DPDP Platform Data Residency and Security: A Buyer’s Checklist

Short answer: DPDP platform data residency is about where a compliance platform stores and processes the consent records, rights requests and personal data you give it. The DPDP Act does not force all data to stay in India. However, the Central Government can restrict transfers to notified countries, and sector rules can be stricter. Therefore, before you buy, check hosting location, sub-processors, logs, encryption, incident reporting and exit terms.
A compliance platform becomes one of your Data Processors. It will hold some of your most sensitive evidence, such as who consented to what and when. So the platform itself must pass the same checks you apply to any vendor. This guide gives you a practical DPDP platform data residency and security checklist. It separates what the law requires from what we recommend, so you can ask sharper questions. To see how platforms compare on features, start with our overview of choosing a DPDP compliance platform.
What does DPDP platform data residency mean?
DPDP platform data residency covers three questions. First, in which country are your records stored? Second, where are they processed, including by sub-processors and support teams? Third, where are backups and logs kept?
These questions matter because a compliance platform processes personal data on your behalf. Under Section 8(2) of the DPDP Act, you may use a Data Processor only under a valid contract. In addition, Section 8(5) makes you responsible for reasonable security safeguards, including for processing done on your behalf.
What the law says about data location
The DPDP Act takes a restriction-list approach. Section 16(1) lets the Central Government restrict transfers to countries or territories it notifies. Rule 15 of the DPDP Rules, 2025 adds that transfers outside India must meet any requirements the Government specifies by order.
However, Section 16(2) keeps stricter sector laws in force. For example, the RBI’s payment data storage direction requires payment system data to be stored only in India. If a provider processes it abroad, the provider must delete it there and bring it back within one business day or 24 hours, whichever is earlier.
Separately, the CERT-In directions of 28 April 2022 require organisations to report specified cyber incidents within 6 hours. In addition, they require organisations to keep ICT system logs for a rolling 180 days within Indian jurisdiction. Meanwhile, Rule 6 of the DPDP Rules requires you to keep logs and personal data for at least one year for security purposes.
Legal requirement vs recommendation: the points above are legal requirements that may apply to you. Preferring India-hosted platforms for DPDP evidence is our recommendation, because it simplifies sector rules and incident response.
How DPDP platform data residency works in practice

In practice, data can leave a region in less obvious ways. For example, backups may replicate to another region. Similarly, support engineers may access systems from abroad. Also, AI features may call a model hosted elsewhere. Likewise, email and SMS sub-processors may sit outside India. Therefore, ask about each path, not just the primary server.
A practical example
A payments company evaluates two platforms. At first, both say “hosted in India”. On questioning, the first platform stores backups in Singapore and uses a translation service in the US. The second keeps primary data, backups and AI translation in an Indian region and lists every sub-processor. Because the company handles payment data, it chooses the second. It then records the reasoning in its vendor file.
The DPDP platform data residency and security checklist
First, use these questions with every shortlisted vendor. Ask for documents, not just answers.
- Hosting region: where does the vendor store primary data, backups and disaster recovery copies?
- Sub-processors: who are they, where are they, and how will the vendor tell you about changes?
- AI and translation: where do AI features process your data, and does the vendor use it for model training?
- Encryption and keys: does the vendor encrypt data at rest and in transit, and who controls the keys? Rule 6 lists encryption, masking and virtual tokens as safeguards.
- Access control: who at the vendor can access your data, from where, and does the vendor log that access?
- Logs: does the vendor keep logs for at least one year under Rule 6, and within India where CERT-In rules apply?
- Incident duties: how fast will the vendor tell you about an incident, so you can meet the Rule 7 72-hour report and the 6-hour CERT-In window?
- Certifications: which audits cover the service, and can you see the reports?
- Exit and deletion: can you export all records, and will the vendor confirm deletion in writing, as Section 8(7)(b) expects of processors?
Record the answers in your processor register. Our guide to vendor risk management under DPDP shows how to keep that register current.
