INDIA
Since October 2017
Pillar Intermediary liability |
Indicator User identity requirement
Regulation on the Use of Aadhaar e-KYC Service of the Unique Identity Authority of India (UIDAI) for Issuing New Mobile Connections and Re-Verification of Existing Subscribers via OTP-Based Authentication
According to the Regulation on the Use of Aadhaar e-KYC Service of the Unique Identity Authority of India (UIDAI) for Issuing New Mobile Connections and Re-Verification of Existing Subscribers via OTP-Based Authentication, Indian citizens are required to register their SIM card with their Aadhaar Card (a type of national identity card). Foreigners have to provide their passport, a photocopy of their Indian visa/ travel permit, a passport-sized photo and contact details.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20220125013040/https://dot.gov.in/sites/default/files/OTP%20Based%20Reverification.PDF?download=1
- https://web.archive.org/web/20231204204245/https://www.indiatoday.in/information/story/heres-how-an-indian-citizen-and-a-foreign-national-can-buy-a-sim-card-in-india-1841117-2021-08-15
INDIA
Since December 2018
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology Intermediaries Guidelines (Amendment) Rules, 2018
According to Art. 3.3 of the Information Technology Intermediaries Guidelines Rules, intermediaries are required to deploy technology-based automated tools or appropriate mechanisms with appropriate controls for proactively identifying and removing or disabling public access to unlawful information or content.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20220120082414/http://www.wipo.int/export/sites/www/copyright/en/doc/liability_of_internet_intermediaries.pdf
- https://web.archive.org/web/20220201093401/https://www.medianama.com/wp-content/uploads/Draft_Intermediary_Amendment_24122018.pdf
- https://web.archive.org/web/20201031191759/https://law.asia/intermediary-liability-rules-not-safe-harbour/
- Show more...
INDIA
Since June 2000, entry into force in October 2000, last amended in August 2023
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology Act, 2000
Section 69 of the Indian Information Technology Act (IITA) requires intermediaries to extend all facilities and technical assistance to intercept, monitor or decrypt information as well as to provide information stored in a computer or provide access to a computer resource when called upon to do so by certain agencies. This extends to online intermediaries, which are required to designate an officer to facilitate the execution of such orders. Intermediaries that fail to meet these obligations may be punished with imprisonment of up to seven years.
Coverage Internet intermediaries
INDIA
Since February 2021
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
According to Art. 4.2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021, a significant social media intermediary (defined as a social media intermediary having a number of registered users in India above five million) providing messaging services must enable identification of the first originator of the information on its computer resource as may be required by a judicial order or an order passed by a competent authority. In complying with an order for the identification of the first originator, a significant social media intermediary will not be required to disclose the contents of the electronic message related to the first originator or other users. No order must be passed in cases where there are less intrusive means of identifying the originator of the information.
Coverage Social media
Sources
- https://web.archive.org/web/20231005153411/https://www.meity.gov.in/writereaddata/files/Information%20Technology%20(Intermediary%20Guidelines%20and%20Digital%20Media%20Ethics%20Code)%20Rules%2C%202021...
- https://web.archive.org/web/20230929034953/https://sflc.in/analysis-information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021/
INDIA
Since March 1997, last amended in 2023
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Telecom Regulatory Authority of India Act, 1997
It is reported that the Telecom Regulatory Authority of India (TRAI), the executive body responsible for the supervision and regulation of services in the telecommunications sector, operates independently of the government in its decision‑making processes. Pursuant to section 3 of the Telecom Regulatory Authority of India Act, TRAI is constituted as a body corporate with perpetual succession and a common seal, and is empowered, subject to the provisions of the Act, to acquire, hold and dispose of movable and immovable property, to enter into contracts, and to sue or be sued in its corporate name.
Coverage Telecommunications sector
INDIA
Since December 1993
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Public Records Act (No. 69 of 1993)
Section 4 of the Public Records Act states that no person shall take or cause to be taken public records out of India without the prior approval of the Central Government, except if done for any official purpose.
Coverage Public sector
INDIA
Since March 2012
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
National Data Sharing and Accessibility Policy
India’s National Data Sharing and Accessibility Policy requires that “non-sensitive data available either in digital or analogue forms but generated using public funds” must be stored within the borders of India. The policy states that data belongs to the "agency/department/ministry/entity which collected them and resides in their IT-enabled facility” (Section 10).
Coverage Public sector
Sources
- https://web.archive.org/web/20230211101614/https://dst.gov.in/sites/default/files/gazetteNotificationNDSAP.pdf
- https://web.archive.org/web/20231006094116/https://www.usitc.gov/publications/332/pub4716.pdf
- https://web.archive.org/web/20220306032815/https://www.itic.org/public-policy/SnapshotofDataLocalizationMeasures6-13-2016.pdf
- https://web.archive.org/web/20211026012321/http://mapit.gov.in/pdf/carculer/NDSAP_2012.pdf
- Show more...
