What Is Data Localisation in India?
Data localisation in India is not a single law. It is a set of sector-specific rules that require particular categories of data to be stored, and in some cases processed, only on systems located inside the country. The strictest version applies to payment systems: since 2018, the Reserve Bank of India (RBI) has required that the entire data relating to a payment transaction be stored only in India. Other regimes are lighter. The Digital Personal Data Protection Act, 2023 (DPDP Act) does not require Indian personal data to stay in India by default — it instead gives the Central Government power to name specific countries where transfer is restricted. CERT-In's 2022 Directions sit in between: they do not restrict where a business is based, but they require security logs to be retained inside Indian jurisdiction for 180 days. A foreign company's obligations depend entirely on which sector it is in — payments, insurance, and general digital operations each carry a different rule.
Legal Basis
Payment System Data — RBI Circular of 6 April 2018
The foundational data localisation rule in India is the RBI circular RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018, dated 6 April 2018, on "Storage of Payment System Data." Its operative instruction is direct: "All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India." The circular defines the scope broadly: the data to be localised "should include the full end-to-end transaction details / information collected / carried / processed as part of the message / payment instruction."
The circular applies to authorised payment systems, scheduled commercial banks (including Regional Rural Banks), urban and state co-operative banks, district central co-operative banks, payments banks, small finance banks, and local area banks. Entities were originally given six months to comply, with a compliance report due by 15 October 2018 and a System Audit Report by 31 December 2018 — historical deadlines now, though the underlying storage obligation is ongoing.
The circular allows one narrow exception: "For the foreign leg of the transaction, if any, the data can also be stored in the foreign country, if required." RBI's published FAQs on the circular sharpen this further. Processing abroad is not itself barred — the FAQs say there is "no bar on processing of payment transactions outside India if so desired by the PSOs" — but the data must come home afterwards: "In case the processing is done abroad, the data should be deleted from the systems abroad and brought back to India not later than the one business day or 24 hours from payment processing, whichever is earlier." For a cross-border transaction with a foreign and a domestic component, a copy of the domestic component "may also be stored abroad, if required," while a purely domestic payment transaction may be stored only in India. This delete-and-repatriate rule, rather than any mirroring allowance, is why global payment processors run India-specific storage instead of routing Indian transactions through a single worldwide data centre.
Digital Personal Data — Section 16 of the DPDP Act, 2023
The DPDP Act takes a different, more permissive approach to cross-border data. Section 16(1) of the Act states: "The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." This is a negative-list mechanism — transfer is allowed by default, and the government's power is to name specific restricted destinations, not to require that data stay in India as a general rule. Section 16(2) then preserves everything else: "Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof." In practice, this is the provision that keeps the RBI payment-data circular, CERT-In's log-retention rule, and any sector regulator's stricter data rule fully in force alongside the DPDP Act — the DPDP Act does not soften them.
CERT-In Directions 2022 — Logs Within Indian Jurisdiction
The CERT-In Directions of 28 April 2022 add a general, cross-sector localisation requirement that is narrower than RBI's but reaches far wider in who it binds: "All service providers, intermediaries, data centres, body corporate and Government organisations shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction." That covers a foreign company's Indian subsidiary, and the foreign company itself where it operates in India as a body corporate. Separately, providers of VPN, VPS, cloud, and data-centre services must record and retain validated subscriber names, contact details, IP address allocations with timestamps, and the purpose for which the service was used, for five years — even after the customer relationship ends.
Insurance — IRDAI Information and Cyber Security Guidelines, 2026
Insurance carries its own version of the same CERT-In rule rather than a separate blanket localisation mandate. The Insurance Regulatory and Development Authority of India's Information and Cyber Security Guidelines, 2026 (Ref. IRDAI/GA&HR/CIR/MISC/51/4/2026, dated 6 April 2026, to be complied with from the current financial year) directly imports CERT-In's location requirement: "ICT infrastructure logs shall be maintained for a rolling period of 180 days and within the Indian jurisdiction as per directions issued by Cert-In from time to time." These guidelines revise the IRDAI cyber security guidelines of 24 April 2023, and apply to "All Insurers including FRBs, Insurance Intermediaries covering Brokers, Corporate Agents, Web Aggregators, TPAs, IMFs, insurance Repositories, ISNP, Corporate Surveyors, MISPs, CSCs and the Insurance Information Bureau of India (IIB)" — a wider net than just the insurer itself. The same guidelines separately require regulated entities to "take appropriate technical and organizational measures to comply with the provisions of Digital Personal Data Protection Act (DPDP) and rules made thereunder," and to "build the right to audit as part of contract with vendors."
