Skip to main content
Blueacrobat Corporation

India’s Digital Personal Data Protection Act, 2023: What It Means for Where NetSuite Data Is Held

India's Digital Personal Data Protection Act, 2023 sets obligations for organisations that process the personal data of people in India. For a company running NetSuite, the practical questions are where a backup or archive of that data is held and who decides. This post separates what the Act sets, what the customer's legal team determines, and what a hosting arrangement can and cannot settle.

3 min read Audit & Compliance LinkedIn Share
A compass resting on a sheet of financial figures

A NetSuite account holds personal data alongside the transactions: customer contacts, employee records, supplier representatives. When a company with operations in India backs that account up, or extracts it before retiring it, the copy carries the same data, and the same obligations follow it.

What does the Act change for a company running NetSuite?

The Digital Personal Data Protection Act, 2023 is India's framework for the processing of digital personal data. It sets out duties for the organisations that decide how personal data is processed, which the Act calls data fiduciaries, rights for the individuals the data concerns, and a Data Protection Board to oversee both. The text of the Act and the rules made under it are published by the Ministry of Electronics and Information Technology, and that is the source to read; this post does not restate its provisions.

What it means for a given company depends on what data it holds, where its operations are, and how the Act and its rules apply to its transfers. That determination belongs to the company's legal or compliance team. A backup or an archive is a processing activity like any other, so it belongs inside that determination rather than outside it.

Does the data have to stay in India?

Whether a particular dataset may be held outside India, and under what conditions, is a question of the Act, its rules and the company's own assessment, not of the hosting product. What a hosting arrangement can do is make the region a decision rather than an accident: the copy is held where the engagement says it is held, the location is documented, and it does not move without a change to the agreement.

On DBVault the hosting region is agreed for each engagement. Regions outside our standard set are considered case by case, so a residency requirement, whether it comes from a law, a contract or an internal policy, is raised during scoping and settled before any data is copied. Data is encrypted in transit and at rest, access to an archive is read-only and assigned through named roles and restriction profiles, and Blueacrobat is ISO/IEC 27001:2022 certified and undergoes an annual SOC 2 Type II examination; the Trust Centre describes the controls.

How does a hosting region get decided?

  • The legal or compliance team states the requirement: which data, which jurisdiction, which conditions on transfer.
  • Scoping records it alongside the record scope and the users who need access, and confirms whether the region is standard or case by case.
  • The engagement documents the region, and the archive or the backup is provisioned there before the first copy is taken.
  • The organisation keeps its own portable copy where it wants one: the archived database can be delivered as MySQL, and records can be exported to CSV, so the hosted copy is never the only one.

None of this makes a company compliant on its own. It makes the location of one processing activity deliberate, documented and consistent with the determination the company has already made. If a region requirement applies to your NetSuite data, say so when you review the DBVault platform, and it will be part of the scope from the first conversation.

Need the archive or the backup held in a particular region?

Latest Blogs

All articles

Latest Case Studies

All case studies