Comparing hosting models
| Model | Strength | Watch-out |
|---|---|---|
| Global SaaS, non-India region | Mature features | Sector rules and transfer orders |
| Global SaaS, India region | Local storage option | Support and sub-processors abroad |
| India-built, India-hosted | Simpler residency story | Check maturity and audits |
Pros and cons of prioritising DPDP platform data residency
Pros:
- Fewer questions from sector regulators and auditors.
- Simpler incident response and log access.
- Lower exposure if transfer restrictions are notified later.
Cons:
- First, it may narrow your vendor shortlist.
- Also, India hosting alone does not prove good security.
- Sub-processors can still move data abroad unless checked.
Contract clauses that make DPDP platform data residency enforceable
Answers in a sales call are not commitments. Therefore, write the key points into the contract. Section 8(2) of the DPDP Act already requires a valid contract with every Data Processor, so this adds little extra effort.
- Location commitment: the regions for primary data, backups and disaster recovery.
- Sub-processor notice: advance notice of new sub-processors, with a right to object.
- Incident timeline: a notice window that leaves you time for the 6-hour CERT-In report and the 72-hour Board report.
- Log access: your right to obtain logs for at least one year.
- Exit and deletion: a full export in a usable format, then written confirmation of deletion.
- Audit rights: access to audit reports, and a way to raise follow-up questions.
Moreover, review these clauses at every renewal. Vendors change hosting and sub-processors over time, so DPDP platform data residency is not a one-time check.
Common mistakes
- Checking only the main server. Meanwhile, nobody checks backups, support access or AI calls.
- No sub-processor list. As a result, the vendor adds services without telling you.
- Slow incident clauses. The contract allows days, but your clocks run in hours.
- No exit plan. Consequently, you cannot get your consent evidence back when you switch.
- Assuming compliance transfers. The vendor’s audits do not make you compliant on their own.
How we measure success
These are the indicators we suggest for DPDP platform data residency. We do not publish benchmark numbers for them.
- Location clarity: the share of data paths, including backups and sub-processors, with a documented location.
- Contract coverage: whether the contract covers incident timelines, deletion and sub-processor notice.
- Log access: the time to retrieve a year-old log entry during a test.
- Exit readiness: whether you have tested a full evidence export.
Frequently asked questions
Does the DPDP Act require data to stay in India?
Not as a general rule. Section 16 lets the Government restrict transfers to notified countries. However, sector laws, such as RBI’s payment data rule, can require local storage.
Is a compliance platform a Data Processor?
Usually yes, because it processes personal data on your behalf. Therefore, Section 8(2) requires a valid contract with it.
How long must logs be kept?
Rule 6 of the DPDP Rules requires at least one year. Separately, CERT-In directions require ICT logs for a rolling 180 days within India.
What should the vendor’s incident notice time be?
Short enough for you to meet your own clocks. Those include the 6-hour CERT-In report and the 72-hour report to the Board under Rule 7.
Do AI features change the residency picture?
They can. So ask where AI models run, whether your data leaves the region, and whether the vendor trains on it.
Does ProtectComply answer these questions?
Yes. In fact, we expect buyers to ask us the same checklist. Our security page is the starting point, and our team will answer the rest in writing.
Summary and next step
In summary, DPDP platform data residency is a vendor question as much as a legal one. Check every data path, write incident and deletion duties into the contract, and keep the answers in your processor register. Then retest before renewal.
Read ProtectComply’s security overview, compare the product modules, or send us your checklist for written answers.
Published by Jupinder Singh Bedi, CEO and Co-Founder, ProtectComply. SEO: Yatin Chaudhary. Legal references: Digital Personal Data Protection Act, 2023, Sections 8(2), 8(5), 8(7) and 16; Digital Personal Data Protection Rules, 2025, Rules 6, 7 and 15; RBI directive on storage of payment system data (2018); CERT-In directions under Section 70B of the IT Act, 28 April 2022. This article is general information, not legal advice.