India Cloud Data Localisation Reference
Which data must stay in India, which cloud providers are approved, and what each regulation requires — RBI, SEBI, DPDP Act, IRDAI, and MeitY mapped side by side.
Regulation-by-Regulation Summary
| Regulator | Entities Covered | Data Localisation Requirement | Strictness | Cloud Permitted? |
|---|---|---|---|---|
| RBI Multiple circulars |
Banks, NBFCs, Payment Aggregators, Payment Gateways, Card Networks | Payment system data: must be stored only in India. End-to-end transaction data, full payment data — no copy abroad. Processing abroad permitted for international transactions only. | Strict | Yes — India regions only |
| SEBI Circular 2023 |
Brokers, Depositories, Stock Exchanges, Mutual Funds, AMCs, RTAs, KRAs | All data of Indian securities market participants must be stored in India. Primary data center in India. Mirror/DR site can be abroad for non-sensitive data. | Strict | Yes — India regions only for primary |
| DPDP Act 2023 Section 16 |
All entities processing personal data of Indian citizens (Data Fiduciaries) | No blanket localisation requirement. Government may notify restricted countries for cross-border transfer. Until notified, transfers are permitted with notice to data principal. Significant Data Fiduciaries may face additional restrictions. | Moderate | Yes — cross-border permitted until restricted |
| IRDAI ISRM 2023 |
Insurance companies, TPAs, insurance intermediaries | All policyholder data must be stored in India. Primary servers in India. Data cannot be transferred outside India without IRDAI approval. | Strict | Yes — India regions only |
| MeitY Cloud Policy |
Central/State Government departments and PSUs | Government data must use MeitY-empanelled Cloud Service Providers (CSPs). Sensitive government data in Government Community Cloud or on-premise. Non-sensitive data may use public cloud. | Tiered | Only MeitY-empanelled CSPs |
| TRAI Various |
Telecom operators, ISPs | Call data records and subscriber data must be stored in India. Cannot be transferred to foreign entities without clearance. | Strict | Yes — India regions only |
Data Classification by Localisation Requirement
| Data Type | Must Stay in India? | Governing Rule |
|---|---|---|
| UPI / IMPS / RTGS / NEFT transaction data | Yes — mandatory | RBI Payment System Data Storage Policy 2018 |
| Card transaction data (PAN, CVV, track data) | Yes — mandatory | RBI circular on storage of payment system data |
| Demat account and securities transaction data | Yes — mandatory | SEBI Circular SEBI/HO/ITD/2023 |
| Insurance policyholder data | Yes — mandatory | IRDAI ISRM Guidelines 2023 |
| KYC data (Aadhaar, PAN, photograph) | Yes — mandatory | RBI KYC Master Directions; Aadhaar Act |
| Personal data of Indian citizens (general) | Not yet mandatory — restricted list pending | DPDP Act 2023 Section 16 — rules not yet notified |
| Health/medical data | Localisation preferred — DPDP rules pending | DPDP Act; National Health Authority guidelines |
| Government/classified data | Yes — must use empanelled CSPs | MeitY Cloud Policy; NCSP 2019 |
| Telecom subscriber and CDR data | Yes — mandatory | TRAI regulations; DoT licence conditions |
| Non-personal, non-regulated business data | No requirement — free transfer | No specific restriction |
RBI — Data Localisation Requirements
Core mandate
All payment system data — end-to-end transaction details, full payment data including customer data, payment sensitive data, payment credentials — must be stored only in India. The RBI circular is explicit: "all the data relating to payment systems operated by them are stored in a system only in India."
