01 - The Regulatory Moment
India Has Entered a New Era of Digital Sovereignty
On November 13, 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, operationalising India's landmark DPDP Act and placing India firmly alongside the EU's GDPR and China's PIPL as a jurisdiction where data sovereignty is legally enforceable, not aspirational. The full compliance deadline of May 13, 2027 is 18 months away. The penalty regime is already active.
But the DPDP Act is only one thread in a much broader regulatory tapestry. Indian enterprises, particularly in BFSI, healthcare, government, and critical infrastructure, operate under overlapping sovereignty mandates from multiple regulators, each with teeth:
250Cr
Maximum penalty per violation under DPDP Act 2025
MeitY DPDP Rules 2025
May 2027
Full DPDP compliance deadline with no grace period
DPDP Enforcement Notification
Jan 2025
SEBI CSCRF in effect with data sovereignty mandates active
SEBI CSCRF 2025
2018
RBI payment data localisation enforced, Mastercard & Amex barred 2021
RBI Circular 2018
What makes this regulatory moment particularly significant for enterprise security operations is not just the mandates themselves. It is their intersection. An organisation's security platform is not a passive observer of data. It actively collects, processes, correlates, and stores telemetry about the organisation's most sensitive systems. When that security platform sends telemetry to foreign cloud infrastructure, it potentially places the organisation's most sensitive operational intelligence, including attack patterns, vulnerability profiles, active incident data, and user behaviour records, under a foreign legal jurisdiction.
02 - The Regulatory Landscape
What Each Regulation Actually Demands From Your Security Platform
The data sovereignty requirements that matter most for enterprise security operations are not abstract governance principles. They are specific, enforceable mandates with penalties attached. Understanding what each regulation requires helps clarify why the choice of security platform architecture is, itself, a compliance decision.
MeitY - Active Nov 2025
Digital Personal Data Protection Act & Rules 2025
Rule 6 mandates retaining personal data, traffic data, and processing logs for a minimum of one year for security purposes. Data Fiduciaries must implement encryption, access controls, access logging, and breach detection. Security platforms that process personal data as part of telemetry collection must comply with the same data residency requirements as the data they protect.
Up to 250 crore per violationRBI - Enforced Since 2018
RBI Payment Data Localisation Mandate
Requires all payment system data to be stored exclusively within Indian borders with no offshore mirrors and no foreign backup copies. Enforced aggressively: American Express barred from new customer onboarding in April 2021; Mastercard barred in July 2021 for non-compliance.
Business bans, operational restrictionsSEBI - Effective Jan 2025
Cybersecurity and Cyber Resilience Framework (CSCRF)
SEBI explicitly states that routing data outside India may violate data sovereignty expectations. Encryption keys and key management operations must be handled within Indian borders. CSPs must be empanelled by approved Indian bodies.
Regulatory action, operational suspensionMeitY / NCIIPC - Ongoing
CERT-In Directions & Critical Infrastructure Protection
CERT-In's 2022 Directions require mandatory reporting of cybersecurity events within 6 hours, retention of IT system logs within Indian jurisdiction, and mandatory maintenance of event logs.
Penalties under IT Act Section 70BIRDAI - Insurance Sector
IRDAI Data Localisation Regulations
Customer data and business data must be stored on servers in India. Insurance companies operating security platforms that process policyholder data must ensure all security telemetry and incident records remain within Indian borders.
Sector-specific regulatory actionAadhaar Act / Health
Aadhaar Biometric Data & Health Data Localisation
The Aadhaar Act prohibits core biometric data storage outside India. The proposed DISHA will mandate health records remain within India. Healthcare organisations should architect their security platforms for full data sovereignty now.
Criminal liability for biometric data exportThe cumulative picture: An enterprise operating in regulated sectors in India faces not one sovereignty mandate but a stack of overlapping requirements across DPDP Act, RBI, SEBI, IRDAI, CERT-In, and Aadhaar Act, each with its own scope, penalties, and enforcement timeline. A security platform that cannot support fully sovereign deployment is not a compliant option for these organisations. It is a regulatory liability.
03 - The Core Problem
The Sovereignty Blind Spot Hidden in Plain Sight
Most organisations investing in data sovereignty compliance focus on their business data: customer records, transaction data, health records. They implement India-resident cloud infrastructure, sign data localisation agreements with vendors, and build compliance frameworks around their core data assets. Then they deploy a foreign cloud-based security platform and unknowingly create the sovereignty violation they were trying to prevent.
The Sovereign Security Paradox: What Foreign Cloud Security Platforms Export
Security telemetry is not neutral operational data. It is a precise map of your organisation's most sensitive vulnerabilities.
What Your Security Platform Collects
- ◆Complete endpoint behaviour telemetry covering every process, every connection, every file access
- ◆Network traffic patterns including internal topology, communication flows, and east-west movement
- ◆Identity and access records: who accessed what, when, and from where
- ◆Cloud workload activity including API calls, resource access, and configuration states
- ◆Active incident data showing what you are being attacked with and where your gaps are
- ◆User behaviour profiles with individual behavioural baselines and anomaly patterns
- ◆Vulnerability and exposure data revealing what your attack surface looks like right now
What Leaves Your Jurisdiction
- ⚠Operational intelligence about your most sensitive infrastructure, potentially subject to foreign law
- ⚠Data that foreign intelligence agencies can access through cloud vendor legal obligations
- ⚠Vulnerability maps that represent existential risk if obtained by sophisticated adversaries
- ⚠Incident records that may need to be reported to CERT-In but are stored in foreign servers
- ⚠Personal data of users processed by the security platform, directly within DPDP scope
- ⚠Financial transaction telemetry, directly within RBI localisation scope for BFSI
- ⚠Operational continuity risk where geopolitical disputes can cut access to your own security intelligence
The hidden risk: Foreign cloud vendors, regardless of their security credentials and compliance certifications, are subject to their home country's intelligence and law enforcement access frameworks. Your security telemetry, the most sensitive operational intelligence your organisation generates, may not be as protected as you believe it to be.
This is not a theoretical concern. When businesses rely on international cloud vendors, their data often travels across borders, sometimes landing in jurisdictions with conflicting laws. For security telemetry, the stakes are higher than for most data categories because this data specifically reveals what your defences look like, where the gaps are, and how an attack on your organisation would proceed.
"Data sovereignty has evolved from a technical challenge to a critical business issue. Organisations that don't address where their most important data and services are located risk service disruption, regulatory non-compliance, and reputational damage."
Archana Venkatraman, Senior Research Director, IDC Europe - Pure Storage Data Sovereignty Research, September 2025
04 - The Architecture
How Spharaka Sphere™ Was Built for Sovereign Deployment from Day One
Spharaka Sphere™ with AuraXP™ is not a foreign platform retrofitted with compliance certificates. It is designed in India, for India's regulatory landscape, with data sovereignty as a first-class architectural property, not a product tier or a configuration option added after the fact.
The fundamental principle is straightforward: all security telemetry collection, AI reasoning, incident investigation, response execution, and organisational memory storage happens within the deployment boundary you define. Nothing leaves that boundary unless you explicitly direct it to. The platform's intelligence is your intelligence, stored on your infrastructure, in your jurisdiction, under your control.
Three Sovereign Deployment Models, One Platform
Spharaka Sphere™ supports three deployment architectures, each designed for a different sovereignty requirement profile. Every deployment delivers the full capability of AuraXP™ with all 40+ specialised agents, the SAGE AI Model™, organisational memory, dynamic playbook generation, and autonomous response execution.
Model 01
India-Resident SaaS
Full Spharaka Sphere™ platform delivered as a managed service on India-resident cloud infrastructure. All processing, storage, and AI reasoning within Indian borders, with no reliance on foreign cloud vendors.
Best for
→Enterprises requiring data residency within India without managing own hardware
→DPDP Act compliance with defined data localisation
→Organisations wanting managed operations with sovereignty guarantees
→Mid-to-large enterprises with standard connectivity
Model 02
On-Premises Software
Full Spharaka Sphere™ platform deployed entirely within the organisation's own data centre infrastructure. Every byte of telemetry, every incident record, every AI reasoning output stays on customer-owned servers.
Best for
→BFSI institutions under RBI payment data localisation
→SEBI-regulated entities requiring India-only key management
→Healthcare organisations with patient data sovereignty needs
→Enterprises with existing data centre infrastructure
Model 03
Spharaka Sphere™ Hardware Appliance
Purpose-built hardware appliance delivering the full Sphere™ platform in a self-contained, pre-hardened physical form factor. Air-gap capable, tamper-evident, hardware-attested, with zero external data egress by design.
Best for
→Defence and national security: classified air-gapped networks
→Critical national infrastructure: power, water, transport
→Government agencies with maximum sovereignty mandates
→Defence R&D and classified research facilities
05 - Compliance Alignment
How Sphere™ Maps to Every Indian Sovereignty Mandate
The Spharaka Commitment
The Sovereignty Guarantee
Every deployment. Every configuration. Every customer. No exceptions.
Zero Data Egress
No security telemetry, incident data, or AI reasoning output leaves your deployment boundary under any configuration.
India-First Architecture
Designed in India, for India's regulatory landscape. Not a foreign platform retrofitted with compliance certificates.
Flexible Sovereignty
Three deployment models (SaaS, on-premises, hardware appliance), each delivering full AuraXP™ capability.
Compliance-Ready
CLASS A certified, DPIIT-recognised, NASSCOM-validated, MSME-certified, and listed on Government e-Marketplace (GEM).
06 - Sector Application
Who Needs Sovereign Cyber Defence Most
BFSI
RBI - SEBI - DPDP
Payment data localisation, encryption key sovereignty, and CSCRF compliance demand fully India-resident security platforms.
Healthcare
DPDP - DISHA (Proposed)
Patient data sovereignty and biometric data restrictions require on-premises or India-resident security deployment.
Government
CERT-In - DPDP - NIC
Sovereign security intelligence, 6-hour incident reporting, and classified network protection.
Defence
MoD - NCIIPC - Air-Gap
Spharaka Sphere™ Hardware Appliance for classified, air-gapped networks with zero external data egress.
Critical Infrastructure
NCIIPC - CERT-In
Power, water, transport, and telecom requiring sovereign OT security with no foreign cloud dependencies.
Manufacturing
DPDP - OT Security
OT/IT convergence security with data sovereignty for industrial control systems and supply chain telemetry.
Designed in India. For India.
CLASS A certified, DPIIT-recognised, NASSCOM-validated, MSME-certified, and listed on Government e-Marketplace (GEM), directly eligible for government and regulated sector procurement.
Data Sovereignty & Cybersecurity FAQ
Comprehensive answers for CISOs, compliance officers, and security architects evaluating sovereign deployment options.
What is data sovereignty in cybersecurity?
Data sovereignty in cybersecurity refers to the principle that security telemetry, incident data, investigation records, and threat intelligence generated by your security platform must remain under the legal and operational control of your organisation, within the jurisdiction your data governance obligations require. When a security platform sends telemetry to a foreign cloud vendor for processing, you lose sovereignty over your most sensitive operational intelligence, including attack patterns, vulnerable system maps, user behaviour profiles, and active incident data, which may then be subject to the laws and intelligence-sharing agreements of the foreign jurisdiction.
What does India's DPDP Act require for enterprise security operations?
India's Digital Personal Data Protection Act 2023, operationalised by the DPDP Rules notified on November 13, 2025, mandates that Data Fiduciaries implement 'reasonable security safeguards' including encryption, access controls, access logging and monitoring, and data breach detection and remediation capabilities. Rule 6 requires retaining personal data, associated traffic data, and processing logs for a minimum of one year. The full compliance deadline is May 13, 2027, with penalties up to 250 crore per violation. Critically, security platforms that process or transmit personal data as part of their telemetry collection must comply with the same data residency and consent requirements as the data they are securing.
