If your website takes payments, stores customer details or serves clients abroad, you will meet compliance names such as PCI DSS, GDPR, SOC 2 and ISO 27001, and in India the DPDP Act and CERT-In directions. This guide explains what each one is, who it applies to, and what it means in practice for a business that runs its website on hosting. It is general information, not legal advice.
Compliance obligations usually fall on the business that collects the data, not only on its host. For most Indian small businesses, the rules that matter are the Digital Personal Data Protection Act, 2023 and the CERT-In directions, plus PCI DSS if you take card payments (use a payment gateway's hosted page to keep that light) and GDPR if you sell to people in the EU. SOC 2, ISO 27001, HIPAA and FedRAMP are mostly about what larger or regulated customers expect from their suppliers. If you need a host's certificates for an audit, ask for current reports in writing.
1. Who is responsible for what
Hosting works on shared responsibility. The host runs the servers, network and physical data centre. You are responsible for your website's code, plugins, passwords, the data you collect and how you use it. On a VPS you also take on the operating system, its updates and its firewall.
That is why no hosting plan can make your website "compliant" on its own. A payment standard or privacy law looks at your whole process: which data you collect, why, who can see it, how long you keep it and what you do when something goes wrong.
2. The frameworks at a glance
| Framework | What it is | Applies to |
|---|---|---|
| DPDP Act, 2023 | India's personal data protection law | Anyone processing digital personal data of people in India |
| CERT-In directions (2022) | Indian cyber-incident reporting and log-keeping rules | Service providers, intermediaries, data centres and organisations in India |
| PCI DSS v4.0.1 | Card industry security standard | Anyone who accepts, processes, stores or transmits card data |
| GDPR | EU data protection law | Businesses offering goods or services to people in the EU, or monitoring them |
| SOC 2 | Independent audit report under AICPA criteria | Service providers whose customers ask for assurance |
| ISO/IEC 27001:2022 | Certifiable information security management system | Any organisation that chooses to certify |
| HIPAA | US health information law | US healthcare providers and their business associates |
| CCPA / CPRA | California consumer privacy law | Businesses above its size thresholds serving California residents |
| FedRAMP, FISMA, SOX | US government and listed-company frameworks | US federal suppliers and US-listed companies |
3. India: the DPDP Act and CERT-In
The Digital Personal Data Protection Act, 2023 covers any digital personal data of people in India: names, email addresses, phone numbers, addresses and more. Even a contact form or a newsletter sign-up counts. In short, it expects you to:
- give a clear notice and collect consent for a specific purpose;
- collect only what you need and keep it only as long as you need it;
- protect it with reasonable security safeguards;
- let people see, correct and erase their data, and handle their complaints;
- report personal data breaches to the Data Protection Board and to the people affected.
The Digital Personal Data Protection Rules, 2025 set out how these duties work in practice, with obligations phased in. Our DPDPA compliance guide for Indian websites covers consent notices and the technical steps.
The CERT-In directions of April 2022 require organisations in India to report specified cyber incidents to CERT-In within 6 hours of noticing them, and require service providers to keep system logs for 180 days within India. Keep your own application logs as well, and know who in your business would make that report.
4. PCI DSS: taking card payments
The Payment Card Industry Data Security Standard applies to anyone who handles card data. The current version is PCI DSS v4.0.1; version 3.2.1 was retired in 2024, and the requirements that v4.0 introduced as "future-dated" became mandatory on 31 March 2025.
Its 12 requirements are grouped into six goals: secure networks, protected account data, vulnerability management, strong access control, monitoring and testing, and an information security policy.
The practical lesson for a small business is to keep card data off your website entirely. With a gateway's hosted payment page or pop-up (Razorpay, PayU, Cashfree, PhonePe and others offer these), card numbers are typed into the gateway's systems, not yours. Your obligations then shrink to the smallest self-assessment questionnaire, but you still must keep the page that sends shoppers to the gateway secure, because an attacker who changes it can redirect them.
Don't save full card numbers or CVV codes in your database, in order notes or in emails, even temporarily. If you need repeat billing, use the gateway's tokens or mandates instead.
5. GDPR: customers in the European Union
The General Data Protection Regulation applies to businesses outside the EU when they offer goods or services to people in the EU or monitor their behaviour, for example with tracking analytics. Its principles, such as lawfulness, purpose limitation, data minimisation and security, are close to the DPDP Act's.
Two details older guides get wrong:
- Breach reporting: you must tell the supervisory authority within 72 hours of becoming aware of a breach. You tell the affected people "without undue delay" only when the breach is likely to put them at high risk.
