Regulation · India
Data residency: what choosing a cloud region does and does not settle
Residency commitments are increasingly common in contracts and are frequently implemented as a region setting and considered done. Two things undo that: the routes by which data leaves anyway, and a legal position that surprises people in both directions.
Facts checked — 2026-09-11
Does choosing a cloud region guarantee residency?
Backups and disaster recovery replicas, which often default elsewhere. Logs and telemetry, which frequently leave the region through monitoring tooling. Support access, where an engineer in another country can read production. Sub-processors — the email, analytics and error-tracking services your application calls. Each is a route by which data leaves the region you promised it would stay in, and each is a question a serious customer audit will ask.
The legal position is worth separating from the contractual one, because they point in opposite directions. Under the GDPR, transfers out of the EEA are prohibited unless an adequacy decision or a safeguard such as Standard Contractual Clauses applies — a permission model. Under the DPDP Act, a data fiduciary may transfer personal data outside India except where the Central Government restricts transfers to a particular country or territory — a restriction model, and no such restriction has been notified to date.
So Indian law is currently permissive about data leaving, and the obligations that actually bind you are the ones in your customer contracts — plus, if you are designated a Significant Data Fiduciary, a localisation duty that can attach to specified categories of data. Residency commitments are usually commercial promises rather than statutory ones, which makes them no less enforceable and considerably easier to make carelessly.
The bottom line
Map where data actually goes — backups, logs, support access and sub-processors — before you sign a residency commitment. The clause will bind you whether or not the law requires it.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.