The future of Statehood in Cyberspace: Assessing the feasibility of data embassies for India in 2026

Background 

A data embassy is a secure data centre located in a foreign country but operating under a bilateral legal agreement that grants the hosting state limited or no jurisdiction over the stored sovereign data. The idea of data embassies emerged as a response to growing concerns over cyberattacks, geopolitical conflicts, and the need to ensure continuity of government functions in the digital era. The concept was pioneered by Estonia after the 2007 cyberattacks, leading to the establishment of its first data embassy in Luxembourg in 2019.

India does not have a separate Data Embassy Policy or any operational data embassies. In response to a question in Parliament, the Ministry of Electronics and Information Technology (MeitY) clarified that issues relating to future sovereign overseas data infrastructure are currently governed by existing laws such as the Information Technology Act, 2000, the Digital Personal Data Protection (DPDP) Act, 2023, and applicable international treaties, and that there is no separate policy providing diplomatic immunity to data embassies.

The DPDP Rules, 2025, provides India’s primary legal framework for digital personal data protection. Complementing this legal framework, the Government approved the National Data Governance Framework in May 2026, aimed at promoting secure and interoperable data sharing across governments. For India, this aligns with its broader Digital Public Infrastructure diplomacy, under which it has signed digital cooperation agreements with numerous countries to share India Stack and related technologies. 

A data embassy is not merely a backup server. It also serves as a cyber deterrence. The growing interest in data embassies is driven by several strategic and operational considerations like ensuring continuity of governance during cyberattacks, wars, or large-scale infrastructure failures. Protecting critical sovereign databases from espionage and state-sponsored cyber operations while supporting India’s ambition to become a trusted global digital power while safeguarding strategic digital assets. 

Timeline: Evolution of Data Embassies and India’s Emerging Digital Sovereignty Framework (2000–2026)

Year Development 
2000Information Technology Act, 2000 comes into force
August 2023 Digital Personal Data Protection (DPDP) Act, 2023 enacted
2025DPDP Rules notified
January 2026India–UAE agree to explore Digital/Data Embassies. 
May 2026National Data Governance Framework (NDGF) approved. 

Source: Author’s compilation based on MeitY, PIB, Parliament Questions, NeGD, and the India–UAE Joint Statement (2026). 

Functioning 

Identification of Critical Government Data: Governments first classify critical sovereign datasets that require uninterrupted availability. These typically include national digital identity databases, population and civil registration records, defence and emergency communication systems and financial and payment infrastructure.

For India, this could include platforms such as Aadhaar with over 1.4 billion enrolments as reflected in official statistics released by UIDAI. According to NPCI UPI processes over 18 billion transactions monthly in 2026 and DigiLocker noted over 500 million registered users. Moreover, given the scale of GSTN, ABHA, and other Digital Public Infrastructure (DPI) even a short disruption could affect hundreds of millions of citizens and essential public services. 

Bilateral Legal Agreement: The bilateral intergovernmental treaty between the originating countries and host countries, making it fundamentally different from ordinary cross-border data storage. The agreement defines the legal, technical, and diplomatic framework governing the operation of the facility and ensures that sovereign data remains under the exclusive control of the originating state. Unlike data localisation, which depends on territorial sovereignty by keeping data within national borders, a data embassy relies on treaty-based sovereignty, where legal authority determines control over sovereign digital assets. 

Secure Data Replication: The three fundamental principles of information security that is confidentiality, integrity, and availability (CIA) can only be preserved when critical government databases are continuously or periodically replicated from domestic data centres to the overseas facility.

The replication process employs advanced cybersecurity measures, including end-to-end encryption, multi-factor authentication (MFA), Hardware Security Modules (HSMs) for cryptographic key management and 24×7 Security Operations Centre (SOC). According to the Indian Cyber Crime Coordination Centre (I4C), India received over 3.6 million cybercrime complaints in 2024, In this context, secure data replication is not merely a backup mechanism but a strategic resilience measure. 

Continuous Monitoring and Cybersecurity Audits: To ensure long-term operational resilience, data embassies require continuous monitoring and periodic cybersecurity audits through regular penetration testing and vulnerability assessments, rather than relying solely on static security controls. World Economic Forum’s Global Cybersecurity Outlook 2025 identifies AI-driven cyberattacks on critical infrastructure as among the fastest-growing cyber risks facing governments worldwide.  

Performance: Assessing India’s Preparedness for Data Embassies

India’s performance cannot be assessed through implementation metrics because no Data Embassy Policy currently exists. But over the past three years, India has significantly strengthened its legal and institutional framework for digital governance, creating the foundational conditions necessary for future data embassies.

