Express Computer
Home  »  Guest Blogs  »  India’s digital sovereignty imperative: Why open, interoperable infrastructure can no longer be an afterthought

India’s digital sovereignty imperative: Why open, interoperable infrastructure can no longer be an afterthought

0 0

By Sharya Unamboowe, Vice President and General Manager, Integration, WSO2

India’s policy direction on data governance has never been clearer. From the Digital Personal Data Protection (DPDP) Act to the National Data Governance Framework and MeitY’s cloud empanelment policy for government workloads, the intent is unambiguous: India’s data must remain under India’s jurisdiction. Yet a quiet contradiction persists, a significant share of Indian enterprise workloads, including those touching sensitive personal and financial data, continues to run on infrastructure owned and legally governed by foreign technology companies.

Closing that gap is no longer just a policy aspiration. For enterprises in BFSI, healthcare, and the public sector, it is fast becoming an operational and compliance necessity; one built on three interlocking priorities: data sovereignty, cloud repatriation, and interoperability. Open-source software, more than any other technology approach, provides the practical foundation for achieving all three.

The data sovereignty gap

India’s regulatory frameworks are explicit about where data must live. The RBI mandates that payment system data be stored exclusively within India. IRDAI and SEBI have their own localisation requirements for insurance and capital markets data. The DPDP Act extends similar obligations to personal data across sectors. And yet, much of this data continues to reside on the infrastructure of hyperscalers such as Amazon Web Services, Microsoft Azure, and Google Cloud. All of these are subject to US laws such as the CLOUD Act, which grants American authorities’ potential access to data held by US companies regardless of where it is physically stored. No data processing agreement can fully neutralise that jurisdictional risk.

True data sovereignty requires the ability to deploy software on infrastructure that falls exclusively under Indian jurisdiction, whether that means domestic providers such as NxtGen, Yotta, or CtrlS, or an organisation’s own on-premises environment.

Cloud repatriation as a strategic move

Cloud repatriation, moving workloads from cloud environments subject to foreign jurisdiction to sovereign or on-premises infrastructure, is gaining traction among Indian enterprises, and not only for regulatory reasons. The scale of this shift globally offers useful context. According to Gartner’s February 2026 forecast, worldwide sovereign cloud IaaS spending will reach $80 billion this year, a 35.6% increase from 2025, with mature Asia-Pacific markets among the fastest-growing regions. Gartner also predicts that organisations will shift 20% of existing workloads from global public clouds to local providers as sovereignty concerns intensify. India is squarely in the path of that wave.

Cost predictability is an equally powerful driver. Hyperscaler pricing is notoriously complex, and in an era where even moderate AI workloads demand significant compute, those costs can escalate quickly and unpredictably.

Indian public sector organisations and large BFSI enterprises are increasingly asking whether workloads that were migrated to hyperscaler clouds for convenience now belong on domestic infrastructure; not as a retreat, but as a deliberate act of cost and risk management. India’s growing domestic cloud ecosystem, backed by the National Cloud initiative and a maturing network of certified data centres, is making this transition increasingly viable. For private enterprises, the case is similar; domestic or on-premises deployment offers greater cost control, reduced foreign jurisdictional exposure, and a cleaner path to demonstrating regulatory compliance.

Interoperability: The antidote to lock-in

Of the three pillars, interoperability is perhaps the least prominent in Indian boardroom conversations, and yet it carries the most long-term consequence. Enterprises that build critical operations on proprietary platforms surrender the ability to migrate, renegotiate, or adapt without significant cost and disruption. In a regulatory environment evolving as rapidly as India’s, that rigidity is a strategic liability.

Interoperability requires adherence to open standards: REST and SOAP APIs, authentication protocols such as OAuth 2.0 and OpenID Connect, and sector-specific standards like HL7 FHIR for healthcare data exchange. These are not back-end technical details. They are what allow Indian enterprises to switch providers, adopt new platforms, and respond to evolving mandates without rebuilding from scratch.

Why open source is the foundation

Data sovereignty, cloud repatriation, and interoperability each demand a degree of flexibility, auditability, and portability that proprietary software is structurally unable to provide. With closed platforms, enterprises have no visibility into how their data is processed, no guarantee it stays within the required jurisdiction, and no practical ability to migrate without the vendor’s cooperation.

Open-source software inverts that dynamic entirely. Its code is auditable; its deployment is flexible with public cloud, sovereign cloud, on-premises, or hybrid options, and its support for open standards is verifiable rather than contractually assumed. For Indian enterprises operating under the DPDP Act, RBI guidelines, or SEBI’s cybersecurity framework, this distinction matters as it is the difference between demonstrable compliance and assumed compliance. India’s own policy signals reflect this.

The National Open-Source Policy and the government’s growing preference for open standards in public digital infrastructure make clear that open source is not a workaround but the architecture of a digitally sovereign India.

The time to act is now

India’s data governance regulations are still maturing, but the direction and pace are both accelerating. Enterprises that wait for full regulatory clarity before addressing infrastructure dependencies will find themselves in reactive remediation rather than strategic transition and at a considerably greater cost.

The organisations best placed for India’s digital future are those building on infrastructure that is open, portable, and jurisdiction-aware today. Digital sovereignty is not a compliance destination. It is an architectural decision, and for Indian enterprises, the window to make it wisely is open right now.

Leave A Reply

Your email address will not be published.