Data Residency (DPDP) — India Data Residency & Consent
Keep every class of data in India, honour data-subject rights, and stay DPDP compliant on a platform built for the DPDP Act 2023.
Overview
India's Digital Personal Data Protection Act 2023 changes where data may live and what rights people hold over it. Residency (DPDP) lets you set, for each class of data, the region it is allowed to reside in and whether any cross-border movement is permitted, with a stated legal basis and an owner accountable for the rule.
Compliance is more than storage location. When a person exercises their rights, access, correction or erasure, the request is tracked against its legal deadline so nothing lapses. Masking rules keep sensitive fields obscured for those who should not see them. Together, residency, subject requests and masking turn DPDP obligations into enforced, auditable controls rather than policy documents.
Explore Data & Analytics →- ✓ India-only residency rules per class of data
- ✓ Cross-border movement governed with a legal basis
- ✓ Data-subject requests tracked to legal deadlines
- ✓ Access, correction and erasure rights handled end to end
- ✓ Masking rules for sensitive fields built in
- ✓ Owners and effective dates on every residency rule
Everything Residency (DPDP) gives you
Residency Rules
Define where each class of data may physically live, defaulting to India-only under the DPDP Act.
Residency Lock
All customer data is stored in India. Each data class records its residency, legal basis and owner, so you can show this to an auditor.
Subject Requests
Log access, correction and erasure requests and track each against its legal deadline.
Deadline Tracking
See days to deadline on every request so DPDP timelines are never missed.
Field Masking
Obscure sensitive fields for unauthorised roles so personal data is not over-exposed.
Residency Audit
Effective dates, owners and status make every residency and masking rule auditable.
How the agent works with Residency (DPDP)
The Flow-Cognition Agent helps you keep DPDP requests on the clock — it works within your residency and masking rules, and every step is logged.
Sense
Tracks data-subject requests and the records each one touches.
Decide
Flags requests nearing their legal deadline and owners who need a nudge.
Act
Drafts the response for an owner to review, and logs every step.
Five-tier model routing · field-level permissions · full audit trail. See the AI layer →
Live in four steps
Classify Data
Group data into classes and decide the residency each class requires.
Set Rules
Pin each class to an allowed region, define cross-border stance and a legal basis.
Handle Requests
Receive data-subject requests and track access, correction or erasure to the deadline.
Prove Compliance
Report on residency and masking coverage with owners and dates for any audit.
Where teams put it to work
India-only storage mandate
A regulated business must keep customer personal data within India; residency rules enforce it per data class and flag any cross-border exception.
Erasure request on deadline
A customer asks to be forgotten; the request is logged, the affected objects are identified, and days-to-deadline keeps fulfilment on the legal clock.
Masked support access
Frontline staff assist customers while masking rules hide full sensitive fields, satisfying DPDP data-minimisation expectations.
The payoff
DPDP compliant
Residency, data-subject rights and masking meet India's DPDP Act 2023 obligations.
Deadlines in view
Every request shows the days remaining, so statutory timelines are easier to meet.
Data stays in India
Every class of customer data is stored and processed in India.
Provable to auditors
Owners, effective dates and coverage reports turn compliance into evidence you can show.
Questions, answered
Yes. All customer data on Office24by7 is stored in India. Residency rules record the class, legal basis and owner for each type of data, so the setup can be audited.
Each request, whether access, correction or erasure, is logged against the contact, linked to the objects it affects, and tracked with a due date and days-to-deadline so it is fulfilled on time.
It is a category of data, such as customer personal data or financial records, that a residency rule applies to. Grouping by class lets you set the right region and cross-border stance for each type.
Masking obscures sensitive fields from roles that do not need to see them, supporting data minimisation. Exempt roles can still view full values where there is a legitimate need.
Yes. Every residency and masking rule carries an owner, effective date and status, and coverage reports show where rules apply, giving you an auditable record of your DPDP posture.
See Residency (DPDP) in your workflow
Start free, or get a guided walkthrough with our team — on the one platform that runs Data & Analytics and your whole business.

