AMLEGALS — Strategic Lawyering
Cloud & Infrastructure

Cloud data privacy in India: DPDPA obligations for AWS, Azure and GCP

Indian organisations that process personal data on AWS, Microsoft Azure or Google Cloud Platform face a layered compliance architecture under the DPDPA. The cloud provider is typically a Data Processor under Section 8(2); the organisation remains the Data Fiduciary with primary accountability. Cross-border data flows to cloud regions outside India engage Section 16’s transfer framework. This guide maps the obligations across both roles.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

Abstract interconnected cloud-server lattice with flowing data nodes on navy and gold background
Short answer

Under the DPDPA, the organisation using cloud infrastructure is the Data Fiduciary (Section 2(i)); the cloud provider is generally a Data Processor (Section 2(k)—“any person who processes personal data on behalf of a Data Fiduciary”). The Data Fiduciary retains accountability for consent (Section 6), notice (Section 5) and security safeguards (Section 8(5)). The Data Processor must process data only on the Data Fiduciary’s instructions (Section 8(2)). Cross-border transfers are governed by Section 16: processing in cloud regions outside India is permitted unless the Central Government restricts transfers to specific countries by notification.

  • Cloud Privacy
  • AWS
  • Azure
  • Google Cloud
  • Data Processor
  • DPDPA
  • Cross-Border Transfers
Cloud provider role
Data Processor (S.2(k))
Customer role
Data Fiduciary (S.2(i))
Transfers
Permitted unless restricted (S.16)
Security
Reasonable safeguards (S.8(5))

Data Fiduciary vs Data Processor: who is accountable

The DPDPA assigns primary accountability to the Data Fiduciary—the entity that determines the purpose and means of processing (Section 2(i)). When an Indian company stores customer data on AWS Mumbai or Azure Central India, that company is the Data Fiduciary. AWS or Azure, processing data on that company’s instructions, is the Data Processor (Section 2(k)).

Section 8(2) provides that a Data Fiduciary “may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.” The Data Processor does not acquire independent obligations toward the Data Principal—it acts on the Fiduciary’s instructions.

Cross-border transfers to cloud regions outside India

Section 16 adopts a negative-list (blacklist) approach. Personal data may be transferred to any country unless the Central Government, by notification, restricts transfers to a specific country. No such notification has been issued as of October 2026, so transfers to cloud regions in Singapore, Ireland, the US or any other jurisdiction remain permissible under the DPDPA.

Section 16(2) preserves stricter obligations in other sectoral laws. The RBI’s 2018 circular on payment system data requires that all payment-related data be stored in India—this survives the DPDPA. A fintech company using AWS US-East for payment records must still comply with the RBI circular, regardless of the DPDPA’s general permissiveness.

  • Section 16(1): transfers permitted to all countries except those restricted by Central Government notification
  • No country has been restricted as of October 2026
  • Section 16(2): sector-specific data-localisation rules (e.g. RBI 2018 circular) continue to apply
  • Cloud customers must verify that their sector does not have a stricter localisation requirement

Security safeguards for cloud-hosted personal data

Section 8(5) requires the Data Fiduciary to protect personal data by taking reasonable security safeguards to prevent a personal data breach. The cloud provider’s infrastructure security (physical access controls, network segmentation, encryption of data at rest) is one layer; the Data Fiduciary’s application-layer controls (IAM policies, encryption key management, access logging) are another.

Rule 6 requires technical and organisational measures appropriate to the nature and volume of personal data processed. For cloud deployments, this means the Data Fiduciary must configure encryption settings, access controls and audit logging—the default cloud configuration is rarely sufficient for DPDPA compliance.

Shared responsibility: cloud provider vs customer under DPDPA
LayerCloud provider responsibilityCustomer (Data Fiduciary) responsibility
Physical infrastructureData-centre security, power, coolingChoice of region (localisation compliance)
NetworkDDoS protection, backbone encryptionVPC configuration, security groups, firewall rules
Storage encryptionServer-side encryption optionsKey management, enabling encryption, key rotation
Access controlIAM service availabilityUser policies, MFA, least-privilege configuration
Breach notificationNotify customer per contract SLANotify Board without delay + 72h report (S.8(6), Rule 7)

Contractual requirements: the Data Processing Agreement

Section 8(2) requires a valid contract between the Data Fiduciary and the Data Processor. In cloud terms, this is the Data Processing Agreement (DPA) or Data Processing Addendum that sits alongside the cloud service agreement.

AWS, Azure and GCP each offer GDPR-aligned DPAs. Indian organisations should verify that the DPA covers DPDPA-specific obligations: processing only on the Fiduciary’s instructions, assisting with breach notification within the 72-hour timeline (Rule 7), and deletion of data upon purpose completion (Section 8(7)).

  • The DPA must reflect Section 8(2)—processing only on the Data Fiduciary’s instructions
  • Breach-notification cooperation must align with Rule 7’s 72-hour detailed-report timeline
  • Data-deletion obligations under Section 8(7) must be contractually enforceable
  • Sub-processor chains (cloud provider using its own sub-processors) must be disclosed and governed

How AMLEGALS advises on cloud data privacy

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises organisations on structuring cloud Data Processing Agreements, mapping cross-border transfer obligations under Section 16 (including sector-specific localisation rules), and designing shared-responsibility security frameworks that meet the Section 8(5) standard.

Bottom line

The DPDPA assigns primary accountability to the customer, not the cloud provider. Cross-border transfers are permitted unless specifically restricted—but sector-specific localisation rules override the general permission.

Key terms
Data Processor
Any person who processes personal data on behalf of a Data Fiduciary (Section 2(k), DPDPA 2023)—in cloud contexts, the cloud service provider.
Negative-list transfer model
Section 16 permits cross-border transfers to all countries except those specifically restricted by Central Government notification—the opposite of a whitelist/adequacy model.
Questions and answers

Cloud Data Privacy: common questions

Is a cloud provider a Data Fiduciary or a Data Processor under the DPDPA?

Generally a Data Processor—it processes personal data on the customer’s instructions under a contract (Section 8(2)). The customer is the Data Fiduciary.

Can I store personal data on AWS US-East under the DPDPA?

Yes, unless the Central Government restricts transfers to the US by notification under Section 16. No such restriction exists as of October 2026. However, sector-specific rules (e.g. RBI’s payment-data localisation) may require Indian storage for certain data categories.

Who notifies the Data Protection Board in case of a breach on cloud infrastructure?

The Data Fiduciary—the customer organisation—must intimate the Board without delay and submit a detailed report within 72 hours (Section 8(6), Rule 7). The cloud provider’s contractual obligation is to notify the customer.

Do I need a DPDPA-specific DPA with my cloud provider?

Section 8(2) requires a valid contract. Most cloud providers offer GDPR-aligned DPAs. Indian organisations should verify that the DPA covers DPDPA-specific requirements—72-hour breach notification, Section 8(7) deletion and processing-only-on-instructions.

Contact

Need guidance on cloud data privacy?

Submit a question about DPDPA compliance for your cloud infrastructure.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Cloud Data Privacy: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Cloud Data Privacy?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Cloud Data Privacy under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Cloud Data Privacy under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Cloud Data Privacy?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Cloud Data Privacy rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Cloud Data Privacy?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Cloud Data Privacy · DPDPA Exposure Assessment