INDIA
Since December 2015
Since March 2017
Since October 2019
Since March 2017
Since October 2019
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Request for Proposal (RFP) for Provisional Empanelment of Cloud Service Offerings of Cloud Service Providers (CSPs)
Guidelines for Government Departments on Contractual Terms Related to Cloud Services
Master Service Agreement: Procurement of Cloud Services
Guidelines for Government Departments on Contractual Terms Related to Cloud Services
Master Service Agreement: Procurement of Cloud Services
In 2015, India’s Ministry of Electronics and Information Technology (MeitY) issued guidelines for a cloud computing empanelment process under which cloud computing service providers may be provisionally accredited as eligible for government procurement of cloud services. The guidelines require such providers to store all data in India to qualify for accreditation.
In addition, Section 2.1.d of the Guidelines for Government Departments on Contractual Terms Related to Cloud Services requires that any government contracts contain a localisation clause mandating that all government data residing in cloud storage networks is located on servers in India.
Also, Section 1.17.4 of the Master Service Agreement: Procurement of Cloud Services outlines, among other things, that cloud service providers must offer cloud services to the purchaser from a MeitY-enrolled data centre which is located in India, the data must be stored within India, and must not be taken out of India without explicit approval by the purchaser.
In addition, Section 2.1.d of the Guidelines for Government Departments on Contractual Terms Related to Cloud Services requires that any government contracts contain a localisation clause mandating that all government data residing in cloud storage networks is located on servers in India.
Also, Section 1.17.4 of the Master Service Agreement: Procurement of Cloud Services outlines, among other things, that cloud service providers must offer cloud services to the purchaser from a MeitY-enrolled data centre which is located in India, the data must be stored within India, and must not be taken out of India without explicit approval by the purchaser.
Coverage Cloud computing services
Sources
- https://web.archive.org/web/20211004024352/https://www.meity.gov.in/writereaddata/files/RFP_CSPs_10_16.pdf
- https://web.archive.org/web/20210514050834/https://www.meity.gov.in/writereaddata/files/Guidelines_Contractual_Terms_Cloud_Procurement_V1.2.pdf
- https://egovstandards.gov.in/sites/default/files/2026-03/Guidelines%20for%20Master%20Service%20Agreement.pdf
- https://web.archive.org/web/20231006094116/https://www.usitc.gov/publications/332/pub4716.pdf
- https://web.archive.org/web/20220622000610/https://itif.org/publications/2021/07/19/how-barriers-cross-border-data-flows-are-spreading-globally-what-they-cost/
- https://www.dataguidance.com/news/india-meity-issues-guidelines-cloud-services
- Show more...
INDIA
Since August 2015
Since March 2024
Since March 2024
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Insurance Regulatory and Development Authority of India (Maintenance of Insurance Records) Regulations, 2015
Insurance Regulatory and Development Authority of India (Protection of Policyholders’ Interests, Operations and Allied Matters of Insurers) Regulations, 2024
Insurance Regulatory and Development Authority of India (Protection of Policyholders’ Interests, Operations and Allied Matters of Insurers) Regulations, 2024
Section 3.9 of the Maintenance of Insurance Records Regulations mandates that insurance providers retain data pertaining to policies and claims on systems located within India, irrespective of whether such data is maintained in electronic form. In addition, Section 53.2 of the Protection of Policyholders’ Interests, Operations and Allied Matters of Insurers Regulations stipulates that all policyholder records must likewise be preserved within the territory of India.
Coverage Insurance sector
Sources
- https://web.archive.org/web/20250403100755/https://financialservices.gov.in/beta/sites/default/files/2024-11/IRDAI%20(Maintenance%20of%20Insurance%20Records)%20Regulations%2C%202015.pdf
- https://web.archive.org/web/20250903164820/https://financialservices.gov.in/beta/sites/default/files/2024-11/IRDAI%20%28Protection%20of%20%20Policyholder%27s%20Interests%2C%20operations%20and%20allied...
- https://web.archive.org/web/20250902214843/https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/asia-pacific/india/topics/data-localization-and-regulation-of-non-personal-...
- https://www.dataguidance.com/notes/india-data-transfers
- Show more...
INDIA
Since March 2016
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
License Agreement for Unified License
Under Condition 39.23(viii) of the Unified Licence Agreement granted by the Department of Telecommunications, licensees are not permitted to transfer “subscriber accounting information” (except for roaming and related billing purposes) or “user information” (except if pertaining to foreign subscribers using an Indian Operator’s network while roaming, and International Private Leased Circuit subscribers) to any person or place outside of India. “User information” is not defined by Indian telecommunications law, and the requirements do not restrict financial disclosures imposed by statute. Condition 39.23(iii) prohibits the transfer of domestic technical network details to any place outside of India.
