DPDP Act compliance checklist for choosing a GPU cloud provider in India

India's Digital Personal Data Protection Act reaches even providers outside India serving Indian users. Here's what actually matters when picking a GPU cloud provider, and what doesn't.

16 July 2026 · compliance

The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to any entity processing digital personal data connected to India — including foreign GPU cloud providers with no Indian office, if they're processing data belonging to people in India. The practical question for most AI/ML teams isn't 'is this provider DPDP compliant' in the abstract — it's a shorter list of concrete things worth asking before you commit.

Timeline: this is a live compliance window, not a finished law

The DPDP Act was passed in August 2023, but the operational Digital Personal Data Protection Rules, 2025 were only notified on 13 November 2025. Implementation is phased: the Data Protection Board became operational immediately, the Consent Manager framework activates in November 2026, and the substantive compliance obligations — notice requirements, security safeguards, breach reporting — become fully enforceable on 13 May 2027. If a provider claims full DPDP certification today, ask what that specifically means, since most substantive obligations aren't yet in force.

No blanket data-localization requirement — but sector rules can override that

Unlike some data protection regimes, the DPDP Act itself doesn't require Indian personal data to stay physically in India. It takes a permissive, 'negative list' approach: data can be transferred anywhere unless the central government specifically restricts that destination. This means a GPU provider hosting outside India isn't automatically non-compliant under DPDP alone. However, sector regulators layer on their own rules — the RBI, for example, mandates that payment data be stored exclusively in India regardless of what DPDP says. If your workload touches payment data, healthcare records, or other regulated categories, check the sector-specific rule, not just DPDP.

What actually matters when evaluating a provider

Where MeitY empanelment fits in — and where it doesn't

MeitY empanelment (via an STQC audit under the MeghRaj/GI Cloud initiative) is primarily a public-sector procurement signal — it's what lets a cloud provider sell into government tenders without each buyer re-running foundational security checks. Private-sector buyers sometimes treat it as a useful third-party validation of baseline security practices, but it is not itself a DPDP certification, and empanelment covers a specific catalogue of services the provider submitted for audit — not necessarily the exact GPU offering you're renting. If a provider advertises MeitY empanelment, it's a reasonable positive signal, but confirm it actually covers the service you're buying.

The honest summary

Most GPU cloud providers — Indian or global — are not yet operating under the DPDP Act's full substantive obligations, because those obligations aren't fully in force until May 2027. That means today's real due diligence is less about certificates and more about specific, concrete questions: where's the data, who can see it, how fast do you find out if something goes wrong, and does your contract with the provider actually support your own DPDP obligations as the data fiduciary.

This is general information based on the DPDP Act, 2023 and the DPDP Rules, 2025 as understood as of mid-2026, not legal advice. Confirm your specific obligations with counsel, particularly if you handle sensitive categories like health, financial, or children's data.