Cross border data transfer framework under DPDPA, RBI payment data localisation, sectoral data residency mandates, data processing agreement requirements and compliance architecture for foreign companies processing personal data of Indian individuals.
Short, direct, on the record.
No. DPDPA adopts a negative list approach under Section 16. Personal data can be transferred outside India to any country unless the Central Government specifically restricts transfer to that country by notification. As of the current date, no countries have been notified as restricted. However, sectoral regulations (RBI for payment data) impose stricter localisation requirements.
The RBI circular of April 2018 requires that all payment system data (full end to end transaction details, information collected, carried and processed as part of the message or payment instruction) must be stored in a system only in India. Foreign payment companies must ensure domestic storage within 24 hours of transaction processing and provide unfettered supervisory access to RBI.
Yes. DPDPA applies to processing of digital personal data outside India if it is in connection with offering goods or services to Data Principals within India. A foreign company processing personal data of Indian individuals (even from abroad) must comply with DPDPA including appointment of a representative in India if notified as a Significant Data Fiduciary.
DPDPA provides for penalties up to INR 250 crore (approximately USD 30 million) as a statutory ceiling for a given default, determined by the Data Protection Board after inquiry. This is not a flat per breach penalty. Specific defaults have defined penalty ceilings: failure to take security safeguards (up to INR 250 crore), failure to notify breach (up to INR 200 crore), non compliance with children data obligations (up to INR 200 crore).
Share the data types, processing locations and the sector for a preliminary compliance assessment.