Data sovereignty under DPDPA 2023: what hosting in India actually means
What the Digital Personal Data Protection Act 2023 actually says about data residency, who it applies to, and what hosting on Indian infrastructure gives you that a US/EU host does not.
The Digital Personal Data Protection Act 2023 (DPDPA) is India’s first comprehensive privacy law. It came into force in stages through 2024 + 2025 and applies to any organization that processes the personal data of Indian data principals — basically every customer in India and most SaaS that ships to India.
What DPDPA requires
The Act is principle-based rather than prescriptive, but the practical requirements are:
- Consent-based processing. Personal data can only be processed for a lawful purpose, with informed consent, and only for as long as necessary.
- Data fiduciary obligations. The data fiduciary (the entity determining the purpose + means of processing) must implement reasonable security safeguards and notify the Data Protection Board of any personal-data breach within 72 hours of becoming aware of it.
- Data principal rights. The data subject can ask for access, correction, erasure, and grievance redressal. Responses are due within 30 days.
- Cross-border transfer. The Central Government may restrict transfer of personal data to specific countries or territories. The current restriction list (as of 2026) does not include the EU or the US, but it is subject to amendment.
What hosting on Indian infrastructure gives you
If you serve Indian customers, the simplest path to DPDPA compliance is to host their data in India. We host in Palitana, Gujarat; your data never leaves India under normal operation. We do not replicate customer data to any region outside India.
The legal jurisdiction is the Republic of India: any disputes are heard by Indian courts, and any breach notification is to the Indian Data Protection Board. The Data Protection Board has the power to levy fines of up to Rs 250 crore per instance for non-compliance.
How WebHost24 fits
Our hosting plans are DPDPA-aligned by default. The default data location is the Palitana data center, the breach notification SLA is 72 hours (we use the same window the Act requires), and the data-subject response SLA is 30 days. Our standard DPA, available at /dpa, covers the formal processor-controller relationship.
If you have a specific data-residency requirement (regulated industry, government customer, healthcare records, etc.) the DPO can scope a single-tenant deployment in a dedicated plan. Message us on WhatsApp.