India’s localization story is widely misread. The DPDPA did not localize anything: it adopted one of the world’s more permissive transfer models, everything flows unless the government blacklists a destination, and the blacklist is empty. The hard requirements live in sector law, and the hardest of them, the RBI’s payments directive, has been enforced against three of the world’s largest card networks. Localization compliance in India is therefore a classification problem: know which of your data is payments, insurance, telecom, or government data, and localize that.
| General rule | DPDPA s.16: transfers allowed except to notified countries (none yet) |
|---|---|
| Hard mandate | RBI: payment-system data stored only in India (April 2018) |
| Enforcement | Card-network onboarding bans, 2021 |
| Regulators | RBI, IRDAI, DoT, MeitY |
The RBI regime in practice
The 2018 circular’s operational rules: payment data at rest exists only in India; foreign processing is allowed but data must return within one business day and be purged abroad; cross-border transactions may keep the foreign leg’s data offshore; and compliance is demonstrated through a system audit report from a CERT-IN-empanelled auditor filed with the RBI. The 2021 card-network bans established that the RBI treats audit deficiencies as market-access issues, not paperwork, and every payment aggregator licensed since then has had localization architecture as a licensing precondition.
The DPDPA layer and its hooks
Today the act adds accountability, not residency: fiduciaries answer for transfers like any other processing, and security-safeguard duties follow the data abroad. Two hooks could change the picture without new legislation: the section 16 blacklist power, and the draft rules’ provision letting the government direct Significant Data Fiduciaries to keep specified data and traffic data within India. Geopolitics makes both live levers; contracts and architectures should treat Indian localization scope as expandable.
Design checklist
Inventory Indian data by regulatory class; place RBI-covered stores in Indian regions with the one-day repatriation pipeline; verify insurer and telecom entities against their sector rules; keep DPDPA transfer records for everything else; and pre-negotiate data-relocation rights with processors. The wider act is covered in the DPDPA guide, and the contrast with China’s mandatory-mechanism model in the PIPL transfers guide. Map your India-facing collection with a free scan.