Compliance & Regulation

Data Localisation in India: What Must Be Stored in the Country

India has no single data localisation law. A sector-by-sector guide to what must be stored in India: payment data, lending, insurance, securities, logs, accounts and government data.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
7 min read
Data centre corridor with servers

Clients often ask whether Indian law requires their data to stay in India. The honest answer is that it depends on the sector. The DPDP Act does not impose general localisation, but several regulators do for the data they supervise. The architecture question is usually which tables must live in an Indian region, not whether the whole system must.

01

The general position under the DPDP Act

The Act lets personal data be transferred outside India, except to countries or territories the central government restricts by notification. It also preserves any other law that gives a higher degree of protection or restriction, so sector rules continue to apply. Under the Rules, Significant Data Fiduciaries may be required to ensure that specified personal data and related traffic data are not transferred outside India. Check for government notifications on both points.

02

Payments

RBI's April 2018 direction requires all payment system providers to store the entire data relating to payment systems they operate only in systems located in India. This covers end-to-end transaction details and information collected, carried or processed as part of a payment message. Processing abroad is permitted, but the data must be deleted from foreign systems and brought back to India within the period RBI specified. For a cross-border transaction, a copy of the domestic leg may also be kept abroad.

Payment data is the strictest case: stored only in India.

03

Other financial sector rules

Other financial regulators have their own requirements.

Digital lendingBorrower data stored on servers located in India; data processed abroad to be deleted there and brought back within 24 hours
Video KYCRecordings and data stored in systems located in India
InsurancePolicy and claim records held in data centres located in India
SecuritiesSEBI's cybersecurity and cloud frameworks expect regulated data to be stored in India, with cloud providers having Indian data centres
OutsourcingRegulators require that regulated entities and the regulator can access data and audit the provider wherever it is
04

Rules that apply across sectors

A few requirements reach almost every company.

System logsCERT-In's 2022 directions require logs of ICT systems to be maintained securely for a rolling 180 days within Indian jurisdiction
Books of accountCompany law requires electronic books of account to remain accessible in India, with backups kept on servers physically located in India
Government dataGovernment departments are expected to use MeitY-empanelled cloud services, with data residing in India
TelecomLicence conditions restrict transfer of subscriber and accounting information outside India
05

Designing for it

Treat residency as a property of each data class, decided at design time.

Classify data by residency ruleIndian region as primaryLogs retained in IndiaBackups in a second Indian regionCheck where SaaS vendors store dataAnalytics and support tools includedDeletion from foreign processing systemsDocument the data flow
06

Common mistakes

The usual failures are indirect: a customer support tool hosted abroad that stores transaction details, error logs with payment data shipped to a foreign monitoring service, or database backups replicated to another country by default. Review every third-party tool that receives regulated data, not only the main database.

Payments
Stored only in India
180 days
Logs kept within Indian jurisdiction
By sector
There is no single localisation law
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact