Nikhil Prasad Singh and Yash S. Mani are Second and Fifth year students at National University of Study and Research in Law, Ranchi.

Data Embassies: The Indian Feasibility Question

The term “data embassy” has gained significant recognition in recent years. In a world where data is treated as the “new oil,” data embassies are increasingly seen as a solution to data localization and privacy concerns.

In practice, a data embassy is a data center that allows a country to store critical data on infrastructure hosted in another nation, while remaining under the sovereign control of the country. A prospective host nation like India formally announced its ambitions to become a global hub for these data centers during the 2023 Union Budget. However, challenges of legal and constitutional feasibility make this objective a tedious prospect.

Data embassies raise complex challenges of governance, jurisdictional certainty, and immunities. Operational challenges also persist, as India must ensure continuous protection of sensitive state data while maintaining political trust with the host country. Against this backdrop, this article inquires whether India’s current legal framework can succeed in accommodating the data embassy model.

Global Models of Data Embassies

The 2017 Estonia-Luxembourg agreement established the world’s first data embassy, and provides the legal blueprint India needs to evaluate against its own models.

Estonia’s digital model is built heavily on e-governance and paperless public services. The 2007 cyberattacks paralyzed Estonian systems and highlighted the vulnerability of the country’s heavy reliance on digital infrastructure, urging the need to develop a contingency plan. Luxembourg emerged as the foremost partner, given its advanced infrastructure and political stability. The arrangement also ensured compliance with international security standards. The bilateral agreement signed in 2017 established the world’s first data embassy, formally titled “The Agreement on the Hosting of Data and Information Systems between the Republic of Estonia and the Grand Duchy of Luxembourg”. The agreement guaranteed Estonia extraterritorial rights over servers hosted in Luxembourg, granting them the same legal protections as diplomatic premises under international law and the Vienna Convention. The arrangement covers the storage of essential state databases, including land registries, identity documents, and national legislation, ensuring uninterrupted governance in times of crisis.

Following the successful establishment of the world’s first data embassy in 2017, Luxembourg extended the model by signing a bilateral agreement with Monaco on hosting Monegasque sovereign data and systems. The principle was to ensure continuity of sovereign data in a secure, politically stable environment. The trend has also extended to the Middle East, with countries like Bahrain and Saudi Arabia formalizing their sovereign data center frameworks.

These European agreements highlight the key structural requirements for a country like India to host data embassies. Luxembourg’s approach demonstrates that such data centers cannot function solely by relying upon general data protection statutes. Instead, a targeted, bilateral treaty akin to the Estonian agreement, which overrides regional statutory enforcements, needs to be undertaken. Without a framework granting these extraterritorial immunities, foreign states are unlikely to risk their sensitive assets.

Can India join in? Legal challenges towards the establishment of data embassies

With rapid global developments on this front, India, amid its own accelerated digital transformation, is also in the race to adopt the data embassy model.

A potential location for such an initiative is GIFT City in Gujarat, India’s flagship international financial hub. Finance Minister Nirmala Sitharaman, in her 2023 budget speech, hinted at the development of data embassies within GIFT City to attract investment and provide a secure environment for global data flows. In 2024, the city received a ₹500-crore investment specifically directed towards data centers when Yotta commissioned its G1 data center in GIFT City. The facility was launched with an initial capacity of 2 MW, scalable to over 350 racks, and tier-ready infrastructure marketed as suitable for sovereign use cases.

Given the potential, it is undeniable that India is well-positioned for such an initiative. However, the path towards establishing a data embassy in the nation is fraught with legal and operational challenges.

The biggest challenge is the lack of specific legislation governing data embassies. Unlike Luxembourg, India has no existing law that clarifies the status of a data embassy. For instance, if a dispute were to arise between the host state and the sovereign state, where would it be adjudicated? Similarly, in the event of a data breach or cyberattack, how would Indian data-privacy laws come into play? In such cases, testing the application of India’s domestic data-governance framework, specifically the Digital Personal Data Protection Act, 2023 (‘DPDP’), against international treaties such as the Vienna Convention on Diplomatic Relations becomes critical.

Notably, the DPDP Act presents several statutory limitations which must be analyzed to understand the structural frictions complicating the successful establishment of data embassies in India. While the Act regulates cross-border data flows, it does not contemplate sovereign data centers located abroad or foreign sovereign data centers within India. Section 3 of the DPDP states that:

…subject to the provisions of this Act, it shall—

(a) apply to the processing of digital personal data within the territory of India where the personal data is collected…” (Emphasis Supplied)

This territorial disconnect is compounded by the application of international treaties. In the case of data embassies established under any bilateral agreements, they may enjoy immunities similar to diplomatic missions under the Vienna Convention and, therefore, cannot be regarded as being “within the territory of India” for the purposes of the DPDP Act. This creates a jurisdictional vacuum. In the event of a severe data breach or a dispute between the host and the sovereign state, the application of Indian data-privacy laws becomes neutralized. Without a treaty framework clarifying dispute resolution mechanisms, providing diplomatic immunity leaves India with an absence of regulatory oversight.

In addition, given the territorially anchored definitions of terms such as “Data Fiduciary” and “Consent Manager,” the DPDP Act cannot practically be applied to a data embassy. Consequently, none of the DPDP Act’s obligations, be it consent requirement, right, or breach notification duties, can be lawfully imposed on a data embassy since it falls outside the territorial jurisdiction of the country.

Even Article 245 of the Constitution, which empowers Parliament to enact laws with extraterritorial application, may prove ineffective. While proponents could argue that India could theoretically amend the DPDP Act or draft new legislation claiming jurisdiction over foreign servers within its borders, this approach fails in practice due to customary international law. The principles of state sovereignty and diplomatic protection would preclude the actual enforcement of domestic statutes against a foreign state’s embassy.

Conclusion

At present, India’s ambition to host data embassies inside GIFT City and other potential data corridors remains incompatible with its statutory framework. The global precedents exist, but for India to successfully establish itself as a host of data embassies, it must first resolve its legal and operational challenges. The most important obstacle in this is the friction between the territorial and definitional limitations of the DPDP Act and the extraterritorial immunities necessary for such data centers. This is compounded by the absence of any specific domestic law or bilateral treaty that may define the status of a data embassy, and the absence of a dispute resolution mechanism. India will therefore require either carefully negotiated bilateral treaties and targeted amendments to the DPDP Act to legally recognize these diplomatic relations and protections.

Share this post