Database

Browse Database

INDIA

Since February 2016, as amended in May 2021

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016
Pursuant to Section 18 of the "Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016", all customer data, including recordings generated through Video-based Customer Identification Processes (V-CIP), must be stored within the territorial jurisdiction of India. The utilisation of cloud-based solutions is permissible only on the condition that the regulated financial institution retains complete control over such data. In addition, the V-CIP infrastructure and associated applications must incorporate mechanisms to prevent access originating from Internet Protocol (IP) addresses located outside India, as well as from spoofed IP addresses.
Coverage Financial sector

INDIA

Since February 2021

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Guidelines for Acquiring and Producing Geo-Spatial data and Geo-Spatial Services including Maps
Under Clause ix of the "Guidelines for Acquiring and Producing Geo-Spatial Data and Geo-Spatial Services including Maps", digital maps and geospatial data with spatial accuracy or value finer than the prescribed threshold must be stored and processed exclusively on domestic cloud infrastructure or on servers physically located within the territory of India. Conversely, data with spatial accuracy or value up to the threshold may be uploaded to cloud platforms.
Coverage Horizontal

INDIA

Since March 2023

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Securities and Exchange Board of India (SEBI) Circular No. SEBI/HO/ITD/ITD_VAPT/P/CIR/2023/033 - Framework for Adoption of Cloud Services by SEBI Regulated Entities (REs)
Principle 3 of the "Framework for Adoption of Cloud Services by SEBI-Regulated Entities (REs)" stipulates that all data, including logs and any other information relating to the regulated entity, which is stored or processed in a cloud environment must remain within the territorial jurisdiction of India. A regulated entity refers to SEBI-registered or recognised intermediaries, such as brokers, mutual funds, KYC registration agencies, and qualified registrars to an issue (QRTAs), as well as market infrastructure institutions, including stock exchanges, clearing corporations, and depositories, all of which are subject to SEBI regulation.
Coverage Financial sector

INDIA

Since November 2023

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Pension Fund Regulatory and Development Authority (PFRDA) Circular No. PFRDA/2023/33/ICS/01 - Policy on adoption of cloud services by intermediaries regulated by PFRDA
Section 5.e of the Annexure to Circular No. PFRDA/2023/33/ICS/01 stipulates that entities regulated by the Pension Fund Regulatory and Development Authority (PFRDA) are required to ensure that all data storage and processing activities, including logs and any other information pertaining to the intermediary hosted on cloud infrastructure, are conducted strictly within the territorial jurisdiction of India.
Coverage Pension services sector

INDIA

Since May 2025

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Reserve Bank of India (Digital Lending) Directions, 2025
Section 13.4 of the "Reserve Bank of India (Digital Lending) Directions, 2025" stipulates that regulated entities must ensure that all data are stored exclusively on servers located within India. Where data are processed outside India, such data must be deleted from servers located abroad and repatriated to India within 24 hours of completion of processing. These requirements apply to all commercial banks; all primary (urban) co‑operative banks, state co‑operative banks, and central co‑operative banks; all non-banking financial companies, including housing finance companies; and all all‑India financial institutions.
Previously, pursuant to Section 4.4.2.2 of Annex 1 of the Regulatory Framework for Digital Lending, entities were required to ensure that all data were hosted on servers located within India, in strict adherence to applicable regulatory directives and legal obligations. This framework was introduced by the Reserve Bank of India, drawing upon the recommendations of the Working Group on Digital Lending, which examined lending practices conducted through online platforms and mobile applications.
Coverage Financial sector

INDIA

Since April 2022, entry into force in September 2022

Pillar Cross-border data policies  |  Indicator Local storage requirement
Indian Computer Emergency Response Team (CERT-In) Direction No. 20(3)/2022-CERT-In
Clause IV of Direction No. 20(3)/2022-CERT-In requires all service providers, intermediaries, data centres, body corporates, and government organisations to enable logs of all their ICT systems (that is, chronological record of system activities—a set of logs that can show who did what, when, and how within an ICT system) and to maintain such logs securely for a rolling period of 180 days within India.
Coverage Horizontal

INDIA

Since April 2018

Pillar Cross-border data policies  |  Indicator Local storage requirement
Reserve Bank of India Directive
In April 2018, the Reserve Bank of India (RBI) issued a directive stating that, within six months, all payment data held by payment companies should be held in local facilities. The Directive noted that this would help the RBI gain "unfettered supervisory access" to transaction data, which it needs to ensure proper monitoring.
Following a negative response from international payment companies such as MasterCard, Visa and American Express, the RBI has proposed (in "Frequently Asked Questions" of its website) to ease this restriction so as to allow payment firms to store data offshore as long as a copy was kept in India. The RBI has further clarified that for cross-border transaction data consisting of a foreign component and a domestic component, a copy of the domestic component may be stored abroad if required.
With respect to the processing of payment transactions outside India, the RBI requires that the data must be stored only in India after processing and should be deleted from systems abroad and brought back to India no later than 24 hours after processing. Any subsequent activity, such as settlement processing after payment processing done outside India, must be undertaken on a real-time basis, pursuant to which the data must be stored only in India.
The RBI has clarified that banks, especially foreign banks, can continue to store banking data abroad. Still, with respect to domestic payment transactions, the data must be stored only in India.
Coverage Financial sector

