Does DPDP require you to store data in India?

Does DPDP require you to store data in India?
Data Localisation

Does DPDP require you to store data in India?

Unlike earlier drafts of the law, the DPDP Act 2023 does not mandate blanket data localisation. But it does restrict where personal data can go — and for SDFs, the rules are stricter.

Quick Answer: The DPDP Act 2023 does not require all personal data to be stored in India. It allows cross-border transfer of personal data to countries notified by the central government as permissible destinations. The government has not yet published this allowlist, which means companies must currently treat all cross-border transfers carefully and be ready to restrict transfers when the list is issued. Significant Data Fiduciaries (SDFs) may face stricter localisation requirements, including a possible obligation to store certain categories of data only in India. Until the government's notifications are published, build your data architecture to be adaptable.

What does the DPDP Act say about transferring personal data outside India?

Section 16 of the DPDP Act allows Data Fiduciaries to transfer personal data outside India, but only to countries or territories that the central government notifies as permissible. The government can restrict transfers to specific countries on grounds of sovereignty, security, bilateral relations, or risk to data principals. This is a whitelist model: transfers are allowed to approved countries, not forbidden everywhere except India.

Which countries can Indian companies send personal data to under DPDP?

As of mid-2026, the government has not yet published the list of permissible countries for cross-border data transfers. This creates genuine uncertainty. Practically, most companies continue to use global cloud infrastructure — AWS, Azure, GCP — in regions outside India, and there is no enforcement action on cross-border transfers in the interim period. But when the allowlist is published, any transfers to unlisted countries will need to be brought within India or restructured.

Do Significant Data Fiduciaries face stricter data localisation rules?

For Significant Data Fiduciaries, the Rules may require that certain categories of personal data — particularly sensitive data or data the government classifies as critical — be stored only in India or only transferred to a very narrow set of approved countries. The specific categories and requirements will come in subordinate legislation. SDFs should treat localisation as a live risk and design their data architecture to support India-resident storage for at least sensitive data categories.

How should companies design cloud infrastructure for DPDP data transfer compliance?

Even if your data is currently stored on global cloud infrastructure, you can reduce localisation risk by: (a) knowing exactly where each category of personal data lives today; (b) verifying that your cloud provider has India-region infrastructure and that you can migrate; (c) choosing cloud services that offer regional data residency guarantees; and (d) building data residency controls into your data pipeline so you can enforce localisation by data type when the government's rules require it. The cost of redesigning data architecture under a compliance deadline is far higher than building flexibility in now.

How does DPDP data localisation affect Indian SaaS companies with global customers?

If you are an Indian SaaS company with customers outside India who send you personal data, cross-border transfer obligations run both ways — your customer in Singapore or the US may have their own data residency or transfer rules, and the DPDP Act governs what you do with data about Indian data principals. Map data flows by geography and by data principal nationality, not just by where your servers sit.

Frequently asked questions

Can I currently transfer personal data to AWS servers in the US?

There is no active enforcement prohibition on transfers to the US or other major jurisdictions while the government's allowlist is pending. However, you should be ready to restructure your cloud infrastructure if the US is not on the allowlist when it is published, or if you process data for an SDF category that requires India-resident storage. Build architecture flexibility now.

What happens if the country I transfer to is not on the allowlist?

Once the allowlist is published, transfers to unlisted countries would be unlawful under Section 16 of the Act. You would need to either migrate the data to an approved country, or to India. The timeline for compliance after the allowlist is published has not been specified — monitor government notifications and build migration capacity in advance.

Does data localisation apply to backup and disaster recovery copies?

The Act's language refers to the transfer of personal data, which logically includes backup copies sent to foreign storage. Your disaster recovery architecture should account for localisation requirements the same way your primary storage does. Design DR replication to stay within approved jurisdictions from the outset.

Map your cross-border data flows

Niti Bharat's Data Inventory & Mapping service identifies where your personal data lives and flows — and flags localisation risks before the government's allowlist forces your hand.

Assess Cross-border Transfer Risk
Previous Post Next Post

Get Free DPDP Checklist