India Faces Legal Hurdle in Plans to Host Foreign Data Embassies at GIFT City
In the Union Budget 2023, the government announced that data embassies would be enabled through bilateral agreements. The Interim Budget 2024 reiterated that the facilities would be created in the special economic zone that houses GIFT IFSC, and the International Financial Services Centres Authority (IFSCA) has drafted a concept note and a draft memorandum of understanding. However, the draft remains under review by central authorities.
Legal analysts from Cyril Amarchand Mangaldas and Khaitan & Co point out that India does not yet have a dedicated legal regime that defines the status of a data embassy or provides enforceable safeguards for the data, systems and premises that would be hosted. Foreign governments would need clear, binding protections covering search, seizure, interception, government access and jurisdiction before they would place sensitive sovereign data in India.
"The single biggest hurdle remains the absence of a dedicated legal framework that grants data embassies formal recognition and provides the premises and data stored within them inviolability and immunity from Indian laws governing search, seizure, interception, requisition or other forms of access by domestic authorities," said Ketaki Mehta, partner at Cyril Amarchand Mangaldas, in an interview with businessline.
The need for such protections is underscored by the growing trend of nations seeking secure locations to store critical data while maintaining sovereign control. Gartner Inc. estimates that by 2029 at least 15 % of countries in geopolitically volatile regions will establish formal data‑embassy agreements.
The Estonia‑Luxembourg model is often cited as a benchmark. In 2017, Estonia entered into a bilateral treaty with Luxembourg that allowed the Estonian government to host its critical databases in Luxembourg’s national data centre while retaining full sovereign control. The agreement clearly defined the legal status of the data, the premises and the rights of both parties.
"Equivalent guarantees regarding access to data and exclusive control are necessary to ensure the security of highly sensitive sovereign assets," Mehta added.
Khaitan & Co’s Supratim Chakraborty notes that India’s existing laws – the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 – were not designed for sovereign data embassies and do not specify how such facilities would interact with domestic regulatory requirements.
"In response to changing geopolitical and regulatory realities, the global conversation has shifted away from the assumption of frictionless cross‑border data flows towards trusted data flows," Chakraborty said. "Countries increasingly expect robust privacy protections, national security safeguards, regulatory certainty and predictable government‑access rules before permitting critical governmental data to be hosted abroad."
Experts agree that data embassies do not need full diplomatic immunity under the Vienna Convention on Diplomatic Relations, but they would require functional immunity for the premises, information systems, equipment, communications, archives and sovereign data stored within them.
Khaitan & Co suggests a "digital inviolability" framework. Under such a framework, India would retain territorial sovereignty and regulate physical infrastructure, utilities and public safety, while the sovereign data and information systems housed within the data embassy would remain under the exclusive legal control of the home state, subject only to mutually agreed access mechanisms.
The legal architecture for data embassies is expected to involve multiple government agencies. Parliament would need to provide the legislative foundation, the Ministry of External Affairs would likely lead bilateral treaty negotiations, the Ministry of Electronics and Information Technology (MeitY) would play a key role in data governance and cybersecurity standards, and IFSCA could oversee implementation within GIFT City.
The absence of a dedicated legal regime remains the primary obstacle to India’s ambition. While infrastructure and technical capabilities are in place, the lack of enforceable safeguards means that foreign governments cannot yet commit to storing sovereign data in Indian facilities.
The government has not yet issued a formal response to the legal concerns raised by the legal community. The IFSCA has not yet released a final policy document, and no treaty has been signed with any country to date.
As India continues to promote GIFT City as a global financial and data hub, the development of a clear, treaty‑backed legal framework will be essential to attract foreign governments and to ensure that data embassies operate under mutually agreed rules of protection and access.
The current situation is that India has announced its intention to host data embassies, has drafted a concept note, and has received interest from countries such as the United Arab Emirates and Singapore. However, without a formal legal regime granting data embassies inviolability and immunity, the project remains at a conceptual stage. The next steps will involve legislative action, treaty negotiations and the establishment of a digital inviolability framework to satisfy the security and sovereignty requirements of potential host nations.