{"id":2626,"date":"2026-09-10T09:02:54","date_gmt":"2026-09-10T09:02:54","guid":{"rendered":"https:\/\/www.newevol.io\/resources\/?p=2626"},"modified":"2026-09-10T11:15:05","modified_gmt":"2026-09-10T11:15:05","slug":"dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud","status":"publish","type":"post","link":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/","title":{"rendered":"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?"},"content":{"rendered":"<p>Most conversations about SIEM architecture and India&#8217;s Digital Personal Data Protection (DPDP) Act start in the wrong place. A security leader asks whether the law permits a cloud of SIEM. A compliance head asks whether keeping logs in the data centre is safer. A vendor answers with whichever architecture it happens to sell.<\/p>\n<p>The Act itself is silent on all of it. It does not name a deployment model, a vendor, or a logging design. What it does expect is that an organisation handling personal data can show it has reasonable security safeguards in place and can account for how that data is handled.<\/p>\n<p>That shifts the question. Instead of asking which model is more compliant, Indian enterprises should ask which model lets them demonstrate, document, and defend the controls protecting their security telemetry.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_66_1 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title ez-toc-toggle\" style=\"cursor: pointer\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #0a0a0a;color:#0a0a0a\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #0a0a0a;color:#0a0a0a\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 eztoc-toggle-hide-by-default' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Why_the_DPDP_Act_Matters_to_Security_Teams\" title=\"Why the DPDP Act Matters to Security Teams\">Why the DPDP Act Matters to Security Teams<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Where_Personal_Data_Shows_Up_in_Security_Telemetry\" title=\"Where Personal Data Shows Up in Security Telemetry\">Where Personal Data Shows Up in Security Telemetry<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Reframing_the_On-Prem_vs_Cloud_Question\" title=\"Reframing the On-Prem vs Cloud Question\">Reframing the On-Prem vs Cloud Question<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Accountability_Stays_with_the_Enterprise\" title=\"Accountability Stays with the Enterprise\">Accountability Stays with the Enterprise<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#What_Each_Model_Makes_Easier_or_Harder_to_Prove\" title=\"What Each Model Makes Easier or Harder to Prove\">What Each Model Makes Easier or Harder to Prove<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Lawful_Basis_and_Data_Retention\" title=\"Lawful Basis and Data Retention\">Lawful Basis and Data Retention<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Data_Principal_Rights_vs_Forensic_Requirements\" title=\"Data Principal Rights vs Forensic Requirements\">Data Principal Rights vs Forensic Requirements<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Processor_Contracts_and_Cloud_Providers\" title=\"Processor Contracts and Cloud Providers\">Processor Contracts and Cloud Providers<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Cross-Border_Transfer_of_Telemetry\" title=\"Cross-Border Transfer of Telemetry\">Cross-Border Transfer of Telemetry<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Administrative_Access_and_Vendor_Support\" title=\"Administrative Access and Vendor Support\">Administrative Access and Vendor Support<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Decision_Matrix_On-Premises_vs_Cloud_SIEM\" title=\"Decision Matrix: On-Premises vs Cloud SIEM\">Decision Matrix: On-Premises vs Cloud SIEM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#An_Auditor-Focused_Checklist\" title=\"An Auditor-Focused Checklist\">An Auditor-Focused Checklist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#When_Each_Model_May_Make_Sense\" title=\"When Each Model May Make Sense\">When Each Model May Make Sense<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Evaluating_Any_SIEM_Platform\" title=\"Evaluating Any SIEM Platform\">Evaluating Any SIEM Platform<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Conclusion\" title=\"Conclusion\">Conclusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#Frequently_Asked_Questions\" title=\"Frequently Asked Questions\">Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#1_Does_the_DPDP_Act_require_an_on-premises_SIEM\" title=\"1. Does the DPDP Act require an on-premises SIEM?\">1. Does the DPDP Act require an on-premises SIEM?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#2_Is_cloud_SIEM_compliant_with_the_DPDP_Act\" title=\"2. Is cloud SIEM compliant with the DPDP Act?\">2. Is cloud SIEM compliant with the DPDP Act?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#3_Can_SIEM_logs_contain_personal_data\" title=\"3. Can SIEM logs contain personal data?\">3. Can SIEM logs contain personal data?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#4_How_long_should_security_logs_be_retained\" title=\"4. How long should security logs be retained?\">4. How long should security logs be retained?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#5_What_should_enterprises_check_in_a_cloud_SIEM_providers_contract\" title=\"5. What should enterprises check in a cloud SIEM provider&#8217;s contract?\">5. What should enterprises check in a cloud SIEM provider&#8217;s contract?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#6_Does_storing_SIEM_data_outside_India_automatically_make_the_deployment_non-compliant\" title=\"6. Does storing SIEM data outside India automatically make the deployment non-compliant?