INDIA
Since July 2005, last amended in October 2023
Pillar Domestic data policies |
Indicator Minimum period for data retention
The Prevention of Money-Laundering (Maintenance of Records) Rules, 2005
According to Section 3 of The Prevention of Money-Laundering (Maintenance of Records) Rules, banking information must be stored for 10 years "from the date of cessation of the transactions between the client and the banking company, financial institution or intermediary, as the case may be".
Coverage Banking companies and financial institutions
INDIA
Since December 2015
Pillar Domestic data policies |
Indicator Minimum period for data retention
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015
As per the Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, a listed entity (i.e. an entity which is listed on the stock market) is required to have a policy for the preservation of documents. The SEBI Listing Regulations require that records, books, papers and documents of the company be preserved as per the following classifications:
- Schedule I - to be preserved permanently. Documents listed under this schedule include incorporation documents, share certificates, register of minutes of board meetings, register of members, etc.
- Schedule II – to be preserved for eight years. Documents listed under this schedule include books of accounts, attendance register of board meetings, register for debenture holders, etc.
- Schedule III – to be preserved for a minimum period of five years or such higher period as may be determined by the board of directors of the company. Documents listed under this schedule include a register of stock options, a register of directors and key managerial personnel, disclosures made under applicable company laws, etc.
As per the SEBI Listing Regulations, documents set out in Schedule I and II can be kept in electronic mode. The complete list of documents under each schedule is set out in the SEBI Listing Regulations.
- Schedule I - to be preserved permanently. Documents listed under this schedule include incorporation documents, share certificates, register of minutes of board meetings, register of members, etc.
- Schedule II – to be preserved for eight years. Documents listed under this schedule include books of accounts, attendance register of board meetings, register for debenture holders, etc.
- Schedule III – to be preserved for a minimum period of five years or such higher period as may be determined by the board of directors of the company. Documents listed under this schedule include a register of stock options, a register of directors and key managerial personnel, disclosures made under applicable company laws, etc.
As per the SEBI Listing Regulations, documents set out in Schedule I and II can be kept in electronic mode. The complete list of documents under each schedule is set out in the SEBI Listing Regulations.
Coverage Listed (Public) Companies
INDIA
Since August 2023, entry into force in May 2027
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Digital Personal Data Protection Act, 2023
Pursuant to Section 10 of the Digital Personal Data Protection Act, a significant data fiduciary must appoint a data protection officer based in India, who is responsible, inter alia, for conducting periodic data protection impact assessments comprising a description of the rights of data principals, the purposes for which their personal data are processed, an evaluation and management of risks to those rights, and any additional matters prescribed in relation to such assessments. Under Section 2, a data fiduciary is defined as any person who, alone or jointly with others, determines the purposes and means of processing personal data; a significant data fiduciary refers to any data fiduciary, or class thereof, designated as such by the Central Government under Section 10; and a data principal denotes the individual to whom the personal data relate.
Coverage Horizontal
INDIA
Since February 2021
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
Under Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021, a "significant" social media intermediary (defined as a social media intermediary having number of registered users in India above 5,000,000) must appoint a Chief Compliance Officer who must ensure compliance with the Rules and will be liable in any proceedings relating to any relevant third-party information, data or communication link made available or hosted by that intermediary where he/she fails to ensure that such intermediary observes due diligence while discharging its duties under the Rules.
Coverage Significant social media intermediaries
INDIA
Since June 2000, as amended in October 2009, last amended in August 2023
Since October 2009
Since October 2009
Since October 2009
Since October 2009
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Information Technology Act, 2000
The Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009
Information Technology (Procedure and Safeguards for Monitoring and Collecting Traffic Data or Information) Rules, 2009
The Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009
Information Technology (Procedure and Safeguards for Monitoring and Collecting Traffic Data or Information) Rules, 2009
Under Section 69 of the Information Technology Act, both central and state governments are empowered to instruct any government agency to intercept, monitor, or decrypt electronic information. This authority can be exercised on the following grounds: in the interest of India's sovereignty or integrity; for the security of the State; to maintain friendly relations with foreign states; for public order; or to prevent or investigate the commission of an offence. Additionally, under Section 69B, the government is authorised to permit any agency to monitor and collect traffic data or information exchanged through a computer resource.
