Cheap electricity alone is not enough to attract data centers. Operators do not move where electricity is cheapest alone. They look for locations where regulation is predictable, institutions are reliable, and digital infrastructure can be trusted at scale. Nepal still has work to do on all three fronts

Assume Meta is exploring South Asia for a new data center. On paper, Nepal may appear attractive: a growing digital economy, improving connectivity, proximity to regional markets, and cleaner electricity for digital infrastructure. For a global technology company, the question is not whether Nepal can host servers, but whether it can be trusted with data at scale. Meta would assess reliable electricity and fiber connectivity, predictable foreign-exchange and environmental approvals, and lawful-access rules that protect hosted data from uncertain regulatory intervention. It would also ask whether critical sectors like banks, telecom companies, payment companies and government agencies can rely on data centers confidently.
The information and communication sector in Nepal is growing faster than the wider economy, with recent national accounts estimating 5.53% growth, compared with GDP growth of 3.85%. As digital infrastructure becomes central to public administration, financial services, cloud adoption and cross-border delivery, the country needs a framework for security, reliability, investor confidence and institutional accountability.
The Data Center and Cloud Service (Operation and Management) Directives, 2024 (the “Directives”), along with the policies and programs for fiscal year 2026/27, are important initial steps in this direction.
The Directives require data center and cloud service providers to be listed with the Department of Information Technology before providing services. Listing requires documents on security and privacy, business continuity, location, tier details, technical manpower, IP pool, physical security and high-level electrical design. Data centers must adopt security standards, protect client data, control unauthorized access, ensure continuity, appoint or obtain compliance support, conduct annual security audits and specify security and backup arrangements in cloud agreements. These provisions create a regulatory perimeter, but not a complete data-hub strategy. If Nepal wants to become a trusted destination for sensitive and cross-border digital infrastructure, reform must address five linked issues.
The first gap is legal status. Nepal should decide whether data centers should be treated not only as commercial service providers, but as a critical national infrastructure. The lapsed IT and Cybersecurity Bill had envisioned critical infrastructure sectors to include energy, ICT, health care, banking and finance. It aimed to prevent cybersecurity threats, enable response and investigation, and impose reporting obligations. Although the Bill did not survive, its logic remains relevant: sectors whose disruption can affect others require heightened protection.
Data centers fit that logic. They support digital systems used by government agencies, banks, telecom operators, hospitals and payment companies. Yet currently they are not recognized as critical infrastructure, despite the risk that even a minor disruption can affect payment systems, public services, communications, business continuity and essential digital access. Nepal should therefore codify a critical infrastructure framework and include data centers within it, with enhanced cybersecurity, resilience, reporting, audit and continuity obligations. Another gap is that the Directives require government data to be stored in at least Tier III facilities, but do not state what sector specific standards should apply to sensitive sectors like banks, insurers, telecom companies, hospitals, payment companies, capital-market institutions or other regulated entities. To resolve this gap, regulators such as, Nepal Rastra Bank, may need to prescribe tier requirements for banks and financial institutions.
The second gap is legal certainty. A credible data-hub economy requires legal trust. Customers must believe that data hosted in Nepal will be governed by predictable and rights-respecting rules. This brings the analysis to data sovereignty, cross-border flows and lawful access.
Consider a hypothetical example. Momo Data Center, a Nepali data center, hosts cloud infrastructure for Meta, with servers physically located in Nepal. The data may include account details, messages, payment information and business data of Meta users in Nepal and abroad. If the Cyber Bureau of Nepal Police suspects that a Facebook account used by Mr. Sujan has hacked other accounts and asks the Department of Information Technology to direct Momo Data Center to provide access, the key question is: access to what? The authority may seek Momo Data Center’s server logs, Mr. Sujan’s account information held by Meta, or the contents of user communications. These are legally different categories. Momo Data Center may control the physical infrastructure, but it does not own the underlying customer data, which may belong to Meta or users such as Mr. Sujan. This shows why the law must distinguish between supervision of the data center operator and access to customer data. The Directives require data centers to comply with directions issued by the Department of Information Technology and law-enforcement agencies. This is important for regulation and security, but it raises whether a data center must provide customer data merely because a department direction has been issued, or whether access must rest on a separate legal basis, such as a court order.
Nepal’s privacy law permits disclosure or use of personal information in limited circumstances, including criminal investigations, court orders or requests by competent authorities. Since the Department regulates data centers under the Directives, one could argue that its directions fall within this framework. Lawful access is not unusual. Every jurisdiction allows state access in appropriate cases. The concern is the lack of clarity on when, how and to what extent access may be exercised.
The existing framework does not provide that detail. It does not clearly state the threshold for access, whether the request must relate to a specific investigation or proceeding, who within the department may authorize it, whether the data center may under any ground decline/seek clarification or challenge an excessive request, whether the customer must be notified, or how requests must be recorded or audited. Without safeguards, directions may be interpreted broadly, creating uncertainty.