\">6. Does storing SIEM data outside India automatically make the deployment non-compliant?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#7_What_evidence_should_an_enterprise_maintain\" title=\"7. What evidence should an enterprise maintain?\">7. What evidence should an enterprise maintain?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Why_the_DPDP_Act_Matters_to_Security_Teams\"><\/span>Why the DPDP Act Matters to Security Teams<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <strong><a href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-2023-siem-compliance-on-prem-vs-cloud\/\">DPDP Act 2023<\/a><\/strong> governs how organisations collect and process the digital personal data of individuals in India. Enterprises acting as Data Fiduciaries carry obligations around purpose limitation, security safeguards, breach of notification, and responding to data principal requests.<\/p>\n<p>Security teams often assume this sits with product, HR, or marketing. It rarely stops there. The Security Operations Centre is one of the largest consumers of user-linked data in the enterprise, and it usually keeps that data longer than anyone else.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Where_Personal_Data_Shows_Up_in_Security_Telemetry\"><\/span><span style=\"font-size: 70%;\">Where Personal Data Shows Up in Security Telemetry<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not every log line is personal data. Whether it falls within scope depends on what the record contains and whether it can be linked, directly or with other available information, to an identifiable person.<\/p>\n<p>In practice, several common data types often can be:<\/p>\n<ul>\n<li>Authentication and directory logs carrying usernames, employee IDs, and login locations<\/li>\n<li>Endpoint telemetry tied to a named device owner<\/li>\n<li>Email security events with sender and recipient addresses<\/li>\n<li>Web proxy and VPN records linking IP addresses to individual sessions<\/li>\n<li>DLP alerts that may quote fragments of file or message content<\/li>\n<li>Case notes and investigation records built during an incident<\/li>\n<\/ul>\n<p>A firewall counter is unlikely to raise a question. A twelve-month archive of user login behaviour is a different matter. A SIEM holds a mix, and the organisation needs to know which parts are which. That mapping exercise, more than the choice of hosting, is what a reviewer wants to see.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Reframing_the_On-Prem_vs_Cloud_Question\"><\/span>Reframing the On-Prem vs Cloud Question<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The Act does not prescribe <strong><a href=\"https:\/\/www.newevol.io\/resources\/blog\/future-of-cybersecurity-siem-architecture\/\">on-premises SIEM<\/a><\/strong>, cloud SIEM, vendor, a retention schedule for security logs, or a particular logging architecture.<\/p>\n<p>A debate framed as &#8220;which one is compliant&#8221; therefore cannot be resolved, because neither option carries a compliance status of its own. A better framing:<\/p>\n<p>Which deployment model allows us to demonstrate that appropriate controls are operating effectively, and to produce evidence of that when asked?<\/p>\n<p>This is a governance question with a technology answer attached, not the other way round. Two enterprises can reach opposite conclusions and both be defensible, provided each can explain its reasoning and back it with records.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Accountability_Stays_with_the_Enterprise\"><\/span>Accountability Stays with the Enterprise<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>One point deserves to state plainly, because it drives a surprising number of poor decisions. Moving your SIEM to a provider cloud does not move accountability for data protection to that provider. The enterprise remains answerable for:<\/p>\n<ul>\n<li><strong>Governance:<\/strong> the policies defining what is collected and why<\/li>\n<li><strong>Security controls:<\/strong> encryption, segmentation, monitoring of the SIEM itself<\/li>\n<li><strong>Access management<\/strong>: who can query telemetry and under what approval<\/li>\n<li><strong>Retention decisions<\/strong>: how long each data category is kept<\/li>\n<li><strong>Vendor oversight<\/strong>: ongoing assurance, not a one-time procurement review<\/li>\n<li><strong>Data-processing arrangements<\/strong>: contracts that define the provider&#8217;s obligations<\/li>\n<li><strong>Incident handling<\/strong>: including incidents affecting the <strong><a href=\"https:\/\/www.newevol.io\/platform\/newevol.php\">SIEM platform<\/a><\/strong><\/li>\n<li><strong>Audit evidence<\/strong>: the records that prove all the above<\/li>\n<\/ul>\n<p>A cloud provider may operate the infrastructure. The enterprise still owns the outcome. The same holds in reverse: running a SIEM in your own rack does not create governance by itself. Self-hosting proves nothing if access approvals were never recorded.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_Each_Model_Makes_Easier_or_Harder_to_Prove\"><\/span>What Each Model Makes Easier or Harder to Prove<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The useful comparison is not features. It is evidence.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Lawful_Basis_and_Data_Retention\"><\/span><span style=\"font-size: 70%;\">Lawful Basis and Data Retention<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Security telemetry needs a defined purpose. &#8220;We might need it someday&#8221; is not one. Enterprises should be able to state, per data source, why it is collected and how long it is held.