
Every CIO has sat through a board meeting where the numbers looked strong: revenue on track, an AI pilot finally showing returns, a cloud migration ahead of schedule. And yet, underneath that confidence, a harder question has started to surface. If a regulator asked tomorrow where a customer’s personal data resides, who has access to it, which AI systems have processed it, and what those systems did with it, could the organization answer with certainty? That is where DPDP and enterprise AI increasingly intersect. As AI moves from analysing information to acting on it, data protection is no longer only about where information is stored. It is also about who or what can access it, what happens to it, and whether every action can be accounted for.
Two years ago, this question carried little urgency. Today it carries real weight, because of one law that moved from dormant to active almost overnight: the Digital Personal Data Protection Act. India’s Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data. The Act distinguishes between a Data Fiduciary, which determines the purpose and means of processing, and a Data Processor, which processes personal data on behalf of a Data Fiduciary. This distinction is important for CIOs because an organization generally cannot transfer its accountability simply by outsourcing hosting, cloud, analytics, or AI operations to a service provider.
The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025. However, the Rules are being implemented in phases: certain provisions took effect on publication, consent-manager provisions take effect after one year, and most operational obligations take effect 18 months after publication. Organizations should therefore treat the transition period as a readiness window, not as an indication that all compliance obligations are immediately enforceable.
What follows is an attempt to explain, plainly and without the usual legal density, what this shift means for CIOs specifically, for the data center industry underneath them, and for India’s broader ambitions.
Why This is no Longer an IT Issue
DPDP is not another line item on a compliance checklist. It represents a structural change in how personal data is collected, processed, governed, and accounted for and that changes what enterprise leadership is responsible for.
Implementation is phased, with several substantive obligations taking effect over time. But that runway should not be mistaken for permission to wait. Data discovery, consent architecture, governance controls, auditability, and infrastructure decisions take time to redesign. With significant financial penalties attached to non-compliance, data governance has moved beyond the legal function to become a board-level technology and risk consideration.
The Industry Sitting Directly Beneath This Shift
While the obligations above apply broadly, one industry experiences them with particular intensity: data centers. This is not a sector standing adjacent to the DPDP conversation. It is the infrastructure layer underneath nearly every other industry’s compliance obligation.
Every enterprise working through DPDP eventually confronts the same questions: where does its data reside, where does it travel, and under whose jurisdiction does it operate? DPDP does not impose blanket localization of all personal data, but it has made jurisdiction, control, and visibility far more consequential infrastructure considerations. Combined with existing sector-specific requirements, this is strengthening the case for enterprises to evaluate India-hosted infrastructure for sensitive and regulated workloads.
Consider what this means for a health insurer using generative AI to analyze medical documentation, summarize claims, or support underwriting. The business case may be compelling — faster turnaround, lower manual effort, and better customer experience — but the CIO now has another set of questions to answer. Where is the underlying personal data being processed? Does it move outside the enterprise’s controlled environment? Who, or which AI system, can access it? And can those interactions be traced when required?
This is where the infrastructure decision changes character. What may once have been evaluated primarily through cost, capacity, and performance must now also account for jurisdiction, control, security, and auditability. For the CIO, the question is no longer simply where should this workload run? It is how confidently can the organization account for what happens to the data once it gets there?
For Significant Data Fiduciaries, additional requirements around impact assessments, audits, and due diligence over algorithmic systems raise the governance bar further. At the same time, AI workloads are placing new demands on the physical layer through higher compute density, advanced cooling, and increasingly complex hybrid architectures. Data architecture, AI governance, and infrastructure design can therefore no longer be treated as separate decisions.
The challenge for the data center industry is now twofold: scale the physical infrastructure AI requires while strengthening the governance architecture enterprises need to trust it.
When AI Moves from Recommending to Acting, Accountability Changes

If data localization is the visible dimension of this shift, autonomous AI agents represent the less understood one and, in my assessment, one of the least appreciated risks in enterprise IT today.
The starting point is a principle every CIO should hold without exception: autonomous execution does not transfer accountability. As AI moves from recommending actions to increasingly executing them, the organization deploying and authorizing those systems remains responsible for how personal data is accessed, processed, and governed. Model providers and technology partners may enable the capability, but the enterprise still needs the controls to understand what its AI systems are doing.
This becomes particularly important as AI agents begin operating across multiple enterprise applications and data environments. An agent may retrieve customer information from one system, analyze it using another, trigger an action in a third, and do all of this with limited human intervention. The efficiency is compelling, but so is the governance challenge. The more autonomous the system becomes, the more important identity, authorization, access control, logging, and traceability become.
The Four-Question AI Agent Test
Before any AI agent touches personal data, every CIO should be able to answer four questions:
1. Who authorized it?
2. What data can it access?
3. What actions or decisions can it make?
4. Can every action be traced and audited?
If any one of those answers is unclear, the enterprise may have an AI capability, but it does not yet have AI governance.
For Significant Data Fiduciaries, that distinction becomes even more important. The framework introduces additional requirements around Data Protection Impact Assessments, audits, and due diligence over algorithmic software used in processing personal data. For CIOs, the practical implication is clear: logging, access control, traceability, and governance cannot be designed after an AI system enters production. They need to be part of the architecture from the beginning.
As AI becomes more autonomous, governance therefore cannot remain a policy document sitting above the technology stack. It has to become part of the infrastructure through which AI operates.
Why Data Centers are No Longer a Neutral Layer
The accountability described above does not remain confined to the enterprise deploying an AI system. It extends directly to the infrastructure hosting it, which means data centers have moved from background utility to accountable participant in the compliance chain.