The Information Technology (Procedure and Safeguards for Interception, Monitoring, and Decryption of Information) Rules of 2009 and the Information Technology (Procedure and Safeguards for Monitoring and Collecting Traffic Data or Information) Rules of 2009, both promulgated under the Information Technology Act, provide procedural guidelines for carrying out such interception and monitoring. For example, Rule 3 of the latter Rules permits the collection and/or monitoring of traffic data or information via a computer resource for several purposes, including: forecasting imminent cyber incidents; monitoring network applications; identifying and determining viruses or computer contaminants; tracking cybersecurity breaches or incidents; identifying individuals who have breached or are suspected of breaching cybersecurity measures; conducting forensic analyses as part of investigations or internal audits of information security practices; accessing stored data for the enforcement of cybersecurity law; or addressing any other cybersecurity-related issues.
The Information Technology (Procedure and Safeguards for Interception, Monitoring, and Decryption of Information) Rules of 2009 and the Information Technology (Procedure and Safeguards for Monitoring and Collecting Traffic Data or Information) Rules of 2009, both promulgated under the Information Technology Act, provide procedural guidelines for carrying out such interception and monitoring. For example, Rule 3 of the latter Rules permits the collection and/or monitoring of traffic data or information via a computer resource for several purposes, including: forecasting imminent cyber incidents; monitoring network applications; identifying and determining viruses or computer contaminants; tracking cybersecurity breaches or incidents; identifying individuals who have breached or are suspected of breaching cybersecurity measures; conducting forensic analyses as part of investigations or internal audits of information security practices; accessing stored data for the enforcement of cybersecurity law; or addressing any other cybersecurity-related issues.
Coverage Horizontal
Sources
- https://web.archive.org/web/20211115020524/https://www.indiacode.nic.in/bitstream/123456789/1999/3/A2000-21.pdf
- https://web.archive.org/web/20231005133242/https://www.meity.gov.in/writereaddata/files/Information%20Technology%20(Procedure%20and%20Safeguards%20for%20Interception,%20Monitoring%20and%20Decryption%2...
- https://web.archive.org/web/20221223012141/https://upload.indiacode.nic.in/showfile?actid=AC_CEN_45_76_00001_200021_1517807324077&type=rule&filename=ru_cen_45_0_00028_1519711141735.pdf
- https://www.dataguidance.com/notes/india-third-country-assessment
- https://web.archive.org/web/20231221030143/https://www.gp-digital.org/world-map-of-encryption/
- Show more...
INDIA
Since December 2023
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Telecommunications Act, 2023
Pursuant to Art. 20(2) of the Telecommunications Act, 2023, in the event of a public emergency or in the interest of public safety, the Central Government, a State Government, or any officer specifically authorised by either, may issue an order—if deemed necessary or appropriate—directing that any message or category of messages, whether sent or received by any person or group of persons, through any telecommunication equipment or network, and relating to any specific subject, be prohibited from transmission, intercepted, detained, or disclosed in an intelligible format to the designated officer identified in the order. It is not clear whether a court order is required to access the data.
Coverage Horizontal
INDIA
Since June 2000, entry into force in October 2000, last amended in August 2023
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Information Technology Act, 2000
The Information Technology Act establishes a safe harbour regime for intermediaries for copyright infringements. Section 79 of the Act provides intermediaries with qualified immunity for unlawful content as long as they follow the prescribed due diligence requirements and do not conspire, abet or aid an unlawful act. However, the protection lapses if an intermediary with "actual knowledge" of any content used to commit an unlawful act or, on being notified of such content, fails to remove or restrict access to it.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20231204123614/https://eprocure.gov.in/cppp/rulesandprocs/kbadqkdlcswfjdelrquehwuxcfmijmuixngudufgbuubgubfugbububjxcgfvsbdihbgfGhdfgFHytyhRtMjk4NzY=
- https://web.archive.org/web/20241127192721/https://www.mondaq.com/india/social-media/1088968/intermediary-liability-in-india--moving-goalposts
- https://web.archive.org/web/20231210112408/https://www.forbesindia.com/article/iim-calcutta/indias-tryst-with-intermediary-liability-from-2000-to-2021-changing-paradigms-in-the-social-media-age/69121/...
- Show more...
INDIA
Since February 2021
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021 establish a safe harbour regime beyond intermediaries for copyright infringement. According to Rule 3.1(d), an intermediary, after receiving 'actual knowledge' through a court order or by being notified by a government agency, must remove information that is prohibited by law in relation to the interest and sovereignty of India, the security of the state, friendly relations with foreign states, public order, decency or morality, contempt of court, defamation, incitement to an offence or information which violates any law which is in force. Such information has to be removed within thirty-six hours from receipt of actual knowledge by the intermediary.