<\/p>\n<p>Retention creates genuine tension. Investigators want long lookback windows, because attacker dwell time is frequently measured in months. Data protection principles discourage keeping personal data beyond what the purpose requires. A workable approach is tiered: shorter windows for high-volume, user-identifying sources, longer windows for lower-volume records with clear investigative value, with the reasoning documented. Indefinite storage is not a defensible strategy. It is usually just an unexamined default.<\/p>\n<p>On-premises deployments give direct control over storage and deletion, but the enterprise has to build and evidence the deletion mechanism itself. Cloud platforms often ship with policy-driven retention tiers that generate their own logs, which can make demonstration easier, though the enterprise must verify that deletion occurs across backups and archives rather than trusting the console.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Data_Principal_Rights_vs_Forensic_Requirements\"><\/span><span style=\"font-size: 70%;\">Data Principal Rights vs Forensic Requirements<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A data principal exercising rights over their personal data can create friction with security operations. A request for touching data held in the SIEM cannot simply be actioned by deleting log records.<\/p>\n<p>Security logs may need preserving for legitimate reasons: an active investigation, a legal hold, a regulatory reporting obligation, or the integrity of an evidence chain. Deleting them on request could compromise an investigation or destroy material the enterprise is required to keep.<\/p>\n<p>The answer is a documented process, agreed between legal, privacy, and security, defining how such requests are assessed, what grounds support retention, who decides, and how the decision is recorded. Build it before the first request arrives, not during it.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Processor_Contracts_and_Cloud_Providers\"><\/span><span style=\"font-size: 70%;\">Processor Contracts and Cloud Providers<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Where a cloud SIEM is used, the provider is processing telemetry on the enterprise&#8217;s behalf. That relationship needs examining in detail:<\/p>\n<ul>\n<li>Contractual responsibilities and security obligations<\/li>\n<li>Data-processing terms and permitted use of customer data<\/li>\n<li>Named sub-processors and how changes are notified<\/li>\n<li>Storage and backup locations<\/li>\n<li>Incident notification timelines and content<\/li>\n<li>Access controls governing provider personnel<\/li>\n<\/ul>\n<p>The compliance question is not &#8220;is the SIEM in the cloud?&#8221; It is &#8220;can we demonstrate appropriate governance over the party processing our telemetry?&#8221; A well-governed cloud deployment with clear contracts and reviewed sub-processors can be easier to defend than an on-premises system nobody has audited in three years.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Cross-Border_Transfer_of_Telemetry\"><\/span><span style=\"font-size: 70%;\">Cross-Border Transfer of Telemetry<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Data flows are rarely as simple as the architecture diagram suggests. Before approving a SIEM design, map:<\/p>\n<ul>\n<li>Where primary telemetry is stored<\/li>\n<li>Where backups and disaster recovery copies reside<\/li>\n<li>Where support and engineering teams access the environment from<\/li>\n<li>Whether threat intelligence lookups send indicators or samples externally<\/li>\n<li>Whether <strong><a href=\"https:\/\/www.newevol.io\/solutions\/automated-response-orchestration.php\">SOAR<\/a><\/strong> actions, ticketing, or analytics integrations create additional flows<\/li>\n<\/ul>\n<p>The point is not that cross-border processing is prohibited. It is that an enterprise should know which jurisdictions are involved and be able to explain them. On-premises deployments can create cross-border flows too, through vendor support access or cloud-hosted threat feeds. Assumptions in either direction rarely survive in contact with a data flow map.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Administrative_Access_and_Vendor_Support\"><\/span><span style=\"font-size: 70%;\">Administrative Access and Vendor Support<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Privileged access to a SIEM is access to the organization&#8217;s most sensitive telemetry. Controls worth evidencing include role-based access, MFA on all administrative accounts, recorded approvals for privileged sessions, session logging for vendor and remote troubleshooting, defined emergency access procedures, and audit trails showing who queried what.<\/p>\n<p>On-premises environments give direct control over these mechanisms, but the burden of building and maintaining them falls internally. Cloud platforms typically provide detailed access logging out of the box, including provider-side access in mature offerings, though the enterprise must confirm what provider activity is visible and retained.