NEWS ANALYSIS4 mins

India's Data Centre Capacity to Quadruple by 2030 Driven by DPDP Act 2023 Mandates

Anarock projects a 300 billion dollar investment in Indian data centres by 2030 as multinational and healthtech enterprises localise infrastructure to meet DPDP Act and sectoral compliance standards.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

According to a 26 August 2026 report by Anarock released via ETDatacenters, India's data centre footprint is projected to quadruple by 2030. The physical capacity will expand from 27 million square feet in the first half of 2026 to 101 million square feet, supported by over 300 billion dollars in investment commitments to reach 6.7 GW capacity. The report identifies the Digital Personal Data Protection Act, 2023 as a primary policy enabler driving multinational companies to establish onshore data infrastructure. This regulatory shift is generating massive non-discretionary colocation demand, with Hyderabad and Delhi-NCR emerging as key geographic growth markets.

Does the DPDP Act apply here?

The infrastructural shift directly affects Data Fiduciaries processing digital personal data within India. The DPDP Act covers this domestic processing, as well as processing outside India connected to offering goods or services to Data Principals in India. For a large healthtech enterprise or hospital network, patient records digitised and stored in these new colocation facilities fall squarely under the Act. Evaluating domestic cloud vendors versus offshore providers is no longer just an IT infrastructure decision, but a core compliance mandate for the Head of Compliance.

Legal implications under DPDP

While the Anarock report highlights onshore processing, it is vital for compliance leaders to understand the exact statutory mechanism. Under Section 16 of the DPDP Act, 2023, cross-border transfers are generally permitted unless the Central Government notifies a specific country or territory as restricted. However, Section 16(2) explicitly preserves any other laws providing a higher degree of restriction on transfers, which often captures health and financial sector regulations. Furthermore, engaging these domestic data centres requires stringent processor contracts under the DPDP Rules 2025, ensuring vendors implement reasonable security safeguards and support the Fiduciary in breach reporting obligations. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning patient consent artefacts must clearly reflect the processing purposes.

Could this happen to you

For a healthtech Head of Compliance, moving patient databases to a domestic data centre creates a critical processor dependency. If that local facility suffers a security incident, the liability rests entirely with you as the Data Fiduciary. The DPDP Rules 2025 require you to intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours. An auditor or the DPBI, established under Section 18 of the Act, will immediately demand your RoPA, processor agreements, and proof of control oversight. Failing to produce a regulator-ready evidence pack could expose your organisation to penalties reaching up to 250 crore rupees for data breach failures, halting enterprise deals and severely damaging patient trust.

What companies should do in the next 30 days

1. Review processor contracts. The compliance team must ensure all agreements with domestic data centres mandate immediate breach notification to the Data Fiduciary to meet the 72-hour regulatory reporting window.

2. Map patient data flows. IT and compliance must collaborate to update the Record of Processing Activities, identifying exactly which colocation facilities hold patient data and establishing clear control owners.

3. Assess sectoral transfer restrictions. The legal team must evaluate if existing health guidelines intersect with Section 16(2) of the DPDP Act to mandate strict local storage, documenting this in your formal evidence pack.

4. Implement consent verification. Operations must verify that patient consent workflows clearly state the processing purposes before personal data is transferred to any third-party infrastructure.

What to watch

The landscape for infrastructure and compliance is compressing rapidly, and exactly 260 days remain until the 13 May 2027 hard compliance deadline. Watch for the Central Government to potentially issue the negative list of restricted countries under Section 16, which could further accelerate domestic data centre migrations. Healthtech compliance teams must also monitor the operationalisation of the Data Protection Board of India for specific formatting requirements regarding breach reporting and audit trails. To evaluate your organisation's current vendor oversight and processor readiness, assess your exposure at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act restrict transferring patient data outside India?

Under Section 16 of the DPDP Act, 2023, cross-border transfers are generally permitted unless the Central Government notifies a negative list of restricted countries. However, healthtech companies must also comply with sectoral regulations preserved by Section 16(2) that may enforce stricter local storage requirements.

What happens if our domestic data centre vendor suffers a security breach?

As the Data Fiduciary, you hold primary liability for the incident. Under the DPDP Rules 2025, you must intimate affected Data Principals without delay and report the breach to the Data Protection Board of India within 72 hours, facing penalties up to 250 crore rupees for non-compliance.

Are we required to obtain patient consent before storing data in colocation facilities?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Your consent records must reflect the specific purposes of processing, requiring clear oversight of how processors manage this data on your behalf.

How much time is left to implement DPDP compliance frameworks?

Exactly 260 days remain until the 13 May 2027 hard compliance deadline. Healthtech compliance teams must finalise their Record of Processing Activities and update all data processor agreements before this date to ensure readiness.