Data Fiduciary vs Data Processor: who is accountable
The DPDPA assigns primary accountability to the Data Fiduciary—the entity that determines the purpose and means of processing (Section 2(i)). When an Indian company stores customer data on AWS Mumbai or Azure Central India, that company is the Data Fiduciary. AWS or Azure, processing data on that company’s instructions, is the Data Processor (Section 2(k)).
Section 8(2) provides that a Data Fiduciary “may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.” The Data Processor does not acquire independent obligations toward the Data Principal—it acts on the Fiduciary’s instructions.
Cross-border transfers to cloud regions outside India
Section 16 adopts a negative-list (blacklist) approach. Personal data may be transferred to any country unless the Central Government, by notification, restricts transfers to a specific country. No such notification has been issued as of October 2026, so transfers to cloud regions in Singapore, Ireland, the US or any other jurisdiction remain permissible under the DPDPA.
Section 16(2) preserves stricter obligations in other sectoral laws. The RBI’s 2018 circular on payment system data requires that all payment-related data be stored in India—this survives the DPDPA. A fintech company using AWS US-East for payment records must still comply with the RBI circular, regardless of the DPDPA’s general permissiveness.
- Section 16(1): transfers permitted to all countries except those restricted by Central Government notification
- No country has been restricted as of October 2026
- Section 16(2): sector-specific data-localisation rules (e.g. RBI 2018 circular) continue to apply
- Cloud customers must verify that their sector does not have a stricter localisation requirement
Security safeguards for cloud-hosted personal data
Section 8(5) requires the Data Fiduciary to protect personal data by taking reasonable security safeguards to prevent a personal data breach. The cloud provider’s infrastructure security (physical access controls, network segmentation, encryption of data at rest) is one layer; the Data Fiduciary’s application-layer controls (IAM policies, encryption key management, access logging) are another.
Rule 6 requires technical and organisational measures appropriate to the nature and volume of personal data processed. For cloud deployments, this means the Data Fiduciary must configure encryption settings, access controls and audit logging—the default cloud configuration is rarely sufficient for DPDPA compliance.
| Layer | Cloud provider responsibility | Customer (Data Fiduciary) responsibility |
|---|---|---|
| Physical infrastructure | Data-centre security, power, cooling | Choice of region (localisation compliance) |
| Network | DDoS protection, backbone encryption | VPC configuration, security groups, firewall rules |
| Storage encryption | Server-side encryption options | Key management, enabling encryption, key rotation |
| Access control | IAM service availability | User policies, MFA, least-privilege configuration |
| Breach notification | Notify customer per contract SLA | Notify Board without delay + 72h report (S.8(6), Rule 7) |
Contractual requirements: the Data Processing Agreement
Section 8(2) requires a valid contract between the Data Fiduciary and the Data Processor. In cloud terms, this is the Data Processing Agreement (DPA) or Data Processing Addendum that sits alongside the cloud service agreement.
AWS, Azure and GCP each offer GDPR-aligned DPAs. Indian organisations should verify that the DPA covers DPDPA-specific obligations: processing only on the Fiduciary’s instructions, assisting with breach notification within the 72-hour timeline (Rule 7), and deletion of data upon purpose completion (Section 8(7)).
- The DPA must reflect Section 8(2)—processing only on the Data Fiduciary’s instructions
- Breach-notification cooperation must align with Rule 7’s 72-hour detailed-report timeline
- Data-deletion obligations under Section 8(7) must be contractually enforceable
- Sub-processor chains (cloud provider using its own sub-processors) must be disclosed and governed
How AMLEGALS advises on cloud data privacy
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises organisations on structuring cloud Data Processing Agreements, mapping cross-border transfer obligations under Section 16 (including sector-specific localisation rules), and designing shared-responsibility security frameworks that meet the Section 8(5) standard.