Coverage Telecommunications sector
INDIA
Since November 2020
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Circular No. SEBI/HO/MIRSD2/DOR/CIR/P/2020/221 - Advisory for Financial Sector Organisations regarding Software as a Service (SaaS) based Solutions
In accordance with Section 3 of the "Advisory for Financial Sector Organisations regarding Software as a Service (SaaS) based Solutions", certain categories of critical data, including credit and liquidity risk data, market risk data, system and sub-system information, supplier details, system configuration data, audit and internal audit records, as well as network topology and design, must be stored within the territorial jurisdiction of India. This advisory, issued by the Securities and Exchange Board of India (SEBI), applies to financial sector entities such as merchant banks, credit rating agencies, Straight Through Processing (STP) service providers, debenture trustees, depository participants, and other financial institutions that utilise SaaS-based solutions for the management of governance, risk, and compliance functions.
Coverage Financial sector
Sources
- https://www.sebi.gov.in/legal/circulars/nov-2020/advisory-for-financial-sector-organizations-regarding-software-as-a-service-saas-based-solutions_48081.html
- https://web.archive.org/web/20250902214843/https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/asia-pacific/india/topics/data-localization-and-regulation-of-non-personal-...
INDIA
Since February 2016, as amended in May 2021
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016
Pursuant to Section 18 of the "Reserve Bank of India (Know Your Customer (KYC)) Directions, 2016", all customer data, including recordings generated through Video-based Customer Identification Processes (V-CIP), must be stored within the territorial jurisdiction of India. The utilisation of cloud-based solutions is permissible only on the condition that the regulated financial institution retains complete control over such data. In addition, the V-CIP infrastructure and associated applications must incorporate mechanisms to prevent access originating from Internet Protocol (IP) addresses located outside India, as well as from spoofed IP addresses.
Coverage Financial sector
Sources
- https://web.archive.org/web/20250826195517/https://www.rbi.org.in/CommonPerson/english/scripts/notification.aspx?id=2607
- https://web.archive.org/web/20250902233504/https://elplaw.in/wp-content/uploads/2024/12/Analysis-of-RBI-Norms-on-KYC-Data-Privacy-and-Confidentiality-Obligations-in-Banking.pdf
- https://web.archive.org/web/20250902233544/https://globaldataalliance.org/wp-content/uploads/2023/07/01092023gdadlcbdr.pdf
- https://web.archive.org/web/20250903000418/https://hyperverge.co/blog/what-is-v-cip-kyc/
- Show more...
INDIA
Since February 2021
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Guidelines for Acquiring and Producing Geo-Spatial data and Geo-Spatial Services including Maps
Under Clause ix of the "Guidelines for Acquiring and Producing Geo-Spatial Data and Geo-Spatial Services including Maps", digital maps and geospatial data with spatial accuracy or value finer than the prescribed threshold must be stored and processed exclusively on domestic cloud infrastructure or on servers physically located within the territory of India. Conversely, data with spatial accuracy or value up to the threshold may be uploaded to cloud platforms.
Coverage Horizontal
Sources
- https://web.archive.org/web/20250902210012/https://dst.gov.in/sites/default/files/Final%20Approved%20Guidelines%20on%20Geospatial%20Data.pdf
- https://web.archive.org/web/20250902210109/https://geospatialworld.net/blogs/india-deregulates-map-making-announces-guidelines-for-geospatial-data-services/
- https://web.archive.org/web/20250902210135/https://digitalpolicyalert.org/event/3277-adopted-guidelines-on-geo-spatial-data-and-geo-spatial-services
- Show more...
INDIA
Since March 2023
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Securities and Exchange Board of India (SEBI) Circular No. SEBI/HO/ITD/ITD_VAPT/P/CIR/2023/033 - Framework for Adoption of Cloud Services by SEBI Regulated Entities (REs)
Principle 3 of the "Framework for Adoption of Cloud Services by SEBI-Regulated Entities (REs)" stipulates that all data, including logs and any other information relating to the regulated entity, which is stored or processed in a cloud environment must remain within the territorial jurisdiction of India. A regulated entity refers to SEBI-registered or recognised intermediaries, such as brokers, mutual funds, KYC registration agencies, and qualified registrars to an issue (QRTAs), as well as market infrastructure institutions, including stock exchanges, clearing corporations, and depositories, all of which are subject to SEBI regulation.
Coverage Financial sector
INDIA
Since November 2023
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Pension Fund Regulatory and Development Authority (PFRDA) Circular No. PFRDA/2023/33/ICS/01 - Policy on adoption of cloud services by intermediaries regulated by PFRDA
Section 5.e of the Annexure to Circular No. PFRDA/2023/33/ICS/01 stipulates that entities regulated by the Pension Fund Regulatory and Development Authority (PFRDA) are required to ensure that all data storage and processing activities, including logs and any other information pertaining to the intermediary hosted on cloud infrastructure, are conducted strictly within the territorial jurisdiction of India.
Coverage Pension services sector
