India
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in India — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send Indian data almost anywhere under India's general privacy law. The government can ban named countries, and so far it has banned none. But some industries are strict. Payments data, insurance records and telecom network data must stay inside India. The main law is passed, but most of it only becomes enforceable in May 2027. The regulator has no members yet.
Data governance in India
The eight things that decide how you handle data about people in India. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, the law reaches you even if you have no office in India. It applies to any organisation anywhere in the world that handles Indians' data. It applies where you do so in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.
Sources
- Official sourceMinistry of Electronics and Information TechnologyDigital Personal Data Protection Act, 2023 (Act No. 22 of 2023), section 3
meity.gov.in
Link checked 18 August 2026
Where the data is allowed to live
Yes, and freely. India uses a banned-country list. The government may name countries you cannot send data to. As of today it has named none. Six industries are the exception, and they are covered below.
Two things could change this overnight. First, the government can add countries to the banned list by notification, with no consultation. Second, a rule aimed at 'Significant the company that decides how data is used' lets a government committee name types of data that may never leave India. The committee has not been formed and no types have been named. But the power has no limit. The earlier draft law split data into ordinary, sensitive and critical, and that split was removed.
Sources
- Official sourceMinistry of Electronics and Information TechnologyDPDP Act 2023, section 16 (restriction on transfer outside India)
meity.gov.in
“The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.”
- Official sourcePress Information Bureau, Government of IndiaDigital Personal Data Protection Rules, 2025 — notification and rule text
static.pib.gov.in
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
There is nothing to sign, no government approval and no standard contract. India's general law needs no paperwork to send personal data abroad. The only question is whether the country is on the banned list, and no country is. Industry rules override this completely.
- Ways to send data out:
- Nothing required
One point sits in Rule 15 of the 2025 Rules. The government may set conditions on making personal data available to a foreign state or its agencies. No such order has been issued. The wording aims at foreign governments getting access, rather than at transfers as such. It could become India's version of Europe's resistance to overseas surveillance demands.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 15
static.pib.gov.in
The regulator, and whether it actually acts
The Data Protection Board of India is meant to enforce, but nobody is enforcing yet. The Board legally exists. As of August 2026 it has no chairperson and no members. The government advertised the five posts in May 2026 and advertised again in June. They were still empty in August. Industry regulators are fully active. The central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.
Sources
- Official sourceMinistry of Electronics and Information TechnologyVacancy circular — Chairperson and Members, Data Protection Board of India, F.No. 2(1)/2026-Pers.I, 6 May 2026
meity.gov.in
- Official sourceMeitY / Digital India CorporationRecruitment for the Board's digital office, 13 July 2026 — evidence the Board was still being staffed
meity.gov.in
How long you must keep it — and when to delete it
There are minimum keeping times and a duty to delete. From May 2027 you must keep logs of how you use data for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last used the service. You must warn the user 48 hours first.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
The three-year deletion duty only applies above a size threshold. It covers shopping and social media platforms with 20 million or more registered Indian users. It also covers online gaming platforms with 5 million or more. The one-year minimum for logs is a common miss. Global systems often delete logs after 30 or 90 days.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 8 and Third Schedule
static.pib.gov.in
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions under section 70B(6) of the IT Act, 28 April 2022 — 180-day log retention
cert-in.org.in
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are two deadlines, and this catches almost everyone out. You have SIX HOURS to report a cyber incident to India's national cyber agency. That is one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and the affected people without delay. You then file a detailed report within 72 hours.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator · Tell affected people
Sources
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions, 28 April 2022 — 6-hour incident reporting
cert-in.org.in
“shall mandatorily report cyber incidents ... to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.”
- Official sourceIndian Computer Emergency Response TeamCERT-In FAQs, May 2022 — clarifies that general logs may sit abroad if producible, but financial transaction logs must stay in India
cert-in.org.in
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Four things catch people out. (1) A child is anyone under 18. India has no lower age for digital consent, unlike Europe. Targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company worth about 2.3 million US dollars, so a foreign company cannot be one. (3) If you are named a 'significant' organisation, your data protection officer must be based in India and answer to the board. (4) The general law expressly keeps stricter industry rules in place. Its relaxed transfer rules give you nothing if you touch payments, insurance or telecom.