In addition, "significant social media intermediaries", defined as having more than five million registered Indian users, need to observe additional due diligence requirements to claim the immunity/safe harbour available. Rule 6 of the Information Technology Rules provides that even if a social media intermediary does not meet this user threshold, the Central Government may still require an intermediary to meet these additional obligations if it believes that their operations create a material risk of harm to the sovereignty and integrity of India or to the security of the State. This discretion to the Central government may lead to the arbitrary imposition of additional obligations on certain intermediaries. The additional due diligence requirements include appointing certain personnel for compliance, enabling identification of the first originator of the information on its platform under certain conditions, and deploying technology-based measures on a best-effort basis to identify certain types of content.
In addition, "significant social media intermediaries", defined as having more than five million registered Indian users, need to observe additional due diligence requirements to claim the immunity/safe harbour available. Rule 6 of the Information Technology Rules provides that even if a social media intermediary does not meet this user threshold, the Central Government may still require an intermediary to meet these additional obligations if it believes that their operations create a material risk of harm to the sovereignty and integrity of India or to the security of the State. This discretion to the Central government may lead to the arbitrary imposition of additional obligations on certain intermediaries. The additional due diligence requirements include appointing certain personnel for compliance, enabling identification of the first originator of the information on its platform under certain conditions, and deploying technology-based measures on a best-effort basis to identify certain types of content.
Coverage Internet Intermediaries
Sources
- https://web.archive.org/web/20230923205328/https://wilmap.stanford.edu/entries/information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021
- https://web.archive.org/web/20230929034953/https://sflc.in/analysis-information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021/
- https://web.archive.org/web/20231208000516/https://prsindia.org/billtrack/the-information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021
- Show more...
INDIA
Since October 2017
Pillar Intermediary liability |
Indicator User identity requirement
Regulation on the Use of Aadhaar e-KYC Service of the Unique Identity Authority of India (UIDAI) for Issuing New Mobile Connections and Re-Verification of Existing Subscribers via OTP-Based Authentication
According to the Regulation on the Use of Aadhaar e-KYC Service of the Unique Identity Authority of India (UIDAI) for Issuing New Mobile Connections and Re-Verification of Existing Subscribers via OTP-Based Authentication, Indian citizens are required to register their SIM card with their Aadhaar Card (a type of national identity card). Foreigners have to provide their passport, a photocopy of their Indian visa/ travel permit, a passport-sized photo and contact details.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20220125013040/https://dot.gov.in/sites/default/files/OTP%20Based%20Reverification.PDF?download=1
- https://web.archive.org/web/20231204204245/https://www.indiatoday.in/information/story/heres-how-an-indian-citizen-and-a-foreign-national-can-buy-a-sim-card-in-india-1841117-2021-08-15
INDIA
Since December 2018
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology Intermediaries Guidelines (Amendment) Rules, 2018
According to Art. 3.3 of the Information Technology Intermediaries Guidelines Rules, intermediaries are required to deploy technology-based automated tools or appropriate mechanisms with appropriate controls for proactively identifying and removing or disabling public access to unlawful information or content.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20220120082414/http://www.wipo.int/export/sites/www/copyright/en/doc/liability_of_internet_intermediaries.pdf
- https://web.archive.org/web/20220201093401/https://www.medianama.com/wp-content/uploads/Draft_Intermediary_Amendment_24122018.pdf
- https://web.archive.org/web/20201031191759/https://law.asia/intermediary-liability-rules-not-safe-harbour/
- Show more...
INDIA
Since June 2000, entry into force in October 2000, last amended in August 2023
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology Act, 2000
Section 69 of the Indian Information Technology Act (IITA) requires intermediaries to extend all facilities and technical assistance to intercept, monitor or decrypt information as well as to provide information stored in a computer or provide access to a computer resource when called upon to do so by certain agencies. This extends to online intermediaries, which are required to designate an officer to facilitate the execution of such orders. Intermediaries that fail to meet these obligations may be punished with imprisonment of up to seven years.
Coverage Internet intermediaries
INDIA
N/A
Pillar Telecom infrastructure & competition |
Indicator Signature of the WTO Telecom Reference Paper
Partial appendment of WTO Telecom Reference Paper to schedule of commitments
India has only partially appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector
INDIA
Since August 2023, entry into force in May 2027
Since November 2025, entry into force in May 2027
From April 2011 to May 2027
Since November 2025, entry into force in May 2027
From April 2011 to May 2027
Pillar Cross-border data policies |
Indicator Conditional flow regime
Digital Personal Data Protection Act, 2023
Digital Personal Data Protection Rules, 2025
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
Digital Personal Data Protection Rules, 2025
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
Section 16.1 of the Digital Personal Data Protection Act stipulates that the Central Government may, by notification, impose restrictions on the transfer of personal data by a data fiduciary for processing to any country or territory outside India as may be specified. In addition, Section 16.2 provides that nothing in Section 16 shall limit the operation of any law currently in force in India that affords a higher level of protection or imposes stricter conditions on the transfer of personal data by a data fiduciary outside India, whether in respect of particular categories of personal data, specific data fiduciaries, or designated classes thereof. Under Section 2, a data fiduciary is defined as any person who, either independently or jointly with others, determines the purpose and means of processing personal data.
