DoT's new Telecommunications Authorisation Rules, 2026 mandate that all telecom network data, logs and systems be stored exclusively within India.

India Bans Telecom Data Transfer Abroad Under New 2026 Rules

The420 Web Correspondent
6 Min Read

The Department of Telecommunications has notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, formally barring communication infrastructure providers from sharing any telecom data, logs or network information outside India, a sweeping data-sovereignty mandate that takes effect immediately and replaces the licensing regime that has governed India’s telecom networks since the Indian Telegraph Act of 1885.

An Absolute Rule With No Exceptions

At the heart of the new framework is Rule 25(3), which requires every system associated with a telecommunications network, along with all related data, logs and information, to be physically located within India. No copy may be routed, shared or made accessible outside the country under any circumstance. Notably, the clause carries no proviso and exempts no category of provider, a deliberately absolute drafting choice that leaves no carve-out even for routine backup, disaster recovery or cross-border technical support arrangements that global telecom and cloud providers have historically relied on.

The rules apply across six categories of authorisation covering the infrastructure layer of India’s telecom networks: infrastructure providers, digital connectivity infrastructure providers, internet exchange point providers, satellite earth station gateway providers, cloud-hosted telecommunication network providers, and national-level mobile number portability providers, the last of which operates through zonal bidding rather than blanket national authorisation.

From Licensing to a Lighter-Touch Regime

The framework marks a structural transition, not merely a data-storage rule. It shifts India’s telecom sector from a multi-layered, paperwork-heavy licensing regime to a streamlined authorisation model under the Telecommunications Act, 2023, giving operators and ISPs the choice to migrate to the new system immediately or continue under existing licences until they naturally expire. A notable design feature is the low barrier of entry created for the new Cloud-Hosted Telecommunication Network Provider category, which carries a ₹10 lakh entry fee and zero annual authorisation charges, a structure officials say is intended to actively encourage cloud providers to build compliant, India-based infrastructure that plugs directly into telecom networks rather than treating localisation purely as a compliance cost.

Internet exchange points have been granted authorisation without the content-blocking obligation that the Telecom Regulatory Authority of India had earlier recommended, following objections from IXP operators who argued that classifying exchanges as telecom networks would saddle them with URL-blocking and filtering responsibilities despite exchanges having no visibility into the content passing through their infrastructure.

Extensive Powers to Enforce Compliance

The rules grant the Central Government considerable latitude to monitor adherence. Authorities may inspect any location where telecommunications equipment and networks are installed, including user premises, and can conduct such inspections without prior notice where immediate action is deemed necessary in the public interest. The government may also appoint a designated auditing agency to examine the processes and systems of authorised entities, though the notification specifies that this agency will neither collect nor require disclosure of information that could harm the competitive position of any user or authorised entity, an attempt to balance oversight with protection of commercially sensitive data.

Telecom infrastructure providers bear sole responsibility for securing all necessary approvals before rolling out networks, and delays in obtaining Right of Way permissions or other regulatory clearances will not be accepted as grounds for non-compliance, placing the administrative burden squarely on operators rather than allowing bureaucratic delay to serve as an excuse.

What Remains Unresolved

Notably, the final notified rules removed all explicit references to Global Mobile Personal Communications by Satellite services, an omission industry observers read as reflecting a cautious government approach to foreign satellite internet operators such as Starlink, particularly given the challenges regulators face in overseeing or restricting such services during periods of geopolitical tension. Separately, the key issue of spectrum allocation for satellite gateway earth stations remains unresolved even as the broader authorisation framework takes effect, a gap industry bodies have flagged as needing early resolution before private satellite players can fully operate under the new regime.

What It Means for India’s Digital Infrastructure

According to a researcher at Algoritha Security, storing telecommunications data within India represents a significant step toward strengthening national cybersecurity, offering investigative agencies faster access to digital evidence and providing additional protection for critical communications infrastructure against foreign cyber threats. The researcher noted, however, that telecom operators will need to substantially increase investment in domestic data centres, cybersecurity infrastructure and compliance systems to meet the new requirements.

Industry figures have echoed that the rules are likely to trigger a significant surge in domestic data centre demand and accelerate broader adoption of cloud-hosted telecommunications networks. Anupam Shrivastava, India head at data centre company Submer and a former BSNL chairman, described the framework as a transformative milestone for India’s national digital infrastructure, one he expects to democratise access to compliant, India-based network infrastructure precisely because of the low-cost entry pathway built into the cloud-hosted provider category.

Stay Connected