HomeBlogDPDP Act 2023: IT Infrastructure Compliance Guide for Indian Tech Companies
SERVERWALE BLOG

DPDP Act 2023: IT Infrastructure Compliance Guide for Indian Tech Companies

Serverwale Team7 May 20263 min read
DPDP Act 2023: IT Infrastructure Compliance Guide for Indian Tech Companies
#DPDP Act India#data protection India IT#data localization India#DPDP compliance infrastructure#Indian data privacy law#IT compliance India#trends

DPDP Act 2023: What It Means for IT Infrastructure

India's Digital Personal Data Protection (DPDP) Act 2023 is now in active enforcement. For Indian tech companies, compliance is not just a legal question — it has direct implications for how you architect, operate, and document your IT infrastructure. This guide covers the infrastructure-specific requirements.

Key DPDP Act Obligations for IT Teams

1. Data Localisation

The DPDP Act restricts cross-border transfer of personal data to countries not notified as approved by the Indian government. In practice, this means:

  • Personal data of Indian citizens should be processed on India-hosted infrastructure
  • Cloud providers must confirm their India region stores and processes data locally
  • On-premise infrastructure in India provides the clearest compliance path

2. Data Minimisation and Storage Limitation

Personal data should be retained only as long as necessary. IT implications:

  • Implement automated data retention policies in your storage systems
  • Configure database purging jobs for data past its retention period
  • Maintain data inventory mapping — where is each type of personal data stored?

3. Security Safeguards

The Act requires "reasonable security safeguards." Industry interpretation:

  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Access controls with principle of least privilege
  • Multi-factor authentication for admin access
  • Vulnerability assessment and penetration testing (VAPT) — minimum annually
  • Incident response plan with 72-hour breach notification capability

4. Audit Trails and Logging

You must be able to demonstrate who accessed personal data, when, and for what purpose:

  • Application-level logging of all personal data access operations
  • Database query logs for tables containing personal data
  • Log retention: minimum 18 months recommended
  • Centralised SIEM (Security Information and Event Management) for log aggregation

DPDP-Compliant Infrastructure Architecture

For SMBs (under 100 employees)

  • India-hosted VPS or server (Delhi/Mumbai DC)
  • Encrypted database (MySQL with encryption at rest enabled)
  • SSL/TLS on all endpoints
  • Regular automated backups with encryption
  • Access logs to a separate, tamper-evident log store

For Mid-Market (100–1,000 employees)

  • Dedicated servers in Indian colocation or on-premise
  • HashiCorp Vault for secrets management
  • SIEM deployment (Graylog, ELK, or Splunk)
  • Network segmentation of personal data processing systems
  • Data Loss Prevention (DLP) tools on endpoints

Infrastructure Compliance Checklist

  • ✅ All personal data stored on India-hosted servers
  • ✅ Encryption at rest on all storage containing personal data
  • ✅ TLS 1.2+ on all data transmission
  • ✅ Access logs with 18-month retention
  • ✅ Automated data retention/purging policies
  • ✅ Breach response runbook documented and tested
  • ✅ Third-party VAPT report (annual)
  • ✅ Data processing agreements with all infrastructure vendors

Infrastructure Vendors and DPDP Compliance

Ensure your infrastructure vendors can provide Data Processing Agreements (DPAs) under DPDP Act. For physical server procurement, Serverwale supplies certified enterprise hardware delivered to your India-based data center — giving you complete physical control over where your personal data is processed and stored. This is the simplest path to DPDP Act infrastructure compliance.

Serverwale Store
ProStation Systems
Cloud Services