What the DPDP Act 2023 means for your business's data storage
13 June 2026
If your business stores customers' names, phone numbers, KYC documents, health records, or student information, India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you. This is a plain-language overview of what it means for where and how you keep that data.
This article is general information, not legal advice. For your specific obligations, talk to a qualified professional — and we're happy to advise on the technical side of getting compliant.
The DPDP Act in one paragraph
The DPDP Act governs how organisations (the Act calls them "Data Fiduciaries") collect, store, and use the personal data of individuals in India. In short: you must collect only what you need, use it only for the purpose you stated, keep it secure, and be able to delete it when it's no longer needed. The DPDP Rules, 2025 add the operational detail — security safeguards, breach reporting, and consent mechanics. Together they move India much closer to GDPR-style expectations.
Which businesses are affected?
Most of them. There's no "we're too small to matter" exemption based on company size. If you handle the personal data of people in India — patients, students, clients, employees — you are in scope. That includes:
- Clinics and hospitals (patient records)
- Colleges and schools (student and parent information)
- CA firms, fintechs, and lenders (KYC and financial data)
- Any business with a customer database
What counts as "personal data" in practice
Personal data is any information that can identify a person: name, phone, email, address, ID numbers, financial details, health records, biometrics. The sensitive categories — health, financial, and children's data — deserve the most care, because a breach there does the most harm and draws the most scrutiny.
The practical question for most businesses is simple: where does this data physically live, and who can reach it? If the honest answer is "a cloud service abroad, and we're not entirely sure," that's the gap to close.
The timeline — and the cost of ignoring it
The Act is law; the Rules phase in obligations over time, with full compliance expected by May 2027. Non-compliance can attract significant financial penalties under the Act. More immediately, a data breach involving foreign cloud storage you don't control is both a legal and a reputational problem you don't want to discover during an incident.
The point isn't to panic — it's to get ahead of it while it's a planning exercise rather than a fire drill.
How on-premise storage solves the problem
The cleanest way to answer "where does our data live and who controls it" is to make the answer "on a server in our building, and we do." Self-hosting sensitive data on hardware you own gives you:
- Data locality — the data physically stays in India, on your premises.
- Access control — you decide exactly who and what can reach it; there's no third party with a standing copy.
- Auditability — you can show where data is and how it's protected.
For most organisations this looks like a Nextcloud (files, documents) or MinIO (object storage) deployment on a small on-site server, with encrypted backups and secure remote access over Tailscale — no data leaving your control, no public ports exposed. It's the same approach we used for the 250-student college whose student records now live on a Mac Mini in their own office.
Where to start
A good first step is an honest audit: list what personal data you hold, where it currently lives, and who can access it. From there, an on-premise plan is usually straightforward.
We offer a free DPDP compliance consultation — we'll review your current setup and tell you plainly what's involved.