When Microsoft told Indian customers on September 21 that they could run “eligible sensitive workloads” in its new Hyderabad cloud region, it attached a condition in the same sentence. This would happen “as supported services become available”. For anyone deciding whether customer data will stay in India, that qualifier carries most of the weight.
Why it matters: Banks, insurers, hospitals and government departments are moving customer data into AI tools. Indian law has several rules on where data must be stored. None of them defines what “data residency” means once that data is fed into an AI model. For now, the term is being defined by the companies selling it.
What Microsoft announced
The India South Central region is not new. Microsoft made it generally available on August 6, 2026. It is the company’s fourth Indian cloud region after Pune, Chennai and Mumbai. Microsoft also runs two regions with Jio. Reuters reported.
What changed on September 21 was the framing. At its AI Infrastructure Summit in New Delhi, the company designated the region a “strategic hub” for Asia and the Global South. It also said all its Indian regions are now “AI-enabled”. Microsoft Foundry, its platform for building applications on AI models, will become available in the region ‘in the coming months’.
Adani Group, Bajaj Finserv, HDFC Bank and PB Pay have signed up. HDFC Bank plans to use the region as a disaster recovery site, Quartz reported.
The press release says the Indian regions offer capabilities “aligned with MeitY guidelines”. It does not name the guidelines. It also hands the compliance question back to the buyer:
“Customers remain responsible for determining which requirements apply to their organizations and workloads.”
Stored in India is not the same as processed in India
“Data residency” usually describes where data sits at rest: files, databases and backups. An AI system also handles data in motion. That includes the prompt a bank employee types, the document a hospital uploads, and the answer the model sends back.
Microsoft’s own documentation for AI models on its cloud separates the two. Stored data stays in the customer’s designated geography. Where prompts and responses are processed depends on the deployment type the customer picks:
- Global: processing may happen in any Azure region where the model is deployed.
- Data Zone: processing stays within a zone Microsoft defines. The zones listed are the US, the EU and Asia Pacific.
- Standard (regional): processing happens in the region where the model is deployed.
Microsoft advises most customers to start with Global Standard. It describes this as the lowest-priced option and the first to get new models. In other words, a customer can store data in Hyderabad and still have every prompt answered somewhere else. Whether a particular model can run regionally in India depends on availability tables that vary by model and region.
Who holds the keys and who can look
Location is one question. Control is another. The release names three tools meant to address it:
- Azure Key Vault, which lets customers manage their own encryption keys.
- Customer Lockbox, which requires a customer’s approval before Microsoft engineers can access their data during a support request.
- Azure confidential computing, which protects data while it is being processed.
The release describes all three as arriving “as supported services become available in India South Central”. It does not say which of them are live in the region today.
There is also a legal question that no data centre address settles. The US CLOUD Act of 2018 allows US authorities to require US-based providers to disclose data in their “possession, custody, or control”, wherever it is stored. Because Microsoft is headquartered in the US, the question is how such obligations could apply to data it controls in India. The release does not say which of them are available in the region today.
What Indian law actually asks for
India has no single localisation rule. It has several, each with a different scope:
- Payment data: The Reserve Bank of India’s (RBI) April 6, 2018 circular on storage of payment system data requires all payment system data to be stored only in India.
- System logs: The Indian Computer Emergency Response Team’s (CERT-In) April 28, 2022 directions require service providers to keep logs for 180 days, within Indian jurisdiction.
- Personal data: Section 16 of the Digital Personal Data Protection (DPDP) Act, 2023 lets personal data go abroad unless the government restricts a destination. Rule 15 of the DPDP Rules, 2025 lets the government set conditions on making data available to foreign states. Rule 13 lets it require Significant Data Fiduciaries to keep specified data in India. Both rules take effect only on May 13, 2027.
The RBI circular, for instance, does not say directly whether payment data sent to a model outside India for a few seconds of processing remains compliant. Microsoft’s release leaves that judgement to the customer. The question is whether an Indian regulator intends to clarify that distinction.
What MediaNama has asked
MediaNama has written to Microsoft India, the Ministry of Electronics and Information Technology (MeitY), HDFC Bank and Bajaj Finserv. We asked Microsoft:
- Which Azure AI services and models can currently be deployed in India South Central with prompts and responses processed only within India?
- Is an India-only Data Zone available, or would Data Zone processing for an Indian customer take place across Asia Pacific?
- Which of Customer Lockbox, Azure Key Vault and Azure confidential computing are available in the region today?
- Do telemetry, diagnostic and abuse-monitoring data for India-hosted AI workloads leave India?
- Which “MeitY guidelines” are the Indian regions aligned with, and has MeitY assessed them against those guidelines?
- How would Microsoft respond to a US CLOUD Act demand for customer data stored in India?
We asked MeitY:
- Has MeitY issued any guidance defining data residency for cloud or AI services, including where processing takes place?
- Against which guidelines, if any, have Microsoft’s Indian cloud regions been assessed?
We asked HDFC Bank and Bajaj Finserv:
- Will AI services in India South Central process customer or payment data, and will that processing stay within India?
- How does the bank assess compliance with the RBI’s payment data storage rules when AI inference is involved?
This copy will be updated with responses as they come in.
Also read: