Data Localisation in India: What Must Be Stored in the Country
India has no single data localisation law. A sector-by-sector guide to what must be stored in India: payment data, lending, insurance, securities, logs, accounts and government data.

Clients often ask whether Indian law requires their data to stay in India. The honest answer is that it depends on the sector. The DPDP Act does not impose general localisation, but several regulators do for the data they supervise. The architecture question is usually which tables must live in an Indian region, not whether the whole system must.
The general position under the DPDP Act
The Act lets personal data be transferred outside India, except to countries or territories the central government restricts by notification. It also preserves any other law that gives a higher degree of protection or restriction, so sector rules continue to apply. Under the Rules, Significant Data Fiduciaries may be required to ensure that specified personal data and related traffic data are not transferred outside India. Check for government notifications on both points.
Payments
RBI's April 2018 direction requires all payment system providers to store the entire data relating to payment systems they operate only in systems located in India. This covers end-to-end transaction details and information collected, carried or processed as part of a payment message. Processing abroad is permitted, but the data must be deleted from foreign systems and brought back to India within the period RBI specified. For a cross-border transaction, a copy of the domestic leg may also be kept abroad.
Payment data is the strictest case: stored only in India.
Other financial sector rules
Other financial regulators have their own requirements.
Rules that apply across sectors
A few requirements reach almost every company.
Designing for it
Treat residency as a property of each data class, decided at design time.
Common mistakes
The usual failures are indirect: a customer support tool hosted abroad that stores transaction details, error logs with payment data shipped to a foreign monitoring service, or database backups replicated to another country by default. Review every third-party tool that receives regulated data, not only the main database.
- RBI: Storage of Payment System Data (April 2018) and FAQs
- CERT-In Directions under section 70B of the IT Act, 28 April 2022
- Digital Personal Data Protection Act, 2023 (MeitY)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





