DPDP Act 2023: What It Means for IT Infrastructure
India's Digital Personal Data Protection (DPDP) Act 2023 is now in active enforcement. For Indian tech companies, compliance is not just a legal question — it has direct implications for how you architect, operate, and document your IT infrastructure. This guide covers the infrastructure-specific requirements.
Key DPDP Act Obligations for IT Teams
1. Data Localisation
The DPDP Act restricts cross-border transfer of personal data to countries not notified as approved by the Indian government. In practice, this means:
- Personal data of Indian citizens should be processed on India-hosted infrastructure
- Cloud providers must confirm their India region stores and processes data locally
- On-premise infrastructure in India provides the clearest compliance path
2. Data Minimisation and Storage Limitation
Personal data should be retained only as long as necessary. IT implications:
- Implement automated data retention policies in your storage systems
- Configure database purging jobs for data past its retention period
- Maintain data inventory mapping — where is each type of personal data stored?
3. Security Safeguards
The Act requires "reasonable security safeguards." Industry interpretation:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Access controls with principle of least privilege
- Multi-factor authentication for admin access
- Vulnerability assessment and penetration testing (VAPT) — minimum annually
- Incident response plan with 72-hour breach notification capability
4. Audit Trails and Logging
You must be able to demonstrate who accessed personal data, when, and for what purpose:
- Application-level logging of all personal data access operations
- Database query logs for tables containing personal data
- Log retention: minimum 18 months recommended
- Centralised SIEM (Security Information and Event Management) for log aggregation
DPDP-Compliant Infrastructure Architecture
For SMBs (under 100 employees)
- India-hosted VPS or server (Delhi/Mumbai DC)
- Encrypted database (MySQL with encryption at rest enabled)
- SSL/TLS on all endpoints
- Regular automated backups with encryption
- Access logs to a separate, tamper-evident log store
For Mid-Market (100–1,000 employees)
- Dedicated servers in Indian colocation or on-premise
- HashiCorp Vault for secrets management
- SIEM deployment (Graylog, ELK, or Splunk)
- Network segmentation of personal data processing systems
- Data Loss Prevention (DLP) tools on endpoints
Infrastructure Compliance Checklist
- ✅ All personal data stored on India-hosted servers
- ✅ Encryption at rest on all storage containing personal data
- ✅ TLS 1.2+ on all data transmission
- ✅ Access logs with 18-month retention
- ✅ Automated data retention/purging policies
- ✅ Breach response runbook documented and tested
- ✅ Third-party VAPT report (annual)
- ✅ Data processing agreements with all infrastructure vendors
Infrastructure Vendors and DPDP Compliance
Ensure your infrastructure vendors can provide Data Processing Agreements (DPAs) under DPDP Act. For physical server procurement, Serverwale supplies certified enterprise hardware delivered to your India-based data center — giving you complete physical control over where your personal data is processed and stored. This is the simplest path to DPDP Act infrastructure compliance.
