You scan a paper file, turn it into a PDF, and upload it to the cloud. Simple enough. But where does that PDF actually live?
That question becomes important when scanned records contain names, addresses, identity details, employee information, customer records, or other personal data. Once a physical record is digitised, its storage and processing can bring it within India's digital personal data protection framework. The DPDP Act expressly covers personal data collected in non-digital form and digitised later.
This makes DPDP data residency document storage an important issue for businesses moving paper archives into digital systems. However, there is a common misunderstanding here. The DPDP Act does not currently say that every piece of personal data must always remain on servers physically located in India. Instead, Section 16 gives the Central Government power to restrict transfers to specified countries or territories. Other Indian laws can also create stronger requirements for particular sectors.
So, where can your scanned documents live? The answer depends on what the records contain, why they are being processed, which laws apply, and how your storage provider handles cross-border processing.
Does DPDP Require Every Scanned Document to Stay in India?
Let’s start with the question businesses usually ask first: Does DPDP mean all scanned documents must be stored in India?
Not exactly.
The Digital Personal Data Protection Act, 2023 regulates the processing of digital personal data. Its definition of processing is broad. It includes activities such as storage, retrieval, indexing, sharing, transmission, and destruction.
The Act also applies when personal data is collected in non-digital form and then digitised. That is directly relevant to records management. A paper employee file sitting in a warehouse may not be digital personal data while it remains purely physical. Once it is scanned into a digital system, the resulting personal data can fall within the Act's scope.
Section 16 is particularly important for the residency question. It states that the Central Government may notify countries or territories outside India to which a Data Fiduciary may be restricted from transferring personal data for processing. It also makes clear that other Indian laws providing a higher degree of protection or greater restrictions on overseas transfers continue to apply.
So the practical answer is more nuanced than “India only” or “anywhere in the world.”
A company needs to determine whether its records contain personal data, whether another law imposes additional restrictions, whether the processing involves overseas infrastructure, and whether its vendor or cloud architecture creates an international transfer.
This distinction matters because a storage contract saying “your data is secure” does not automatically answer the residency question.
You need to know where the primary data is stored, where backups are stored, where processing happens, and who can access it.
That is the foundation of a sensible data residency review.
What Happens When Paper Records Become Digital Data?
Here is where many records projects get complicated.
A company may have millions of physical records. Some may contain employee information. Others may contain customer details, contact information, financial records, identification documents, contracts, or other information connected to identifiable individuals.
The company then sends those records for scanning.
The moment those pages are digitised, the information can become digital personal data within the scope of the DPDP Act, depending on its content and context.
That means digitisation should not be treated as a purely operational activity.
The organisation should understand what data is being captured, why it is being captured, how long it needs to be retained, who can access it, and where the resulting digital files will be processed.
This is especially important when scanning is outsourced.
The DPDP Act distinguishes between a Data Fiduciary and a Data Processor. A Data Fiduciary determines the purpose and means of processing, while a Data Processor processes personal data on behalf of the Data Fiduciary. The Act also states that a Data Fiduciary remains responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor.
That creates an important business lesson.
Outsourcing scanning or storage does not mean outsourcing responsibility.
If a company sends employee files to a third party for scanning and digital storage, it still needs to understand how that third party handles the information.
This is where data hosting record management becomes more than a technical procurement question. It becomes part of the organisation's records governance process.
A good provider should be able to explain its storage architecture, access controls, backup arrangements, retention process, security safeguards, and data-handling practices.
Why Your Cloud Storage Location Matters
Suppose your scanned records are stored in a cloud environment.
You ask the provider, “Are my files in the cloud?”
That answer is not enough.
The next questions should be:
Where is the primary storage located?
Where are backups maintained?
Where are disaster-recovery copies stored?
Can support teams outside India access the environment?
Does the provider use third-party infrastructure?
Where does OCR or AI processing happen?
Are logs or metadata transferred outside India?
These questions matter because “storage” is only one part of data processing.
The DPDP Act defines processing broadly enough to include storage, retrieval, indexing, sharing, and transmission. Therefore, an organisation looking only at the physical location of its main database may miss other parts of the data flow.
For example, a scanned document may be stored on an Indian server but processed by an OCR service located elsewhere. A backup may also be maintained in another jurisdiction. A support provider could potentially access records from outside India.
The result is a data flow that looks like this:
Paper file → Scanning → OCR → Indexing → Primary storage → Backup → Retrieval → Sharing
Every step deserves attention.
The 2025 DPDP Rules add another layer for Significant Data Fiduciaries. MeitY's explanatory note states that certain personal data identified by the Central Government may be subject to specific restrictions, including requirements that the data and related traffic data not be transferred outside India.
This is an important reason not to treat DPDP as a simple “Indian server versus foreign server” question.
The actual compliance position can depend on the type of data, the organisation, the processing activity, and other applicable legal requirements.
This is also why cloud data management solutions should be evaluated for governance features, not just storage capacity.
A platform should help an organisation understand access, movement, retention, and control of its records.
What Should You Ask Your Records Management Provider?
Before signing a digitisation or cloud storage agreement, ask the provider for a clear data-flow explanation.
Do not settle for broad statements such as “enterprise-grade security” or “global cloud infrastructure.” Those descriptions may sound reassuring, but they do not tell you where your records are actually processed.
Ask for the storage and processing locations relevant to your account.
You should also ask whether backups and disaster-recovery copies are held in different jurisdictions. If they are, understand what information is replicated and under what contractual arrangements.
Access is another important area.
A provider may store the database in India but have technical support teams located elsewhere. That does not automatically mean the arrangement is unlawful, but it is a reason to understand the access model and applicable transfer requirements.
Your contract should also address data ownership, permitted processing, confidentiality, security measures, retention, deletion, incident handling, subcontractors, and what happens when the relationship ends.
Dox and Box's published terms state that customers retain ownership of their documents and data and that Dox and Box uses that data for delivering its services. Its privacy policy also describes encryption, role-based access controls, cloud infrastructure, backups, monitoring, and audit trails.
These are the kinds of details businesses should examine when evaluating a records management provider.
The question is not simply whether the provider offers cloud storage.
The better question is whether you can understand and control the complete lifecycle of your records.
How to Build a DPDP-Ready Document Storage Workflow
So, what should a practical workflow look like?
Start before scanning.
First, classify the archive. Identify which records contain personal data and which do not. Then identify any sector-specific rules, contractual restrictions, or other legal requirements that may apply to particular records.
Next, define the purpose for digitisation.
The DPDP Act requires processing to be connected to a lawful purpose, and where consent is the basis, consent must relate to the specified purpose and necessary personal data.
Then decide what metadata is genuinely required.
Do not collect unnecessary information just because your document management system has extra fields. A large archive can quickly become harder to govern when excessive metadata is captured without a clear purpose.
After that, establish access rules.
An employee who needs access to invoices may not need access to employee identity documents. A legal team may need a different permission structure from a finance team.
Role-based access can help organisations enforce these distinctions.
Dox and Box states that its data governance platform provides role-based access, audit trails, retention policy automation, and centralised document control.
The next step is to map the data flow.
A basic internal register can document:
- Storage location: Where the primary digital records are hosted.
- Backup location: Where recovery copies are maintained.
- Processing location: Where OCR, extraction, indexing, or other processing occurs.
- Access location: Which teams, vendors, or support personnel can access the records.
- Exit process: How records are returned, migrated, or securely deleted when the contract ends.
This gives the organisation something more useful than a generic cloud-security statement. It creates a practical map of where information travels.
Retention should also be built into the workflow.
The DPDP Act requires a Data Fiduciary to erase personal data when the specified purpose is no longer being served, unless retention is necessary under another law.
For records managers, this means retention schedules should not sit separately from the digital storage system. The retention rule should connect to the record category and its lifecycle.
That is where modern records platforms can make a difference.
Where Dox and Box Fits Into the Picture
So, where should an organisation start if it has thousands or millions of physical records and wants to digitise them without losing control over where the data goes?
Start with the records lifecycle rather than choosing storage first.
The process should look something like this:
Classify → Digitise → Index → Secure → Store → Control Access → Monitor → Retain → Dispose
Dox and Box provides physical records management, scanning and digitisation, indexing, retrieval, AI-driven document processing, and data governance capabilities. Its digital records service also connects physical and digital records through digitisation, indexing, cloud integration, and controlled access.
That makes it relevant for businesses that want to move from paper archives to structured digital records while keeping records management and data governance connected.
But there is an important point to remember.
No provider can give an organisation a universal “DPDP-compliant” answer without understanding the organisation's data, sector, processing purposes, contracts, and applicable laws.
The organisation remains responsible for assessing its legal and operational requirements.
Dox and Box can support the operational side by providing structured document storage, digitisation, access controls, indexing, retrieval, and governance capabilities.
The real goal of DPDP data residency document storage is therefore not simply putting every PDF inside India and assuming the problem is solved.
It is knowing what data you hold, where it goes, who can access it, why it is being processed, how long it should remain available, and what happens when it reaches the end of its lifecycle.
That is the level of control a modern digital archive needs.

Content Writer

+91-9580 374 374