- Data location: GDPR does not require data to stay inside the EU. It restricts transfers to other countries unless safeguards apply, such as an adequacy decision or standard contractual clauses.
6. SOC 2 and ISO 27001: proving security to customers
SOC 2 is an audit report issued by an independent CPA firm against the AICPA's Trust Services Criteria: security (always included), and optionally availability, processing integrity, confidentiality and privacy. A Type I report checks the design of controls at one point in time; a Type II report checks that they worked over a period, usually 3 to 12 months.
ISO/IEC 27001:2022 is an international certification for an information security management system: risk assessment, policies, controls from its Annex A and continual improvement. Certificates under the older 2013 version had to move to the 2022 version by October 2025.
Neither is a law. You meet them when a larger customer, often a bank, a multinational or a SaaS buyer, asks for your report or certificate, or for your suppliers'.
7. US frameworks: HIPAA, CCPA, FedRAMP, FISMA and SOX
- HIPAA protects US patients' health information. A host that stores it must sign a Business Associate Agreement. It rarely applies to Indian clinics, which fall under the DPDP Act instead.
- CCPA, as amended by the CPRA, gives California residents rights over their personal data. It applies to businesses above its revenue or data-volume thresholds.
- FedRAMP and FISMA apply to cloud services and systems used by US federal agencies.
- SOX covers financial reporting controls at US-listed companies, including IT systems that feed their accounts.
If you don't sell to these markets or sectors, you can usually set them aside.
8. A practical checklist for your website
- Map your data.List what personal data your site collects, why, where it is stored and who can see it.
- Collect less.Remove form fields you don't need, and delete old enquiries and orders on a schedule.
- Publish a clear privacy noticeand ask for consent where you rely on it, for example for marketing emails.
- Use HTTPS everywhereand a gateway's hosted page for payments.
- Protect logins.Unique passwords, two-factor authentication for every administrator, and no shared accounts.
- Patch.Update your CMS, plugins and themes, and remove what you don't use.
- Back up and test restores, and keep one copy away from the server.
- Plan for incidents.Decide who investigates, who reports to CERT-In within 6 hours and who informs customers.
9. Where Domain India fits
Domain India hosting gives you building blocks for this checklist. Every hosting plan includes free SSL. Measured on our servers on 20 September 2026, cPanel accounts get an Imunify360 web application firewall with automatic malware cleanup, CloudLinux CageFS keeps each account isolated on cPanel and DirectAdmin, and JetBackup 5 takes a weekly backup every Sunday with 5 copies kept. Your client area supports two-factor authentication.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If your auditors need control over logs, encryption at rest, firewall rules or where each component runs, a self-managed VPS gives you root access to set those yourself. Prices on the card are live and exclude 18% GST. If you need a host's certificates or audit reports for your own compliance work, ask our team what is available before you buy, and get it in writing.
Frequently asked questions
Does using a compliant host make my website compliant?
No. Hosting works on shared responsibility. The host secures its servers and network, but you remain responsible for your website's code, passwords, the personal data you collect and how you use and protect it.
Which data protection law applies to an Indian website?
The Digital Personal Data Protection Act, 2023 applies to digital personal data of people in India, including data from contact forms and sign-ups. The CERT-In directions of 2022 add incident reporting within 6 hours. GDPR also applies if you offer goods or services to people in the EU.
Do I need PCI DSS if I use Razorpay or another gateway?
Yes, but the burden is small if you use the gateway's hosted payment page or pop-up, because card numbers never reach your website. You still need to keep your own site secure so nobody can tamper with the checkout.
Does GDPR require my data to be stored in Europe?
No. GDPR restricts transfers of personal data outside the EU unless safeguards apply, such as an adequacy decision or standard contractual clauses. It does not require data to be stored inside the EU.
What is the difference between SOC 2 Type I and Type II?
A Type I report checks that security controls are designed properly at one point in time. A Type II report checks that they actually worked over a period, usually 3 to 12 months, so customers usually prefer Type II.
How quickly must I report a data breach?
Under GDPR, to the supervisory authority within 72 hours of becoming aware of it. In India, specified cyber incidents must be reported to CERT-In within 6 hours, and personal data breaches must also be reported under the DPDP Act and its Rules.
Ready to tighten your setup? Start with the checklist above, read our DPDPA guide, and compare cPanel hosting or VPS plans. For questions about your account, open a support ticket or use our 24/7 live chat.
Free SSL, a server-side web application firewall, account isolation and weekly backups on every cPanel plan.
See cPanel plans