🇮🇳 India Data Localisation

India Cloud Data Localisation Reference

Which data must stay in India, which cloud providers are approved, and what each regulation requires — RBI, SEBI, DPDP Act, IRDAI, and MeitY mapped side by side.

⚠️ This reference is based on regulations as of 2024-25. India's data localisation landscape is actively evolving — always verify against the latest circulars from the relevant regulator before making compliance decisions.

Regulation-by-Regulation Summary

Quick reference — click a regulator tab for full details
RegulatorEntities CoveredData Localisation RequirementStrictnessCloud Permitted?
RBI
Multiple circulars
Banks, NBFCs, Payment Aggregators, Payment Gateways, Card Networks Payment system data: must be stored only in India. End-to-end transaction data, full payment data — no copy abroad. Processing abroad permitted for international transactions only. Strict Yes — India regions only
SEBI
Circular 2023
Brokers, Depositories, Stock Exchanges, Mutual Funds, AMCs, RTAs, KRAs All data of Indian securities market participants must be stored in India. Primary data center in India. Mirror/DR site can be abroad for non-sensitive data. Strict Yes — India regions only for primary
DPDP Act 2023
Section 16
All entities processing personal data of Indian citizens (Data Fiduciaries) No blanket localisation requirement. Government may notify restricted countries for cross-border transfer. Until notified, transfers are permitted with notice to data principal. Significant Data Fiduciaries may face additional restrictions. Moderate Yes — cross-border permitted until restricted
IRDAI
ISRM 2023
Insurance companies, TPAs, insurance intermediaries All policyholder data must be stored in India. Primary servers in India. Data cannot be transferred outside India without IRDAI approval. Strict Yes — India regions only
MeitY
Cloud Policy
Central/State Government departments and PSUs Government data must use MeitY-empanelled Cloud Service Providers (CSPs). Sensitive government data in Government Community Cloud or on-premise. Non-sensitive data may use public cloud. Tiered Only MeitY-empanelled CSPs
TRAI
Various
Telecom operators, ISPs Call data records and subscriber data must be stored in India. Cannot be transferred to foreign entities without clearance. Strict Yes — India regions only

Data Classification by Localisation Requirement

Data TypeMust Stay in India?Governing Rule
UPI / IMPS / RTGS / NEFT transaction dataYes — mandatoryRBI Payment System Data Storage Policy 2018
Card transaction data (PAN, CVV, track data)Yes — mandatoryRBI circular on storage of payment system data
Demat account and securities transaction dataYes — mandatorySEBI Circular SEBI/HO/ITD/2023
Insurance policyholder dataYes — mandatoryIRDAI ISRM Guidelines 2023
KYC data (Aadhaar, PAN, photograph)Yes — mandatoryRBI KYC Master Directions; Aadhaar Act
Personal data of Indian citizens (general)Not yet mandatory — restricted list pendingDPDP Act 2023 Section 16 — rules not yet notified
Health/medical dataLocalisation preferred — DPDP rules pendingDPDP Act; National Health Authority guidelines
Government/classified dataYes — must use empanelled CSPsMeitY Cloud Policy; NCSP 2019
Telecom subscriber and CDR dataYes — mandatoryTRAI regulations; DoT licence conditions
Non-personal, non-regulated business dataNo requirement — free transferNo specific restriction

RBI — Data Localisation Requirements

Source: RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-18 (April 2018) + subsequent circulars

Core mandate

All payment system data — end-to-end transaction details, full payment data including customer data, payment sensitive data, payment credentials — must be stored only in India. The RBI circular is explicit: "all the data relating to payment systems operated by them are stored in a system only in India."

What "payment data" includes

Data CategoryMust be in India?Notes
Customer data (name, mobile, email linked to payment)YesFull data, not just identifier
Payment sensitive data (card number, CVV, PIN)YesStorage of CVV and PIN prohibited even in India — tokenisation required
Payment credentials (MPIN, OTP)YesCannot leave India under any circumstances
Transaction data (amount, date, merchant, status)YesComplete transaction history
International transaction dataIndia copy mandatoryA copy must be stored in India even if processing occurs abroad
Fraud analytics models trained on payment dataAmbiguous — legal opinion requiredModel weights vs. underlying data — grey area

Who must comply

All Payment System Operators (PSOs) authorised by RBI — banks, NBFCs with payment licences, Payment Aggregators (PAs), Payment Gateways (PGs), Prepaid Payment Instrument (PPI) issuers, card networks, ATM operators, White Label ATM operators, and Trade Receivables Discounting Systems (TReDS).