Under the Act, an enterprise’s obligations do not lapse because a processor, such as a data center, mishandled data. Enterprise clients, increasingly aware of this, are incorporating stronger audit rights and security warranties directly into colocation contracts. A facility unable to demonstrate its own security discipline is no longer simply a vendor risk. It becomes a liability on another organization’s regulatory filing.
Client conversations have shifted accordingly, from available capacity to demonstrable jurisdiction. As cross-border transfer rules and Significant Data Fiduciary localization requirements are finalized, they will directly determine which categories of international clients a given facility can serve, and under what guarantees. The ability to prove, in terms that would satisfy a regulator, that data has not left Indian jurisdiction is becoming a procurement requirement rather than a point of differentiation.
Government policy is reinforcing this shift directly. The Union Budget for 2026 to 2027 introduced a twenty year tax holiday, extending through 2047, for foreign cloud providers building infrastructure on Indian soil to serve global markets. Combined with the IndiaAI Mission’s influence on public infrastructure investment, the intent is clear. India is positioning its data centers as the trusted domestic layer for both its own regulated industries and a share of global cloud demand.
For decades, enterprises evaluated data centers primarily on availability, resilience, connectivity and cost. Those requirements have not disappeared. But a new dimension is being added: provability.
Can the infrastructure provider demonstrate where data resides? Can it support the enterprise’s security and audit requirements? Can workloads be isolated appropriately? Can the architecture support regulatory obligations as they evolve?
In the DPDP era, infrastructure doesn’t merely host compliance-sensitive workloads. It increasingly forms part of the architecture through which compliance is demonstrated.
How Industries Are Adopting AI While Meeting DPDP’s Requirements

Progress here in most of the industries is uneven, and financial services are notably ahead of most other sectors.
Banks illustrate the most advanced response to date. Institutions are segmenting data lakes and automating consent management to reconcile a genuine tension between DPDP’s erasure requirements and RBI’s data retention mandates. Most large banks anticipate being designated Significant Data Fiduciaries, and a few BFSI leaders are treating that designation as an opportunity to formalize data discipline that had previously been deferred. A 2026 FICCI-EY risk survey found that 51% of senior business leaders now rank data breaches as their organization’s single greatest risk, ahead of most conventional operational concerns.
This discipline is visible in how AI is being deployed. Insurance companies are using generative AI to summarize medical and legal claims documentation, reducing turnaround from days to minutes. Several Indian banks now train fraud detection models on synthetic data specifically to avoid exposing real customer information during training, a direct and practical response to DPDP’s requirements.
Other sectors are adopting AI at comparable speed, though governance has not always kept pace. Indian enterprises are among the fastest global adopters of AI and generative AI, frequently outpacing the maturity of their own internal governance frameworks. Healthcare, retail, and e-commerce are realizing measurable returns, particularly through vernacular and voice-first deployments designed for a linguistically diverse user base. This acceleration, however, carries a corresponding risk. As digitization advances, so does the sophistication of AI-enabled fraud, including deepfake driven impersonation and synthetic identity fraud, developments that increasingly intersect with DPDP compliance rather than remaining a separate security concern.
What Should a CIO Now Expect from an Infrastructure Partner?
The organization that can answer, with confidence, where its data resides, who is accountable for every AI agent in production, and how its infrastructure partners meet these same standards, will be the one best positioned as enforcement intensifies.
The implications of DPDP and Agentic AI extend beyond an enterprise’s internal technology architecture. They also change the standard CIOs should apply to the infrastructure partners underneath it.
As AI moves into production and personal data flows across increasingly distributed environments, infrastructure can no longer be evaluated only on capacity, availability, performance, and cost. CIOs increasingly need to understand whether the partners they depend on can support the same standards of control, visibility, resilience, and accountability that the enterprise itself is expected to demonstrate.
That changes the questions enterprises should be asking:
Sovereignty: Can I maintain visibility and jurisdictional control over critical data and workloads?
Security & Governance: Can the environment support the isolation, access controls, security, traceability, and auditability my organization requires?
Scalability: Can the infrastructure move with us from AI experimentation to production without requiring a fundamental redesign?
Interoperability: Can it work with the hyperscaler, cloud, and on-premise investments we already have rather than forcing a rip-and-replace?
Operational Visibility: As infrastructure becomes more distributed, can my teams maintain a unified view of where workloads run, how they perform, and how the environment is being managed?
These are no longer simply vendor-selection questions. They are becoming part of how enterprises design for AI readiness and regulatory accountability from the outset.
This is where infrastructure moves from being something an enterprise simply consumes to something it strategically designs around its data, AI, and regulatory requirements.
Building for the New Standard of Enterprise AI
This is the thinking behind Techno Digital’s Sovereign Digital Infrastructure Platform.
It begins with the physical foundation: AI-ready data centers and colocation infrastructure in India, designed for the resilience, security, scalability, and control required by enterprise and increasingly dense AI workloads.
On that foundation, we bring together Private Cloud, Private AI, Cloud Management, and Managed Services, enabling enterprises to build infrastructure around their own data, regulatory, and transformation requirements.
Sovereignty, however, does not have to mean isolation. Enterprises can continue leveraging existing hyperscaler, cloud, and on-premise investments while maintaining greater control over the workloads and data that require it.
For us, this is what built-to-suit digital infrastructure means: designing the right combination of data center infrastructure, colocation, cloud, AI, and managed services around the enterprise—not forcing the enterprise to adapt to the infrastructure.
Ultimately, it is about giving enterprises greater choice over where workloads run, where data resides, how environments are governed, and how infrastructure scales as AI moves into production.
Because in the Agentic AI era, the infrastructure question is no longer simply: Where should we host this workload?
It is: How much control can we retain over everything that happens to it?