The enactment of the Digital Personal Data Protection (DPDP) Act, 2023 established a comprehensive legal framework for the processing and protection of digital personal data. And parallel, the National Data Governance Framework (2026) aims to improve secure data sharing, interoperability, and governance across government departments. MeitY Estimated Budget for the year 2026–27 is approximately ₹27,000 crore, with significant allocations towards Digital India, cybersecurity, AI, and digital public infrastructure. 

India has increasingly leveraged Digital Public Infrastructure (DPI) as an instrument of digital diplomacy by signing over 20 Memoranda of Understanding (MoUs) with partner countries on digital identity, digital payments, and e-governance. Notable examples include Mauritius, where India supported the launch of UPI and RuPay and Sri Lanka, which adopted UPI-based cross-border payment connectivity with India.

The Government of India has strengthened its cybersecurity ecosystem over the last three years through institutions such as the Indian Computer Emergency Response Team (CERT-In), the National Critical Information Infrastructure Protection Centre (NCIIPC), the Indian Cyber Crime Coordination Centre (I4C), and sector-specific Security Operations Centres (SOCs). Arguably India’s digital ecosystem is expanding faster than its cyber resilience architecture. 

While the country has built one of the world’s largest Digital Public Infrastructure networks, its increasing dependence on interconnected digital systems also increases the potential Cyber attacks. In this context, data embassies should not be viewed solely as cybersecurity infrastructure but as instruments of strategic national resilience. The most significant policy development occurred on 19 January 2026, when India and the United Arab Emirates (UAE) agreed to explore the establishment of Digital/Data Embassies. 

This marks India’s first official diplomatic engagement with the concept of sovereign overseas data infrastructure. A distinctive feature of the India–UAE proposal is that it is based on a mutually recognised sovereignty framework, suggesting that both countries are exploring reciprocal arrangements rather than a conventional hosting model. And if this initiative is successful than it could establish a new model of digital strategic partnership, where sovereign data protection becomes an integral component of bilateral relations alongside trade, defence, and technology cooperation.

Impact 

India’s interest in data embassies is not driven by the need to preserve state existence, as was the case for Estonia. Rather, it is driven by the need to ensure uninterrupted governance for one of the world’s largest Digital Public Infrastructure ecosystems which reflects India’s approach is conceptually different from existing international models. An important impact of recent developments has been the evolution from territorial sovereignty to functional digital sovereignty.

Data embassies extend the idea of sovereignty beyond physical borders by ensuring that a state’s essential digital functions remain operational even if domestic infrastructure is compromised. Earlier discussions primarily focused on data localisation and domestic data governance. The exploration of data embassies broadens this perspective where international cooperation complements domestic legal safeguards. In the twenty-first century, protecting data may become as strategically important as protecting oil reserves or energy infrastructure.

The data embassy supports India’s ambition to become a global Digital Public Infrastructure leader. It demonstrates long-term commitment to protecting sovereign digital assets and ensuring uninterrupted government services through which countries and investors increasingly evaluate the reliability of a nation’s digital governance. As India expands initiatives such as the IndiaAI Mission, protecting government datasets becomes increasingly important. A future data embassy could secure strategic AI training datasets and preserve critical government information.

India has already positioned itself as a provider of Digital Public Infrastructure to developing countries. Further by exporting sovereign data governance models, digital continuity frameworks and cyber resilience standards to other Global South countries if a treaty-based data embassy model is successfully developed. The wider adoption of data embassy model could contribute to the emergence of new norms in international cyber law.

Data embassies raise important legal questions regarding diplomatic immunity in cyberspace, Jurisdiction, and State responsibility. The data embassies is effective for India’s long-term technology strategy as future quantum computing could weaken today’s encryption methods. Data embassies could early on adopt quantum key distribution and quantum-resistant cryptography for next-generation sovereign cybersecurity. 

Emerging Issues

One of the core issues is the  absence of a dedicated legal framework for data embassies which creates uncertainty regarding sovereignty, jurisdiction, and diplomatic immunity. Another major challenge is the lack of institutional and administrative preparedness. At present, no dedicated nodal agency, implementation roadmap, standard operating procedures (SOPs). Unlike diplomatic missions governed by the Vienna Convention on Diplomatic Relations there is no international convention governing data embassies.

Diplomatic and geopolitical considerations also pose significant challenges. Establishing data embassies requires long-term bilateral agreements with trusted partner countries that provide legal certainty, political stability, and robust cybersecurity capabilities. Differences in domestic laws, judicial processes, data protection standards, and geopolitical interests may complicate negotiations on sovereign control, diplomatic immunity, and jurisdiction over digital assets.

Large-scale sovereign data centres consume substantial electricity and require continuous cooling systems. As India pursues its climate commitments, future data embassies must also consider energy efficiency and green computing. If data embassies rely heavily on foreign cloud providers, that may result in technological dependence rather than strengthened sovereignty. 

