{"id":801,"date":"2026-04-02T06:23:33","date_gmt":"2026-04-02T06:23:33","guid":{"rendered":"https:\/\/cloudfirst.in\/insight\/?p=801"},"modified":"2026-04-06T07:03:15","modified_gmt":"2026-04-06T07:03:15","slug":"dpdp-act-and-cloud-storage-what-indian-enterprises-must-know","status":"publish","type":"post","link":"https:\/\/cloudfirst.in\/insight\/dpdp-act-and-cloud-storage-what-indian-enterprises-must-know\/","title":{"rendered":"DPDP Act and Cloud Storage: What Indian Enterprises Must Know"},"content":{"rendered":"\n<p>For years, Indian enterprises treated cloud storage as an IT infrastructure decision \u2014 a question of cost, performance, and reliability. The <a href=\"https:\/\/cloudfirst.in\/insight\/what-is-the-dpdp-act\/\" data-type=\"post\" data-id=\"798\">Digital Personal Data Protection<\/a> Act 2023 changes that. Cloud storage decisions now have legal dimensions, and getting them wrong carries penalties of up to \u20b9250 crore.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your Cloud Provider Is a Data Processor Under the DPDP Act<\/h2>\n\n\n\n<p>The DPDP Act defines a <strong>Data Processor<\/strong> as any entity that processes personal data on behalf of a Data Fiduciary. When your organisation stores customer records or employee data on AWS S3, Azure Blob Storage, or Google Cloud Storage, your cloud provider is acting as a Data Processor.<\/p>\n\n\n\n<p>This has a specific legal consequence: you need a formal <strong>Data Processing Agreement (DPA)<\/strong> with your cloud provider. All three major cloud providers have standard DPAs available:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>AWS:<\/strong> AWS Data Processing Addendum<\/li>\n\n\n\n<li><strong>Microsoft Azure:<\/strong> Microsoft Products and Services Data Protection Addendum<\/li>\n\n\n\n<li><strong>Google Cloud:<\/strong> Google Cloud Data Processing Addendum<\/li>\n<\/ul>\n\n\n\n<p>The issue for most Indian enterprises is not that these agreements do not exist \u2014 it is that they have never been formally executed and documented. If you cannot produce a signed DPA with your cloud provider, you have a compliance gap that needs to be closed today.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Data Residency: Where Is Your Data Actually Stored?<\/h2>\n\n\n\n<p>One of the most pressing cloud implications of the DPDP Act is data residency. The Act empowers the Government of India to restrict the transfer of certain categories of personal data outside Indian territory. All three major cloud providers have data centre regions in India:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Cloud Provider<\/strong><\/td><td><strong>Indian Regions<\/strong><\/td><\/tr><tr><td>AWS<\/td><td>Mumbai (ap-south-1), Hyderabad (ap-south-2)<\/td><\/tr><tr><td>Microsoft Azure<\/td><td>Central India (Pune), South India (Chennai), West India (Mumbai)<\/td><\/tr><tr><td>Google Cloud<\/td><td>Mumbai (asia-south1), Delhi (asia-south2)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Questions You Need to Answer Right Now<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which cloud regions contain personal data of Indian citizens?<\/li>\n\n\n\n<li>Is any personal data being replicated to regions outside India for backup or DR purposes?<\/li>\n\n\n\n<li>Are any SaaS applications used by your organisation storing Indian personal data outside India?<\/li>\n\n\n\n<li>Do your cloud provider agreements specify where your data is stored and replicated?<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Data Retention and Deletion in Cloud Storage<\/h2>\n\n\n\n<p>The DPDP Act introduces a clear obligation to delete personal data once the purpose for which it was collected has been fulfilled. In cloud storage terms, this means you need automated retention policies configured on all cloud storage resources containing personal data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Platform-Specific Retention Tools<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>AWS S3:<\/strong> S3 Lifecycle Policies that automatically expire and delete objects after a specified number of days<\/li>\n\n\n\n<li><strong>Azure Blob Storage:<\/strong> Lifecycle Management policies that delete blobs after defined retention periods<\/li>\n\n\n\n<li><strong>Google Cloud Storage:<\/strong> Object Lifecycle Management rules for automatic deletion<\/li>\n<\/ul>\n\n\n\n<p>If your cloud storage buckets do not have retention and deletion policies configured, you are not DPDP-compliant for any personal data stored there.