4 min

India's Data Centre Boom: Evaluating DPDP Act Colocation Trends and Vendor Risks

A projected fourfold expansion in India's data centre capacity is being driven by multinational companies reacting to the DPDP Act, 2023. Compliance leaders must evaluate onshore vendor risks, cross-border transfer realities under Section 16, and the strict breach timelines of the Rules, 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What Happened

According to an Anarock report published by ETDatacenters, India's data centre capacity is projected to quadruple from 27 million square feet in H1 2026 to 101 million square feet by 2030. This massive infrastructure expansion is supported by over 300 billion dollars in investment commitments and government policy support. The report attributes this non-discretionary colocation demand primarily to the compliance pressures of the Digital Personal Data Protection Act, 2023.

Multinational corporations are rapidly setting up onshore data infrastructure to align with emerging regulatory frameworks. The Anarock report asserts that the DPDPA is creating legal obligations for personal data to be stored and processed within Indian borders, forcing a fundamental restructure of IT ecosystems for enterprise entities.

Does The DPDP Act Apply Here

The Act applies to the processing of digital personal data within India, as well as processing outside India if connected to offering goods or services to Data Principals in India. The infrastructure shift highlighted by Anarock reflects Data Fiduciaries proactively navigating these territorial boundaries. When large enterprises utilize data centres to store or compute personal data, the data centre operators typically act as Data Processors.

While colocation vendors supply the physical and network security, the legal obligation for reasonable security safeguards under the Act rests squarely on the Data Fiduciary delegating this processing. Enterprise compliance leaders must ensure these facilities meet regulatory expectations regardless of their geographic location.

Legal Implications Under DPDP

A critical nuance for compliance leaders is distinguishing market perception from statutory text. The Anarock report suggests the Act explicitly forces personal data to be stored within Indian borders. However, under Section 16, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. The Act uses a negative list approach, not a strict localization mandate.

Despite this, Section 16(2) preserves existing sectoral laws, such as financial data localization rules imposed by the RBI, which demand onshore infrastructure. Furthermore, the DPDP Rules, 2025 impose strict turnaround times for breach reporting and data rights fulfillment. Managing complex offshore supply chains increases the risk of missing these statutory deadlines, pushing compliance teams to prefer onshore Data Processors where oversight is more direct. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, and securing consent records is often viewed as operationally simpler with localized infrastructure.

Could This Happen To You

For a Head of Compliance at a large enterprise, relying on rapidly expanding geographic hubs for colocation introduces immediate vendor risk. If a newly commissioned data centre experiences a security incident, the Data Protection Board of India will demand an evidence pack from your organization, not just the facility operator. You must be able to prove that you imposed reasonable security safeguards on the processor through binding agreements and regular audits.

If a breach occurs, the Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the Board within 72 hours. An unvetted data centre provider failing to notify you immediately could result in your enterprise missing this 72-hour window. For a Data Fiduciary, this failure exposes the business to penalties of up to 250 crore rupees and severe reputational damage.

What Companies Should Do In The Next 30 Days

First, initiate a comprehensive Data Processor audit. The Head of Compliance should mandate the IT operations team to produce a consolidated list of all colocation and cloud vendors storing digital personal data. The resulting artifact must be a documented risk matrix evaluating each vendor against DPDP Act security requirements.

Second, execute addendums to existing data processing agreements. Legal teams must insert strict notification clauses requiring onshore and offshore data centres to report suspected incidents within 24 hours to ensure the enterprise can meet its own 72-hour regulatory reporting window. The artifact is an updated, signed contract for all tier-one infrastructure providers.

Third, evaluate your cross-border transfer maps. Compliance teams should identify if any data flows to jurisdictions that might appear on future Section 16 restricted lists, creating a contingency plan for onshore migration if a restriction is enacted. To evaluate your organization's readiness for vendor oversight, run a self-assessment at freescan.complydp.com today.

What To Watch

The operationalization of the Data Protection Board of India under Section 18 will set the tone for how strictly vendor agreements are scrutinized during investigations. We await the formal constitution of the Board and subsequent enforcement actions regarding processor oversight and security safeguards.

Organizations must also monitor the Central Government for any initial notifications under Section 16 restricting specific territories for cross-border processing. Exactly 257 days remain until the 13 May 2027 hard deadline. Enterprise compliance teams must use this window to ensure their infrastructure partners are thoroughly audited and fully regulator-ready.

Sources

Frequently asked questions

Does the DPDP Act mandate data localization in India?

No, the DPDP Act does not strictly mandate data localization. Under Section 16, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. However, other sectoral laws requiring localization remain valid under Section 16(2).

Why are multinational companies expanding onshore data infrastructure?

While the Act allows cross-border transfers by default, the strict timelines in the DPDP Rules, 2025 make local processing attractive. Managing breach intimations within 72 hours and ensuring reasonable security safeguards is often operationally simpler with domestic Data Processors.

Are data centre providers considered Data Fiduciaries?

In most colocation and infrastructure scenarios, data centre providers act as Data Processors. The enterprise client remains the Data Fiduciary and holds the primary legal responsibility to ensure the processor implements reasonable security safeguards.

What happens if a data centre experiences a security breach?

The Data Fiduciary is ultimately accountable to the Data Protection Board of India. They must provide intimation to affected Data Principals without delay and submit a detailed report to the Board within 72 hours, risking penalties of up to 250 crore rupees for failures.

How should compliance teams prepare for the May 2027 deadline?

Compliance teams must secure robust data processing agreements with all infrastructure vendors. With exactly 257 days remaining until the 13 May 2027 hard deadline, enterprises must finalize their audit trails and vendor oversight mechanisms to ensure compliance.