4 mins
India Data Centre Capacity Forecast to Hit 101 Million Square Feet by 2030
Anarock reports a massive expansion in domestic data centre infrastructure driven by financial incentives and evolving vendor strategies under the DPDP Act 2023. We analyze the legal reality of cross-border transfers and what this means for enterprise vendor oversight.
Last updated:
What happened
Anarock reports that India data centre capacity will quadruple to 101 million square feet by 2030. The real estate services firm attributes this expansion to favorable government financial policies and legal obligations related to the Digital Personal Data Protection Act, 2023. Data centres recently gained infrastructure status, unlocking access to long-tenure financing. Providers can now secure loans for up to 12 years at interest rates between 9.5 and 10.5 percent. A proposed tax holiday through 2047 aims to attract eligible global cloud service providers to build localized architecture.
Does the DPDP Act apply here?
The Anarock report claims the DPDPA 2023 creates legal obligations for personal data to be stored and processed within India. This is a common market misconception that compliance teams must correct for their executive boards. Section 16 of the Digital Personal Data Protection Act, 2023 operates on a negative list model. Cross-border transfers of personal data are permitted unless the Central Government issues a notification restricting transfers to specific countries or territories. The Act does not contain a blanket data localization mandate. However, Section 16(2) preserves stricter sectoral regulations. Healthtech platforms and hospital chains handle health records often governed by National Digital Health Mission policies or financial rules that separately require domestic processing.
Legal implications under DPDP
Enterprises moving operations to domestic data centres are legally engaging Data Processors. Under the Act, a Data Fiduciary remains entirely accountable for the actions of its processors. The Rules, 2025 require Fiduciaries to implement technical and organizational measures to protect data regardless of where the server sits. If an Indian data centre suffers a security incident, the Fiduciary holds the regulatory burden. The Rules mandate that the Data Fiduciary submit a detailed breach report to the Data Protection Board of India within 72 hours. The Fiduciary must also intimate affected Data Principals without delay. Relying on a localized cloud provider does not transfer this legal liability.
Could this happen to you
Many large healthtech enterprises assume that migrating to an Indian data centre automatically satisfies regulatory scrutiny. A domestic server location is useless during an audit if your compliance team cannot produce an evidence pack. When the DPBI investigates a complaint against your clinic network or platform, they look at your internal controls. The regulator will demand your Record of Processing Activities and verifiable consent artefacts. If your data centre vendor blocks access to audit logs or fails to support your breach response workflows, your enterprise faces the regulatory penalties. A Chief Compliance Officer needs health-grade vendor oversight that provides immediate visibility into how patient data flows through these new data centres.
What companies should do in the next 30 days
1. Map your data flows. The compliance team should document exactly which Data Processors store patient data locally versus offshore.
2. Review cloud contracts. Legal teams need to amend service level agreements to mandate that domestic data centres report any security incidents to you well before your 72-hour regulatory window closes.
3. Assess sectoral rules. Identify any specific health or financial data categories in your systems that fall under stricter localization laws preserved by Section 16(2).
4. Test control ownership. Assign a specific control owner to monitor vendor compliance and maintain the required audit trails.
What to watch
The Central Government has not yet notified any restricted countries under the Section 16 negative list. Enterprises should watch for these notifications to finalize their long-term cloud architecture strategies. We also await the physical establishment of the Data Protection Board of India under Section 18, which will begin enforcing processor oversight standards. Exactly 254 days remain until the DPDP hard compliance deadline of 13 May 2027. To evaluate your vendor oversight controls and audit readiness, run a diagnostic at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act require all personal data to stay in India?
No. Section 16 of the Act uses a negative list approach. Cross-border data transfers are permitted unless the Central Government notifies a specific restricted country, though stricter sectoral laws may still apply.
How do infrastructure policies affect data centre costs?
Data centres now hold infrastructure status in India. This allows operators to secure long-tenure financing of up to 12 years at interest rates between 9.5 and 10.5 percent, driving massive expansion.
Are we compliant if we move all our processing to an Indian data centre?
No. A domestic server does not eliminate your obligations as a Data Fiduciary. You must still manage consent, issue itemised notices, and maintain a Record of Processing Activities for DPBI audits.
What is the timeline for DPDP Act enforcement?
The regulatory window is closing quickly. Exactly 254 days remain until the hard compliance deadline of 13 May 2027.
ComplyDP