How does RBI data localisation affect enterprise cybersecurity platforms?
RBI's data localisation mandate requires financial institutions to store and process payment system data exclusively within Indian borders, with no offshore mirrors and no foreign backup copies. This directly impacts security platforms: any cloud-based security tool that sends financial transaction logs, user identity data, or system telemetry to servers outside India is creating a direct regulatory compliance failure. RBI has enforced this aggressively, barring American Express and Mastercard from onboarding new Indian customers for non-compliance with data localisation in 2021. Security platforms used by BFSI organisations must therefore be deployable in a fully on-premises or India-resident configuration.
What is SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF)?
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), which came into effect on January 1, 2025, mandates that Regulated Entities (REs) including stock exchanges, brokerages, depositories, and mutual funds maintain comprehensive cybersecurity controls. Key data sovereignty provisions include: encryption keys and key management operations must be handled within Indian borders; routing data outside India in ways that expose it to foreign regulatory access may violate data sovereignty expectations; and REs must ensure CSPs are empanelled by approved Indian bodies. SEBI is actively consulting on formal data localisation requirements for capital markets entities.
What is Spharaka Sphere™'s approach to data sovereignty?
Spharaka Sphere™ is designed with deployment sovereignty as a first-class architectural property, not an afterthought. It supports three sovereign deployment models: (1) SaaS on India-resident cloud infrastructure for organisations requiring Indian data residency without managing their own hardware; (2) On-premises software deployment, where the full Sphere™ platform runs within the organisation's own data centre with all telemetry, incident data, and AI reasoning staying on-premises; and (3) Spharaka Sphere™ Hardware Appliance, a purpose-built, pre-configured security appliance for air-gapped and maximum-sovereignty environments like defence, critical national infrastructure, and classified research facilities. No security telemetry leaves the deployment boundary under any configuration.
Why is Spharaka Sphere™ uniquely positioned for Indian enterprise compliance?
Spharaka Sphere™ is uniquely positioned for Indian enterprise compliance because it is designed in India for India's regulatory landscape. Its flexible deployment architecture supports the full range of sovereignty requirements across DPDP Act, RBI, SEBI, IRDAI, and CERT-In mandates. It is CLASS A certified, DPIIT-recognised, NASSCOM-validated, MSME-certified, and listed on the Government e-Marketplace (GEM), making it directly eligible for government and regulated sector procurement. The Spharaka Sphere™ Hardware Appliance specifically addresses the defence and national security requirement for fully air-gapped, hardware-level sovereign deployment. No foreign cloud vendor dependency. No sovereign intelligence exported to foreign jurisdiction.
What is the sovereign blind spot in foreign cloud security platforms?
Foreign cloud-based security platforms create what can be called a 'sovereign blind spot': they detect threats, collect telemetry, and process incident data about your most sensitive systems, but that intelligence is stored, processed, and potentially subject to legal access in the foreign vendor's jurisdiction. This means your vulnerability profiles, active incident data, lateral movement patterns, and user behaviour analytics may be accessible to foreign intelligence agencies through the cloud vendor's legal obligations, or lost to you in the event of geopolitical disputes affecting cross-border data access. For defence, critical infrastructure, BFSI, and government organisations, this is not a theoretical risk. It is a direct conflict with their sovereignty obligations.
About the Author
Vishnu Nair is a Founding Member and Director of Growth and Partnerships at Spharaka Networks™. Connect on LinkedIn.
Sovereign Cyber Defence
Your Security Intelligence Should Stay Under Your Control.
Spharaka Sphere™ is the only autonomous cyber defence platform architected for full sovereignty compliance, from India-resident SaaS to air-gapped Spharaka Sphere™ Hardware Appliance deployment.


