← Resources · July 24, 2026
Science & Technology GS3GS2 3 min read

Government bars communication infra providers from sharing data outside India

What happened
01

The Department of Telecommunications (DoT) notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, on 20 July 2026, under the Telecommunications Act, 2023

02

The rules require communication infrastructure providers — including cloud-based telecom network operators, mobile tower and satellite gateway operators, and other authorised network entities — to store all systems, data, logs and information associated with their telecommunication networks exclusively within India

03

No copies of such data, logs or information may be routed, shared or made available outside the country

04

The DoT has been empowered to access and inspect sites where telecommunication equipment and networks are established (including user premises) and to audit an entity's compliance processes and systems

Static topic 1 of 3 · Science & Technology

Telecommunications Act, 2023 — From Licensing to Authorisation

The Telecommunications Act, 2023 (Act No. 44 of 2023) replaced the colonial-era Indian Telegraph Act, 1885 and the Indian Wireless Telegraphy Act, 1933 as the primary law governing telecommunication in India. It shifts the regulatory approach from a "licensing" regime to a lighter-touch "authorisation" regime for providing telecom services, establishing/operating networks, and possessing radio equipment.

Key Details

  • Passed by Lok Sabha on 20 December 2023 and Rajya Sabha on 21 December 2023; received Presidential assent on 25 December 2023
  • Empowers the central government to prescribe rules for authorisation, spectrum assignment and network security — the 2026 Rules are a delegated-legislation instrument issued under this Act
  • Also streamlines spectrum allocation, mandating administrative assignment for specified uses (e.g., satellite communication) alongside auction-based assignment for others
Connection to this news

The 2026 Rules operationalise the Act's authorisation framework specifically for network infrastructure providers, adding a binding data-localisation condition as part of the authorisation terms.

Static topic 2 of 3 · Science & Technology

Data Localisation in India — A Sectoral, Not Unified, Framework

India regulates cross-border data flows through a patchwork of sector-specific mandates rather than a single horizontal law. The telecom infrastructure rule adds to precedents set in the financial and personal-data domains.

Key Details

  • RBI's "Storage of Payment System Data" circular (6 April 2018) required all payment system operators to store the complete end-to-end transaction data only on systems located in India, with a six-month compliance deadline; foreign-leg processing data must be deleted from overseas systems and repatriated within 24 hours
  • The Digital Personal Data Protection Act, 2023 (Section 16) takes a "negative list" (blacklist) approach — cross-border transfer of personal data is permitted by default, restricted only for countries the central government specifically notifies; no such notification had been issued as of mid-2026
  • Unlike the DPDP Act's default-permissive approach, the 2026 telecom rules impose an absolute in-India storage mandate on network infrastructure data, reflecting the more security-sensitive nature of telecom network data (logs, routing, architecture) compared to general personal data
Connection to this news

The telecom rules represent one of India's most stringent data-localisation mandates to date — an absolute bar rather than a conditional restriction — reflecting the national-security sensitivity of telecom network infrastructure as opposed to ordinary commercial personal data.

Static topic 3 of 3 · Science & Technology

Regulatory Oversight — DoT's Inspection and Audit Powers

The 2026 Rules give the DoT direct inspection and audit authority over authorised entities, including access to user premises, to verify compliance with data-localisation and network-security conditions.

Key Details

  • The DoT may appoint designated agencies to conduct compliance audits of authorised entities' systems and processes
  • The Telecommunications Act, 2023 separately empowers the government to take control of telecom networks/services in the interest of national security, public order or during emergencies
  • Such inspection powers mirror those under the earlier licensing regime (Unified License conditions), now recast under the authorisation framework
Connection to this news

The inspection and audit mechanism gives the government a direct enforcement tool to ensure telecom infrastructure providers do not evade the new in-India data-storage requirement.

Key facts & data
  • Telecommunications (Authorisation for Telecommunication Network) Rules, 2026 notified: 20 July 2026
  • Enabling statute: Telecommunications Act, 2023 (Act No. 44 of 2023), assented 25 December 2023
  • Entities covered: cloud-based telecom networks, mobile tower operators, satellite gateway operators, other authorised network infrastructure providers
  • Comparable precedent: RBI payment-data localisation circular, 6 April 2018 (six-month compliance window)
  • DPDP Act, 2023, Section 16 uses a blacklist (negative-list) approach to cross-border personal data transfer; no countries notified as of mid-2026
Read it? Now lock it in. The quiz for this day’s brief covers this story.
Take the quiz