Audit and reporting

All PSOs were required to submit a System Audit Report (SAR) by December 31, 2018 confirming compliance. RBI inspections verify data localisation as part of IT examination. Non-compliance can result in licence suspension or cancellation.

Cloud implications

AWS Mumbai (ap-south-1), Azure India Central/South, and GCP Mumbai (asia-south1) are all permitted for RBI-regulated payment data — provided data is configured to stay within Indian regions, no cross-region replication to non-India regions is enabled, and the cloud contract includes appropriate data residency commitments. Multi-region replication that includes non-India regions is not permitted for payment data.

SEBI — Cloud and Data Localisation (CSCRF 2024)

Source: SEBI Circular SEBI/HO/ITD/ITD-PoD-1/P/CIR/2023/130 + CSCRF 2024

Core requirements

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) 2024 requires all SEBI-regulated entities (REs) to ensure that primary data and critical systems are located in India. A DR site may be abroad for certain categories of REs, subject to conditions.

Entity-tier requirements

Entity TypePrimary DCDR SiteCloud Permitted?
Market Infrastructure Institutions (Stock Exchanges, Depositories, Clearing Corps)India — mandatoryIndia — mandatoryYes — India region only, pre-approval from SEBI
Qualified REs (large brokers, AMCs, portfolio managers >₹1,500Cr AUM)India — mandatoryIndia preferred; abroad with approvalYes — India region mandatory for primary
Mid-size REs (brokers, smaller AMCs, RTAs)India — mandatoryIndia preferredYes — India region
Small REsIndia preferredFlexibleYes — cloud permitted with risk assessment

Data categories requiring India storage

Order data, trade data, client account data, settlement data, KYC data, client PAN/Aadhaar-linked data, audit logs of trading activity — all must be stored in India. Non-critical data (marketing analytics, product research) has no localisation requirement.

Cloud pre-approval process

Market Infrastructure Institutions must obtain SEBI approval before migrating to cloud. Other regulated entities must inform SEBI and ensure the cloud provider signs a data processing agreement confirming Indian data residency, audit access rights, and regulatory inspection rights.

DPDP Act 2023 — Cross-Border Data Transfer

Source: Digital Personal Data Protection Act 2023, Section 16 + pending rules

Current position (2024-25)

The DPDP Act does NOT currently impose blanket data localisation. Cross-border transfer of personal data is permitted by default, except to countries or territories that the Central Government may notify as restricted. As of 2025, no restricted countries have been officially notified.

Section 16 — Transfer of personal data outside India

A Data Fiduciary may transfer personal data outside India (except to restricted countries). Transfer requires: (1) the Data Principal has consented to the specific transfer, or (2) the transfer is necessary for performance of a contract, or (3) transfer is permitted under any law. Once the Government notifies restricted countries, transfer to those countries will be prohibited.

Significant Data Fiduciary (SDF) obligations

The Government may impose additional localisation requirements specifically on SDFs — entities processing large volumes of sensitive personal data. SDFs are notified by the Government — as of 2025, the SDF list has not been formally published. When published, SDFs may face mandatory India storage for certain data categories.

Practical compliance position

ScenarioCompliance Position
Indian company stores personal data in AWS/Azure/GCP India regionFully compliant — data in India
Indian company stores personal data in US/EU cloud regionCurrently permitted — restricted list not notified
Indian company using global CDN that caches personal data outside IndiaGrey area — obtain legal opinion
SaaS provider processing Indian user data in USCurrently permitted — disclosure required in privacy policy
Transfer to China/Pakistan (if notified as restricted)Will be prohibited once notified

What to do now

Even without mandatory localisation, best practice is: (1) Maintain a data map showing where personal data of Indian citizens is stored. (2) Ensure vendor contracts include data residency provisions. (3) Be ready to migrate to India-region storage quickly once the restricted country list is notified. (4) Implement consent mechanisms that capture transfer consent where data is stored outside India.

IRDAI — Insurance Data Localisation

Source: IRDAI Information and Cyber Security Guidelines (ISRM) 2023

Core mandate

IRDAI requires all insurers and intermediaries to ensure that policyholder data and all insurance transaction data is stored exclusively in India. No transfer of policyholder data outside India is permitted without prior IRDAI approval.

Entities covered

All IRDAI-regulated entities: general insurers, life insurers, health insurers, reinsurers, insurance brokers, corporate agents, TPAs (Third Party Administrators), insurance repositories, surveyors and loss assessors, web aggregators.

