Two things happened in the last year. A client's procurement team sent me a vendor questionnaire with the line "confirm all personal data is stored within India", and a WhatsApp group of agency owners started forwarding a post claiming Indian agencies must now host everything on Indian servers or face ₹250 crore penalties.
One of those is a real business requirement. The other is a sales pitch with a statute number attached. Here's the actual legal position, where your clients' data really sits, and how to answer the questionnaire without either lying or losing the account.
Does Indian law require client social media data to be stored in India?
Not as a general rule. The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 13 November 2025 — 22 rules, after a ten-month consultation. Rule 15 deals with sending personal data abroad, and its operative text permits the transfer "subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify".
Read that carefully, because it's the opposite of what most people assume. It's a negative list: transfers are allowed by default, and the government can restrict specific destinations. As things stand, no country has been notified as restricted under Section 16 of the Act. India debated hard localisation for years — in the 2018 and 2019 drafts — and landed somewhere else.
What does force Indian storage is narrower and older than the DPDP regime:
| Rule | What it actually requires | Does it apply to your agency? |
|---|---|---|
| DPDP Rules 2025, Rule 15 (notified 13 Nov 2025) | Transfer abroad allowed, subject to requirements the Central Government may specify by order. No restricted countries notified yet. | Yes, as a processor — but it does not require Indian storage. |
| SDF obligations under the DPDP Rules | The government may specify categories of personal data that a Significant Data Fiduciary must not transfer outside India. | Not directly. But if your client is designated an SDF, it can reach you through your contract. |
| CERT-In Directions (28 April 2022, s.70B IT Act) | Maintain logs of all ICT systems for a rolling 180 days, stored within India; report specified cyber incidents within 6 hours of noticing them. | Yes. This is the one most agencies have never heard of and it has been in force since 2022. |
| RBI payment-data circular (6 April 2018) | The entire data relating to payment systems must be stored in a system only in India. | Not to you — it binds payment system operators. It's why your Razorpay data is already in India. |
So the honest answer to "must client data live in India?" is: your content calendar, no; your security logs, yes; your payment rails, already handled by your gateway. The obligations that do land on an agency are about consent, purpose and deletion rather than geography — we covered those in detail in what the DPDP Act means for marketing agencies, including why you're a Data Processor rather than a Fiduciary and what the 13 May 2027 deadline actually covers.
Where does your client's data actually sit right now?
This is the question worth answering, and almost nobody has. Do the map before someone makes you.
| System | Personal data in it | Where it sits |
|---|---|---|
| Meta Business Suite / Instagram | DM inbox, commenter profiles, lead-ad submissions, audience data | Meta's global infrastructure. Not yours to place, and not negotiable. |
| Google Drive / Workspace | Creatives, briefs, exported lead lists, contest entries | Data regions offer US, EU or no preference only — India is not an option. |
| Your scheduling / reporting tool | Captions, media, sometimes analytics tied to handles | Usually US or EU. Ask; most vendors will tell you in writing. |
| WhatsApp groups | Approvals, phone numbers, forwarded customer complaints, contest entries | On every group member's phone, including the freelancer who left in March. |
| Someone's laptop | The lead-form CSV, downloaded "just to check the numbers" | Rudrapur. Or a café in Dehradun. No access control, no deletion log. |
| Payments (Razorpay, bank) | Client billing details, transaction data | India, by RBI mandate. |
Look at row two. Google Workspace's data-region controls let an admin pin covered data to the United States or the European Union — and that's the full list. India is not one of the choices. If your Drive holds a client's downloaded lead list and their questionnaire demands Indian storage, the truthful answer is that Workspace cannot do it, whatever you'd like to write in the box.
And look at rows four and five, because that's where the actual exposure is. Nobody has ever been harmed by a caption sitting on a US server. People are harmed by a spreadsheet of 4,000 phone numbers from a Diwali contest living in a WhatsApp group with eleven members, four of whom no longer work at your agency.
Why are enterprise clients suddenly asking this?
Three reasons, all of them rational.
- The clock is running. MeitY notified the Rules with a phased runway — obligations switching on across 14 November 2025, 14 November 2026 and May 2027, with full compliance expected by 13 May 2027. Large companies are working backwards from that date, and vendor due diligence is the cheapest box to tick first.
- You are their processor. A Data Fiduciary can only engage a processor under a valid contract. Their legal team can't sign that contract without knowing what you hold and where. The questionnaire isn't suspicion, it's paperwork they've been told to produce.