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Decision_Matrix_On-Premises_vs_Cloud_SIEM\"><\/span>Decision Matrix: On-Premises vs Cloud SIEM<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table class=\"table table-bordered\" style=\"font-weight: 400;\" data-tablestyle=\"MsoNormalTable\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\">\n<p><strong><span data-contrast=\"auto\">Consideration<\/span><\/strong><\/p>\n<\/td>\n<td style=\"text-align: center;\">\n<p><strong><span data-contrast=\"auto\">On-Premises SIEM<\/span><\/strong><\/p>\n<\/td>\n<td style=\"text-align: center;\">\n<p><strong><span data-contrast=\"auto\">Cloud SIEM<\/span><\/strong><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Data-location control<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Direct and verifiable; location is a design decision<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Defined by provider regions and contract; must be confirmed, including backups<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Retention control<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Full control; deletion mechanisms must be built and proven<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Policy-driven tiers with native logging; verify deletion across all copies<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Vendor access visibility<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Limited vendor access, but support sessions need monitoring<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Provider access is broader; look for transparency logging and approval workflows<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Processor governance<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Fewer processors involved; internal governance still&nbsp;required<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Central to the model; needs contract review and sub-processor tracking<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Cross-border considerations<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Usually simpler, though support and threat feeds can still create flows<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Requires explicit mapping of storage, backup, and support locations<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Scalability<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Constrained by procurement cycles and capacity planning<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Elastic; suits variable&nbsp;ingest&nbsp;and rapid growth<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Audit evidence<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Evidence must be assembled from internal systems<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Platform-generated reporting, but scope of coverage must be validated<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>\n<p><span data-contrast=\"auto\">Operational responsibility<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Fully internal, including patching and availability<\/span><\/p>\n<\/td>\n<td>\n<p><span data-contrast=\"auto\">Shared; enterprise&nbsp;retains&nbsp;configuration and governance responsibility<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><span class=\"ez-toc-section\" id=\"An_Auditor-Focused_Checklist\"><\/span>An Auditor-Focused Checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Whichever model is chosen, an enterprise should be able to answer these without preparation:<\/p>\n<ol>\n<li>What categories of personal data can enter the SIEM?<\/li>\n<li>Why is each category collected, and against what stated purpose?<\/li>\n<li>What is the documented retention period per data source, and what justifies it?<\/li>\n<li>Who can access the data, and how is that access approved?<\/li>\n<li>Can privileged access activity be demonstrated with logs?<\/li>\n<li>Where is telemetry stored, including backups and archives?<\/li>\n<li>From which locations can support personnel access it?<\/li>\n<li>Which processors and sub-processors are involved?<\/li>\n<li>How are third-party integrations reviewed and governed?<\/li>\n<li>How are data principal requests touching security logs handled?<\/li>\n<li>How are logs preserved during investigations and legal holds?<\/li>\n<li>Can evidence for all of the above be produced during an audit?<\/li>\n<\/ol>\n<p>If the answers exist and are documented, either architecture can be defended. If they do not, neither can.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"When_Each_Model_May_Make_Sense\"><\/span>When Each Model May Make Sense<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>On-premises may suit enterprises with:<\/strong><\/p>\n<ul>\n<li>Strict internal governance or sector expectations around data location<\/li>\n<li>Existing <strong><a href=\"https:\/\/www.sattrix.com\/managed-services\/soc-as-a-service.php\">SOC infrastructure<\/a> <\/strong>and skilled operations staff<\/li>\n<li>Architectural constraints such as air-gapped or restricted environments<\/li>\n<li>A preference for direct, verifiable control over storage and deletion<\/li>\n<\/ul>\n<p><strong>Cloud may suit enterprises with:<\/strong><\/p>\n<ul>\n<li>Rapidly growing or unpredictable log volumes<\/li>\n<li>Limited capacity to manage infrastructure internally<\/li>\n<li>Distributed sites, remote workforces, or multi-cloud estates<\/li>\n<li>Confidence in provider governance backed by strong contractual controls<\/li>\n<\/ul>\n<p>Many enterprises land on a hybrid: sensitive sources retained locally, broader analytics in the cloud. That can work, provided the split is deliberate and documented rather than a byproduct of two separate procurement decisions.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Evaluating_Any_SIEM_Platform\"><\/span>Evaluating Any SIEM Platform<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The same criteria apply to every platform under consideration, including <strong><a href=\"https:\/\/www.newevol.io\/solutions\/unified-data-architecture-for-security-analytics.php\">modern analytics-driven<\/a><\/strong> options such as NewEvol. Ask about data-location options and residency guarantees, granularity of access controls and administrative visibility, retention management at the data-source level, native auditability and exportable evidence, the integration architecture and what data leaves the environment, and how detection analytics handle user-identifying attributes.