What "payment data" includes
| Data Category | Must be in India? | Notes |
|---|---|---|
| Customer data (name, mobile, email linked to payment) | Yes | Full data, not just identifier |
| Payment sensitive data (card number, CVV, PIN) | Yes | Storage of CVV and PIN prohibited even in India — tokenisation required |
| Payment credentials (MPIN, OTP) | Yes | Cannot leave India under any circumstances |
| Transaction data (amount, date, merchant, status) | Yes | Complete transaction history |
| International transaction data | India copy mandatory | A copy must be stored in India even if processing occurs abroad |
| Fraud analytics models trained on payment data | Ambiguous — legal opinion required | Model weights vs. underlying data — grey area |
Who must comply
All Payment System Operators (PSOs) authorised by RBI — banks, NBFCs with payment licences, Payment Aggregators (PAs), Payment Gateways (PGs), Prepaid Payment Instrument (PPI) issuers, card networks, ATM operators, White Label ATM operators, and Trade Receivables Discounting Systems (TReDS).
Audit and reporting
All PSOs were required to submit a System Audit Report (SAR) by December 31, 2018 confirming compliance. RBI inspections verify data localisation as part of IT examination. Non-compliance can result in licence suspension or cancellation.
Cloud implications
SEBI — Cloud and Data Localisation (CSCRF 2024)
Core requirements
SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) 2024 requires all SEBI-regulated entities (REs) to ensure that primary data and critical systems are located in India. A DR site may be abroad for certain categories of REs, subject to conditions.
Entity-tier requirements
| Entity Type | Primary DC | DR Site | Cloud Permitted? |
|---|---|---|---|
| Market Infrastructure Institutions (Stock Exchanges, Depositories, Clearing Corps) | India — mandatory | India — mandatory | Yes — India region only, pre-approval from SEBI |
| Qualified REs (large brokers, AMCs, portfolio managers >₹1,500Cr AUM) | India — mandatory | India preferred; abroad with approval | Yes — India region mandatory for primary |
| Mid-size REs (brokers, smaller AMCs, RTAs) | India — mandatory | India preferred | Yes — India region |
| Small REs | India preferred | Flexible | Yes — cloud permitted with risk assessment |
Data categories requiring India storage
Order data, trade data, client account data, settlement data, KYC data, client PAN/Aadhaar-linked data, audit logs of trading activity — all must be stored in India. Non-critical data (marketing analytics, product research) has no localisation requirement.
Cloud pre-approval process
Market Infrastructure Institutions must obtain SEBI approval before migrating to cloud. Other regulated entities must inform SEBI and ensure the cloud provider signs a data processing agreement confirming Indian data residency, audit access rights, and regulatory inspection rights.
DPDP Act 2023 — Cross-Border Data Transfer
Current position (2024-25)
Section 16 — Transfer of personal data outside India
A Data Fiduciary may transfer personal data outside India (except to restricted countries). Transfer requires: (1) the Data Principal has consented to the specific transfer, or (2) the transfer is necessary for performance of a contract, or (3) transfer is permitted under any law. Once the Government notifies restricted countries, transfer to those countries will be prohibited.
Significant Data Fiduciary (SDF) obligations
The Government may impose additional localisation requirements specifically on SDFs — entities processing large volumes of sensitive personal data. SDFs are notified by the Government — as of 2025, the SDF list has not been formally published. When published, SDFs may face mandatory India storage for certain data categories.
Practical compliance position
| Scenario | Compliance Position |
|---|---|
| Indian company stores personal data in AWS/Azure/GCP India region | Fully compliant — data in India |
| Indian company stores personal data in US/EU cloud region | Currently permitted — restricted list not notified |
| Indian company using global CDN that caches personal data outside India | Grey area — obtain legal opinion |
| SaaS provider processing Indian user data in US | Currently permitted — disclosure required in privacy policy |
| Transfer to China/Pakistan (if notified as restricted) | Will be prohibited once notified |
What to do now
Even without mandatory localisation, best practice is: (1) Maintain a data map showing where personal data of Indian citizens is stored. (2) Ensure vendor contracts include data residency provisions. (3) Be ready to migrate to India-region storage quickly once the restricted country list is notified. (4) Implement consent mechanisms that capture transfer consent where data is stored outside India.
IRDAI — Insurance Data Localisation
Core mandate
IRDAI requires all insurers and intermediaries to ensure that policyholder data and all insurance transaction data is stored exclusively in India. No transfer of policyholder data outside India is permitted without prior IRDAI approval.
