News

DoT Introduces Data Localisation and Compliance Framework

The Department of Telecommunications (DoT) has notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026 under the Telecommunications Act, 2023, introducing a new authorisation framework for telecommunication infrastructure providers to strengthen regulatory oversight, enhance data security and transition the sector from a licensing regime to an authorisation-based framework.

It applies to Infrastructure Providers (IPs), Digital Connectivity Infrastructure Providers (DCIPs), Internet Exchange Point Providers (IXPs), Satellite Earth Station Gateway Providers, Cloud-Hosted Telecommunication Network Providers and Mobile Number Portability Providers; of these, the first five are authorised at the national level, while Mobile Number Portability is granted on a zonal basis.

Key Regulatory Developments

  1. Mandatory Data Localisation: Under Rule 25(3) of the Rules, every new authorised entity is required to ensure that all telecommunication network systems, together with all associated data, logs and information, are stored within India. The Rules further prohibit any copies of such data, logs or information from being routed, shared or made available outside India.
  2. Enhanced Regulatory Oversight: For monitoring compliance, the Central Government may access and inspect sites where telecommunication equipment or networks are established, including equipment located at users’ premises, conduct compliance audits and appoint designated agencies to audit the processes and systems established by authorised entities. The Rules also permit inspections without prior notice where immediate action is considered necessary in the public interest.
  3. Protection of Commercially Sensitive Information: While designated agencies may conduct compliance audits, they are prohibited from collecting or requiring disclosure of information where such disclosure is likely to harm the competitive position of the authorised entity or its users.
  4. Network Rollout Obligations: Authorised entities remain solely responsible for obtaining all approvals and permissions required for network rollout. The Rules expressly clarify that delays or non-availability of Right of Way (RoW) permissions shall not constitute a valid ground for non-compliance with obligations under the authorisation framework.

The introduction of mandatory data localisation requirements is expected to strengthen India’s digital infrastructure and cybersecurity framework while increasing demand for domestic data centre capacity. The recognition of Cloud-Hosted Telecommunication Network Providers under the authorisation framework is also expected to facilitate greater integration of cloud infrastructure with telecommunication networks. The Rules represent a significant step in implementing the Telecommunications Act, 2023, establishing a comprehensive regulatory framework for telecommunication infrastructure with a focus on data sovereignty, enhanced compliance and secure digital communications.