<\/p>\n<p>A platform that answers these clearly makes the compliance story easier to write, in either deployment model.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>There is no DPDP-mandated correct SIEM deployment model. The defensible choice is the architecture where the enterprise can demonstrate control over security telemetry, data access, retention, processing, and the data flows around it.<\/p>\n<p>Document the reasoning behind the decision, record the alternatives considered and why they were set aside, and keep the evidence current. An enterprise that can walk an auditor through that reasoning is in a far stronger position than one that picked up an architecture because it sounded safer.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_Does_the_DPDP_Act_require_an_on-premises_SIEM\"><\/span><span style=\"font-size: 70%;\">1. Does the DPDP Act require an on-premises SIEM?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No. The Act does not specify deployment models for security tooling. It expects reasonable security safeguards and accountability for how personal data is handled.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Is_cloud_SIEM_compliant_with_the_DPDP_Act\"><\/span><span style=\"font-size: 70%;\">2. Is cloud SIEM compliant with the DPDP Act?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A cloud SIEM is neither compliant nor non-compliant by default. Compliance depends on governance, contracts, access controls, retention practices, and the enterprise&#8217;s ability to evidence them.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_Can_SIEM_logs_contain_personal_data\"><\/span><span style=\"font-size: 70%;\">3. Can SIEM logs contain personal data?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Often, yes. Authentication records, endpoint telemetry, email events, and IP-linked session data can relate to identifiable individuals. Applicability depends on what a specific log contains and whether it can be linked to a person.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_How_long_should_security_logs_be_retained\"><\/span><span style=\"font-size: 70%;\">4. How long should security logs be retained?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>There is no single answer. Retention should be set per data source, balancing investigative need against the principle of not keeping personal data longer than the purpose requires, with the reasoning documented.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_What_should_enterprises_check_in_a_cloud_SIEM_providers_contract\"><\/span><span style=\"font-size: 70%;\">5. What should enterprises check in a cloud SIEM provider&#8217;s contract?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Data-processing terms, security obligations, storage and backup locations, named sub-processors and change notification, incident notification timelines, provider access controls, and deletion commitments on termination.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_Does_storing_SIEM_data_outside_India_automatically_make_the_deployment_non-compliant\"><\/span><span style=\"font-size: 70%;\">6. Does storing SIEM data outside India automatically make the deployment non-compliant?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not automatically. Cross-border processing is subject to applicable restrictions and government notifications, so enterprises should map jurisdictions, review the current legal position, and take advice rather than assume either outcome.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_What_evidence_should_an_enterprise_maintain\"><\/span><span style=\"font-size: 70%;\">7. What evidence should an enterprise maintain?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A data inventory for the SIEM, documented retention policies with justification, access control records and privileged session logs, processor contracts and reviews, data flow maps, and the documented process for handling data principal requests touching security logs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most conversations about SIEM architecture and India&#8217;s Digital Personal Data Protection (DPDP) Act start in the wrong place. A security leader asks whether the law permits a cloud of SIEM. A compliance head asks whether keeping logs in the data centre is safer. A vendor answers with whichever architecture it happens to sell. The Act&hellip; <a class=\"more-link\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\">Continue reading <span class=\"screen-reader-text\">DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?<\/span><\/a><\/p>\n","protected":false},"author":6,"featured_media":2629,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,15],"tags":[],"class_list":["post-2626","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-siem","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol\" \/>\n<meta property=\"og:description\" content=\"Most conversations about SIEM architecture and India&#8217;s Digital Personal Data Protection (DPDP) Act start in the wrong place. A security leader asks whether the law permits a cloud of SIEM. A compliance head asks whether keeping logs in the data centre is safer. A vendor answers with whichever architecture it happens to sell. The Act&hellip; Continue reading DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\" \/>\n<meta property=\"og:site_name\" content=\"NewEvol\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/NewEvolPlatform\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-10T09:02:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-10T11:15:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Krunal Medapara\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@krunalpatel17\" \/>\n<meta