Sovereignty & Data Residency
What "Sovereign AI" Actually Means Under DPDP
· 13 minute read
Sovereign AI is a sales phrase. DPDP is a statute. If you are buying agents for a ministry, PSU or campus, you need the gap between those two mapped before the RFP is issued.
If you sit in a state data centre review or a university syndicate meeting in 2026, you will hear the same sentence: we need sovereign AI. The vendor nods. A slide titled Bharat stack appears. Someone writes the phrase into the minutes. Nobody opens the statute.
That is how bad purchases start. Not with malice. With a word that sounds like law and behaves like marketing.
The Digital Personal Data Protection Act, 2023 does not define sovereign AI. It does not define sovereignty. It regulates the processing of digital personal data. Once you accept that narrower fact, you can finally test a vendor. Until you accept it, you are scoring adjectives.
This article is the test we walk through with departmental DPOs, NIC / SDC owners and university counsel before an agent is allowed near a production record. It is written for Indian public institutions. It is not legal advice. It is the map we wish every RFP already contained.
Why the phrase spread faster than the statute
Three things happened at once. Ministries began asking for AI in citizen service. Hyperscalers began selling India regions as if geography were control. And DPDP, after years of drafts, was finally notified with rules. The market needed a single word that covered all three anxieties. Sovereign AI became that word.
The cost of the shortcut is now visible in files. A PSU scores two bids as equivalent on sovereignty because both offer Mumbai. One bid runs inference on the PSU's rack. The other sends every prompt to a foreign model host whose abuse-review queue sits in another country. The scores should not have been the same. The RFP never defined the word, so the committee could not mark the difference.
Privacy as a fundamental right is not new. A nine-judge bench of the Supreme Court said so in Puttaswamy in 2017. What is new is that agentic systems process personal data in ways a 2011 web form never did. An agent is given a goal. It then decides which systems to read, which chunks to retrieve, and which tool to call. The statute still applies. The old checklist does not.
What the Act actually covers
The Act received Presidential assent on 11 August 2023 as Act 22 of 2023. MeitY notified the Act and the Digital Personal Data Protection Rules, 2025 on 13 November 2025. Commencement is phased. That phasing is the first place vendor decks lie by omission.
- 13 November 2025: provisions that constitute the Data Protection Board of India took effect.
- 13 November 2026: consent-manager provisions take effect.
- 13 May 2027: remaining operational obligations, including the day-to-day duties most AI buyers care about, take effect.
Until those operational provisions commence, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to be the live privacy regime. A vendor who says we are DPDP compliant today, without saying which phase they mean, is selling a date, not a control.
The Act applies to processing of digital personal data in India. It also applies extra-territorially to anyone who offers goods or services to Data Principals in India and processes personal data in connection with that offering. It does not apply to purely personal or domestic use, or to personal data a person has deliberately made public, or that a law requires to be made public.
Personal data under Section 2 is data about an individual who is identifiable by or in relation to that data. Digital personal data is that data in digital form, including data later digitised from paper. The definition is broad on purpose. A grievance ticket, a scholarship form, a hostel record, a vendor's Aadhaar number in a GeM invoice, a voice note to a campus helpdesk, and the embedding of any of those things can all be personal data. The format does not save you.
What the Act does not cover
DPDP does not regulate non-personal data. It does not, by itself, localise all government data in India. It does not assign intellectual property in model weights. It does not require Indian shareholding. It does not bless a product because the weights are open, the company is DPIIT recognised, or the cloud region is named India South. Those may be good procurement choices. They are not statutory synonyms for compliance.
The three roles that matter
Every agent stack in a department has to be mapped onto three statutory roles. If this map is missing, everything downstream — notice, transfer, breach, exit — will be argued after an incident instead of before a purchase.
| Role | Who it is in an AI deployment | What they owe |
|---|---|---|
| Data Principal | The citizen, student, employee or vendor the records describe | Rights of access, correction, erasure, grievance and nomination, once operational provisions commence |
| Data Fiduciary | The department, board or university that decides why the agent exists and how it is allowed to work | Notice, lawful basis, security, processor contracts, purpose limitation, breach duties |
| Data Processor | The vendor, SI, cloud or model host that processes only on the fiduciary's instructions | Only what the contract allows. The fiduciary stays accountable. |
If your ministry decides that a grievance agent will read CPGRAMS tickets, pull scheme eligibility and draft a reply, the ministry is the Data Fiduciary. Prcept AI, or any other platform running inside that perimeter, is a processor unless the contract quietly hands it purpose-setting power. That last sentence is where most sovereign decks collapse.
Joint fiduciaries are common and almost never written down. A state resident desk that routes into revenue, social welfare and urban bodies may be determining a common purpose with those bodies. A university and an exam board sharing an evaluation agent may be joint fiduciaries. If you cannot name them on one page, you will not know who notifies a breach.
Lawful basis is not a banner
Processing is lawful only with consent, or for a legitimate use listed in Section 7. That is a shorter list than people who grew up on GDPR expect. There is no general legitimate interests ground for a private vendor to invent a new analytics purpose. There is no casual contractual necessity clause that lets an SI keep training a model because it improves the product.
For the State, the important limbs of Section 7 are the provision of subsidy, benefit, service, certificate, licence or permit as prescribed, and the performance of a function under law, including in the interest of sovereignty and integrity of India or security of the State. Those limbs are real. They are also bounded.
A welfare-eligibility agent that reads a notified State database to tell a resident whether they qualify for a scheme can often sit on Section 7. A campus chatbot that scrapes hostel CCTV transcripts to score students cannot. An agent that fine-tunes a public model on citizen letters so the vendor's next customer gets smarter answers has no legitimate-use story at all.
