Last reviewed: 5 August 2026.
This pillar is the procurement overview for Week 2. For workload-specific implementation, continue with the Tally data-residency guide and the CA-firm hosting checklist.
The practical position: The business deciding why and how personal data is used will usually remain the Data Fiduciary. A hosting company may act as its Data Processor for application data, while also acting as a Data Fiduciary for its own billing, support, abuse, identity-verification and customer-account records. The contract and architecture must address both roles.
Why Indian businesses should ask these questions in 2026
The Government of India notified the Digital Personal Data Protection Rules, 2025 in November 2025. The Government’s published overview describes an eighteen-month phased compliance period, giving organisations time to adjust systems and operating practices. That preparation window should not be treated as permission to wait. Infrastructure decisions made now can either simplify compliance or create a costly migration later.
The framework expects Data Fiduciaries to maintain reasonable security safeguards, manage processor relationships, support data-principal rights, preserve accountability and respond to personal-data breaches. The final responsibility cannot simply be outsourced to a VPS or cloud provider. A provider can supply controls and evidence; the customer must choose, configure and govern them correctly.
“DPDP-ready hosting” is not a government certification
There is no universal hosting badge that transfers a customer’s obligations to a provider. Treat “DPDP-ready,” “compliant cloud” and “India data centre” as starting claims that require technical and contractual definition. A credible provider should be able to answer where data is stored, who can access it, what is logged, how backups work, how incidents are escalated and what happens when the service ends.
The most useful due-diligence question is not “Are you DPDP compliant?” It is:
Which documented controls, locations, processes and contract terms will support our obligations for this exact workload?
1. Which legal entity is providing the service?
Confirm the legal name on the quotation, invoice, service agreement, privacy terms and data-processing clauses. A brand, billing portal, network operator and facility partner may be different organisations. That layered model is normal, but responsibility must be traceable.
- Who signs the service agreement?
- Who invoices and collects payment?
- Who processes customer-account and support data?
- Who operates the IP network and handles abuse reports?
- Which subprocessors or facility partners may access systems or records?
StreamData’s infrastructure stack should be read layer by layer. The background is documented in Who Owns the Network Behind StreamData Networks? and the broader verification method appears in How to Verify a Hosting Provider’s Infrastructure Claims.
2. What data role will the provider perform?
For data stored inside a customer’s application, the host will commonly process data on the customer’s instructions. For its own customer records, fraud controls, support tickets, service telemetry, legal requests and security operations, the provider may determine its own purposes and means.
Ask the provider to distinguish:
| Data category | Likely role to clarify | Evidence to request |
|---|---|---|
| Application database and uploaded files | Processor on the customer’s instructions | Processing terms, access model, location, encryption and deletion procedure |
| Billing and account contacts | Provider’s own fiduciary activity | Privacy notice, retention period and rights channel |
| Support tickets and remote sessions | Role depends on content and purpose | Access approval, recording policy, staff controls and retention |
| Security, network and authentication logs | Mixed operational and legal purposes | Log fields, storage location, retention, access and disclosure process |
| Backups and disaster-recovery copies | Processor function for hosted workload data | Frequency, geography, encryption, restore testing and expiry |
3. Where will every copy of the data exist?
“Hosted in India” should identify more than the primary server. Ask for the city or region of the production system, backup target, replicas, snapshots, object storage, monitoring platform and disaster-recovery environment. Also ask whether administrative access, ticketing, analytics or security tooling transfers personal data or metadata outside India.
The DPDP Act does not impose a blanket rule that every category of personal data must remain in India. Section 16 allows the Central Government to restrict transfers to notified countries or territories, and other Indian laws may impose stricter requirements for particular sectors or data classes. Location therefore remains a procurement and risk decision even where a universal localisation requirement does not apply.
4. What security safeguards are included—and what must the customer configure?
The DPDP Rules describe a control set that includes protection techniques such as encryption, masking or tokenisation, access controls, monitoring and logs, backup and continuity measures, processor-contract provisions and appropriate technical and organisational measures. A host should map its service to those control areas without implying that infrastructure alone completes the customer’s compliance programme.
| Control area | Questions for the provider | Customer-side decision |
|---|---|---|
| Encryption | Is storage encrypted? Who controls keys? Is backup encrypted? Is traffic protected in transit? | Enable application/database encryption and define key ownership |
| Access control | Does the service support MFA, role separation, console restrictions and approved remote access? | Apply least privilege and remove dormant users |
| Monitoring | Which platform records privileged, network and security events? Are alerts staffed continuously? | Choose events, recipients and escalation thresholds |
| Resilience | Are backups part of the plan? Are restores tested? What are the stated RPO and RTO? | Set recovery objectives and maintain an independent copy where necessary |
| Vulnerability handling | Who patches the hypervisor, host OS, guest OS, control panel and applications? | Document the shared-responsibility boundary |
5. Can the provider produce usable logs?
Logs must be useful for prevention, detection, investigation and evidence—not merely generated. Ask what events are recorded, whether clocks are synchronised, how integrity is protected, who can search the logs and how quickly they can be exported during an incident.
The CERT-In Directions of 28 April 2022 separately require covered organisations to maintain ICT-system logs securely for a rolling period of 180 days within Indian jurisdiction and to provide them when directed. The Directions also impose a six-hour reporting requirement for specified cyber incidents once noticed or brought to notice. These are operational timelines: a provider that cannot retrieve accurate logs or escalate rapidly can become a bottleneck.
