>if they can convince Telegram to hand over the data.
Or if they hack Telegram's servers. Or ask some other agency like the NSA (that hacks systems all the time) to do that for them.
As for the legal aspects, I'm fairly sure Telegram can be made to comply, no individual user's is worth losing (tens/hundreds of) millions of customers in that particular country. It's not like Telegram can't do that technically*, the server-side database encryption key is by definition in the RAM of the server system.
* That hasn't prevented them from actively misleading customers with their split-key-and store-parts-under-multiple-jurisdictions -scheme.