Data embassies may eventually become instruments of geopolitical influence rather than merely cybersecurity infrastructure. Just as countries today compete over semiconductor supply chains and submarine cables, future strategic competition may extend to hosting sovereign digital infrastructure.

Way Forward 

India should adopt a phased strategy for developing data embassies. The first phase should focus on establishing a dedicated legal framework and identifying trusted partner countries. The second phase should develop technical standards for secure data replication, cybersecurity, and interoperability, while integrating post-quantum cryptography and AI-enabled cyber defence. The final phase should operationalise pilot data embassies for selected critical government databases before gradually expanding the model to other strategic digital assets.

Digital Public Infrastructure has transformed digital resilience into a strategic national priority. A successful data embassy framework would provide an additional layer of resilience against cyberattacks, geopolitical crises, and natural disasters. The government should promote indigenous cloud infrastructure, encryption technologies, and cybersecurity solutions under Digital India and also incorporate post-quantum cryptography, quantum key distribution, and AI-driven threat intelligence into future data embassy standards.

Simultaneously, India should negotiate pilot agreements with trusted strategic partners, allocate dedicated financial resources, adopt post-quantum cybersecurity standards, and develop measurable performance indicators for operational readiness. The government could work through platforms such as the G20, United Nations, or ITU to promote common principles for sovereign digital infrastructure. 

References

Department of Telecommunications. (n.d.). DigiLocker. https://www.digilocker.gov.in/

Indian Cyber Crime Coordination Centre. (n.d.). Public notice. Ministry of Home Affairs. https://cybercrime.gov.in/assets/learning-corner/PublicNotice.pdf

Ministry of Electronics and Information Technology. (2025). Digital Personal Data Protection Rules, 2025. Government of India. https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa?pageTitle=Digital-Personal-Data-Protection-Rules-2025

Ministry of Electronics and Information Technology. (n.d.). Archive: Integrated finances. Government of India. https://www.meity.gov.in/documents/reports/archive-integrated-finances-QzMxATMtQWa

Ministry of Electronics and Information Technology. (n.d.). Our performance. Government of India. https://www.meity.gov.in/ministry/our-performance?page=1

National e-Governance Division. (2026). National Data Governance Framework. Government of India. https://negd.gov.in/ndg/

National Payments Corporation of India. (n.d.). UPI product statistics. https://www.npci.org.in/product/upi/product-statistics

Organisation for Economic Co-operation and Development. (1980). OECD guidelines on the protection of privacy and transborder flows of personal data. https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0289

Press Information Bureau. (2025, January 3). Cabinet approves Digital Personal Data Protection Rules, 2025 [Press release]. Government of India. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014&lang=1&reg=3

Press Information Bureau. (2026, January 19). India–UAE joint statement during the visit of His Highness Sheikh Mohamed Bin Zayed Al Nahyan to India [Press release]. Government of India. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2216270&reg=48&lang=2

Rajya Sabha. (2026). Unstarred Question No. 561: Data embassies. Parliament of India. https://sansad.in/getFile/annex/267/AU561_y13xrw.pdf?source=pqars

The Indian Express. (2026, January 20). India explores setting up data embassy in UAE. https://indianexpress.com/article/india/india-explores-setting-up-data-embassy-in-uae-10483502/

Unique Identification Authority of India. (n.d.). Aadhaar app crosses 31 million downloads. Government of India. https://uidai.gov.in/images/Aadhaar_App_crosses_31_million_downloads.pdf

International Telecommunication Union. (n.d.). Media centre. https://www.itu.int/en/mediacentre/Pages/default.aspx

World Economic Forum. (2025). Global cybersecurity outlook 2025. https://www.weforum.org/publications/global-cybersecurity-outlook-2025/

About the Contributor

Riddhi Suthar is a researcher and policy enthusiast with interests in public policy, governance, international relations, maritime affairs, and strategic studies. Their work focuses on evidence-based policy analysis, geopolitical developments, and emerging global challenges, with particular attention to India’s strategic and developmental priorities. She is engaged in analytical writing, policy research, and academic discussions related to governance, security, and international affairs.

Acknowledgement 

The author extends sincere gratitude to Simona Hughes and Paridhi Passi, and the IMPRI team for their expert guidance and constructive feedback throughout the process.

Disclaimer 

All views expressed in the article belong solely to the author and not necessarily to the organization.

Read more at IMPRI:

30 years of Forests, Funds and Freedom Panchayats (Extension to Scheduled Areas) Act, 1996

Right to Walk Urban governance challenge or opportunity for municipalities?

Author

Talk to Us