Sovereign Cloud in India: Why Enterprises Are Moving Off Global Hyperscalers
Let’s discard the lazy explanation first. Indian enterprises are not moving workloads off global hyperscalers out of protectionism, and this is not an anti-cloud story. The hyperscalers are excellent platforms, and for plenty of workloads they remain the right answer. What is actually happening is more precise, and more interesting: after a decade of pricing jurisdictional risk at roughly zero, enterprises are repricing it. The law changed. The geopolitics changed. And AI changed what a cloud region holds — no longer just your systems, but your models, your training data and every prompt your organisation types. At L&T Vyoma, we watch this from the receiving end, and the pattern is consistent: the hyperscaler isn’t being fired. It is being re-scoped. The regulated core and the AI layer are coming home to sovereign cloud in India, and this piece explains the forces doing the pulling.
Force One: The Law Grew Teeth
India’s regulatory floor has hardened from guidance into statute. The DPDP Act 2023 governs personal data with penalties that reach ₹250 crore for violations, and its cross-border transfer regime works on a government-controlled negative list — lawful today is not guaranteed lawful tomorrow, which turns every offshore dependency into a standing migration risk. Underneath the Act sit the sector mandates with longer histories: RBI’s requirement that payment data be stored in India, SEBI’s 2023 framework binding cloud adoption for regulated entities to MeitY-prescribed data centers, ABDM shaping how health data moves. A compliance officer reading that stack reaches an uncomfortable conclusion about shared foreign infrastructure: you can be contractually assured on it, but you cannot be architecturally certain.
The DPDP Act and the Real Source of Localization Pressure
Precision matters here, because the DPDP Act is widely misread. The Act does not impose blanket data localization. Earlier drafts — the 2019 and 2021 bills — did propose hard localization, a mandatory local copy of sensitive data and tight limits on sending critical data abroad. The version that became law in 2023 walked away from that. Under Section 16, and the DPDP Rules notified through 2025, cross-border transfer is permitted by default and restricted only to destinations the government specifically names on a negative list. On paper, that is permissive.
What Actually Moves, and What Stays
Honest sovereignty strategy is triage, not exodus. Global-facing, stateless workloads — content delivery, international products, commodity web tiers — often stay exactly where they are, and should. What moves is the regulated core and the AI layer: payment and KYC data, health records, citizen-facing services, and the training, fine-tuning and inference built on all of it. This is why we’re wary of vendors selling sovereignty as an all-or-nothing migration. The enterprises doing this well run a two-estate model: global platforms for global work, sovereign infrastructure for the workloads where jurisdiction is the risk. The skill is in drawing the line deliberately instead of discovering it during an audit.
What They Move To
A credible sovereign destination has to clear four bars, and “a data center in India” clears only the first. Residency: the data stays in-country. Operator: an Indian entity runs the infrastructure, so no foreign parent’s obligations reach into the hall — ours are L&T-operated campuses in Mumbai and Chennai, Tier III certified, DPDP-aligned by architecture. Capability: sovereignty must not cost you the modern stack, which is why the AI Factory runs current NVIDIA Blackwell, Hopper and RTX fleets in liquid-cooled halls built for beyond 100 kW per rack — the same class of compute the global platforms offer, on Indian soil. And breadth: public cloud, colocation and managed services, so the two-estate model has somewhere real to land. The Cloud Calculator prices the sovereign estate before you commit to it.
To Know More: https://larsentoubrovyoma.com/