Cloud adoption process under IRDAI

StepRequirement
Risk assessmentFormal risk assessment before any cloud adoption. Board-level approval required.
Contract requirementsCloud provider agreement must include: data stored in India, audit rights for IRDAI, data portability on exit, no sub-processing outside India without approval.
IRDAI notificationNotify IRDAI before migrating core systems to cloud. Not pre-approval for most entities but regulatory inspection rights must be contractually secured.
Exit strategyMust maintain an exit plan — ability to migrate data out of cloud provider within defined RTO if provider relationship ends.
Data classificationPolicyholder PII: India only. Claims data: India only. Financial data: India only. Anonymised analytics: permitted outside India.

Approved cloud regions for IRDAI entities

Any cloud region physically located in India is permitted: AWS ap-south-1 (Mumbai), Azure India Central (Pune) / India South (Chennai), GCP asia-south1 (Mumbai), NIC Cloud, and other MeitY-empanelled private cloud providers in India.

MeitY — Government Cloud Policy

Source: National Cloud Services Policy 2019; MeitY Cloud Empanelment Process

Government data classification

Data CategoryWhere It Must GoExamples
Sensitive (S)Government Community Cloud or on-premise onlyNational security, defence, police records, classified intelligence
Restricted (R)MeitY-empanelled CSP — India region mandatoryAadhaar-linked data, tax records, health ministry data, judicial records
Official (O)MeitY-empanelled CSP — India region preferredGovernment department operations, citizen service data
Open (Open)Any cloud — no restrictionPublic government websites, open data portals, public notifications

MeitY-empanelled Cloud Service Providers (as of 2024)

ProviderEmpanelment StatusServices Approved
Amazon Web Services (AWS)EmpanelledCompute, Storage, Database, AI/ML — India regions
Microsoft AzureEmpanelledCompute, Storage, Database, AI — India regions
Google Cloud Platform (GCP)EmpanelledCompute, Storage, Database — India regions
NIC Cloud (National Informatics Centre)Government Community CloudFull stack — government preference for sensitive data
ESDS Cloud (eNlight)EmpanelledIaaS, PaaS — India-based provider
Tata CommunicationsEmpanelledIaaS, connectivity
Oracle CloudEmpanelledIaaS, PaaS, SaaS — India region
IBM CloudEmpanelledIaaS, AI services
Government departments using non-empanelled cloud providers for government data are in violation of MeitY policy regardless of other factors. The empanelment list is updated periodically — always verify at meity.gov.in/cloud-empanelment.

Cloud Provider India Region Reference

ProviderIndia Region(s)Services AvailableRBI EligibleSEBI EligibleMeitY Empanelled
AWS ap-south-1 (Mumbai)
ap-south-2 (Hyderabad)
Full stack including GovCloud-equivalent controls Yes Yes Yes
Microsoft Azure Central India (Pune)
South India (Chennai)
West India (Mumbai)
Full stack; Sovereign cloud options available Yes Yes Yes
GCP asia-south1 (Mumbai)
asia-south2 (Delhi)
Full stack; Assured Workloads available Yes Yes Yes
Oracle Cloud India West (Mumbai)
India East (Hyderabad)
IaaS, PaaS, Oracle database services Verify per use case Verify per use case Yes
IBM Cloud Chennai IaaS, Watson AI, limited PaaS Verify per use case Verify per use case Yes
Alibaba Cloud Mumbai IaaS, PaaS Not recommended — Chinese entity Not recommended Not empanelled
NIC Cloud Multiple DC (Delhi, Hyderabad, Bhopal, Pune) Government-focused IaaS Limited — primarily for gov Not typical Government Community Cloud

Key contractual requirements for regulated entities

Data residency clause: Cloud contract must explicitly commit that data is stored only within specified India regions and will not be replicated to non-India regions without written consent.
Regulatory inspection rights: Contract must grant the regulator (RBI, SEBI, IRDAI) the right to audit the cloud provider's India infrastructure relevant to the entity's data.
Sub-processor disclosure: Cloud provider must disclose all sub-processors (CDN, analytics tools) and confirm they do not process Indian data outside India.
Data portability on exit: Entity must be able to export all data within defined timeline (typically 30 days) if relationship ends.
Breach notification: Cloud provider must notify the entity of any data breach within 72 hours — aligning with CERT-In requirements.
Sovereign jurisdiction: Contract should specify Indian law as governing law and Indian courts as jurisdiction for disputes involving regulated data.