DPDP Act enforcement began in 2026 with penalties up to ₹250 crore. If your subscriber data sits on US or EU email servers, your compliance depends on infrastructure you don’t control. neuMails keeps everything on AWS Mumbai.
The Digital Personal Data Protection Act 2023 is no longer a future concern. Compliance deadlines for major data fiduciaries passed in November 2025, and the Data Protection Board initiated its first enforcement actions in early 2026. Every Indian business that collects subscriber emails is a Data Fiduciary under the Act — including yours.
Cross-border data transfers are permitted today, but the Central Government holds the power to restrict destination countries at any time, and Significant Data Fiduciaries may face localisation mandates. Businesses that keep personal data on Indian infrastructure carry none of this regulatory risk.
In which country is subscriber data stored, processed and backed up? Vague answers mean US or EU by default.
Will they contractually guarantee Indian data residency? Global platforms cannot without Indian datacenters.
Can they produce data-flow evidence for a DPDP audit? Your compliance posture depends on their answer.
Free migration from Mailchimp, Brevo or SendGrid — lists, templates and automations moved to Indian infrastructure.
Start Free Trial