The third gap is sustainability design. Nepal’s Environment Protection Regulations, 2020 prescribe an Initial Environmental Examination (IEE) for an information technology industry with investment of Rs 250 million to Rs 2 billion in machinery or equipment, and an Environmental Impact Assessment (EIA) for an information technology industry with investment above Rs 2 billion in machinery or equipment. However, the regulations do not clearly identify data centers as a separate category requiring environmental review.
This creates an interpretive issue. One could argue that the authorities did not specifically envision modern data centers when listing environmental review categories for the information technology industry. At the same time, the requirement may still apply incidentally if a data center falls within the relevant investment threshold. Environmental review may therefore arise because of investment size, not because the law has assessed data centers as distinct digital infrastructure. This is not sufficient. Nepal should not rely only on generic environmental categories for conventional industrial or building projects. Data centers create distinct impacts across the energy system, water resources, waste management, local resilience and climate-related siting risks.
Nepal should, therefore, develop a data-center-specific sustainability framework, framed not only as “environmental impact” but as sustainable digital infrastructure governance. The framework should ask whether the project is sustainable digital infrastructure. Regulators should assess the facility’s power requirement, grid capacity, renewable-energy procurement, responsibility for grid connection or upgrade costs, cooling-water use, backup generator and battery management, e-waste disposal, and whether the site is environmentally sensitive, water-stressed, disaster-prone or insecure. This would reduce ambiguity and attract investment without shifting environmental, energy or infrastructure costs to the public.
The fourth gap is institutional coordination. Once data center regulation is viewed through land, water, electricity, environment, fiber connectivity and physical resilience, the Department of Information Technology cannot assess overall project viability alone. The directives do not fully address the broader approvals and infrastructure conditions required to establish a data center in Nepal. A data center is not merely an ordinary IT service facility. Its operation depends on continuous electricity supply, backup power, cooling systems, water availability, fiber redundancy, secure physical access, disaster resilience and local infrastructure support across regulatory domains. Electricity supply and connection involve the Nepal Electricity Authority; fiber connectivity involves Nepal Telecommunication Authority and service providers; land use and building permits involve local governments; environmental approvals arise under environmental law; and foreign investment and foreign exchange issues involve the Department of Industries and Nepal Rastra Bank.
A project may face delays if land use approval, environmental clearance, electricity connection, foreign investment approval, building permits and security clearances are reviewed separately, without coordinated viability assessment.
Nepal should therefore translate the land-water-energy-infrastructure nexus into institutional design. For major data center projects, a coordinated approval mechanism or single-window review could bring relevant authorities together at the project assessment stage so that grid capacity, water availability, fiber connectivity, environmental suitability, disaster risk, local infrastructure and security concerns are examined predictably, without replacing sectoral regulators. This would improve discipline and investor confidence. Investors would receive a clearer view of site viability before capital commitments. Regulators would assess cumulative project impact instead of isolated components, and infrastructure providers could plan electricity, fiber, road access and public-service requirements in advance.
The fifth gap is foreign-exchange facilitation, directly connected to the directives. If the law requires tier-rating certificates, annual security audits, international-standard compliance and compliance officers or compliance-service organizations, operators must be able to pay the foreign vendors and experts in foreign currency needed to meet those obligations. Foreign exchange facilitation should therefore be treated as digital-infrastructure policy, not banking formality.
Nepal has already seen how foreign-exchange bottlenecks can affect infrastructure sectors. In telecom, reports noted that providers could not pay international vendors for bandwidth, equipment and consultancy services due to foreign-currency recommendation issues. Internet service was reportedly disrupted after an Indian upstream provider cut bandwidth because Nepali providers could not make international bandwidth payments. That experience is an early warning. Both sectors depend on cross-border payments for infrastructure, bandwidth, equipment, maintenance and specialized services. If foreign-exchange approvals become unpredictable, data center operators may face delays in certification, maintenance, security upgrades, connectivity and support. A data center cannot promise international standards while struggling to pay vendors, certifiers, auditors or connectivity providers.
Nepal should create a predictable foreign-exchange facilitation mechanism for listed data center and cloud-service providers. Payments for recognized certification bodies, security audits, critical equipment, software, maintenance, bandwidth, cloud interconnection and specialized technical services should be treated as essential digital-infrastructure payments, subject to documentation, not arbitrary delay.
If Nepal wants to be more than a low-cost location for servers, it must become a jurisdiction that serious data users can trust. That means treating data centers as critical infrastructure, setting clear limits on lawful access, embedding sustainability into sitting and approvals, coordinating infrastructure decisions across agencies, and ensuring predictable foreign-exchange access for essential services. These are not separate reform agendas; they are the foundations of credibility. Nepal’s opportunity is real, but credibility will not be declared, it will be built. And if Nepal builds it well, data centers will not simply store data here; they will anchor the next phase of the country’s digital economy.