The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to any entity processing digital personal data connected to India — including foreign GPU cloud providers with no Indian office, if they're processing data belonging to people in India. The practical question for most AI/ML teams isn't 'is this provider DPDP compliant' in the abstract — it's a shorter list of concrete things worth asking before you commit.
Timeline: this is a live compliance window, not a finished law
The DPDP Act was passed in August 2023, but the operational Digital Personal Data Protection Rules, 2025 were only notified on 13 November 2025. Implementation is phased: the Data Protection Board became operational immediately, the Consent Manager framework activates in November 2026, and the substantive compliance obligations — notice requirements, security safeguards, breach reporting — become fully enforceable on 13 May 2027. If a provider claims full DPDP certification today, ask what that specifically means, since most substantive obligations aren't yet in force.
No blanket data-localization requirement — but sector rules can override that
Unlike some data protection regimes, the DPDP Act itself doesn't require Indian personal data to stay physically in India. It takes a permissive, 'negative list' approach: data can be transferred anywhere unless the central government specifically restricts that destination. This means a GPU provider hosting outside India isn't automatically non-compliant under DPDP alone. However, sector regulators layer on their own rules — the RBI, for example, mandates that payment data be stored exclusively in India regardless of what DPDP says. If your workload touches payment data, healthcare records, or other regulated categories, check the sector-specific rule, not just DPDP.
What actually matters when evaluating a provider
- Where is training/inference data actually processed and stored? Get a specific answer (city, not just 'cloud'), even though DPDP itself doesn't mandate India-only storage for most personal data.
- Does the provider have a way to handle grievances and rights requests? The DPDP Rules require data fiduciaries to provide clear privacy notices and respond to correction/erasure requests. If you're the data fiduciary (you collected the data, the GPU provider just processes it for you), this obligation is largely yours, not theirs — but your provider needs to support you doing it (e.g., letting you actually delete data on request).
- Do they support the required breach notification timeline? Data fiduciaries must report breaches to the Data Protection Board and affected individuals — check whether your processing agreement with the provider gives you visibility into incidents fast enough to meet that obligation.
- Retention and logging. The DPDP Rules require certain processing logs to be retained for at least one year. Confirm your provider's default log retention doesn't fall short of that if you're relying on their infrastructure for this.
Where MeitY empanelment fits in — and where it doesn't
MeitY empanelment (via an STQC audit under the MeghRaj/GI Cloud initiative) is primarily a public-sector procurement signal — it's what lets a cloud provider sell into government tenders without each buyer re-running foundational security checks. Private-sector buyers sometimes treat it as a useful third-party validation of baseline security practices, but it is not itself a DPDP certification, and empanelment covers a specific catalogue of services the provider submitted for audit — not necessarily the exact GPU offering you're renting. If a provider advertises MeitY empanelment, it's a reasonable positive signal, but confirm it actually covers the service you're buying.
The honest summary
Most GPU cloud providers — Indian or global — are not yet operating under the DPDP Act's full substantive obligations, because those obligations aren't fully in force until May 2027. That means today's real due diligence is less about certificates and more about specific, concrete questions: where's the data, who can see it, how fast do you find out if something goes wrong, and does your contract with the provider actually support your own DPDP obligations as the data fiduciary.
This is general information based on the DPDP Act, 2023 and the DPDP Rules, 2025 as understood as of mid-2026, not legal advice. Confirm your specific obligations with counsel, particularly if you handle sensitive categories like health, financial, or children's data.