How the Rules Compare
| Sector / Framework | Regulator | What Must Be In India | Source |
|---|---|---|---|
| Payment systems (banks, PSOs, payment aggregators) | RBI | Entire end-to-end transaction data. On a cross-border transaction the foreign leg, and a copy of the domestic component, may also sit abroad; a purely domestic transaction only in India. Data processed abroad must be deleted there and brought back within 24 hours or one business day, whichever is earlier | RBI circular, 6 April 2018 + FAQs |
| Any body corporate with Indian operations (incl. foreign subsidiaries, VPN/cloud/data-centre providers) | CERT-In | 180 days of ICT system logs, retained within Indian jurisdiction; VPN/cloud/data-centre subscriber and IP records for 5 years | CERT-In Directions, 28 April 2022 |
| Insurers and insurance intermediaries | IRDAI | Same 180-day, in-India log rule as CERT-In, applied across insurers, brokers, agents, TPAs and web aggregators | IRDAI Information and Cyber Security Guidelines, 2026 |
| Personal data generally | MeitY / Central Government | Nothing, by default — transfer is permitted unless the destination country is specifically notified as restricted | Section 16, DPDP Act 2023 |
Read together, India does not have one uniform "data localisation law." It has a strict rule for payment data, a general log-retention rule for any regulated digital operation, a sector echo of that rule for insurance, and a permissive default for personal data generally that can tighten only through a specific government notification.
Why This Matters for a Foreign Company
For a foreign company setting up in India, these rules shape infrastructure decisions before they shape legal ones. A payment or fintech business cannot simply route Indian transactions through a global data centre and sync back on its own schedule — the 24-hour/one-business-day rule forces India-specific processing or storage infrastructure. The CERT-In Directions bind service providers, intermediaries, data centres, body corporate and Government organisations alike, so an Indian subsidiary is inside the 180-day in-India log requirement from day one of operations regardless of size, and a foreign company operating in India is caught as a body corporate in its own right. A company relying on a corporate VPN gateway for its India staff should confirm the gateway itself, not just the parent's global VPN vendor, is retaining the required subscriber and IP records for five years. An insurer, broker, TPA, or web aggregator entering the Indian market inherits the IRDAI version of the same log rule, on top of whatever RBI or DPDP obligations apply separately. None of this is displaced by the DPDP Act: Section 16(2) specifically keeps every one of these sector rules alive.
A quick applicability check:
- Does the business operate a payment system, or process payments on behalf of others? — the RBI in-India storage rule and 24-hour mirror rule apply.
- Does the business have any Indian legal presence — subsidiary, branch, or liaison office — or provide VPN, cloud, or data-centre services to Indian customers? — the CERT-In 180-day in-India log rule applies.
- Is the business an insurer, broker, corporate agent, TPA, or web aggregator? — the IRDAI 2026 Guidelines apply the same log rule, plus DPDP compliance and vendor-audit obligations.
- Does the business process personal data of people in India, including remotely from outside the country? — the DPDP Act applies, but cross-border transfer is permitted unless the destination is specifically notified as restricted.
