Data LocalisationIndia
AMLEGALS / Services / Data Localisation
Data Localisation

India data localisation compliance for foreign companies

Cross border data transfer framework under DPDPA, RBI payment data localisation, sectoral data residency mandates, data processing agreement requirements and compliance architecture for foreign companies processing personal data of Indian individuals.

Counsel that connects the technical, the commercial, and the legal, across ten offices in India.
DPDPA
2023
RBI
Data Localisation
Cross Border
Transfer
10
India Offices
01

DPDPA cross border transfer framework

  • Section 16 of DPDPA: transfer of personal data outside India permitted to all countries except those notified by the Central Government as restricted.
  • Negative list approach: transfers are permitted unless the destination country is specifically restricted by government notification.
  • Data Fiduciary obligations apply regardless of where data is processed: notice, consent, purpose limitation and data breach notification.
  • Significant Data Fiduciary obligations: additional requirements including data protection impact assessment and appointment of DPO resident in India.
02

RBI and sectoral data localisation mandates

  • RBI circular of April 2018: entire payment data (end to end transaction details) must be stored exclusively in India.
  • Applicable to payment system operators, banks and entities in the payment ecosystem.
  • Data mirroring (storing a copy abroad) permitted but primary data must reside in India with unfettered access for RBI.
  • IRDAI, SEBI and telecom sector specific data handling and storage guidelines.
03

Compliance architecture design

  • Data mapping: identifying personal data of Indian Data Principals processed by the foreign company.
  • Data flow analysis: cross border transfer pathways and storage locations.
  • Technical measures: encryption, access controls, data segregation and audit logging.
  • Contractual framework: data processing agreements, standard contractual clauses and inter company data transfer agreements.
04

How AMLEGALS assists

  • Data localisation impact assessment for foreign companies with India data flows.
  • DPDPA compliance programme design including privacy notice, consent mechanism and breach response.
  • RBI data localisation compliance for payment service providers.
  • Data processing agreement drafting and cross border transfer mechanism advisory.
Answers

What clients ask before they commit.

Short, direct, on the record.

01Does DPDPA require all personal data of Indians to be stored in India?

No. DPDPA adopts a negative list approach under Section 16. Personal data can be transferred outside India to any country unless the Central Government specifically restricts transfer to that country by notification. As of the current date, no countries have been notified as restricted. However, sectoral regulations (RBI for payment data) impose stricter localisation requirements.

02What are the RBI data localisation requirements for payment companies?

The RBI circular of April 2018 requires that all payment system data (full end to end transaction details, information collected, carried and processed as part of the message or payment instruction) must be stored in a system only in India. Foreign payment companies must ensure domestic storage within 24 hours of transaction processing and provide unfettered supervisory access to RBI.

03Does a foreign company without an India office need to comply with DPDPA?

Yes. DPDPA applies to processing of digital personal data outside India if it is in connection with offering goods or services to Data Principals within India. A foreign company processing personal data of Indian individuals (even from abroad) must comply with DPDPA including appointment of a representative in India if notified as a Significant Data Fiduciary.

04What penalties does DPDPA impose for non compliance?

DPDPA provides for penalties up to INR 250 crore (approximately USD 30 million) as a statutory ceiling for a given default, determined by the Data Protection Board after inquiry. This is not a flat per breach penalty. Specific defaults have defined penalty ceilings: failure to take security safeguards (up to INR 250 crore), failure to notify breach (up to INR 200 crore), non compliance with children data obligations (up to INR 200 crore).

Engage AMLEGALS

Discuss India data localisation or DPDPA compliance

Share the data types, processing locations and the sector for a preliminary compliance assessment.

Get in Touch[email protected]
Engagements are conducted under attorney work product and privilege.