Entities covered
All IRDAI-regulated entities: general insurers, life insurers, health insurers, reinsurers, insurance brokers, corporate agents, TPAs (Third Party Administrators), insurance repositories, surveyors and loss assessors, web aggregators.
Cloud adoption process under IRDAI
| Step | Requirement |
|---|---|
| Risk assessment | Formal risk assessment before any cloud adoption. Board-level approval required. |
| Contract requirements | Cloud provider agreement must include: data stored in India, audit rights for IRDAI, data portability on exit, no sub-processing outside India without approval. |
| IRDAI notification | Notify IRDAI before migrating core systems to cloud. Not pre-approval for most entities but regulatory inspection rights must be contractually secured. |
| Exit strategy | Must maintain an exit plan — ability to migrate data out of cloud provider within defined RTO if provider relationship ends. |
| Data classification | Policyholder PII: India only. Claims data: India only. Financial data: India only. Anonymised analytics: permitted outside India. |
Approved cloud regions for IRDAI entities
Any cloud region physically located in India is permitted: AWS ap-south-1 (Mumbai), Azure India Central (Pune) / India South (Chennai), GCP asia-south1 (Mumbai), NIC Cloud, and other MeitY-empanelled private cloud providers in India.
MeitY — Government Cloud Policy
Government data classification
| Data Category | Where It Must Go | Examples |
|---|---|---|
| Sensitive (S) | Government Community Cloud or on-premise only | National security, defence, police records, classified intelligence |
| Restricted (R) | MeitY-empanelled CSP — India region mandatory | Aadhaar-linked data, tax records, health ministry data, judicial records |
| Official (O) | MeitY-empanelled CSP — India region preferred | Government department operations, citizen service data |
| Open (Open) | Any cloud — no restriction | Public government websites, open data portals, public notifications |
MeitY-empanelled Cloud Service Providers (as of 2024)
| Provider | Empanelment Status | Services Approved |
|---|---|---|
| Amazon Web Services (AWS) | Empanelled | Compute, Storage, Database, AI/ML — India regions |
| Microsoft Azure | Empanelled | Compute, Storage, Database, AI — India regions |
| Google Cloud Platform (GCP) | Empanelled | Compute, Storage, Database — India regions |
| NIC Cloud (National Informatics Centre) | Government Community Cloud | Full stack — government preference for sensitive data |
| ESDS Cloud (eNlight) | Empanelled | IaaS, PaaS — India-based provider |
| Tata Communications | Empanelled | IaaS, connectivity |
| Oracle Cloud | Empanelled | IaaS, PaaS, SaaS — India region |
| IBM Cloud | Empanelled | IaaS, AI services |
Cloud Provider India Region Reference
| Provider | India Region(s) | Services Available | RBI Eligible | SEBI Eligible | MeitY Empanelled |
|---|---|---|---|---|---|
| AWS | ap-south-1 (Mumbai) ap-south-2 (Hyderabad) |
Full stack including GovCloud-equivalent controls | Yes | Yes | Yes |
| Microsoft Azure | Central India (Pune) South India (Chennai) West India (Mumbai) |
Full stack; Sovereign cloud options available | Yes | Yes | Yes |
| GCP | asia-south1 (Mumbai) asia-south2 (Delhi) |
Full stack; Assured Workloads available | Yes | Yes | Yes |
| Oracle Cloud | India West (Mumbai) India East (Hyderabad) |
IaaS, PaaS, Oracle database services | Verify per use case | Verify per use case | Yes |
| IBM Cloud | Chennai | IaaS, Watson AI, limited PaaS | Verify per use case | Verify per use case | Yes |
| Alibaba Cloud | Mumbai | IaaS, PaaS | Not recommended — Chinese entity | Not recommended | Not empanelled |
| NIC Cloud | Multiple DC (Delhi, Hyderabad, Bhopal, Pune) | Government-focused IaaS | Limited — primarily for gov | Not typical | Government Community Cloud |