AMLEGALS — Strategic Lawyering
← All Insights
Article

India Data Residency and Cloud Architecture: What the Negative List Framework Means for Your Infrastructure

Anandaday MisshraJuly 2026
India Data Residency and Cloud Architecture: What the Negative List Framework Means for Your Infrastructure

The Negative List Framework

Unlike the GDPR's adequacy framework (where transfers are prohibited unless the destination country is deemed adequate), the DPDPA uses a negative list approach under Section 16. All cross-border transfers are permitted UNLESS the Central Government specifically restricts transfer to a particular jurisdiction. This is architecturally simpler but operationally deceptive — because the restriction can come at any time via notification.

What Section 16 Actually Says

Section 16(1) empowers the Central Government to restrict transfer of personal data to any country or territory outside India, by notification. Until such notification is issued, transfer to any jurisdiction is permitted. Section 16(2) provides that this power shall be exercised having regard to factors including: whether the foreign country provides adequate data protection, strategic and security interests of India, and India's relationship with that country.

Cloud Architecture Implications

For global companies using cloud infrastructure, the negative list framework creates a mapping obligation. Every data routing path — including CDN edge nodes, disaster recovery sites, AI processing clusters, analytics platforms, and backup storage — must be mapped against the current restricted jurisdiction list. The challenge is that cloud-native architectures route data dynamically. A CDN request may be served from Singapore one moment and from a restricted jurisdiction the next, depending on traffic patterns.

CDN and Edge Computing Risks

Content Delivery Networks cache data at edge locations worldwide. If personal data is included in cached content (personalised pages, user-specific API responses), that data is physically present at every edge location that serves the content. If any CDN edge location is in a restricted jurisdiction, the caching constitutes a cross-border transfer in contravention of Section 16.

Disaster Recovery and Business Continuity

Most enterprise disaster recovery architectures replicate data across geographically dispersed regions for resilience. If a DR site is in a restricted jurisdiction, the replication constitutes a transfer. Companies must ensure DR architecture either excludes restricted jurisdictions or implements data segregation that keeps Indian personal data within permitted regions.

AI and ML Training Data

AI systems trained on Indian personal data may process that data on GPU clusters located in jurisdictions that offer optimal compute pricing — which may include restricted jurisdictions. The DPDPA does not distinguish between processing for inference and processing for training. Both constitute cross-border transfer if the processing occurs outside India in a restricted jurisdiction.

Practical Compliance Steps

Step 1: Map every system that processes Indian personal data and identify every jurisdiction where that data physically resides or transits. Step 2: Monitor the Central Government's restricted jurisdiction notifications (these will be published in the Official Gazette). Step 3: Implement geographic routing controls in your cloud infrastructure to ensure Indian personal data does not route through restricted jurisdictions. Step 4: Review all vendor and sub-processor agreements for data routing commitments. Step 5: Implement technical controls (geo-fencing, region-locked storage, CDN configuration) that prevent data from reaching restricted jurisdictions even under failover scenarios.

Need guidance on this topic?

We advise organisations across India on DPDPA compliance, AI governance and cross border data transfers.

Get in Touch →