INDIA

Since March 2014, entry into force in April 2014

Pillar Cross-border data policies  |  Indicator Local storage requirement
Companies (Accounts) Rules, 2014
Rule 3.5 of the Companies (Accounts) Rules of 2014 provides that if company books and papers (or backups of them) are kept electronically in any location, they must also be periodically stored on a server physically located in India. 
Coverage Horizontal

INDIA

N/A

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
Partial appendment of WTO Telecom Reference Paper to schedule of commitments
India has only partially appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

INDIA

Since August 2023, entry into force in May 2027
Since November 2025, entry into force in May 2027
From April 2011 to May 2027

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Digital Personal Data Protection Act, 2023

Digital Personal Data Protection Rules, 2025

Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
Section 16.1 of the Digital Personal Data Protection Act stipulates that the Central Government may, by notification, impose restrictions on the transfer of personal data by a data fiduciary for processing to any country or territory outside India as may be specified. In addition, Section 16.2 provides that nothing in Section 16 shall limit the operation of any law currently in force in India that affords a higher level of protection or imposes stricter conditions on the transfer of personal data by a data fiduciary outside India, whether in respect of particular categories of personal data, specific data fiduciaries, or designated classes thereof. Under Section 2, a data fiduciary is defined as any person who, either independently or jointly with others, determines the purpose and means of processing personal data.
Section 15 of the Digital Personal Data Protection Rules, which implement the Digital Personal Data Protection Act, provides that personal data processed by a data fiduciary under the Act may be transferred outside the territory of India, subject to the requirement that the data fiduciary complies with such conditions as the Central Government may prescribe, by general or special order, in relation to making such personal data available to any foreign State, or to any person, entity, or agency under the control of, or associated with, such a State; in addition, section 13.4 of the Rules requires a significant data fiduciary to implement measures ensuring that personal data specified by the Central Government, on the basis of recommendations of a committee constituted for that purpose, is processed subject to the restriction that both the personal data and the traffic data relating to its flow are not transferred outside the territory of India. “Significant data fiduciary” is defined as any data fiduciary or class of data fiduciaries notified as such by the Central Government under section 10 of the Act.
Once the Digital Personal Data Protection Act is fully in force, on 13 May 2027, the Information Technology Rules will be repealed. Rule 7 of Information Technology Rules states that the export of sensitive personal data or information within or outside India is permissible, provided that the same standards of data protection required in India are adhered to and that transfer is necessary for the performance of a lawful contract or has been consented to by the provider of the information. Sensitive personal information includes passwords, financial information such as bank account or credit/debit card details, sexual orientation, physical and mental health condition, and biometric information, among others.
Coverage Horizontal
Sources

INDIA

Since March 1997, last amended in 2023

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Telecom Regulatory Authority of India Act, 1997
It is reported that the Telecom Regulatory Authority of India (TRAI), the executive body responsible for the supervision and regulation of services in the telecommunications sector, operates independently of the government in its decision‑making processes. Pursuant to section 3 of the Telecom Regulatory Authority of India Act, TRAI is constituted as a body corporate with perpetual succession and a common seal, and is empowered, subject to the provisions of the Act, to acquire, hold and dispose of movable and immovable property, to enter into contracts, and to sue or be sued in its corporate name.
Coverage Telecommunications sector

INDIA

Since December 1993

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Public Records Act (No. 69 of 1993)
Section 4 of the Public Records Act states that no person shall take or cause to be taken public records out of India without the prior approval of the Central Government, except if done for any official purpose. 
Coverage Public sector

INDIA

Since March 2012

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
National Data Sharing and Accessibility Policy
India’s National Data Sharing and Accessibility Policy requires that “non-sensitive data available either in digital or analogue forms but generated using public funds” must be stored within the borders of India. The policy states that data belongs to the "agency/department/ministry/entity which collected them and resides in their IT-enabled facility” (Section 10).
Coverage Public sector

INDIA

Reported in 2019, last reported in 2025

Pillar Intellectual Property Rights (IPRs)  |  Indicator Practical or legal restrictions related to the enforcement of patents
Practical restrictions related to the enforcement of patents
It is reported that the potential threat of patent revocations, lack of presumption of patent validity, and the narrow patentability criteria under the India Patents Act impact companies across different sectors. In addition, it has been reported that courts take a significant amount of time to make a final decision in a patent case. A patent lawsuit ordinarily takes approximately five to seven years to be finally decided after trial if contested by the other party. The Commercial Courts Act is helping to speed up the process with case management hearings and time-bound trials. However, the backlog of cases at the court and the shortage of judicial officers have an impact on the time it takes for a final decision on a case.
Coverage Horizontal

INDIA

Since December 1988

Pillar Intellectual Property Rights (IPRs)  |  Indicator Participation in the Patent Cooperation Treaty (PCT)
Patent Cooperation Treaty
India is a party to the Patent Cooperation Treaty (PCT).
Coverage Horizontal

Report issue     Report new measure