5 minutes

Can we keep Indian personal data on US or EU cloud?

The DPDP Act permits transferring digital personal data to US and EU servers by default, subject to a negative list and overriding sectoral localization laws.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Yes, you can store digital personal data on US or EU cloud servers under the Digital Personal Data Protection Act, 2023. Section 16 of the Act establishes a default position that cross-border transfers are permitted. The Central Government holds the power to restrict transfers to specific countries by issuing a notification. This mechanism creates a negative list. Until a country is explicitly restricted, transferring data out of India remains generally lawful under this primary privacy framework. This shifts the compliance burden away from pre-approving specific destinations. Companies building infrastructure on global cloud providers can route data to Frankfurt or Virginia data centers without violating the primary statute.

Section 16(1) states the Central Government may notify countries or territories where data transfers are restricted. Currently, no negative list exists. A SaaS platform hosting its database in the US does not need government authorization to move the data. The statutory text uses restriction rather than permission. A data fiduciary moves data freely until a government notification blocks that specific jurisdiction. Legal teams must monitor official gazette notifications for additions to this restricted list. A sudden geopolitical shift could trigger a notification. If the Central Government adds a host country to the negative list, fiduciaries must stop transferring data to that jurisdiction. Contracts with infrastructure providers require exit clauses. An organization needs technical flexibility to migrate databases back to an Indian server region if their current hosting location receives a restriction notice.

Section 16(2) provides a specific exception to the default permissive rule. It dictates that if another Indian law imposes stricter restrictions on data transfers, that specific law applies. The DPDP Act does not erase existing data localization mandates. If a platform processes payment data, Reserve Bank of India localization directives override the permissive default of the DPDP Act. Financial institutions face strict rules regarding where they store core banking or payment gateway records. Telecom operators deal with Department of Telecommunications licensing requirements that restrict offshore routing. Health data management platforms navigate similar overlapping rules. A software vendor cannot rely solely on Section 16(1) when selling to highly regulated industries. You must map the data category against sectoral laws before confirming a foreign cloud architecture.

The Act applies whenever you process digital personal data in India. Under Section 3(a), collection within the territory triggers compliance, whether the data originates in digital form or is digitized subsequently. Under Section 3(b), the law also applies to processing outside India if that processing connects to offering goods or services to Data Principals within the territory. Storing data in a US data center means the DPDP Act follows the data. A foreign entity with zero physical presence in India falls under the statute. Your organization retains obligations regarding notices and verifiable parental consent mechanics. An individual user in Mumbai requesting data erasure holds the same rights whether the database sits in Bengaluru or London. The physical location of the server changes the transfer mechanic but leaves the fiduciary obligations intact.

Section 3(c) outlines boundaries where the Act does not apply. Personal data processed by an individual for a personal or domestic purpose falls outside the law. A user saving contacts on a personal mobile device synced to a US cloud drive does not trigger fiduciary obligations. The Act also exempts personal data made publicly available by the Data Principal to whom it relates. If a user publishes their own phone number on a public web forum, scraping that specific data does not require consent. The exemption also covers data made public by any other person under a legal obligation. A business cannot claim the public data exemption just because a database leaked online. B2B platforms hosting enterprise employee records or customer lists process non-public data for commercial purposes. They fall entirely under the scope of Section 3.

Section 1 establishes the short title and commencement structure of the law. Section 1(2) dictates that the Act comes into force on dates appointed by the Central Government through official gazette notifications. The text explicitly allows different dates for different provisions. Any reference to the commencement of the Act means the coming into force of that specific provision. Under the DPDP Rules 2025, fiduciaries face a compliance deadline of 13 May 2027. This countdown forces organizations to map their cross-border data flows now. Procurement departments at large Indian enterprises reject vendors who fail to demonstrate compliance readiness. Selling software to these buyers requires proof that foreign processors meet DPDP standards.

Enterprise clients force vendors to prove DPDP compliance before signing contracts. Under the rules, Data Fiduciaries maintain detailed logs. They ensure their data processors can support a 72-hour breach reporting window to the Data Protection Board. When a B2B SaaS provider relies on EU cloud infrastructure, they document that no sectoral laws block the transfer. They verify that their foreign processors can meet these incident timelines. Producing a clean record of processing activities that maps cross-border data flows clears procurement delays. Many global platforms stall in sales cycles because Indian buyers enforce strict supply chain audits. You do not need to execute specific standard contractual clauses to move data from India to the US under the DPDP Act. The default transferability reduces initial regulatory friction. The commercial friction remains high. Buyers demand localization options when they doubt a foreign processor can meet the 72-hour reporting rule.

What to do next

1. Map your data flows to identify exactly which servers process data from Data Principals in India.

2. Check if any data categories fall under sectoral localization rules, such as Reserve Bank of India mandates for financial records.

3. Build an evidence trail showing how your foreign processors meet the 72-hour breach reporting timelines required by the Rules, 2025.

Stop losing enterprise deals over data location questions. ComplyDP helps B2B SaaS vendors map cross-border flows, manage DPDP obligations, and prove compliance to enterprise buyers. Run an infrastructure check today at freescan.complydp.com.

Sources

Frequently asked questions

Do we need specific transfer contracts like SCCs for DPDP?

No. The DPDP Act does not require specific data transfer agreements or transfer impact assessments to move data to the US or EU. Transfers are permitted unless the destination is on a notified negative list or blocked by a sectoral law.

Can Indian banks store customer data on our foreign cloud?

Usually no. While the DPDP Act permits it, Section 16(2) defers to stricter laws. The Reserve Bank of India requires payment data to be stored only in India. Software vendors selling to financial institutions often provide local hosting options to meet these sectoral rules.

What happens if our cloud provider is in a country added to the negative list?

If the Central Government notifies your host country under Section 16(1), you must cease transferring data to that jurisdiction. Companies should maintain architectural flexibility to migrate data to an Indian region or a non-restricted jurisdiction if official gazette notifications block a specific country.

Does the DPDP Act apply if we have no offices in India?

Yes. Section 3(b) extends the Act to processing outside India if it connects to offering goods or services to Data Principals within India. A US company with zero physical presence in India must comply if they target users in the territory.