4 mins
HealthTech Data Localization Surges as Data Center Footprint Quadruples
India's data center capacity will quadruple by 2030 as healthtech legal teams localize data hosting to mitigate DPDP vendor risks and simplify compliance.
Last updated:
What happened
According to an Anarock report covered by ETDatacenters on August 26, 2026, India's data center footprint is projected to expand fourfold to 101 million square feet by 2030. This is a massive scale up from the 27 million square feet recorded in the first half of 2026. The growth is fueled by over 300 billion dollars in investment commitments.
The report names the Digital Personal Data Protection Act, 2023 as a primary policy intervention driving this expansion. Multinational companies are increasingly localizing their infrastructure to establish onshore data processing facilities. This shift creates non-discretionary colocation demand as companies move beyond traditional tier one markets to secure domestic hosting options.
Does the DPDP Act apply here?
The DPDP Act governs digital personal data processed within India, as well as processing outside India connected to offering goods or services to Data Principals in India. The Anarock report claims the Act creates legal obligations to store data within Indian borders. General Counsels must clarify this distinction for their boards. Section 16 of the DPDP Act permits cross-border data transfers unless the Central Government restricts specific countries via a notified negative list.
Despite the lack of a blanket localization mandate, market realities drive the shift. Healthtech platforms process high volumes of clinical and patient information. The DPDP Act 2023 does not create a separate sensitive data category, but the risk and volume of health data often trigger Significant Data Fiduciary (SDF) designation under the Act and Rules 2025. Legal teams prefer onshore data processors to simplify vendor risk assessments and limit liability.
Legal implications under DPDP
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. When using offshore cloud processors, the Data Fiduciary retains full liability for DPDP compliance. If an offshore vendor experiences a security incident, the Data Fiduciary must still meet the breach response requirements detailed in the DPDP Rules 2025. This includes intimation to affected Data Principals without delay and a detailed report to the Data Protection Board of India (DPBI) within 72 hours.
Investigating a breach across multiple international jurisdictions complicates this 72-hour timeline and increases litigation risk. Local colocation demand is surging because healthtech general counsels require clear contractual controls, direct audit rights, and enforceable indemnification from domestic vendors. Utilizing onshore data centers eliminates cross-border transfer compliance hurdles and provides a stronger defensibility narrative for regulator engagement.
Could this happen to you
Imagine a ransomware attack at your offshore cloud hosting provider. Could your outside counsel guarantee they will secure forensic evidence and notify the DPBI within 72 hours? For a healthtech legal head, an offshore vendor failure means direct DPDP liability. Penalties can reach up to 250 crore rupees for failing to take reasonable security safeguards.
The geographic diversification of Indian data centers gives your enterprise highly available, redundant domestic hosting options. Moving your healthtech data flows onshore simplifies the complex vendor oversight obligations mandated for SDFs under the Rules 2025. It aligns your architecture with health-grade privacy standards without the bureaucracy of banking infrastructure, directly protecting patient trust and enterprise valuation.
What companies should do in the next 30 days
1. Map current health data flows to identify all offshore Data Processors and evaluate the cost of onshore migration.
2. Update your vendor contracts to include specific limitation of liability clauses, indemnity for DPDP fines, and mandatory 24-hour breach notification service level agreements.
3. Run a mock DPBI 72-hour breach reporting drill with your current cloud provider to test their incident response capabilities.
4. Prepare documentation under the DPDP Rules 2025 for SDF obligations, ensuring you can demonstrate verifiable consent records during an audit.
What to watch
Monitor the Central Government for any Section 16 negative list notifications restricting cross-border transfers to specific territories. Additionally, watch for the official notification establishing the DPBI headquarters as outlined in Section 18 of the DPDP Act, which will signal operational enforcement readiness.
Exactly 256 days remain until the 13 May 2027 hard compliance deadline. To evaluate your vendor risk, data flow mapping capabilities, and onshore migration readiness, run a check at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act require all personal data to be stored in India?
No. Under Section 16 of the DPDP Act, cross-border transfers are generally permitted unless the Central Government restricts transfers to specific notified countries on a negative list. However, many healthtech companies choose onshore hosting to simplify compliance.
Why are healthtech companies moving data to Indian data centers?
Storing data onshore simplifies vendor risk assessments, ensures stricter contractual controls, and helps companies meet the strict 72-hour breach reporting timeline required by the DPDP Rules 2025. It also provides a stronger defensibility narrative during regulator audits.
What is the penalty for failing to protect patient data under the DPDP Act?
The Act imposes fines up to 250 crore rupees for failing to implement reasonable security safeguards to prevent personal data breaches. Data Fiduciaries bear this liability even if the breach occurs at a third-party processor.
Does health data have special protections under the DPDP Act?
The DPDP Act 2023 does not create a separate sensitive data category for health information. However, processing large volumes of high-risk health data can trigger Significant Data Fiduciary (SDF) obligations under the Rules 2025, requiring stricter governance.
When do companies need to comply with the DPDP Act?
Enforcement readiness is accelerating as the regulatory framework finalizes. Companies must complete their compliance preparations, including vendor contract updates and consent management rollouts, before the hard compliance deadline on 13 May 2027.
ComplyDP