NEWS ANALYSIS4 mins

DPDP Act and RBI Mandates Drive India Data Center Growth: TCO and Risk Analysis for BFSI CFOs

An analysis of the structural demand for domestic data centers driven by DPDP Act security requirements and RBI localization rules, detailing the contingent liability and infrastructure cost implications for BFSI finance leaders.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

OpenPR released a market analysis report projecting structural demand for the India data center server market between 2026 and 2034. The report identifies the Digital Personal Data Protection Act, 2023 and RBI payment data rules as primary drivers for domestic data storage. Financial services, healthcare, and government sectors are leading this infrastructure expansion alongside cloud and AI workloads. However, the report notes infrastructure challenges including high power costs, grid reliability issues, and a shortage of skilled data center operations talent.

Does the DPDP Act apply here?

The Act applies to digital personal data processed within India by these data centers acting as Data Processors for financial institutions. For BFSI entities, processing includes KYC data, loan origination files, and transaction histories. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India, regardless of where the physical servers sit. While the market report loosely cites the DPDP Act as a data localisation mandate, banking operations trigger overlapping RBI mandates that legally force physical storage inside the country.

Legal implications under DPDP

Under Section 16 of the DPDP Act, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. However, Section 16(2) preserves sector-specific regulations that impose stricter transfer restrictions, directly validating the RBI payment data rules that BFSI CFOs must budget for. Beyond server location, the DPDP Rules, 2025 require Data Fiduciaries to maintain verifiable oversight over their data center vendors. If a local data center experiences an incident, the BFSI entity must still execute breach intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.

Could this happen to you

For a CFO at a large bank or NBFC, data center infrastructure is a massive capital expenditure or recurring SaaS line item. As you evaluate TCO and vendor consolidation, failing to align infrastructure contracts with DPDP requirements creates massive contingent liability. If your local data center suffers an outage or breach due to the grid and talent shortages noted in the report, the DPBI will look at you, the Data Fiduciary. The Board can impose penalties up to 250 crore rupees for failing to take reasonable security safeguards. An auditor will ask for your processor agreements, breach response testing logs, and proof that consent is the primary basis for processing, except where Section 7 legitimate uses apply, before underwriting your cyber insurance premium.

What companies should do in the next 30 days

1. The CFO and Chief Compliance Officer must review all existing data center and cloud processor agreements to ensure they contain DPDP-compliant audit rights and breach notification SLAs.

2. Finance teams should quantify the EBITDA impact of compliance versus the penalty exposure ceiling, provisioning adequate budget for automated consent and breach workflow tooling.

3. Legal and IT must map all third-party data flows to verify compliance with both RBI rules and DPDP cross-border frameworks, creating an audit-ready data inventory.

4. Test your incident response workflows to confirm your team can gather forensics from vendors and notify the DPBI within the 72-hour window mandated by the Rules, 2025.

What to watch

Monitor the Central Government for the notification of the Section 16 negative list for cross-border transfers. BFSI entities should also prepare for Significant Data Fiduciary designation under Section 10, which requires appointing an India-based DPO and conducting independent data audits based on processing volume and risk. Exactly 275 days remain until the 13 May 2027 hard deadline. To assess your current vendor oversight and breach readiness without adding another disconnected tool, run a self-assessment at freescan.complydp.com today.

Sources

Frequently asked questions

How does the DPDP Act impact our data center TCO and vendor consolidation?

The Act holds Data Fiduciaries responsible for processor compliance. Consolidating vendors to those who can meet the 72-hour breach reporting SLA required by the DPDP Rules, 2025 reduces audit fees and lowers contingent liability.

Are we forced to localize all data under the DPDP Act?

The DPDP Act permits cross-border transfers unless restricted by a Central Government negative list. However, Section 16 preserves sector-specific laws, meaning BFSI entities must still comply with stricter RBI payment data localization mandates.

What is the financial penalty exposure if our local data center suffers a breach?

Failing to implement reasonable security safeguards carries penalty ceilings up to 250 crore rupees under the DPDP Act. This directly impacts cyber insurance premiums and corporate EBITDA if not properly mitigated.

How does BFSI data volume affect our regulatory obligations?

High volumes of financial data and associated risks will likely trigger Significant Data Fiduciary designation under Section 10 of the Act. This requires appointing a Data Protection Officer based in India and conducting independent audits.

Can our finance and compliance teams manage vendor oversight manually?

Managing vendor SLAs and breach workflows across multiple data centers via spreadsheets is highly inefficient. Automated compliance platforms provide the evidence trails needed for auditors and the DPBI, reducing long-term compliance budgeting.