Cybersecurity / capability
Data Residency and Sovereign Cloud Security
Residency is answered by a contract and control by an access log. The map covers administrative reach into DPDP-regulated data, vendor access included.
The question is not where the data sits. It is who can reach it, and what you can prove.
Data localisation is the easy half and it is answered by a contract. The harder half is administrative access. Which support engineer, in which country, under which provider's agreement, can see or move your regulated data? Is there a log that would satisfy someone who is not inclined to take your word for it?
Next step