Orbital Data Centres: Why Policy Needs to Move Before the Technology Scales
Shivani Patil
19 Aug 2026
The case for a regulatory sandbox for orbital compute & data storage.

We love Marvel movies at TakeMe2Space. To a grown up dealing with policy, Marvel's stories repeatedly explore what happens when extraordinary capabilities appear faster than the institutions around them can respond. The problem is rarely the technology itself — it's what happens when capability expands faster than the frameworks governing its use.
There's a simple policy lesson in that. Technology moves fast because innovators build, test and improve. Regulation moves differently — policymakers need time to understand a new technology, identify its implications, debate the risks, and establish the rules. That gap is often what allows innovation to grow. But it also raises a question: at what point does an emerging technology become important enough for policy to catch up?
Orbital Data Centres are quickly approaching that point.
What Is an Orbital Data Centre?
An Orbital Data Centre (ODC) is, in essence, a data centre moved off the ground and into orbit — a spacecraft or satellite platform built to store, process and run compute workloads in space rather than simply relaying data back to Earth. In the case of data generated in space (Earth Observation), instead of downlinking every byte a spacecraft captures for processing on the ground, an ODC can process imagery, run AI inference, and store selected data in orbit itself.
ODCs and in-orbit computing are moving fast from demonstration towards commercial deployment, with the potential to disrupt how storage, compute and AI workloads are delivered. But when the server moves into orbit, the regulatory question moves with it.
Why Orbital Data Centres Are Becoming a Regulatory Question
An Orbital Data Centre can simultaneously be a registered space object, a telecommunications platform, a computing environment, and a repository or processor of data. India already regulates each of these domains — just not together, and not with orbit in mind. Today's frameworks include:
Indian Space Policy 2023 — the principal space-authorisation architecture for private space activity in India.
IN-SPACe's 2024 NGP (Norms, Guidelines and Procedures) — the operational rules for how private space entities are authorised and supervised.
The Digital Personal Data Protection (DPDP) Act 2023 and DPDP Rules 2025 — India's core data-protection and localisation obligations.
The Information Technology Act 2000 — the underlying digital and legal-liability framework.
CERT-In Directions 2022 — cybersecurity incident-reporting and compliance obligations.
Each of these does real work on the ground. None was specifically designed around a computing environment in orbit — and that gap is where an Orbital Data Centre creates genuinely new questions, not just an edge case of an existing one.
The Open Questions Orbital Data Centres Raise
Moving compute into orbit surfaces practical questions that none of the frameworks above were written to answer on their own:
Where does data processing legally take place when the server is in orbit?
How do data localisation and data-protection obligations apply to an Orbital Data Centre?
What does cybersecurity compliance look like when connectivity can be intermittent?
How can infrastructure that cannot be physically accessed be audited?
Who bears liability when an orbital platform causes damage?
How should personal data, non-personal data, regulated workloads, and AI systems be governed in orbit?
These may not constitute an immediate regulatory crisis. But orbital infrastructure has the potential to become strategically important, to affect individual and consumer rights, and to disrupt existing markets for storage and compute. The question isn't whether regulation is needed today — it's whether we should wait until the technology becomes consequential before understanding how it should be governed.
Why a Regulatory Sandbox — Not a Regulatory Crisis
A sandbox would give policymakers a supervised environment to empirically test the technology, the controls, and the rules together — enabling supervised testing of in-orbit data storage, processing, AI inference, disaster recovery, and other orbital digital infrastructure before full-scale deployment. It would be learning before legislating, and testing before scaling.
What a Regulatory Sandbox for Orbital Data Centres Could Deliver
Through successive cohorts, regulators could establish which existing obligations work unchanged in orbit, which require a different mode of compliance, and which need to be re-specified. That evidence could inform the Baseline Orbital Compute Assurance (BOCA) — a working standard for what "compliant" looks like for in-orbit computing — along with incident-response models, technical standards, and, eventually, formal regulatory guidance and legislation.
The Bottom Line
Technology moves fast. Policy doesn't have to move first — but it does need to move early enough to understand what's coming. For orbital computing, the sandbox is that opportunity: a controlled space to test before the real deployment begins.
Perhaps this is where TakeMe2Space advocates for taking regulations to space.
Read our policy paper on India's strategic opportunity in space-based infrastructure here to go deeper on the regulatory case for Orbital Data Centres.
