar.<\/span><\/strong><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt; font-family: ED Garamond;\"><strong><span style=\"color: #000080;\">**National Forensic Sciences University, Gandhinagar.<\/span><\/strong><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn1\" href=\"#fnref1\">1.<\/a> Asian Development Bank, Cloud Computing as a Key Enabler for Digital Government across Asia and the Pacific (2021) Chs. 2-3.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn2\" href=\"#fnref2\">2.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a>.<\/span><\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn3\" href=\"#fnref3\">3.<\/a> Justin Hemmings, Sreenidhi Srinivasan and Peter Swire, &#8221;Defining the Scope of &#8216;Possession, Custody, or Control&#8217; for Privacy Issues and the CLOUD Act&#8221; (2020) 10, 631, available at &lt;https:\/\/nationalsecurity.law.georgetown.edu\/wp-content\/uploads\/2020\/05\/Defining-the-Scope-of-Possession-Custody-or-Control.pdf&gt;.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn4\" href=\"#fnref4\">4.<\/a> 18 USC S. 2713; Theodore Christakis, &#8220;Extraterritorial Enforcement Jurisdiction in Cyberspace: Normative Shifts&#8221; (2023) Leiden Journal of International Law.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn5\" href=\"#fnref5\">5.<\/a> PwC India, &#8220;On-Soil Storage of Payments Data&#8221; (2018).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn6\" href=\"#fnref6\">6.<\/a> Amazon Web Services, MeitY (Ministry of Electronics and Information Technology) Empanelment (2026).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn7\" href=\"#fnref7\">7.<\/a> Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), (2016) OJ L119\/1; Cybersecurity Law of the People&#8217;s Republic of China (adopted 7 November 2016, effective 1 June 2017) Art. 37.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn8\" href=\"#fnref8\">8.<\/a> David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn9\" href=\"#fnref9\">9.<\/a> Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn10\" href=\"#fnref10\">10.<\/a> David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84.<\/p>\n<p style=\"margin-left: 18pt;\">8<\/span>&#8212;<\/span>12.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn11\" href=\"#fnref11\">11.<\/a> David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84, 12&#8212;15.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn12\" href=\"#fnref12\">12.<\/a> David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-84, 12&#8212;15; Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn13\" href=\"#fnref13\">13.<\/a> 18 USC S. 2713.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn14\" href=\"#fnref14\">14.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a><\/span>, Ss. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593491\">8<\/a> and <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593450\">10<\/a>.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn15\" href=\"#fnref15\">15.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a><\/span>,S. 33; Aastha Kaul, &#8220;The Digital Personal Data Protection Act, 2023: Strengthening Privacy in the Digital Age&#8221; (2024) International Journal of Law Review and Analysis (forthcoming).<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn16\" href=\"#fnref16\">16.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593456\">16<\/a>.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn17\" href=\"#fnref17\">17.<\/a> Reserve Bank of India, Storage of Payment System Data.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn18\" href=\"#fnref18\">18.<\/a> Reserve Bank of India, Storage of Payment System Data.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn19\" href=\"#fnref19\">19.<\/a> PwC India, &#8220;On-Soil Storage of Payments Data&#8221; (2018).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn20\" href=\"#fnref20\">20.<\/a> Khaitan &amp; Co., &#8220;RBI Releases Master Direction to Regulate Outsourcing of IT Services&#8221; (15-5-2023).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn21\" href=\"#fnref21\">21.<\/a> <span style=\"font-style: italic;\">United States<\/span> v. <span style=\"font-style: italic;\">Microsoft Corpn.<\/span>, 829 F 3d 197 (2d Cir 2016).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn22\" href=\"#fnref22\">22.<\/a> <span style=\"font-style: italic;\">United States<\/span> v. <span style=\"font-style: italic;\">Microsoft Corpn.<\/span>, 829 F 3d 197, 222-25 (2d Cir 2016).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn23\" href=\"#fnref23\">23.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002921086\"><span style=\"font-style: italic;\">United States<\/span> v. <span style=\"font-style: italic;\">Microsoft Corpn.<\/span><\/span><\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002921086\">2018 SCC OnLine US SC 72<\/a> : 584 US ___ : 138 S Ct 1186 (2018).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn24\" href=\"#fnref24\">24.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002921086\"><span style=\"font-style: italic;\">United States<\/span> v<span style=\"font-style: italic;\">. Microsoft Corpn.<\/span><\/span><\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002921086\">2018 SCC OnLine US SC 72<\/a> : 584 US ___ : 138 S Ct 1186 (2018).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn25\" href=\"#fnref25\">25.<\/a> Justin Hemmings, Sreenidhi Srinivasan and Peter Swire, &#8221;Defining the Scope of &#8216;Possession, Custody, or Control&#8217; for Privacy Issues and the CLOUD Act&#8221; (2020) 10, 631, available at &lt;https:\/\/nationalsecurity.law.georgetown.edu\/wp-content\/uploads\/2020\/05\/Defining-the-Scope-of-Possession-Custody-or-Control.pdf&gt;.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn26\" href=\"#fnref26\">26.<\/a> 18 USC S. 2523.