- The six-hour clock needs you. Under the CERT-In Directions, reportable incidents go to CERT-In within six hours of being noticed. If the breach is a leaked login to their Instagram account and you're the one holding it, their six hours depend on how fast you answer a phone call at 11 PM. That's why the contract now asks for a named contact and a notification commitment.
This is also, quietly, an opportunity. Most agencies bidding against you will answer the questionnaire with vibes. If you turn up with an actual data map, a named security contact and a written offboarding commitment, you look like a different tier of vendor — which matters most in exactly the markets where enterprise retainers live, like Gurugram and Bengaluru.
How do you answer a data-residency questionnaire honestly?
Five rules, learned by getting it wrong once.
- Never guess a region. If you don't know where a vendor stores data, write "confirming with vendor" and go get it in writing — from their documentation or their support desk. A wrong answer in a signed vendor form is a far bigger problem than a blank one. Ask every vendor you use, including ours; any vendor that won't answer in writing has told you something.
- Distinguish content from personal data. A caption and a creative are not personal data. A DM thread, a lead-ad submission and a contest entry are. Answer at that granularity and the form gets much easier — and much more credible.
- Say what you cannot do. "Google Workspace does not offer an India data region; covered data is pinned to [US/EU]" is a perfectly acceptable answer. "All data is stored in India" when it isn't will not survive their next audit.
- Name a person and a clock. Give a security contact, a phone number and a commitment — we'll notify you within X hours of noticing an incident. Given their six-hour obligation, pick a number well inside it.
- Commit to deletion, then actually build it. The last question is always about offboarding. Write what you'll delete, from where, and in how many days — then make sure that's a process and not a promise.
The three fixes that matter more than server location
If you do nothing else this quarter, do these. They cost nothing and they close the gaps a residency form never asks about.
Stop holding client passwords
The single largest personal-data risk at most Indian agencies isn't a foreign server, it's the shared Google Sheet of client logins — and the ex-employee who still has the link. Token-based access through Meta's official API means you never hold the password at all, which we walked through in Instagram auto-posting without password sharing. When the questionnaire asks how you access their accounts, "we don't hold credentials" is the strongest sentence you can write.

Get the lead exports off laptops
Every lead-gen client generates a CSV of names and phone numbers, and every agency has downloaded one. Decide where lead data lives, keep it in one system with access control, and stop the WhatsApp forwarding habit. If a client's leads must reach their sales team, send them into the client's CRM — don't make your agency a second uncontrolled copy of their customer database.
Make offboarding a checklist, not a feeling
When a retainer ends: remove your team from their Business Manager, revoke tokens, delete the Drive folder after handover, exit the WhatsApp group, and write the date you did it. The same discipline applies when a staff member leaves mid-retainer. We build this into client onboarding in reverse — whatever access you grant on day one should have a documented way to be taken back, and a system with per-client roles makes that a click instead of an archaeology project. That's the practical case for keeping client work inside one agency system rather than spread across a dozen personal accounts.
FAQ
Does India require social media data to be stored in India?
No, not generally. Rule 15 of the DPDP Rules 2025 allows personal data to be transferred outside India subject to any requirements the Central Government specifies by order — a negative-list approach rather than a localisation mandate. Narrower rules apply to payment data and to security logs.
Can I store client data in Google Drive and still be compliant?
For ordinary content and creatives, yes. But note that Google Workspace data regions offer only the United States, the European Union or no preference — India is not an available region. So you can tell a client where the data sits, but you cannot promise to pin it inside India on Workspace.
Why do enterprise clients ask agencies about data residency now?
Because the DPDP Rules were notified on 13 November 2025 with a phased runway ending 13 May 2027. Large companies are auditing vendors ahead of that date, and an agency holding logins, direct messages and lead-form exports counts as a vendor processing personal data on their behalf.
What is the riskiest client data an agency holds?
Almost never the content calendar. It's the lead-form export in someone's downloads folder, the contest entries with phone numbers on WhatsApp, and the DM inbox. Those are real personal data with no access control — and they're what a residency questionnaire should have asked about.
Sources
- DPDP Rules 2025, Rule 15 — text on transfer of personal data outside India.
- PIB: DPDP Rules, 2025 notified — notification date and phased commencement.
- CERT-In Directions, 28 April 2022 — 180-day log retention within India and 6-hour incident reporting.
- RBI circular on storage of payment system data — 6 April 2018, payment data stored only in India.
- Google Workspace data regions — available regions are the US, the EU, or no preference.
One system, per-client roles, revocable access
Run every brand in its own workspace with role-based staff access, token-based publishing instead of shared passwords, and one-click offboarding — plus calendar, approvals, reports and GST invoicing. From ₹999/month.
Start Free Trial