
Introduction
India’s build-out of AI compute capacity is increasingly discussed in terms of capital, tax, procurement and long-term financing. At a closed-door meeting on ‘Financing India’s Frontier & Compute Ecosystem’, industry executives asked for long-term demand commitments, easier financing, a clear exit framework for lenders and lessors, and tax relief on imported GPUs. Each proposal has a data protection dimension that has received little attention. A GPU cluster processes the personal data in its customers’ training datasets, prompts, outputs and logs. Since the principal substantive obligations under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) take effect from 13 May 2027, clusters financed today will operate for most of their contractual life under that regime.
Background
The central difficulty in financing AI compute is the availability of bankable long-term contracts, not capital. Yotta, which the report says was empanelled under the IndiaAI Mission in February last year, has committed to contribute more than 50% of the Mission’s total GPU computing capacity. The suggested four- to five-year demand commitments from government departments, research institutions and strategic AI programmes at commercially sustainable prices, and proposed that the National Frontier AI & Compute Fund act through credit enhancement or backstop guarantees, not merely finance GPU purchases.
Compute Providers as Processors, Customers as Fiduciaries
Under the DPDP Act, the person who determines the purpose and means of processing is the Data Fiduciary, and a person processing on its behalf is the Data Processor. A GPU cloud provider renting capacity to a department, research institution or enterprise will ordinarily be a Data Processor, the illustration to Rule 8(3) of the DPDP Rules itself treats a cloud service provider hosting a company’s customer records in that way. Section 8(1) keeps the Data Fiduciary responsible for compliance even where a Data Processor is used, and Section 8(2) permits a Data Processor to be engaged, for activities related to offering goods or services to Data Principals, only under a valid contract. The long-term compute contracts that industry wants to be bankable will therefore also allocate data protection obligations.
Section 8(5) requires reasonable security safeguards, including for processing by a Data Processor, and Rule 6 prescribes minimum measures: encryption, obfuscation, masking or virtual tokens, access controls, logging and monitoring, backups, and security provisions in the processor contract. A provider that uses customer data for its own purposes, such as tuning its own models, risks being treated as a Data Fiduciary for that processing.
Long-Term Government Demand and State Data
Four- to five-year commitments would make the State the anchor customer. The State is a “person” under the Act and can be a Data Fiduciary. Section 7 recognises certain legitimate uses by the State, and Section 17(2)(a) permits exemption of specified instrumentalities, but only by notification and on grounds such as the sovereignty and integrity of India, security of the State and public order. Section 17(4) relaxes some provisions for State processing, including the erasure duty in Section 8(7), but leaves Section 8(5) in place. Operators should expect security, audit and localisation requirements to be passed down to them: Section 16(2) preserves stricter Indian laws on transfers, and Rule 13(4) requires Significant Data Fiduciaries to ensure that personal data specified by the Central Government, and its traffic data, are not transferred outside India.
Exit Framework for Lenders and Lessors: The Data Left Behind
A clear exit framework is, in substance, certainty on what happens when a financed cluster is enforced against, repossessed, re-leased or sold. Servers housing GPUs typically include storage and memory that can retain customer data after a contract ends. Without a defined data protocol, three exposures arise.
First, unauthorised processing of, accidental disclosure of, or loss of access to personal data during repossession may be a personal data breach under Section 2(u). Section 8(6) requires intimation to the Data Protection Board of India (“Board”) and each affected Data Principal, and Rule 7 requires a detailed report to the Board within 72 hours, or a longer period the Board allows. Second, Section 8(7) requires erasure once the purpose is no longer served, unless retention is necessary under law, and requires the Data Fiduciary to cause its Data Processor to erase data. This must be sequenced with Rule 8(3), under which personal data, associated traffic data and processing logs must be retained for a minimum of one year from the date of processing, for the purposes in the Seventh Schedule, including where a Data Processor holds them, unless another law requires longer. An exit protocol that wipes media immediately on enforcement may conflict with that requirement; it should provide for secure return of the data and logs to the customer or a designated custodian before sanitisation. Third, failure to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore, and failure to notify a breach up to ₹200 crore, under the Schedule to the Act. Liability sits primarily with the Data Fiduciary and, by contract, with the provider, but a lender or lessor that takes hands-on control without defined data protection responsibilities may be drawn into a dispute.
A bankable exit framework should therefore address data expressly: a chain-of-custody process on enforcement, return of data and logs, certified sanitisation before any asset is moved or sold, a Data Processor undertaking from any step-in operator, and notification mechanics towards customers and the Board.
Data Protection and Bankability
Lenders price contingent liabilities. A penalty ceiling of ₹250 crore for a security failure is significant when a cluster is financed at a value of that order. Lenders are likely to examine data protection compliance in credit diligence, alongside title, insurance and offtake risk. If the proposed National Frontier AI & Compute Fund provides credit enhancement or backstop guarantees, in our view, security and data protection standards would be a reasonable condition of eligibility, since they protect the underlying cash flows.
AMLEGALS Remarks
The proposals are directed at making AI compute financeable. Operators and financiers should treat data protection as a structuring issue: contracts should allocate Data Fiduciary and Data Processor roles, carry the Rule 6 safeguards, and include audit rights, breach notification timelines and a change-in-law mechanism. Financing documents should contain DPDP covenants and representations, defined custody, return and sanitisation steps on enforcement or re-leasing, and a processor undertaking from any step-in operator.
Operators serving international customers should map which workloads fall within Section 17(1)(d) and keep separate controls for them, remembering that Section 8(5) still applies. As the proposals remain industry submissions, their final shape, and how the Board applies the Act to compute infrastructure, will depend on the specific facts and terms of each arrangement.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
