Account Security (Password, 2FA)

Navigating Compliance Requirements in the Web Hosting Industry: A Deep Dive into Compliance Standards

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

If your website takes payments, stores customer details or serves clients abroad, you will meet compliance names such as PCI DSS, GDPR, SOC 2 and ISO 27001, and in India the DPDP Act and CERT-In directions. This guide explains what each one is, who it applies to, and what it means in practice for a business that runs its website on hosting. It is general information, not legal advice.

Key takeaways

Compliance obligations usually fall on the business that collects the data, not only on its host. For most Indian small businesses, the rules that matter are the Digital Personal Data Protection Act, 2023 and the CERT-In directions, plus PCI DSS if you take card payments (use a payment gateway's hosted page to keep that light) and GDPR if you sell to people in the EU. SOC 2, ISO 27001, HIPAA and FedRAMP are mostly about what larger or regulated customers expect from their suppliers. If you need a host's certificates for an audit, ask for current reports in writing.

1. Who is responsible for what

Hosting works on shared responsibility. The host runs the servers, network and physical data centre. You are responsible for your website's code, plugins, passwords, the data you collect and how you use it. On a VPS you also take on the operating system, its updates and its firewall.

That is why no hosting plan can make your website "compliant" on its own. A payment standard or privacy law looks at your whole process: which data you collect, why, who can see it, how long you keep it and what you do when something goes wrong.

2. The frameworks at a glance

FrameworkWhat it isApplies to
DPDP Act, 2023India's personal data protection lawAnyone processing digital personal data of people in India
CERT-In directions (2022)Indian cyber-incident reporting and log-keeping rulesService providers, intermediaries, data centres and organisations in India
PCI DSS v4.0.1Card industry security standardAnyone who accepts, processes, stores or transmits card data
GDPREU data protection lawBusinesses offering goods or services to people in the EU, or monitoring them
SOC 2Independent audit report under AICPA criteriaService providers whose customers ask for assurance
ISO/IEC 27001:2022Certifiable information security management systemAny organisation that chooses to certify
HIPAAUS health information lawUS healthcare providers and their business associates
CCPA / CPRACalifornia consumer privacy lawBusinesses above its size thresholds serving California residents
FedRAMP, FISMA, SOXUS government and listed-company frameworksUS federal suppliers and US-listed companies

3. India: the DPDP Act and CERT-In

The Digital Personal Data Protection Act, 2023 covers any digital personal data of people in India: names, email addresses, phone numbers, addresses and more. Even a contact form or a newsletter sign-up counts. In short, it expects you to:

  • give a clear notice and collect consent for a specific purpose;
  • collect only what you need and keep it only as long as you need it;
  • protect it with reasonable security safeguards;
  • let people see, correct and erase their data, and handle their complaints;
  • report personal data breaches to the Data Protection Board and to the people affected.

The Digital Personal Data Protection Rules, 2025 set out how these duties work in practice, with obligations phased in. Our DPDPA compliance guide for Indian websites covers consent notices and the technical steps.

The CERT-In directions of April 2022 require organisations in India to report specified cyber incidents to CERT-In within 6 hours of noticing them, and require service providers to keep system logs for 180 days within India. Keep your own application logs as well, and know who in your business would make that report.

4. PCI DSS: taking card payments

The Payment Card Industry Data Security Standard applies to anyone who handles card data. The current version is PCI DSS v4.0.1; version 3.2.1 was retired in 2024, and the requirements that v4.0 introduced as "future-dated" became mandatory on 31 March 2025.

Its 12 requirements are grouped into six goals: secure networks, protected account data, vulnerability management, strong access control, monitoring and testing, and an information security policy.

The practical lesson for a small business is to keep card data off your website entirely. With a gateway's hosted payment page or pop-up (Razorpay, PayU, Cashfree, PhonePe and others offer these), card numbers are typed into the gateway's systems, not yours. Your obligations then shrink to the smallest self-assessment questionnaire, but you still must keep the page that sends shoppers to the gateway secure, because an attacker who changes it can redirect them.

Never store card numbers

Don't save full card numbers or CVV codes in your database, in order notes or in emails, even temporarily. If you need repeat billing, use the gateway's tokens or mandates instead.

5. GDPR: customers in the European Union

The General Data Protection Regulation applies to businesses outside the EU when they offer goods or services to people in the EU or monitor their behaviour, for example with tracking analytics. Its principles, such as lawfulness, purpose limitation, data minimisation and security, are close to the DPDP Act's.

Two details older guides get wrong:

  • Breach reporting: you must tell the supervisory authority within 72 hours of becoming aware of a breach. You tell the affected people "without undue delay" only when the breach is likely to put them at high risk.
  • Data location: GDPR does not require data to stay inside the EU. It restricts transfers to other countries unless safeguards apply, such as an adequacy decision or standard contractual clauses.

