Asia-Pacific India

India Data Localization: RBI Rules, DPDPA, and Sector Mandates

Where India actually requires local data storage: RBI payments localization, insurance and telecom rules, and the DPDPA's negative-list transfer model.

Regulation

RBI Directive DPSS.CO.OD No.2785 (April 2018); DPDPA 2023 s.16; sectoral regulations

Max Penalty

RBI supervisory action including business restrictions; DPDPA penalties up to INR 250 crore

Enforcing Authority

Reserve Bank of India; IRDAI; DoT; Data Protection Board of India

Official Source

www.rbi.org.in

Executive Summary

  • India has no general data-localization law: the DPDPA allows cross-border transfers to all countries except those the government blacklists (none notified yet).
  • The binding localization mandates are sectoral, led by the RBI's April 2018 directive requiring end-to-end payment-system data to be stored only in India.
  • The RBI enforced it concretely: new-card onboarding bans on Mastercard, American Express, and Diners Club in 2021 for non-compliance, lifted only after certified remediation.
  • Insurance (IRDAI), telecom licensing, and government-procurement rules add their own residency requirements; the DPDPA's draft rules let the government impose localization on Significant Data Fiduciaries for specified data.
  • Compliance design is data-classification work: identify which flows carry regulated payment, insurance, or telecom data and architect residency for those, not for everything.

India’s localization story is widely misread. The DPDPA did not localize anything: it adopted one of the world’s more permissive transfer models, everything flows unless the government blacklists a destination, and the blacklist is empty. The hard requirements live in sector law, and the hardest of them, the RBI’s payments directive, has been enforced against three of the world’s largest card networks. Localization compliance in India is therefore a classification problem: know which of your data is payments, insurance, telecom, or government data, and localize that.

General ruleDPDPA s.16: transfers allowed except to notified countries (none yet)
Hard mandateRBI: payment-system data stored only in India (April 2018)
EnforcementCard-network onboarding bans, 2021
RegulatorsRBI, IRDAI, DoT, MeitY

The RBI regime in practice

The 2018 circular’s operational rules: payment data at rest exists only in India; foreign processing is allowed but data must return within one business day and be purged abroad; cross-border transactions may keep the foreign leg’s data offshore; and compliance is demonstrated through a system audit report from a CERT-IN-empanelled auditor filed with the RBI. The 2021 card-network bans established that the RBI treats audit deficiencies as market-access issues, not paperwork, and every payment aggregator licensed since then has had localization architecture as a licensing precondition.

The DPDPA layer and its hooks

Today the act adds accountability, not residency: fiduciaries answer for transfers like any other processing, and security-safeguard duties follow the data abroad. Two hooks could change the picture without new legislation: the section 16 blacklist power, and the draft rules’ provision letting the government direct Significant Data Fiduciaries to keep specified data and traffic data within India. Geopolitics makes both live levers; contracts and architectures should treat Indian localization scope as expandable.

Design checklist

Inventory Indian data by regulatory class; place RBI-covered stores in Indian regions with the one-day repatriation pipeline; verify insurer and telecom entities against their sector rules; keep DPDPA transfer records for everything else; and pre-negotiate data-relocation rights with processors. The wider act is covered in the DPDPA guide, and the contrast with China’s mandatory-mechanism model in the PIPL transfers guide. Map your India-facing collection with a free scan.

Frequently Asked Questions

Does the DPDPA require storing data in India?

No. Section 16 adopts a negative-list model: transfers are permitted to any country the central government has not restricted by notification, and no restriction list has been notified. But section 16(2) preserves stricter sectoral laws, so RBI, IRDAI, and telecom mandates continue unchanged, and the draft rules reserve power to require SDFs to keep specified data in India.

What exactly does the RBI mandate cover?

The April 2018 directive requires the entire end-to-end transaction data of payment systems, customer data, payment credentials, transaction details, to be stored in systems located only in India. Processing may occur abroad, but the data must be brought back within one business day and deleted from foreign systems, with limited exceptions for the foreign leg of cross-border transactions. Compliance is verified by CERT-IN-empanelled audit.

Has localization been enforced?

Yes, visibly. In 2021 the RBI barred Mastercard, American Express, and Diners Club from onboarding new domestic customers for non-compliance with the 2018 circular; the bans lasted months (Mastercard's nearly a year) until certified compliance. It remains one of the clearest localization-enforcement episodes anywhere.

Do other sectors have residency rules?

Insurance: IRDAI regulations require core records to be maintained in India. Telecom: license conditions restrict subscriber data transfers and require local storage of specified records. Government data: procurement and cloud-empanelment rules (MeitY) require empanelled providers to host designated workloads in India. Company accounts: MCA rules require books of account backups on servers in India.

How should global architectures respond?

Classify before you architect: most Indian personal data can flow globally under the DPDPA's permissive default, so the residency burden attaches to regulated classes, payments, insurance, telecom, government workloads. The standard pattern is an India data plane for regulated stores (local region of a hyperscaler qualifies, subject to audit), global processing with one-day repatriation for payments, and contract clauses reserving relocation if DPDPA blacklists or SDF directions arrive.

Regulatory Crosswalk

DPDPAPIPL localizationGDPR Chapter V

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.