4 min read

India Data Centre Footprint Quadruples as DPDP Act Drives Onshore Processing

Anarock projects India's data centre capacity will reach 101 million square feet by 2030. Discover why the DPDP Act is creating non-discretionary colocation demand and how EdTech companies must adapt their parental consent and breach workflows.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What Happened

According to a recent report by Anarock released on 26 August 2026, India's data centre footprint is projected to quadruple to 101 million square feet by 2030. This massive expansion, up from 27 million square feet in H1 2026, is fueled by over 300 billion dollars in investment commitments. The Economic Times reports that this surge represents non-discretionary colocation demand. Multinational companies are rapidly establishing onshore data infrastructure in direct response to the Digital Personal Data Protection Act, 2023.

Does The DPDP Act Apply Here

The DPDP Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. For large EdTech enterprises, this applies directly to student profiles, learning analytics, and verifiable parental consent tokens. While the Act applies universally to this data, the shift to onshore infrastructure indicates companies are actively minimizing jurisdictional risk. By processing personal data within Indian borders, data fiduciaries reduce the complexity of cross-border data flows and align closely with DPBI evidence requirements.

Legal Implications Under DPDP

Under Section 16 of the DPDP Act, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. However, the DPDP Rules, 2025 introduce precise operational specifics that make domestic colocation highly attractive for risk mitigation. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For EdTech platforms handling children's data, maintaining local infrastructure simplifies the RoPA and ensures that behavioral tracking prohibitions are tightly controlled within domestic systems.

Could This Happen To You

If your EdTech platform relies on offshore cloud instances to manage user onboarding, you face increasing compliance friction. The DPBI will demand an immediate evidence pack demonstrating how parental consent artefacts are collected, stored, and segregated. Generic compliance tools often fail to understand parental tokens or age-gating nuances, leaving significant gaps in your RoPA. In the event of a personal data breach, your incident response plan must execute an intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025. Chief Product Officers and Heads of Legal must ask if their current infrastructure can isolate children's data processing and prove compliance with Rule 10 workflows without breaking the user experience.

What Companies Should Do In The Next 30 Days

1. Map onshore infrastructure needs: The Head of Compliance should evaluate current cloud vendors against the DPDP cross-border framework and assess the cost of moving core personal data workloads domestically.

2. Implement Rule 10 workflows: The CPO must design age-gating and parental token systems that integrate seamlessly into onboarding, maintaining clear audit trails on local servers.

3. Update DPIAs for offshore processing: Control owners must document the risk of any personal data processed outside India, particularly where algorithmic recommendations are involved.

4. Prepare the 72-hour breach protocol: Legal teams must draft breach intimation templates that satisfy the DPDP Rules, 2025, ensuring local IT teams can pull necessary logs immediately.

What To Watch

The industry is closely monitoring the Central Government for the publication of the negative list under Section 16, which will dictate restricted territories for data transfers. Expect heightened DPBI enforcement scrutiny around children's data and verifiable parental consent mechanisms as domestic colocation options expand. Companies have limited time to transition their infrastructure and compliance architectures before regulatory audits commence. Exactly 257 days remain until the DPDP hard compliance deadline of 13 May 2027. Assess your current infrastructure and consent workflows at freescan.complydp.com to determine your regulatory readiness.

Sources

Frequently asked questions

Does the DPDP Act require all data to be stored in India?

No. Under Section 16, cross-border transfers are generally permitted unless the Central Government restricts transfer to a negative list of notified countries. However, companies are rapidly expanding onshore infrastructure to simplify compliance, control data flows, and meet strict DPBI audit requirements.

How does the DPDP Act impact EdTech platforms processing children's data?

The DPDP Act strictly prohibits behavioral tracking of children and requires verifiable parental consent before processing their data. To meet these obligations under the Rules, 2025, EdTech platforms must deploy clear parental token workflows and age-gating mechanisms.

What are the breach notification timelines under the DPDP Rules, 2025?

In the event of a personal data breach, data fiduciaries must execute an intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025.

What is the penalty for failing to comply with children's data obligations?

Non-compliance with the obligations concerning the processing of children's personal data can attract penalties up to 200 crore rupees per instance under the DPDP Act. Failing to maintain clear evidence packs exposes platforms directly to these fines.

When is the final deadline to comply with the DPDP Act?

The final enforcement timeline is rapidly approaching, with exactly 257 days remain until the DPDP hard compliance deadline of 13 May 2027. Data fiduciaries must finalize their consent workflows and breach protocols before this date.