Consent, where you actually use it, has a shape. It must be free, specific, informed, unconditional and unambiguous. Withdrawal must be as easy as the original yes. Pre-ticked boxes, bundled app permissions, and a banner that says by continuing you agree fail that test. An agent that keeps emailing a citizen after they tapped stop has left the lawful basis, even if the first turn was clean.
What sovereign can honestly mean
Once you drop the slogan, four claims are testable. A vendor should be able to evidence each one, or strike it from the bid. If they cannot evidence a claim, the claim is not a requirement. It is a hope.
- Control of purpose: the institution, not the vendor, decides why personal data is processed. New workflows are change-controlled instructions, not weekly release notes.
- Control of means: inference, embeddings, logs and tool calls happen on infrastructure the institution can inspect. Silent fallbacks to a public model are a change of means.
- Absence of silent transfer: no prompt, embedding, gradient or telemetry leaves the perimeter unless a written transfer decision exists.
- Contractual ownership: fine-tunes, adapters, prompts and evaluation sets remain the institution's property on exit, with a deletion certificate that names backups.
Notice what is not on that list. Indian shareholding. A tricolour on the login page. A press note about a partnership with a ministry. Those things can be relevant to Make in India scoring. They do not move personal data back inside your perimeter.
How an agent creates new processing the notice never described
A web form is honest about its greed. It has fields. An agent is given an objective and then goes looking. That is the point of agentic systems, and it is why DPOs cannot reuse a 2011 SPDI checklist.
Typical new processing that nobody put in the notice includes: retrieving family-member records because the model thought they were relevant; embedding an entire PDF that contained a neighbour's name; writing a plan trace that repeats identifiers; sending the prompt to a guardrail API in another country; keeping the failed tool-call payload in a foreign APM because the demo environment was never turned off.
Each of those is processing. Each needs a purpose and a basis, or it needs to be blocked. Purpose tags on workflows, tool allow-lists, and an egress proxy are how you keep the agent inside the notice. A prettier privacy policy is not.
What to put in the next note
Ask counsel to write three sentences into the file, not a white paper.
- Which lawful basis covers each agent workflow, named by section, not by vibe.
- Who is the Data Fiduciary, who is a joint fiduciary if anyone, and who is a processor or sub-processor, with countries.
- Which data classes never leave the perimeter, including embeddings, plan traces, reviewer screenshots and backups.
If a vendor cannot populate those three sentences from their architecture diagram, they are selling a word, not a system. If your own team cannot populate them, you are not ready to connect a production database, no matter how impressive the sandbox was.
A 90-day path that still survives May 2027
Do not wait for the last commencement date to start acting like the Act is real. The Board exists now. Sector rules already apply. Standing up the map in 2026 is how you avoid a scramble eighteen months later.
- Days 1–15: inventory every current or planned agent, including unofficial ChatGPT use by officers on official records.
- Days 16–40: write the role map and the lawful-basis table. Kill any workflow that has no basis.
- Days 41–70: force staging through an egress proxy. Document every outbound call. Convert undeclared APIs into either a listed exception or a removal.
- Days 71–90: put purpose tags, a training ban, an exit schedule and a deletion certificate into the draft MSA. Refuse to sign without them.
Turn the three sentences into a standing file
The three sentences — basis, roles, perimeter classes — should not live in this article. They should live on the first page of every agent file you open this quarter. Copy them into the template your department already uses for new IT proposals. If a proposal cannot fill them, it is not a proposal. It is a demo request.
Run the 90-day path once on a real workflow, not on a greenfield fantasy. Inventory unofficial use. Kill the workflows with no basis. Proxy the rest. Put the MSA clauses on the next paper you sign. A path that is only theoretical will lose to the next urgent portal.
When someone says we need sovereign AI in a meeting, ask them which of the four testable claims they mean. If they cannot pick one, they are not ready to buy. That question, asked calmly, will save more money than any model benchmark.
Prcept AI is built so those three sentences are true by default: on-premise or air-gapped agents, no training on institutional data, logs that stay inside your network. Demand the same evidence from us that you demand from anyone else.
Questions this usually raises
- Does the DPDP Act define sovereign AI?
- No. The Act regulates digital personal data. It never uses the phrase sovereign AI. Sovereignty language in a bid is a procurement and architecture claim, not a statutory category.
- Does DPDP force all government AI to run only on Indian servers?
- No. DPDP uses a negative-list model for cross-border transfers under Section 16 and Rule 15. Sector circulars such as the RBI payment-data directive can still force localisation even when DPDP does not.
- When do the main DPDP duties start applying?
- MeitY notified the Act and the 2025 Rules on 13 November 2025. The Data Protection Board stood up immediately. Consent-manager provisions apply from 13 November 2026. Most remaining operational duties apply from 13 May 2027. The IT Act and 2011 SPDI Rules still govern until those duties commence.
- If a vendor is DPIIT recognised, are they automatically DPDP compliant?
- No. DPIIT recognition is a procurement and eligibility fact. DPDP compliance is about purpose, lawful basis, processor control, security and transfer decisions. A certificate cannot replace that map.
- Are government departments exempt from DPDP when they run agents?
- The State has specific legitimate uses under Section 7. That is not a general exemption from security, purpose limitation, processor contracts, or the duty to be able to explain what the agent did with a citizen's record.
- What should go in the file before a pilot touches production data?
- Three sentences: the lawful basis for each workflow, who is fiduciary and who is processor, and which data classes including embeddings and traces never leave the perimeter. If those sentences cannot be written, the pilot is not ready.