India Orders Wind Turbine Makers to Report on Data Localization for Cybersecurity
India's Ministry of New and Renewable Energy has mandated wind turbine manufacturers to submit reports on data localization and cybersecurity compliance. Requirements include server locations, data storage, and operational control within India.

The Ministry of New & Renewable Energy (MNRE) has ordered all wind turbine manufacturers listed under the Approved List of Models and Manufacturers (ALMM) to submit a status report on their cybersecurity compliance protocols by the end of the month. The directive, reported by The Hindu BusinessLine, aims to bolster cybersecurity for critical infrastructure.
Key requirements include mandating that data centers and servers be located in India. All data pertaining to wind turbines must be stored and maintained within the country, with no real-time operational data allowed to be transferred outside India. Furthermore, the operational control of wind turbines must be conducted exclusively from a facility located within India. R&D centers are also to be established in India within one year of July 31, 2025.
This move addresses growing concerns about the vulnerability of critical infrastructure, such as power grids and telecommunication systems, to cyberattacks. Such systems are increasingly viewed as potential targets in modern warfare, as highlighted by a recent cyberattack on a UK power plant. The ministry's order likely falls under its authority to update the list of approved wind turbine models and manufacturers.
These mandates follow warnings from India's think tank, NITI Aayog, which in 2024 identified significant cybersecurity risks associated with wind turbines connected to the national grid. The NITI Aayog report specifically pointed to potential threats from foreign-origin power plant controller (PPC) software if protocols are not adhered to. The push for data localization also implies an increased demand for domestic data center infrastructure.