Data localisation is not a binary question: What non-BFSI organisations should get right under India’s evolving framework

Rather than localising all data, organisations should adopt a governance framework in which datasets must be stored, backed up or made accessible from India.
Chandrasekhar G. Tampi
Chandrasekhar G. Tampi
Published on
4 min read

In this Leading Questions piece, Chandrasekhar G Tampi discusses how non-BFSI firms in India are not subject to blanket data‑localisation but must inventory and govern data, comply with sectoral rules, ensure India‑accessible backups and contractual safeguards, and be prepared to localise specific datasets when required.

Question: Does Indian law require entities other than in the financial sector, to store all personal and business data in India?

Answer: No, Indian data protection laws (The Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”)) do not impose an obligation that non-financial sector companies store all personal or business data exclusively in India. Ordinary personal and business data may be hosted overseas. However, that is subject to specific statutes, sectoral regulations, contractual undertakings or directions that may require data to be stored, backed-up, accessed or produced within India.

Indian data protection laws regulate specified sensitive personal data or information and its collection, handling and permit overseas transfer. Overseas transfer may be permitted when the recipient maintains same standard for data protection as is required under the SPDI Rules and where the transfer is either necessary for performance of a lawful contract or has been consented. The Digital Personal Data Protection Act, 2023 adopts a broadly permissive cross-border transfer regime, subject to restrictions that the Central Government may notify in accordance with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) which may specify categories of personal data that must be processed without transfer outside India.

However, Aadhaar information requires different treatment. It is pertinent to note that treatment of:

1. Aadhar Information: A private entity cannot use Aadhaar authentication as a routine KYC tool, but where Aadhaar information is lawfully handled, the data has to be segregated and handled under the applicable UIDAI framework.

2. CERT-In: CERT-In directions that require entities to retain ICT system logs accessible within India for a rolling 180-day period. However, there is some flexibility on local storage under CERT-In FAQs so long as they can be produced when directed.

3. The Companies Act, 2013 and the Rules: Require companies with electronic books of account outside India to ensure that it remains accessible in India, with a daily back-up on Indian servers.

Further, data localisation obligations are often encountered indirectly, when a business provides services to the financial institutions, whereby, their regulatory and contractual requirements may flow down to the service provider. The financial institutions commonly pass India-residency, India-back-up, audit, access-control, sub-outsourcing, security and incident-notification obligations to service providers. For a service provider, these contractual requirements can be more consequential than its direct regulatory exposure.

Question: Can employee HR, payroll and performance data be stored on overseas servers?

Answer: Yes, subject to applicable privacy, security and cross-border transfer requirements. No standalone, India only localisation requirement applies to routine employee, HR, payroll or performance records. A global human resource software system or overseas cloud environment may therefore be used, subject to applicable governance standards. 

Under the SPDI Rules framework, an organisation should demonstrate a lawful collection purpose, appropriate consent processes where required, reasonable security practices and, for an overseas transfer, a recipient that ensures the same level of protection required under the SPDI Rules. Security and vendor diligence are operational requirements, not merely contractual statements.

Aadhaar must be treated separately. First, determine whether collection or retention is necessary. If Aadhaar information is lawfully handled in a permitted context, it should be segregated and handled in accordance with the applicable UIDAI Data Vault and other Aadhaar-framework requirements. A general overseas cloud repository should not be used for Aadhaar data subject to the UIDAI requirements.

Question: Does holding other organisation’s KYC and bank-account information for invoicing trigger RBI payment-data localisation requirements?

Answer: RBI’s Circular on Storage of Payment System Data dated April 06, 2018, as clarified in subsequent FAQs, applies to data of payment systems and their operators. A company receiving static client bank details for invoicing, receivables or vendor administration does not thereby operate a payment system. Such information is not equivalent to end-to-end payment instructions or transaction data.

Nevertheless, invoicing-related information may form part of electronic books of account, including invoices, vouchers and supporting records. Under the Companies Act, 2013 and Rule 3 of the Companies (Accounts) Rules, 2014, electronic books and papers maintained outside India must remain accessible in India, and a complete daily back-up must be maintained on servers physically located in India. This is a targeted obligation, not full localisation. A company may use an overseas ERP, invoicing or accounting platform.

The Indian GST framework reinforces the record keeping obligation. Registered persons must maintain complete and accurate accounts, invoices and supporting records and produce them, in hard copy or electronically readable form, with access credentials when required by tax authorities. However, the GST authorities do not independently require hosting servers to be located in India. Therefore, the respective legal, finance and technology teams alike in organisations should delineate the accounting parameters, confirm India-based daily back-ups where the Companies (Accounts) Rules apply and periodically test retrieval procedures.

Question: What should general counsel and in-house legal teams do now?

Answer: Rather than localising all data, organisations should adopt a governance framework in which datasets must be stored, backed up or made accessible from India. Blanket localisation is often unnecessary, costly and disruptive. Storing Indian data overseas without clear contractual safeguards or contingency plan will be difficult to justify. The focus should be on knowing where data sits and being able to localise it when required by law, regulation or contract.

First, prepare a data inventory and identify the data subjects, processing purpose, storage location, cloud provider, retention period, applicable contracts and any legal restrictions relating to Aadhaar data, electronic books of account, ICT logs data from clients that may need to be separated.

Second, review contracts with cloud providers and other technology vendors, to ensure they clear security, confidentiality, sub-processing, audit rights, incident reporting, regulatory cooperation, data retention, deletion and migration support.

Finally, ensure segregation and migration to India of data if legal requirements or customer contracts change.

Chandrasekhar G Tampi is Partner at Luthra and Luthra Law Offices India.

Bar and Bench - Indian Legal news
www.barandbench.com