Practical Example
A Singapore-headquartered payment gateway signs up Indian merchants and initially authorises and settles transactions through its regional data centre in Singapore, leaving the transaction records there before forwarding settlement files to its Indian banking partner. Processing in Singapore is not the problem — RBI's FAQs expressly allow processing outside India. The storage arrangement is what fails: the entire end-to-end transaction data must sit in a system located in India, and because processing is happening abroad, the FAQs require the data to be deleted from the Singapore systems and brought back to India within one business day or 24 hours of that processing, whichever is earlier. The company rebuilds its pipeline so every processed transaction lands in Indian storage inside that window, keeping abroad only the foreign leg and, where genuinely needed, a copy of the domestic component. Once it incorporates an Indian subsidiary to hold its RBI authorisation, that subsidiary is also a "body corporate" under the CERT-In Directions: it must retain 180 days of ICT system logs on infrastructure in Indian jurisdiction and report qualifying incidents to CERT-In within six hours of becoming aware of them. If the same group later launches an embedded-insurance product distributed through an Indian corporate agent, that agent — and the group's own ICT systems supporting it — fall under the IRDAI 2026 Guidelines' identical log-retention requirement.
Common Mistakes
- Assuming the DPDP Act imposes a general data-localisation requirement. It does not. Section 16 is a permissive default with a notification-based restriction power — the blanket India-only obligation comes from RBI's payment-data circular, not from the DPDP Act.
- Believing a same-day sync satisfies the RBI rule. The FAQs are specific: data processed abroad must be deleted from the foreign system and brought back within one business day or 24 hours, whichever is earlier — a copy sent to India while the original stays abroad is not compliance, and a "nightly batch" job that runs later can fall outside the window.
- Stretching the cross-border exception to cover domestic transactions. The circular's foreign-leg allowance and the FAQs' allowance for a copy of the domestic component to sit abroad both apply only to cross-border transactions. Data for a purely domestic payment transaction may be stored only in India.
- Assuming a cloud provider's default log retention meets CERT-In's rule. The 180-day retention must be within Indian jurisdiction specifically — logs kept on infrastructure located outside India do not satisfy the Directions even if retained for the full 180 days.
- Overlooking intermediaries when checking IRDAI applicability. The 2026 Guidelines apply not only to insurers but explicitly to brokers, corporate agents, web aggregators, TPAs, IMFs, insurance repositories, corporate surveyors, MISPs and CSCs.
Frequently Asked Questions
Does India have one single "data localisation law"?
No. India regulates data location through separate, sector-specific rules rather than one statute. The strictest rule — full in-India storage — applies to payment system data under an RBI circular. CERT-In's Directions add a 180-day in-India log-retention rule for any regulated digital operation, IRDAI applies the same log rule to insurance, and the DPDP Act governs personal data generally through a more permissive, notification-based mechanism.
Can a foreign payment processor use servers located outside India at all?
Yes. Processing outside India is not barred at all, and on a cross-border transaction the foreign leg, plus a copy of the domestic component, may be stored abroad. But the India copy is always mandatory, a purely domestic transaction may be stored only in India, and where processing happens abroad RBI's FAQs require the data to be deleted from the foreign system and brought back within one business day or 24 hours, whichever is earlier.
Does the DPDP Act require personal data about Indians to stay in India?
Not by default. Section 16 of the DPDP Act lets the Central Government restrict transfers to specific notified countries, but transfer is otherwise permitted. Section 16(2) separately confirms that any stricter sector law — such as RBI's payment-data rule — continues to apply in full alongside the DPDP Act.
Do CERT-In's log-retention rules apply to a foreign company's Indian subsidiary?
Yes. Any "body corporate" with Indian operations, including a small Indian subsidiary or branch, must retain 180 days of ICT system logs on infrastructure within Indian jurisdiction and report qualifying cyber incidents to CERT-In within six hours of becoming aware of them.
Are insurers subject to a separate data localisation rule from IRDAI?
Insurers follow the same 180-day, in-India log-retention rule as CERT-In's general Directions, restated in IRDAI's Information and Cyber Security Guidelines, 2026. That guideline applies broadly across insurers, brokers, corporate agents, web aggregators, TPAs, and several other insurance intermediary categories, alongside separate obligations to comply with the DPDP Act.
See also: DPDP Act 2023, CERT-In & Cybersecurity Compliance, and Digital Identity for Business.
Setting up India operations that need to meet RBI, CERT-In, or IRDAI data rules? Beacon Filing helps foreign companies map, localise, and audit their India data infrastructure alongside their broader compliance calendar.