How the DPDP Act Is Reshaping India’s Data Centre and Cloud Compliance Landscape

In today’s data-driven economy, information is no longer incidental to business operations; it is indeed a strategic asset central to innovation, trust, and competitive advantage. As enterprises accelerate adoption of cloud computing, Artificial Intelligence, and hyperscale infrastructure, regulatory compliance is no longer a downstream legal check; it is increasingly an architectural design consideration.

Against this backdrop, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) represents a structural shift in India’s data governance regime. It requires organisations to reassess not only how personal data is processed, but how underlying infrastructure is designed, controlled, and audited.

For infrastructure providers such as Larsen & Toubro–Vyoma, the DPDP Act is therefore not merely a compliance obligation; it is a catalyst for building privacy-centric, sovereign, and future-ready cloud ecosystems.

Understanding the DPDP Framework

The DPDP Act establishes India’s first dedicated and comprehensive framework for personal data protection, moving beyond the fragmented regime under the Information Technology Act, 2000. It adopts a principles-based approach anchored in:

  • Consent-driven processing
  • Purpose limitation and data minimisation
  • Accountability of data fiduciaries
  • Statutory rights for data principals

The establishment of the Data Protection Board of India signals a transition toward more structured and active regulatory oversight.

From a global standpoint, the DPDP Act aligns in principle with frameworks such as the GDPR, particularly in its emphasis on accountability, transparency, and breach notification- while retaining operational flexibility suited to India’s digital growth trajectory.

For enterprises operating across jurisdictions, this convergence necessitates harmonised compliance strategies supported by infrastructure capable of meeting both domestic and international standards.

Implications for Data Centres and Cloud Providers

Data centres and cloud platforms form the backbone of digital service delivery and act as custodians of large volumes of sensitive and personal data. The DPDP Act materially alters the compliance expectations applicable to this layer.

Compliance can no longer be policy-driven alone, it must be embedded into infrastructure design.

Key implications include:

  • Infrastructure-level accountability for storage, processing, and security controls
  • Increased relevance of sovereign cloud architectures to address cross-border regulatory risk
  • Heightened emphasis on auditability and traceability, particularly in relation to data flows and access

For providers such as L&T–Vyoma, this translates into a shift toward “compliance-by-design”, where regulatory safeguards are integrated across each layer of service delivery.

Core Compliance Imperatives

  1. Consent and Data Governance
    The DPDP Act mandates valid, informed, and auditable consent for processing. This necessitates systems capable of capturing granular permissions, maintaining audit trails, and enabling dynamic withdrawal, requiring integration across application and infrastructure layers.
  2. Data Minimisation and Lifecycle Control
    The requirement to process only necessary data has direct architectural implications. Infrastructure must support classification, segregation, automated retention, and enforceable deletion policies at scale.
  3. Security Safeguards and Breach Response
    The Act elevates expectations around data security and incident reporting. This makes real-time monitoring, identity and access management, and integrated incident response frameworks essential, particularly in distributed cloud environments.

Enabling DPDP-Ready Infrastructure

L&T–Vyoma’s approach reflects an integrated view of performance, compliance, and sovereignty.

The launch of Sovereign Cloud Platform (SCP) by L&T- Vyoma depicts a strategic response of to India’s evolving regulatory landscape.

Key features include:

  • Data localisation within Indian jurisdiction
  • Air-gapped environments for critical workloads
  • Encryption and audit mechanisms aligned with global standards
  • Fine-grained access control frameworks

This enables organisations to mitigate cross-border regulatory exposure while maintaining operational control.

Integrated Managed Services Ecosystem

  • Continuous threat monitoring and detection
  • Managed incident response
  • Backup-as-a-Service with encrypted storage
  • Compliance assessments and infrastructure audits

Such capabilities support a transition from reactive compliance to proactive governance.

Compliance as a Strategic Differentiator

Regulatory compliance is often viewed as a cost centre; however, in the current environment, it is emerging as a differentiator.

Organisations that demonstrate:

  • Robust data protection practices
  • Transparent governance
  • Sovereign data control

are better positioned to build trust with regulators, customers, and partners—particularly in regulated sectors.

Infrastructure providers that enable this trust at scale become integral to enterprise resilience and growth.

The Unresolved Layer: Cloud-Specific Ambiguities

Notwithstanding its structured framework, the DPDP Act leaves certain critical aspects open to interpretation—particularly in cloud environments. These include the allocation of liability between data fiduciaries and infrastructure providers, the treatment of metadata and system logs, the permissibility of cross-border access in distributed architectures, and the extent of responsibility in multi-tenant and shared responsibility models.

The manner in which these issues are clarified through regulatory guidance and enforcement practice will be decisive in shaping contractual structures, infrastructure design choices, and compliance strategies. In this interim phase, cloud providers must adopt forward-looking and defensible positions that align technical capabilities with evolving regulatory expectations.

 

Priya Patwa

Priya Patwa

Head - Legal