Data residency and data sovereignty are not the same thing

Data residency and data sovereignty are not the same thing

Guide

Data residency and data sovereignty are not the same thing

One is about geography. The other is about which government can compel access. Procurement questionnaires routinely conflate them, and the difference decides what a provider can honestly promise you.

Topic
Compliance
Reading
About 8 minutes
Published
4 August 2026
Applies to
All plans

The short version

Residency is where the bytes physically sit. Sovereignty is whose law reaches them, which depends on the contracting entity, its corporate parentage and where it operates. A provider can hold your data in India and still be reachable by a foreign order. Ask both questions separately.

01Two questions wearing one name

“Is our data in India?” is usually asked as one question. It is two, and they have different answers.

Residency is a factual question about geography. Which building holds the disks? Which country is that building in? This is verifiable and providers can answer it precisely.

Sovereignty is a legal question about compulsion. If a court or agency issues an order for your data, who receives it, and which country’s law governs whether they must comply? This depends on the legal entity you contracted with, who owns that entity, and where it does business — not on where the hardware sits.

Treating them as one question produces the most common procurement mistake in this area: accepting an in-country data centre as an answer to a sovereignty concern.

02What residency actually gets you

Residency is genuinely useful, and worth insisting on for several concrete reasons.

  • Latency. Physics. Compute close to your users and your data sources is faster, and for interactive inference this is often the dominant consideration.
  • Transfer obligations. Keeping personal data in-country removes the cross-border transfer question from your compliance surface for that data. It does not remove your other duties.
  • Egress cost and time. Moving training data across borders repeatedly is slow and expensive.
  • Sector rules. Some Indian regulators expect specified data to remain in-country. Where that applies, residency is not a preference but a requirement.

What residency does not do is change who can be compelled to hand over the data, or what your own obligations are as the entity that collected it.

03What sovereignty adds

Sovereignty turns on the contract and the corporate structure, and there are three things to establish.

Which entity is on the contract. A named legal entity, incorporated where? A local subsidiary of a foreign parent is a different sovereignty position from a locally incorporated independent business, even when both operate the same data centre.

Which courts hear a dispute. Governing law and jurisdiction clauses decide where you would litigate and what recourse you actually have. This is often the clause that matters most and gets read least.

What the provider must do on receiving an order. Will they notify you, where notification is lawful? Will they resist over-broad requests? Do they publish anything about how many such requests they receive?

The part people find uncomfortable

No provider can promise immunity from lawful orders in the jurisdictions where it operates. A provider claiming otherwise is either misunderstanding the question or misrepresenting the answer. What a provider can do is tell you precisely which jurisdictions apply, and what it will do when an order arrives.

04Why the distinction bites in practice

Three situations where conflating the two causes real problems.

The subsidiary case. Your data is in Mumbai, in a data centre operated by the Indian subsidiary of a company headquartered elsewhere. Residency: satisfied. Sovereignty: the parent may be reachable by its home jurisdiction, and whether that reaches your data is a question for lawyers rather than engineers.

The split-stack case. Compute is in India; billing runs through a foreign payment processor; analytics sit with a foreign vendor; support tickets live in a foreign helpdesk. Your workload is resident. Your customer records are distributed across several jurisdictions. Our own Privacy Policy is explicit that account-level data may be processed outside India, because pretending otherwise would be false.

The backup case. Primary storage is in-country and backups replicate elsewhere for durability. Ask specifically about backups; they are frequently outside the scope of a residency claim.

05Questions that separate the two

Ask these as two groups, and notice if a provider answers a sovereignty question with a residency answer.

Diligence questions by category
ResidencySovereignty
Which country and facility holds the primary data?Which legal entity am I contracting with, and where is it incorporated?
Where do backups and snapshots live?Who ultimately owns that entity?
Where does account and billing data sit?Which law governs the contract, and which courts?
Where does support correspondence live?What happens when a government order arrives, and will I be told?
Which sub-processors touch the data, and where?Have you disclosed the volume of such requests?

06Where we sit, precisely

Stated so you can check it rather than take it on trust.

Residency. Instances and the models behind Medusa run on our own hardware in Mumbai. Account, billing and analytics data may be processed outside India by service providers, which our Privacy Policy sets out along with the safeguards relied on.

Sovereignty. The contracting entity is an Indian sole proprietorship, and the governing law and jurisdiction are Indian — set out in our Terms and business details. There is no foreign parent in the structure.

That is a genuine difference from a local subsidiary of a foreign provider, and it is the honest reason to ask about structure rather than only about geography. It is also not a claim of immunity from anything: Indian orders reach an Indian entity, as they should.

Our companion post on what the DPDP Act asks of you covers the duties that remain yours regardless of where the compute sits.

For anything not covered in our published documents: privacy@vijaycloud.com.

Leave a Reply

Your email address will not be published. Required fields are marked *