4 min read

DPDP Act Drives India Data Centre Expansion to 101 Million Square Feet

Anarock projects India's data centre footprint will quadruple by 2030 as enterprises adapt to DPDP Act cross-border rules. Compliance heads must evaluate onshore vendor contracts and regulatory audit readiness.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

On August 26, 2026, ETDatacenters reported an Anarock projection that India's data centre footprint will quadruple to 101 million square feet by 2030. This marks a sharp increase from 27 million square feet in H1 2026. The expansion is backed by over $300 billion in investment commitments. Anarock cites the Digital Personal Data Protection Act, 2023 as a primary driver, stating the regulation creates legal obligations requiring personal data to be stored and processed within Indian borders. This environment generates non-discretionary colocation demand for multinational companies establishing onshore infrastructure.

Does the DPDP Act apply here?

The Act governs digital personal data processed within India. The Anarock report claims the Act mandates strict local storage, which requires careful legal qualification. Section 16(1) of the DPDP Act operates on a negative list, permitting cross-border transfers unless the Central Government specifically restricts a destination country. The legislation itself does not impose a blanket localization requirement. Section 16(2) preserves existing sectoral laws that demand higher protection or localization, such as Reserve Bank of India mandates for financial data. Enterprises frequently choose onshore colocation to preempt negative list risks and simplify their compliance architecture.

Legal implications under DPDP

Shifting data to local facilities alters processor relationships and compliance burdens. When a Data Fiduciary contracts an onshore colocation provider, that vendor acts as a Data Processor under the Act. The fiduciary retains full accountability for notice, purpose limitation, and consent records. Infrastructure partners must support the fiduciary's regulatory obligations directly. The DPDP Rules, 2025 require a detailed breach report to the Data Protection Board of India within 72 hours. Colocation contracts need strict service level agreements ensuring the facility operator notifies the control owner well before that window closes.

Could this happen to you

Compliance heads face immediate exposure if their localized infrastructure partners fail a regulatory audit. An incident at a vendor facility triggers direct scrutiny of the fiduciary. The Data Protection Board of India, established under Section 18, will demand an evidence pack verifying your vendor oversight. Auditors expect signed processor agreements, risk assessments for the new data center, and logs proving access controls. If your compliance team cannot produce a regulator-ready audit trail mapping data flows to the new onshore facility, the enterprise risks severe financial penalties.

What companies should do in the next 30 days

1. Direct the control owner to update the RoPA to map which enterprise datasets are migrating to new onshore facilities. 2. Review all Data Processor agreements with colocation providers to ensure incident response times align with the 72-hour DPBI reporting rule. 3. Conduct a DPIA on the new physical infrastructure to document security safeguards, vendor access limitations, and data retention enforcement mechanisms.

What to watch

The Central Government is expected to notify the specific countries restricted under Section 16, which could force further data repatriation. Multinational enterprises should track these notifications to adjust their cross-border routing. You have exactly 255 days remaining until the DPDP hard compliance deadline of 13 May 2027. Begin mapping your vendor network and processor agreements today by running a vendor exposure assessment at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act mandate data localization in India?

No. Section 16 of the DPDP Act permits cross-border transfers unless the destination is on a restricted negative list notified by the Central Government. However, Section 16(2) upholds stricter sectoral localization laws, such as RBI guidelines for financial data.

How does using an Indian data centre affect my DPDP compliance?

Using a local data centre makes the facility provider your Data Processor. You remain the Data Fiduciary and must ensure the provider contract includes audit rights and breach reporting mechanisms that meet DPDP Rules 2025 timelines.

What breach notification timelines apply to onshore data processors?

The DPDP Rules 2025 require Data Fiduciaries to submit a detailed breach report to the Data Protection Board of India within 72 hours. Your processor agreements with data centres must guarantee they notify you well within this window.

What evidence will the Data Protection Board require during an audit?

The Board will request your Records of Processing Activities (RoPA), signed processor agreements, and documented workflows for breach intimation. A clear audit trail proving oversight of your data centre vendors is expected.