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security Obligations for Cloud Storage<\/h2>\n\n\n\n<p>For cloud storage, reasonable security safeguards under the DPDP Act include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Encryption at rest:<\/strong> All cloud storage containing personal data must be encrypted at rest<\/li>\n\n\n\n<li><strong>Encryption in transit:<\/strong> All data transfers must use TLS\/HTTPS<\/li>\n\n\n\n<li><strong>Access controls:<\/strong> Strict IAM policies, bucket policies, and ACLs on all storage containing personal data<\/li>\n\n\n\n<li><strong>Access logging:<\/strong> Enable access logging on all storage resources containing personal data<\/li>\n\n\n\n<li><strong>Backup security:<\/strong> Backup archives must be encrypted, access-controlled, and covered by retention policies<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">SaaS Applications and the DPDP Act<\/h2>\n\n\n\n<p>Most Indian enterprises are also heavy users of SaaS applications \u2014 Salesforce, HubSpot, Workday, Zoom, and hundreds of others. Every SaaS application that processes personal data of Indian citizens makes its vendor a Data Processor under the DPDP Act. You need a DPA with every such vendor and visibility into where each SaaS vendor stores data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Cloud Storage DPDP Audit: What to Do This Quarter<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 1 \u2014 Map your cloud regions.<\/strong> Identify every cloud account and document which regions are active and what data is stored there<\/li>\n\n\n\n<li><strong>Step 2 \u2014 Identify personal data in cloud storage.<\/strong> Use AWS Macie, Microsoft Purview, or Google Cloud DLP to scan for personal data<\/li>\n\n\n\n<li><strong>Step 3 \u2014 Review and execute DPAs.<\/strong> Confirm DPAs are in place with AWS, Microsoft, Google, and every SaaS vendor that processes personal data<\/li>\n\n\n\n<li><strong>Step 4 \u2014 Configure retention policies.<\/strong> Set automated retention and deletion policies on all cloud storage containing personal data<\/li>\n\n\n\n<li><strong>Step 5 \u2014 Audit security controls.<\/strong> Review encryption, access controls, and logging on all cloud storage resources<\/li>\n<\/ul>\n\n\n\n<p><strong>CloudFirst helps Indian enterprises audit cloud infrastructure for DPDP Act compliance. Contact us \u2192 cloudfirst.in\/contact-sales.php<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<p><strong>Q: Does the DPDP Act require all data to be stored in India?<\/strong><\/p>\n\n\n\n<p>Not currently. The Act permits cross-border data transfers except to countries the Government specifically restricts. However, the Government can notify data localisation requirements for specific categories of data at any time.<\/p>\n\n\n\n<p><strong>Q: Is an AWS S3 bucket in the Mumbai region automatically DPDP compliant?<\/strong><\/p>\n\n\n\n<p>Storing data in an Indian region satisfies the data residency aspect of compliance, but it does not make you automatically compliant. You still need a DPA with AWS, appropriate retention policies, encryption, access controls, and breach notification procedures.<\/p>\n\n\n\n<p><strong>Q: How does the DPDP Act interact with RBI data localisation requirements?<\/strong><\/p>\n\n\n\n<p>RBI has its own data localisation requirements for payment data \u2014 all payment system data must be stored only in India. The DPDP Act operates alongside these sector-specific requirements; both apply.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For years, Indian enterprises treated cloud storage as an IT infrastructure decision \u2014 a question of cost, performance, and reliability. The Digital Personal Data Protection Act 2023 changes that. Cloud&hellip;<\/p>\n","protected":false},"author":1,"featured_media":802,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud"],"_links":{"self":[{"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/posts\/801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/comments?post=801"}],"version-history":[{"count":2,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/posts\/801\/revisions"}],"predecessor-version":[{"id":804,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/posts\/801\/revisions\/804"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/media\/802"}],"wp:attachment":[{"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/media?parent=801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/categories?post=801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudfirst.in\/insight\/wp-json\/wp\/v2\/tags?post=801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}