Buyer Questions7 min read

Does DPDP Require Storing Indian Data In India?

Understand how the DPDP Act, 2023 and the DPDP Rules, 2025 handle cross-border data transfers, the Section 16 negative list mechanism, extraterritorial applicability, and what B2B SaaS vendors must prove to enterprise clients to unblock procurement.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Does DPDP Require Storing Data Exclusively Within India?

The short answer is no. A common misconception among global technology vendors is that the Digital Personal Data Protection Act, 2023, and the operational framework outlined in the DPDP Rules, 2025, mandate strict, overarching data localization for all processing activities. Under Section 16(1) of the Act, cross-border data flows are permitted by default. The Central Government holds the power to, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to specific countries or territories outside India. This establishes a clear negative list mechanism. If a jurisdiction is not actively placed on this restricted list by the government, Data Fiduciaries may freely transfer digital personal data there for processing. This represents a highly pragmatic and significant shift toward enabling global digital trade, recognizing that modern cloud infrastructure relies on dynamic, borderless data routing. For B2B technology companies, enterprise SaaS providers, and global startups, this negative list mechanism provides a much smoother operational baseline. It removes the immediate friction of localized server mandates for general personal data, allowing organizations to leverage centralized, cost-effective global cloud deployments across unrestricted jurisdictions without facing baseline localization barriers.

Understanding Extraterritorial Applicability Under Section 3

While general data transfers are broadly permitted, understanding exactly where and when the law applies is critical for global compliance. Section 3 sets clear territorial boundaries for the DPDP Act. Section 3(a) dictates that the Act applies to the processing of digital personal data within the territory of India, regardless of whether the personal data is collected in digital form or collected in non-digital form and digitized subsequently. More importantly for global vendors operating without a physical Indian entity, Section 3(b) establishes a robust extraterritorial scope. The Act explicitly applies to the processing of digital personal data outside the territory of India if such processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India. If your B2B SaaS platform is hosted in Europe or the United States but actively targets, markets to, and services Data Principals in India, your overseas processing activities fall squarely under the DPDP Act's jurisdiction. Conversely, Section 3(c) outlines vital exemptions to this applicability. The DPDP Act does not apply to personal data processed by an individual for any personal or domestic purpose. Furthermore, under Section 3(c)(ii), it specifically exempts personal data made or caused to be made publicly available by the Data Principal to whom such personal data relates, or by any other person who is under a legal obligation to do so.

The Critical Catch: Sectoral Laws and Section 16(2)

The general freedom to transfer data across borders comes with a critical, overriding caveat. Section 16(2) of the DPDP Act states that nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for, or restriction on, the transfer of personal data by a Data Fiduciary outside India. This essentially means the DPDP Act acts as a baseline standard, not a statutory ceiling. If you process specific categories of data regulated by industry-specific administrative bodies, their stricter data localization mandates will completely override the DPDP Act's permissive stance. For example, payment systems data is currently subject to strict localization directives from the Reserve Bank of India (RBI), which heavily restricts cross-border movement and requires core data to be stored exclusively within India's borders. If a software platform processes a mix of general profile data and highly regulated financial data, the system architecture must appropriately bifurcate these streams. General data can leverage global cloud servers under Section 16(1), while payment data must remain tethered to domestic Indian infrastructure to satisfy the requirements preserved by Section 16(2).

Navigating B2B Procurement, Notice, and Sub-Processor Chains

Transferring personal data overseas legally requires strict administrative hygiene and transparent communication with Data Principals, with procedures further formalized in the DPDP Rules, 2025. Consent remains the primary legal basis for processing personal data, except in specific scenarios where Section 7 legitimate uses explicitly apply. When relying on consent as your lawful basis, your privacy notice must clearly and accurately reflect your international data transfer practices in accordance with the prescribed rules. Ambiguity regarding where a Data Principal's data is sent is a massive compliance liability. In the B2B context, your enterprise clients, acting as Data Fiduciaries, bear the ultimate regulatory accountability for these cross-border flows. When your company acts as a Data Processor, tier-one enterprises will heavily scrutinize your sub-processor chains during the procurement phase. Large banks, healthcare networks, and telecom providers are increasingly forcing their vendors to provide exhaustive, documented proof of their geographical processing footprint. You must be able to prove unequivocally that no downstream sub-processor operates within a restricted territory notified under Section 16(1). Without an airtight evidence pack mapping these geographical data flows and server locations, your enterprise deals will inevitably stall in prolonged vendor risk assessment limbo.

Managing Overseas Data Breaches and Incident Response

Operating cloud infrastructure outside India does not grant any leniency regarding security breach management. In fact, cross-border network architectures often complicate incident response efforts significantly. The DPDP framework, bolstered by the precise reporting timelines and formats set out in the DPDP Rules, 2025, mandates robust procedures to report personal data breaches to both the Data Protection Board of India and the affected Data Principals. If a critical breach originates at an overseas data center or is triggered by a vulnerability in a foreign sub-processor's system, your internal security teams must rapidly navigate different time zones, varied regulatory standards, and fragmented server logs to gather accurate forensic evidence. The regulatory reporting clock starts ticking regardless of geographical hurdles, international communication delays, or the physical location of the breached server. Enterprise clients will rigorously audit your breach response playbooks specifically to evaluate your cross-border readiness. They will demand ironclad contractual guarantees in Data Processing Agreements stating that you can identify, contain, and report an overseas security incident fast enough to protect the Data Fiduciary from facing severe financial penalties under the Act and its Rules.

What To Do Next to Prepare for Enforcement

With compliance deadlines rapidly approaching as detailed by the DPDP Rules, 2025, B2B SaaS teams must operationalize their cross-border data controls immediately. It is crucial to note Section 1(2) of the DPDP Act, which grants the Central Government the authority to appoint different dates for different provisions of the Act to come into force. While specific obligations might see a phased rollout, structural data mapping must begin now. Manual spreadsheets are entirely insufficient for tracking dynamic, globally distributed cloud computing environments. First, deploy a dynamic Record of Processing Activities (RoPA) that maps every individual data flow against both the anticipated Section 16(1) negative list and sectoral laws protected by Section 16(2). Second, comprehensively audit your sub-processor agreements to ensure you have strict contractual obligations preventing unauthorized data transfers to any restricted territories. Third, implement an automated compliance platform that generates continuous, auditor-ready evidence of your processing locations. Your next major enterprise contract depends entirely on your ability to prove structural DPDP compliance. Stop losing lucrative deals to procurement delays and extended vendor risk assessments. Get your cross-border data flows audited and mapped today at freescan.complydp.com.

Sources

Frequently asked questions

Can I transfer personal data from India to the USA under DPDP?

Yes, under Section 16(1) of the DPDP Act, 2023, cross-border data transfers to the USA are permitted by default unless the Central Government explicitly adds the USA to a notified negative list. However, you must still maintain valid grounds for processing, such as consent or Section 7 legitimate uses, and comply with any sector-specific localization rules and the DPDP Rules, 2025.

Does the DPDP Act apply if our servers are located outside India?

Yes. Under Section 3(b) of the Act, extraterritorial applicability is clearly established if your overseas processing of digital personal data is connected to offering goods or services to Data Principals within the territory of India. Your server location does not exempt you from strict compliance with the Act and its subsequent Rules.

What happens if an overseas sub-processor experiences a data breach?

The primary Data Fiduciary remains responsible for breach reporting under the DPDP Act and the DPDP Rules, 2025. This requires intimation to affected Data Principals and a detailed incident report to the Data Protection Board of India. The geographical location of the sub-processor does not alleviate the obligation to report the breach promptly according to the prescribed regulatory timelines.