6. How will a personal-data breach be handled?
A provider’s incident process should support two regulatory tracks that can overlap: personal-data breach duties under the DPDP framework and specified cyber-incident reporting under CERT-In. Ask for a written escalation matrix rather than a generic promise to “notify promptly.”
- What event starts the notification clock?
- Who contacts the customer, through which channels and at what severity?
- Will the provider supply affected systems, dates, data categories, indicators, actions and likely impact?
- Can evidence be preserved while containment continues?
- Will the provider support the customer’s notices to affected individuals and the Data Protection Board?
- Who coordinates CERT-In reporting when both parties have relevant duties?
The Government’s DPDP overview says affected individuals must be informed without delay and explains that breach messages should describe what happened, the likely impact, mitigation steps and a contact route. The customer needs those facts from the infrastructure layer quickly.
7. What do backups actually cover?
A snapshot is not automatically a compliant backup, and a backup is not a disaster-recovery plan. Confirm scope, frequency, retention, encryption, immutability, geographic location, restore testing and deletion. Determine whether deleted personal data remains in backups, how long it remains and how it is prevented from returning to production except for a controlled restore.
Also determine whether the provider’s published backup policy makes the customer responsible for independent copies. If a managed backup is purchased, list it as a separate deliverable with restore objectives and test evidence.
8. Can data-principal requests be executed across the infrastructure?
Rights such as access, correction and erasure are application-level processes, but infrastructure can affect whether they are completed accurately. The business should know where personal data is indexed, cached, replicated, logged and backed up. Ask whether the provider can assist with exports, deletion of volumes and snapshots, secure media handling and termination certificates.
Do not promise instant deletion from every immutable backup if the architecture cannot deliver it. Instead, document backup expiry, access restrictions and the rule that restored data must be re-subjected to approved deletion workflows.
9. What happens when the contract ends?
Exit controls are part of privacy engineering. Before purchase, agree on export format, migration support, account closure, snapshot expiry, IP return, credential revocation, log retention and deletion confirmation. Identify any records the provider must retain under law.
CERT-In’s Directions require data centres, VPS providers, cloud providers and certain other services to maintain specified validated customer information for five years or longer where law requires, even after cancellation or withdrawal. That obligation is different from retaining the customer’s application database.
10. Which evidence will the provider share?
Ask for evidence proportionate to the workload:
- Current architecture and responsibility matrix
- Named production and backup locations
- Applicable facility and information-security certificates with holder, scope and validity
- Relevant policy extracts for access, incident response, backup and deletion
- Subprocessor or partner list
- SLA, maintenance and service-credit terms
- Penetration-test or assurance summary where appropriate
- Sample incident and log-export workflow
A certificate held by a facility partner should be described as facility assurance, not as a certificate issued to the hosting brand. The ownership terminology behind these layers is explained in What “Owned Datacenter” Actually Means When You Buy Hosting in India.
A 12-question procurement checklist
- Which legal entity contracts and processes each category of data?
- Is the provider a processor, a fiduciary, or both for different records?
- Where are production, backup, logs, monitoring and disaster-recovery copies located?
- Which staff, affiliates and partners can access customer systems or data?
- Which encryption and key-management options are included?
- Which logs are retained, for how long, and within which jurisdiction?
- Can the provider support six-hour CERT-In escalation where applicable?
- How quickly will the customer receive breach facts and evidence?
- What backup, RPO, RTO and restore-testing commitments are written into scope?
- How are data exports, erasure, snapshot expiry and contract termination handled?
- Which controls are provider-managed and which remain customer-managed?
- Which claims are contractual, and which are only website descriptions?
What StreamData can—and cannot—do for compliance
StreamData can provide an infrastructure option, technical scope, support path and access to the broader Advika network and facility ecosystem. It can help a customer select server location, isolation, storage, network protection and operational support. It cannot decide the customer’s lawful purpose, design consent, classify all personal data, write the customer’s privacy notice or guarantee compliance for an application it does not control.
The strongest procurement outcome is a shared-responsibility document attached to the order. It should name the exact service, location, legal entity, network, security scope, backup model, support level and incident process.
Frequently asked questions
Does hosting personal data in India automatically satisfy the DPDP Act?
No. Location can support risk and sector requirements, but compliance also depends on lawful processing, notice, consent or legitimate use, security, rights handling, retention, contracts and incident response.
Is a hosting provider always only a Data Processor?
No. It may be a processor for customer-hosted data and a Data Fiduciary for its own account, billing, support, fraud, abuse and operational records.
Does the DPDP Act require all personal data to stay in India?
No blanket localisation rule applies to every category. The Government may restrict transfers to notified countries or territories, and other laws can impose stricter sector-specific requirements.
What is the most important clause in the hosting contract?
There is no single clause. At minimum, define roles, instructions, safeguards, access, subprocessors, locations, breach escalation, backup, audit evidence, return or deletion and exit support.
Should a business wait until the phased deadline?
No. Data mapping, contract changes, logging, backup design, incident procedures and migration can take months. 2026 should be used to test and document the operating model.
Bottom line
DPDP readiness is not a product label. It is the ability to show how personal data moves through an architecture, who is responsible at each point, which controls protect it, which evidence exists and how the organisation responds when something changes or goes wrong. Indian businesses should buy hosting only after those answers are written into the technical and commercial scope.
This article is an infrastructure and procurement guide, not legal advice. Sector-specific and contractual requirements should be reviewed with qualified legal and security professionals.