India
India's data regime moved from principle to statute — and much of it mandates on-shore control that self-hosting satisfies literally, not by attestation.
DPDP Act, 2023
The demand
The Digital Personal Data Protection Act makes a Data Fiduciary accountable for lawful, consent-based processing of digital personal data, breach notification to the Data Protection Board, and Data Principal rights — access, correction, and erasure. Significant Data Fiduciaries carry added duties: data-protection impact assessments and independent audits.
Owned infrastructure
When you own the storage layer, erasure and correction are operations you can actually perform and evidence, consent state is a record you hold, and processing history is auditable end to end. You cannot honor a data-principal right you have delegated to a black box.
RBI payment-data localization
The demand
The Reserve Bank of India requires the entire payment data lifecycle to be stored only within India. Storage is on-shore, full stop — a hard localization mandate, not a preference.
Owned infrastructure
In-country self-hosted storage meets this by construction. The failure mode is a managed data or inference service that transparently replicates or routes payment data to a region outside India — a localization breach you cannot see because you do not control the data path.
CERT-In Directions, 2022
The demand
Report cyber incidents within six hours of noticing them, enable and retain logs for 180 days within Indian jurisdiction, and synchronize system clocks to an Indian time source.
Owned infrastructure
Self-hosted, integrity-verified logging with in-country retention and your own observability stack answers this directly. Six-hour reporting and 180-day log custody are hard to satisfy when the logs live in an opaque service you cannot query or hold.
Sectoral residency (SEBI, IRDAI)
The demand
Securities-market and insurance regulators layer their own systems-audit, data-localization, and resilience obligations on top of the general regime for regulated financial entities.
Owned infrastructure
One owned, well-documented environment produces the systems-audit evidence and data-locality guarantees these regulators expect — without standing up a separate compliance estate per authority.
