NEWS ANALYSIS4 mins

Proofpoint Expands India Operations: Evaluating Vendor Liability and AI Security Under the DPDP Act

Proofpoint's new AI security centre in Hyderabad highlights the growing need for localized data privacy capabilities. EdTech General Counsels must evaluate how domestic security infrastructure impacts vendor liability, breach reporting, and verifiable parental consent under the DPDP Act.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

According to a report by CIOL, Proofpoint is expanding its operations within India to address data privacy, data sovereignty, and artificial intelligence risks. The cybersecurity provider is launching a new AI security centre in Hyderabad and opening a new office in Delhi. This physical and operational expansion is specifically designed to provide localized enterprise security infrastructure.

Does the DPDP Act apply here?

The Digital Personal Data Protection Act, 2023, under Section 3, applies to the processing of digital personal data within the territory of India, or outside India if connected to offering goods or services to Data Principals in India. Proofpoint's expansion into data privacy and sovereignty solutions directly involves the processing and protection of such data. For EdTech enterprises, this includes student data, parent contact details, and user activity telemetry.

The Act does not apply to corporate intellectual property or fully anonymized datasets. However, any cybersecurity log or AI training data that contains personal identifiers falls strictly under the purview of the Act. Evaluating vendor tools that process this data is a critical step for legal and compliance leaders.

Legal implications under DPDP

Under Section 8 of the DPDP Act, 2023, Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches. Proofpoint's localized AI security capabilities assist organizations in fulfilling this statutory mandate. Furthermore, the DPDP Rules, 2025, notified in November 2025, require that any personal data breach must be intimated to affected Data Principals without delay, accompanied by a detailed report to the Data Protection Board of India within 72 hours.

For EdTech General Counsels, localized data processing solutions can strengthen contract defensibility. While cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries, keeping cybersecurity telemetry onshore aids in managing strict regulatory audits. Additionally, consent is the primary basis for processing, except where Section 7 legitimate uses apply. This means localized security and AI tools must not inadvertently process student data without verifiable parental consent mechanisms in place, as mandated by the Act.

Could this happen to you

As an EdTech Legal Head, evaluating vendor risk is a core liability concern. If your current security vendor experiences a breach or fails to secure parental consent tokens effectively, your organization bears the primary penalty risk of up to 250 crore rupees per breach. The Data Protection Board of India will scrutinize your vendor contracts, limitation of liability clauses, and data processing agreements to determine fault.

If a breach occurs, the Board will demand hard evidence of your reasonable security safeguards and your 72-hour breach response workflows. Proofpoint's move to establish physical infrastructure in Delhi and Hyderabad highlights a growing regulatory expectation for domestic data oversight. Relying on legacy security providers that route EdTech user telemetry offshore without proper indemnities creates severe compliance blind spots and negotiation risks.

What companies should do in the next 30 days

1. Review vendor indemnities. The Legal Head must audit existing cybersecurity agreements for explicit liability allocation in the event of a breach, resulting in an updated contract addendum.

2. Map cybersecurity data flows. The Chief Product Officer and Legal team should identify exactly where security tools process student data, producing a localized data flow map.

3. Assess Rule 10 workflows. The Legal team must ensure that any integrated security or AI tools respect verifiable parental consent states, documenting this in a defensible compliance memo.

4. Test breach reporting. The compliance team must simulate a 72-hour reporting drill with the current security stack, creating an incident readiness report.

What to watch

Exactly 266 days remain until the DPDP hard compliance deadline of 13 May 2027. EdTech General Counsels should monitor the establishment of the Data Protection Board of India under Section 18 of the Act, which will dictate how breach penalties are calculated and enforced. Future phases of the DPDP Rules, 2025, may further define specific technical standards for reasonable security safeguards.

Outside counsel spend will likely shift toward localized audit readiness as these operational rules solidify. To evaluate if your current vendor contracts and consent workflows provide adequate defensibility, check your exposure at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act require all cybersecurity data to be stored in India?

No. Under the DPDP Act, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries on a negative list. However, localized processing aids in rapid compliance and contract defensibility.

How does the DPDP Act treat student data processed by AI security tools?

The DPDP Act requires verifiable parental consent for processing children's data and strictly prohibits behavioral tracking. Security tools must respect Rule 10 workflows and ensure they do not illegally profile minors during threat analysis.

What happens if an EdTech security vendor suffers a data breach?

The Data Fiduciary remains primarily responsible under Section 8. Per the DPDP Rules, 2025, the fiduciary must intimate affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours, facing up to 250 crore rupees in penalties for failures.

Can we rely on legitimate uses for processing cybersecurity telemetry?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Certain network security functions may qualify under specific provisions, but legal teams must carefully document this to survive regulatory scrutiny.

When will the Data Protection Board of India begin auditing fiduciaries?

The Central Government will establish the DPBI under Section 18 of the Act. With exactly 266 days remaining until the 13 May 2027 hard deadline, fiduciaries must prepare their breach reporting and vendor indemnities now.