triplicate

Blog

The DPDP Act and where your backups live

An outline map of India with a shield over it

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) has prompted many businesses to ask a simple-sounding question: are we allowed to keep backups outside India? The short answer is that the Act itself is less restrictive about location than many people assume, but other rules may apply to you, and the details matter.

This post is general information, not legal advice. The Act, its Rules and sector regulations are detailed and still being interpreted. If you are making a compliance decision, speak to a lawyer who knows your sector.

The basics of the Act

The DPDP Act governs the processing of digital personal data, meaning data about an identifiable individual that is in digital form (or was collected offline and then digitised). Some terms worth knowing:

  • Data Principal: the person the data is about.
  • Data Fiduciary: the organisation that decides why and how personal data is processed. If you run a business that collects customer details, this is usually you.
  • Data Processor: an organisation that processes data on behalf of a Data Fiduciary. A backup or cloud storage provider is typically a processor for the business data it stores.

The Act sets out obligations such as processing data for a lawful purpose with notice and consent (or another legitimate use), taking reasonable security safeguards, notifying personal data breaches, and erasing data when it is no longer needed for its purpose, unless the law requires it to be retained. The Rules under the Act were notified in November 2025, with obligations coming into force in phases. Penalties for some failures can be large, up to ₹250 crore for the most serious categories.

The Act generally does not apply to personal data processed by an individual for purely personal or domestic purposes. Your own family photo backups are not what it is aimed at.

What the Act says about transferring data abroad

This is where much of the confusion lies. The DPDP Act does not require personal data to be stored only in India.

Instead, it takes a “negative list” approach: a Data Fiduciary may transfer personal data outside India except to countries or territories that the central government notifies as restricted. Until a country is notified, the Act itself does not block transfers there.

The Act also says that this does not override other Indian laws that impose a higher degree of protection or a stricter restriction on transfer. That leads to the more important part for many businesses.

Sector rules can be stricter

Depending on your industry, other regulations may require data to stay in India regardless of the DPDP Act. Examples to check include:

  • Payments: the Reserve Bank of India’s 2018 directive on storage of payment system data requires such data to be stored only in India, with some limited exceptions for processing abroad.
  • Banking, insurance and securities: RBI, IRDAI and SEBI have issued rules and guidelines on outsourcing, cloud use and data location for regulated entities.
  • Government and public sector work: contracts and empanelment terms often specify Indian data centres.
  • Healthcare and telecom: have their own data handling requirements.

If you fall into any of these, the sector rules usually decide where your backups may live, not the DPDP Act alone.

What this means for backups

Backups are personal data processing too. A copy of your customer database in a backup bucket is still your customers’ personal data. Some practical points:

Know where every copy is

You should be able to answer, for each backup copy: which provider holds it, in which country, and under what contract. “Somewhere in the cloud” is not an answer you want to give a regulator or an enterprise customer.

Choose processors carefully

As a Data Fiduciary, you remain responsible for personal data processed on your behalf. Look for a provider that:

  • states clearly which regions your data is stored in
  • encrypts data, and ideally lets you hold the keys
  • has a process for notifying you of breaches promptly
  • can delete data when you ask, and confirm it

Plan for erasure

The Act expects personal data to be erased when it is no longer needed. Backups make this tricky, since you cannot easily remove one customer from an old encrypted snapshot. A common approach is to set clear retention periods so backups expire on a schedule, and to document that approach. Discuss the specifics with your adviser.

Keep the option of an in-India copy

Even if you are not required to keep data in India today, it is sensible to have at least one copy here. Regulations can change, enterprise customers may ask, and it gives you a recovery point under Indian jurisdiction.

The DPDP Act does not, by itself, ban backups abroad. Sector rules, contracts and future notifications might. Know where every copy lives and why.

A short checklist

  1. List every system that holds personal data, and every place it is backed up.
  2. Note the country and provider for each backup copy.
  3. Check whether any sector regulation applies to you, and what it says about location.
  4. Confirm your backup providers’ breach notification and deletion processes in writing.
  5. Set and document backup retention periods.
  6. Review this list when new Rules or notifications are issued.

Closing note

triplicate is being designed with location in mind: copy 2 stays in a home region you choose (Mumbai for Indian customers, once it launches), and copy 3 sits on another continent with a different provider. Enterprise customers will be able to bring their own encryption keys. See the regions and security pages, or talk to us about specific requirements.

Keep reading