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn27\" href=\"#fnref27\">27.<\/a> Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221; (Cross-Border Data Forum, 19 April 2020)<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn28\" href=\"#fnref28\">28.<\/a> David Vaile, Kevin Kalinich, Patrick Fair and Adrian Lawrence, &#8220;Data Sovereignty and the Cloud&#8221; (2013) UNSW Law Research Paper 2013-64; Prashant Dubey, &#8220;Cloud Computing and Data Sovereignty: Navigating Legal and Regulatory Challenges&#8221; (2024) 2(7) International Journal for Legal Research and Analysis.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn29\" href=\"#fnref29\">29.<\/a> Amazon Web Services, Clarifying Lawful Overseas Use of Data (CLOUD) Act (AWS Compliance Centre, updated 8-2-2026).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn30\" href=\"#fnref30\">30.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593456\">16<\/a>.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn31\" href=\"#fnref31\">31.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\">Digital Personal Data Protection Act, 2023<\/a><\/span>, S. <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593456\">16<\/a>.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn32\" href=\"#fnref32\">32.<\/a> Reserve Bank of India, Master Direction on Outsourcing of Information Technology Services, RBI\/2023-24\/102 (Issued on 10-4-2023).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn33\" href=\"#fnref33\">33.<\/a> Jukka Ruohonen, &#8220;Recent Trends in Cross-Border Data Access by Law Enforcement Agencies&#8221; (2021) Springer, available at &lt;https:\/\/arxiv.org\/pdf\/2302.09942&gt;.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn34\" href=\"#fnref34\">34.<\/a> Intel, &#8220;Intel<\/span><span style=\"vertical-align: super;\">&reg;<\/span> Software Guard Extensions (Intel<\/span><span style=\"vertical-align: super;\">&reg;<\/span> SGX)&#8221;, Product Documentation (16-10-2024).<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn35\" href=\"#fnref35\">35.<\/a> Wikipedia, Trusted Execution Environment, available at &lt;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Trusted_execution_environment\">https:\/\/en.wikipedia.org\/wiki\/Trusted_execution_environment<\/a>&gt;.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn36\" href=\"#fnref36\">36.<\/a> 18 USC S. 2523.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn37\" href=\"#fnref37\">37.<\/a> Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221;, Cross-Border Data Forum (19-4-2020); Reed Smith, &#8220;Does the UK-US Agreement under the US CLOUD Act Affect UK&#8217;s Adequacy under the GDPR? approach to data access?&#8221;, Technology Law Dispatch (12-10-2022).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn38\" href=\"#fnref38\">38.<\/a> Mayer Brown, &#8220;The Legal Nature of the UK-US CLOUD Agreement&#8221;, Cross-Border Data Forum (19-4-2020).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn39\" href=\"#fnref39\">39.<\/a> Erwan Guerineau, &#8220;The European Union&#8217;s Blocking Statute against Extraterritorial Legislation: An Effective Instrument for Protecting the EU&#8217;s Economic Interests?&#8221;, Custax &amp; Legal (31-7-2023).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn40\" href=\"#fnref40\">40.<\/a> Norton Rose Fulbright, &#8220;Potential Impacts of the EU Blocking Statute&#8221;, Regulation Tomorrow (10-12-2018).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn41\" href=\"#fnref41\">41.<\/a> Sidley Austin, &#8220;EU Blocking Statute: Toward Enhanced Enforcement?&#8221;, Sidley (3-2-2022).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn42\" href=\"#fnref42\">42.<\/a> Mayer Brown, &#8220;EU Top Court Issues First-Ever Judgment on the EU Blocking Statute Against US Sanctions&#8221; (21-12-2021).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Divyansh Godara* and Pragya Bhadana**<\/p>\n","protected":false},"author":67011,"featured_media":388669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42503,1191],"tags":[108271,108273,108269,108268,108272,108270],"class_list":["post-388668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-legal-analysis","category-op-ed","tag-cloud-data-sovereignty-financial-institutions-india","tag-cross-border-data-access-and-digital-sovereignty-india","tag-dpdp-act-cloud-computing-jurisdiction-conflict","tag-india-data-sovereignty-us-cloud-act-analysis","tag-mumbai-server-fallacy-cloud-law-analysis","tag-rbi-data-localisation-and-extraterritorial-access-laws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>India&#039;s Data Sovereignty and the US CLOUD Act | SCC Times<\/title>\n<meta name=\"description\" content=\"Analysis of India&#039;s data sovereignty framework and conflicts with the US CLOUD Act.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws\" \/>\n<meta property=\"og:description\" content=\"Analysis of India&#039;s data sovereignty framework and conflicts with the US CLOUD Act.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/\" \/>\n<meta property=\"og:site_name\" content=\"SCC Times\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/scc.online\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-27T07:30:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"886\" \/>\n\t<meta property=\"og:image:height\" content=\"590\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Editor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Editor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/\"},\"author\":{\"name\":\"Editor\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"headline\":\"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws\",\"datePublished\":\"2026-06-27T07:30:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/\"},\"wordCount\":3673,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/India-data-sovereignty-US-CLOUD-Act-analysis.webp\",\"keywords\":[\"cloud data sovereignty financial institutions India\",\"cross border data access and digital sovereignty India\",\"DPDP Act cloud computing jurisdiction conflict\",\"India data sovereignty US CLOUD Act analysis\",\"Mumbai server fallacy cloud law analysis\",\"RBI data localisation and extraterritorial access laws\"],\"articleSection\":[\"Op Eds\",\"OP. ED.