ailiteracynepal 🇳🇵
Text size

Chapter 03 · Section II · 16 min read

Cross-border data and the cloud

Almost every "Nepali" digital service in 2026 actually runs on a server in another country, and that single fact reshapes who can read, subpoena, lose, or leverage Nepali data in ways most policy conversations have not yet caught up with.

There is a quiet fiction at the heart of the Nepali digital economy. When you open the eSewa app, or refresh your bank’s mobile portal, or message a doctor through a telemedicine startup, the interface speaks Nepali, the brand is Nepali, the support number is a Kathmandu landline, and the company is registered at the Office of the Company Registrar. Underneath, however, the bytes are abroad. The application server is almost certainly in AWS Mumbai (ap-south-1) or AWS Singapore (ap-southeast-1). The database may be in the same region or in a second one for redundancy. The machine-learning model that decides whether your transaction is fraudulent is hosted by a third-party vendor running on Google Cloud or Azure. The customer-support chat transcripts are processed by a SaaS tool whose servers are in Frankfurt or Dublin. Your data, in other words, has left the country before you finished typing.

Why this happened — and why it is mostly rational

It is worth being honest about why Nepali companies host abroad. There is no large-scale, production-grade public cloud operated inside Nepal. The two domestic datacentre operators — including the Government Integrated Data Center in Singha Durbar and a handful of private telco-attached facilities — are reliable for static workloads but lack the regional redundancy, managed-services depth, and elastic pricing that any modern application stack now assumes. AWS in Mumbai is roughly 35 milliseconds away from Kathmandu, comes with a hundred managed services a small Nepali team could not operate themselves, and bills per second. Building the same thing on a rack in Tinkune, with a generator, a UPS, a fibre lease from two ISPs, a security contractor, and a sysadmin on rotation, costs more and breaks more often. The market answer has been clear: ship to Mumbai and move on.

The cost of that rational choice, however, is sovereignty.

What “cross-border” actually means in practice

Three things change the moment your data sits on a foreign cloud.

First, two legal systems apply. Nepali law applies because your company is Nepali and your customer is Nepali. The host country’s law also applies because the bytes are physically there. If a server containing Nepali health records sits in Mumbai, Indian law governs what an Indian court can order the cloud provider to disclose, what data-breach notice rules apply, and what counts as a lawful intercept. Your Nepali contract with the cloud vendor cannot override the host country’s compulsory legal processes. The vendor will comply with the court order, and you may not even be told about it for some time, if at all.

Second, lawful-access requests from foreign governments can reach Nepali data. The United States CLOUD Act lets US authorities compel American cloud providers to produce data wherever in the world that data is stored. India’s Information Technology Act lets Indian authorities issue interception orders to operators on Indian soil. Most large cloud vendors publish transparency reports listing the volume of such requests they receive each year; the requests run into the tens of thousands annually for each major provider, and the data being requested is overwhelmingly not the data of the host country’s own citizens. Your Khalti transaction log is, in principle, reachable through legal processes that the Nepali state has no role in.

Third, breach-notification rules differ. Under EU law, a serious personal-data breach must be reported to the supervisory authority within 72 hours. Under India’s DPDP Act, the rules are stricter still in some respects. Under current Nepali law, the obligation is vague and the enforcement body unstaffed. If your Nepali wallet has a breach on its Mumbai-hosted database, you may first learn about it from an Indian regulator, or from a Reddit thread, weeks before your own bank ever notifies you.

What NRB has already done, and what remains open

Nepal Rastra Bank, to its credit, saw the residency question earlier than most regulators in the region. The current bank-IT guidelines push commercial banks toward keeping primary banking data on infrastructure located in Nepal, with foreign hosting permitted only for non-core systems and with explicit central-bank approval. In practice, this is why the big banks operate hybrid stacks: the core banking system runs in a Nepali datacentre, but the mobile app’s backend, the fraud-detection model, and the customer-analytics layer often sit abroad. NRB has, in other words, drawn a residency line — narrowly, around the most regulated bytes — and accepted that everything else will flow.

No other Nepali regulator has drawn a comparable line. Telecom call data, health records, education data, transport data, and the entire startup-and-app ecosystem operate in a residency vacuum. The default is foreign hosting, the rule is silence, and the exception is whatever individual ministers happen to demand in a specific procurement.

The honest middle path

There is a temptation, when you first realise the scale of cross-border exposure, to leap to one of two extreme positions. The first is full sovereignty: build a national cloud, mandate that all Nepali data live on it, and ban foreign hosting. The second is resigned outsourcing: accept that the cloud is global, that residency is a fiction, and that the country has no leverage anyway. Both are wrong, and they are wrong in symmetrical ways.

Full sovereignty would be enormously expensive, would lock the country out of the genuine productivity gains that managed cloud services bring, and would centralise risk in a single domestic operator that — given current institutional capacity — would almost certainly be worse run than AWS. Pure outsourcing concedes the question entirely, leaves citizens exposed to legal processes in countries they have never visited, and gives the state no ability to enforce its own rules.

This is unglamorous work. It does not produce a single press release. It requires the data-protection authority Nepal does not yet have, the technical staff most ministries lack, and the willingness to tell some vendors no. It is, however, the only path that is honest about both the constraints and the stakes.

Check your understanding

Quick check

A new Nepali health-tech startup is building a telemedicine platform that will hold electronic medical records for hundreds of thousands of patients. Which policy stance most accurately reflects the proportionate response to cross-border data risk?

What comes next

Residency answers the question of where data lives. It does not answer the question of whether the person ever meaningfully agreed to its collection in the first place, and what the state is allowed to watch you do once it has been collected. The next section is about consent — the difference between meaningful agreement and a ceremonial scroll-and-tap — and about where the line between safety surveillance and behavioural prediction actually sits.