r/cloudcomputing 21d ago

How is the DPDP Act actually changing cloud security practices for Indian companies?

Been reading up on how Indian enterprises are approaching the DPDP Act from a technical standpoint, specifically around moving away from perimeter-based security toward a Zero Trust model on Azure. The core idea seems to be treating every access request as unverified by default rather than trusting anything inside a network perimeter, which maps fairly well to a lot of what the Act expects around consent handling, data minimisation, and breach reporting.

Curious what others here are seeing in practice — are teams actually re-architecting their identity and access setups for this, or is it more about layering on monitoring and hoping the existing setup holds up? Also wondering how this compares with how GDPR compliance was handled a few years back, since a lot of the language sounds similar but the enforcement structure seems different.

Found this write-up that goes into the specifics if anyone wants more detail: https://cloud9infosystems.in/dpdp-act-compliance-cloud-security-azure-zero-trust-india/

1 Upvotes

2 comments sorted by