\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/\",\"name\":\"India's Data Sovereignty and the US CLOUD Act | SCC Times\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/India-data-sovereignty-US-CLOUD-Act-analysis.webp\",\"datePublished\":\"2026-06-27T07:30:08+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"description\":\"Analysis of India's data sovereignty framework and conflicts with the US CLOUD Act.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/India-data-sovereignty-US-CLOUD-Act-analysis.webp\",\"contentUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/India-data-sovereignty-US-CLOUD-Act-analysis.webp\",\"width\":886,\"height\":590,\"caption\":\"India data sovereignty US CLOUD Act analysis\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/27\\\/india-data-sovereignty-us-cloud-act-analysis\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\",\"name\":\"SCC Times\",\"description\":\"Bringing you the Best Analytical Legal News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\",\"name\":\"Editor\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"caption\":\"Editor\"},\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/author\\\/editor_4\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"India's Data Sovereignty and the US CLOUD Act | SCC Times","description":"Analysis of India's data sovereignty framework and conflicts with the US CLOUD Act.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/","og_locale":"en_US","og_type":"article","og_title":"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws","og_description":"Analysis of India's data sovereignty framework and conflicts with the US CLOUD Act.","og_url":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/","og_site_name":"SCC Times","article_publisher":"https:\/\/www.facebook.com\/scc.online\/","article_published_time":"2026-06-27T07:30:08+00:00","og_image":[{"width":886,"height":590,"url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.jpg","type":"image\/jpeg"}],"author":"Editor","twitter_card":"summary_large_image","twitter_title":"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws","twitter_misc":{"Written by":"Editor","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#article","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/"},"author":{"name":"Editor","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"headline":"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws","datePublished":"2026-06-27T07:30:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/"},"wordCount":3673,"commentCount":0,"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.webp","keywords":["cloud data sovereignty financial institutions India","cross border data access and digital sovereignty India","DPDP Act cloud computing jurisdiction conflict","India data sovereignty US CLOUD Act analysis","Mumbai server fallacy cloud law analysis","RBI data localisation and extraterritorial access laws"],"articleSection":["Op Eds","OP. ED."],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/","url":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/","name":"India's Data Sovereignty and the US CLOUD Act | SCC Times","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#primaryimage"},"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.webp","datePublished":"2026-06-27T07:30:08+00:00","author":{"@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"description":"Analysis of India's data sovereignty framework and conflicts with the US CLOUD Act.","breadcrumb":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#primaryimage","url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.webp","contentUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.webp","width":886,"height":590,"caption":"India data sovereignty US CLOUD Act analysis"},{"@type":"BreadcrumbList","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/27\/india-data-sovereignty-us-cloud-act-analysis\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.scconline.com\/blog\/"},{"@type":"ListItem","position":2,"name":"The Mirage of the Server: Analysing the Conflict between Indian Data Sovereignty and Extraterritorial Cloud Laws"}]},{"@type":"WebSite","@id":"https:\/\/www.scconline.com\/blog\/#website","url":"https:\/\/www.scconline.com\/blog\/","name":"SCC Times","description":"Bringing you the Best Analytical Legal News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.scconline.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe","name":"Editor","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","caption":"Editor"},"url":"https:\/\/www.scconline.com\/blog\/post\/author\/editor_4\/"}]}},"jetpack_featured_media_url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/India-data-sovereignty-US-CLOUD-Act-analysis.webp","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/users\/67011"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/comments?post=388668"}],"version-history":[{"count":2,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388668\/revisions"}],"predecessor-version":[{"id":388674,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388668\/revisions\/388674"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media\/388669"}],"wp:attachment":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media?parent=388668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/categories?post=388668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/tags?post=388668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}