Section 15 of the Digital Personal Data Protection Rules, which implement the Digital Personal Data Protection Act, provides that personal data processed by a data fiduciary under the Act may be transferred outside the territory of India, subject to the requirement that the data fiduciary complies with such conditions as the Central Government may prescribe, by general or special order, in relation to making such personal data available to any foreign State, or to any person, entity, or agency under the control of, or associated with, such a State; in addition, section 13.4 of the Rules requires a significant data fiduciary to implement measures ensuring that personal data specified by the Central Government, on the basis of recommendations of a committee constituted for that purpose, is processed subject to the restriction that both the personal data and the traffic data relating to its flow are not transferred outside the territory of India. “Significant data fiduciary” is defined as any data fiduciary or class of data fiduciaries notified as such by the Central Government under section 10 of the Act.
Once the Digital Personal Data Protection Act is fully in force, on 13 May 2027, the Information Technology Rules will be repealed. Rule 7 of Information Technology Rules states that the export of sensitive personal data or information within or outside India is permissible, provided that the same standards of data protection required in India are adhered to and that transfer is necessary for the performance of a lawful contract or has been consented to by the provider of the information. Sensitive personal information includes passwords, financial information such as bank account or credit/debit card details, sexual orientation, physical and mental health condition, and biometric information, among others.
Section 15 of the Digital Personal Data Protection Rules, which implement the Digital Personal Data Protection Act, provides that personal data processed by a data fiduciary under the Act may be transferred outside the territory of India, subject to the requirement that the data fiduciary complies with such conditions as the Central Government may prescribe, by general or special order, in relation to making such personal data available to any foreign State, or to any person, entity, or agency under the control of, or associated with, such a State; in addition, section 13.4 of the Rules requires a significant data fiduciary to implement measures ensuring that personal data specified by the Central Government, on the basis of recommendations of a committee constituted for that purpose, is processed subject to the restriction that both the personal data and the traffic data relating to its flow are not transferred outside the territory of India. “Significant data fiduciary” is defined as any data fiduciary or class of data fiduciaries notified as such by the Central Government under section 10 of the Act.
Once the Digital Personal Data Protection Act is fully in force, on 13 May 2027, the Information Technology Rules will be repealed. Rule 7 of Information Technology Rules states that the export of sensitive personal data or information within or outside India is permissible, provided that the same standards of data protection required in India are adhered to and that transfer is necessary for the performance of a lawful contract or has been consented to by the provider of the information. Sensitive personal information includes passwords, financial information such as bank account or credit/debit card details, sexual orientation, physical and mental health condition, and biometric information, among others.
Coverage Horizontal
Sources
- https://web.archive.org/web/20251216131748/https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- https://web.archive.org/web/20251216133658/https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- https://web.archive.org/web/20260501180450/https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf
- https://web.archive.org/web/20150909231036/http://www.wipo.int/wipolex/en/text.jsp?file_id=338328
- https://www.dataguidance.com/notes/india-data-protection-overview
- https://web.archive.org/web/20260501181151/https://digitalpolicyalert.org/event/35475-ministry-of-electronics-and-information-technology-issued-digital-personal-data-protection-rules-including-data-lo...
- https://web.archive.org/web/20160405081123/https://clientsites.linklaters.com/Clients/dataprotected/Pages/India.aspx
- Show more...
INDIA
Since March 1997, last amended in 2023
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Telecom Regulatory Authority of India Act, 1997
It is reported that the Telecom Regulatory Authority of India (TRAI), the executive body responsible for the supervision and regulation of services in the telecommunications sector, operates independently of the government in its decision‑making processes. Pursuant to section 3 of the Telecom Regulatory Authority of India Act, TRAI is constituted as a body corporate with perpetual succession and a common seal, and is empowered, subject to the provisions of the Act, to acquire, hold and dispose of movable and immovable property, to enter into contracts, and to sue or be sued in its corporate name.
Coverage Telecommunications sector
INDIA
Since December 1993
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Public Records Act (No. 69 of 1993)
Section 4 of the Public Records Act states that no person shall take or cause to be taken public records out of India without the prior approval of the Central Government, except if done for any official purpose.
Coverage Public sector