6. SOC 2 and ISO 27001: proving security to customers

SOC 2 is an audit report issued by an independent CPA firm against the AICPA's Trust Services Criteria: security (always included), and optionally availability, processing integrity, confidentiality and privacy. A Type I report checks the design of controls at one point in time; a Type II report checks that they worked over a period, usually 3 to 12 months.

ISO/IEC 27001:2022 is an international certification for an information security management system: risk assessment, policies, controls from its Annex A and continual improvement. Certificates under the older 2013 version had to move to the 2022 version by October 2025.

Neither is a law. You meet them when a larger customer, often a bank, a multinational or a SaaS buyer, asks for your report or certificate, or for your suppliers'.

7. US frameworks: HIPAA, CCPA, FedRAMP, FISMA and SOX

  • HIPAA protects US patients' health information. A host that stores it must sign a Business Associate Agreement. It rarely applies to Indian clinics, which fall under the DPDP Act instead.
  • CCPA, as amended by the CPRA, gives California residents rights over their personal data. It applies to businesses above its revenue or data-volume thresholds.
  • FedRAMP and FISMA apply to cloud services and systems used by US federal agencies.
  • SOX covers financial reporting controls at US-listed companies, including IT systems that feed their accounts.

If you don't sell to these markets or sectors, you can usually set them aside.

8. A practical checklist for your website

  1. Map your data.
    List what personal data your site collects, why, where it is stored and who can see it.
  2. Collect less.
    Remove form fields you don't need, and delete old enquiries and orders on a schedule.
  3. Publish a clear privacy notice
    and ask for consent where you rely on it, for example for marketing emails.
  4. Use HTTPS everywhere
    and a gateway's hosted page for payments.
  5. Protect logins.
    Unique passwords, two-factor authentication for every administrator, and no shared accounts.
  6. Patch.
    Update your CMS, plugins and themes, and remove what you don't use.
  7. Back up and test restores
    , and keep one copy away from the server.
  8. Plan for incidents.
    Decide who investigates, who reports to CERT-In within 6 hours and who informs customers.

9. Where Domain India fits

Domain India hosting gives you building blocks for this checklist. Every hosting plan includes free SSL. Measured on our servers on 20 September 2026, cPanel accounts get an Imunify360 web application firewall with automatic malware cleanup, CloudLinux CageFS keeps each account isolated on cPanel and DirectAdmin, and JetBackup 5 takes a weekly backup every Sunday with 5 copies kept. Your client area supports two-factor authentication.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

If your auditors need control over logs, encryption at rest, firewall rules or where each component runs, a self-managed VPS gives you root access to set those yourself. Prices on the card are live and exclude 18% GST. If you need a host's certificates or audit reports for your own compliance work, ask our team what is available before you buy, and get it in writing.

Frequently asked questions

Does using a compliant host make my website compliant?

No. Hosting works on shared responsibility. The host secures its servers and network, but you remain responsible for your website's code, passwords, the personal data you collect and how you use and protect it.

Which data protection law applies to an Indian website?

The Digital Personal Data Protection Act, 2023 applies to digital personal data of people in India, including data from contact forms and sign-ups. The CERT-In directions of 2022 add incident reporting within 6 hours. GDPR also applies if you offer goods or services to people in the EU.

Do I need PCI DSS if I use Razorpay or another gateway?

Yes, but the burden is small if you use the gateway's hosted payment page or pop-up, because card numbers never reach your website. You still need to keep your own site secure so nobody can tamper with the checkout.

Does GDPR require my data to be stored in Europe?

No. GDPR restricts transfers of personal data outside the EU unless safeguards apply, such as an adequacy decision or standard contractual clauses. It does not require data to be stored inside the EU.

What is the difference between SOC 2 Type I and Type II?

A Type I report checks that security controls are designed properly at one point in time. A Type II report checks that they actually worked over a period, usually 3 to 12 months, so customers usually prefer Type II.

How quickly must I report a data breach?

Under GDPR, to the supervisory authority within 72 hours of becoming aware of it. In India, specified cyber incidents must be reported to CERT-In within 6 hours, and personal data breaches must also be reported under the DPDP Act and its Rules.

Ready to tighten your setup? Start with the checklist above, read our DPDPA guide, and compare cPanel hosting or VPS plans. For questions about your account, open a support ticket or use our 24/7 live chat.

Build on secure, isolated hosting

Free SSL, a server-side web application firewall, account isolation and weekly backups on every cPanel plan.

See cPanel plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Hosting Compliance: DPDP, PCI DSS, GDPR | Domain India