name=\"twitter:site\" content=\"@NewEvolPlatform\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Krunal Medapara\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\",\"url\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\",\"name\":\"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol\",\"isPartOf\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png\",\"datePublished\":\"2026-09-10T09:02:54+00:00\",\"dateModified\":\"2026-09-10T11:15:05+00:00\",\"author\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage\",\"url\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png\",\"contentUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png\",\"width\":1920,\"height\":900,\"caption\":\"On-Premises SIEM\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.newevol.io\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#website\",\"url\":\"https:\/\/www.newevol.io\/resources\/\",\"name\":\"NewEvol\",\"description\":\"Innovation in Motion\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.newevol.io\/resources\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680\",\"name\":\"Krunal Medapara\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg\",\"contentUrl\":\"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg\",\"caption\":\"Krunal Medapara\"},\"description\":\"Krunal Mendapara is the Chief Technology Officer, responsible for creating product roadmaps from conception to launch, driving the product vision, defining go-to-market strategy, and leading design discussions.\",\"sameAs\":[\"https:\/\/www.newevol.io\/\",\"https:\/\/x.com\/krunalpatel17\"],\"url\":\"https:\/\/www.newevol.io\/resources\/author\/krunal-medapara\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/","og_locale":"en_US","og_type":"article","og_title":"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol","og_description":"Most conversations about SIEM architecture and India&#8217;s Digital Personal Data Protection (DPDP) Act start in the wrong place. A security leader asks whether the law permits a cloud of SIEM. A compliance head asks whether keeping logs in the data centre is safer. A vendor answers with whichever architecture it happens to sell. The Act&hellip; Continue reading DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?","og_url":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/","og_site_name":"NewEvol","article_publisher":"https:\/\/www.facebook.com\/NewEvolPlatform\/","article_published_time":"2026-09-10T09:02:54+00:00","article_modified_time":"2026-09-10T11:15:05+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png","type":"image\/png"}],"author":"Krunal Medapara","twitter_card":"summary_large_image","twitter_creator":"@krunalpatel17","twitter_site":"@NewEvolPlatform","twitter_misc":{"Written by":"Krunal Medapara","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/","url":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/","name":"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud? - NewEvol","isPartOf":{"@id":"https:\/\/www.newevol.io\/resources\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage"},"image":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage"},"thumbnailUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png","datePublished":"2026-09-10T09:02:54+00:00","dateModified":"2026-09-10T11:15:05+00:00","author":{"@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680"},"breadcrumb":{"@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#primaryimage","url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png","contentUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2026\/09\/newevol-onprem-vs-cloud-banner-noflow-1920x900-1.png","width":1920,"height":900,"caption":"On-Premises SIEM"},{"@type":"BreadcrumbList","@id":"https:\/\/www.newevol.io\/resources\/blog\/dpdp-act-compliant-siem-should-indian-enterprises-choose-on-prem-or-cloud\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.newevol.io\/resources\/"},{"@type":"ListItem","position":2,"name":"DPDP Act Compliant SIEM: Should Indian Enterprises Choose On-Prem or Cloud?"}]},{"@type":"WebSite","@id":"https:\/\/www.newevol.io\/resources\/#website","url":"https:\/\/www.newevol.io\/resources\/","name":"NewEvol","description":"Innovation in Motion","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.newevol.io\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/7929a2b0ea108d69f18541bb94a98680","name":"Krunal Medapara","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.newevol.io\/resources\/#\/schema\/person\/image\/","url":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg","contentUrl":"https:\/\/www.newevol.io\/resources\/wp-content\/uploads\/2022\/03\/krunal-mendapara-1-scaled.jpg","caption":"Krunal Medapara"},"description":"Krunal Mendapara is the Chief Technology Officer, responsible for creating product roadmaps from conception to launch, driving the product vision, defining go-to-market strategy, and leading design discussions.","sameAs":["https:\/\/www.newevol.io\/","https:\/\/x.com\/krunalpatel17"],"url":"https:\/\/www.newevol.io\/resources\/author\/krunal-medapara\/"}]}},"_links":{"self":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/comments?post=2626"}],"version-history":[{"count":1,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2626\/revisions"}],"predecessor-version":[{"id":2628,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/posts\/2626\/revisions\/2628"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/media\/2629"}],"wp:attachment":[{"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/media?parent=2626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/categories?post=2626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newevol.io\/resources\/wp-json\/wp\/v2\/tags?post=2626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}