- What you have to do here:
- Get a parent's consent for children · No tracking or ads to children · Appoint a data protection officer
Sources
- Official sourceMinistry of Electronics and Information TechnologyDPDP Act 2023, sections 9, 10 and 16(2)
meity.gov.in
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rules 4, 10 and 13, and First Schedule
static.pib.gov.in
What's changing next
Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable. The government has publicly refused to delay it or to exempt startups. Some time before then the Board should get its members. Enforcement starts at that point.
Watch four changes. Each can happen with a single notification and no consultation. The banned list of destination countries. The committee that can name data which may never leave India. The list of organisations named 'significant'. And the securities regulator's rule that data must stay in India. That rule is formally adopted but on hold since December 2024, and it can be brought back with no warning.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 1(2) — phased commencement
static.pib.gov.in
What to do: Diarise 13 November 2026 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payments data must stay in the country
Official name: Storage of Payment System Data · RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-18 · Regulator directive
All payment system data must be stored in a system only in India. No mirror abroad is permitted. Only the foreign leg of a cross-border transaction may be stored overseas. For those, a copy of the domestic part may also be held abroad.
Enforced by Reserve Bank of India
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryYou may handle the data abroad. But you must delete it there and return it to India. The deadline is 24 hours or one business day, whichever is earlier.
- Independent auditSystem Audit Report by a CERT-In empanelled auditor.
Sources
- Official sourceReserve Bank of IndiaStorage of Payment System Data, 6 April 2018
rbi.org.in
“All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India.”
Link checked 18 August 2026
Telecoms data must stay in the country
Official name: Telecommunications (Authorisation) Rules, 2026 · Government rules
India's newest and strictest rule on keeping data in the country. Every system of a telecommunication network must sit inside India. So must all data, logs and information that go with it. No copies may be routed, shared or made available outside India. Remote access from abroad needs government permission first.
Enforced by Department of Telecommunications
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThere is no exemption and no exception. It covers cloud-hosted telecom network providers, internet exchange points and satellite gateway operators.
- Keep logs — 6 monthsAudit trail of remote access, held in India.
Sources
- Official sourceDepartment of TelecommunicationsDepartment of Telecommunications — Telecommunications (Authorisation) Rules, 2026
dot.gov.in
Insurance data rules
Official name: IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025 · Directly binding regulation
Records of all policies issued and all claims made in India must be held in data centres located and maintained in India only.
Enforced by Insurance Regulatory and Development Authority of India
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country
Sources
- Official sourceInsurance Regulatory and Development Authority of IndiaIRDAI — Maintenance of Information by Regulated Entities Regulations, 2025
irdai.gov.in
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Digital Personal Data Protection Act, 2023 · Act No. 22 of 2023 · Act of parliament
India's general privacy law. It is relaxed about sending data abroad. The government can ban named countries, and it has banned none. It is heavy on consent and children's protection. Organisations named as large must also answer for their data from inside India. Most of the law becomes enforceable on 13 May 2027. Penalties are fixed caps, not a percentage of turnover.
That is a long gap: the duty is real law today, but no penalty can follow until 13 May 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Data Protection Board of India — not yet operational
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Nothing required
What you have to do
- Get consent — from 13 May 2027
- Tell people what you do — from 13 May 2027Must be available in English and the 22 scheduled Indian languages.
- Let people see their data — from 13 May 2027
- Let people correct their data — from 13 May 2027
- Let people delete their data — from 13 May 2027
- Allow a nominee — from 13 May 2027India-specific: a person may nominate someone to exercise their rights on death or incapacity.
- Report breaches to the regulator — within 72 hours, from 13 May 2027
- Tell affected people — from 13 May 2027
- Keep data for a minimum period — 1 year, from 13 May 2027Logs of how you use data.
- Delete data after a period — applies at: E-commerce and social media with 20m+ Indian users; online gaming with 5m+, 3 years, from 13 May 2027
- Get a parent's consent for children — applies at: under 18, from 13 May 2027
- No tracking or ads to children — from 13 May 2027
- Appoint a data protection officer — applies at: Significant Data Fiduciaries onlyMust be based in India and answerable to the board of directors.
- Publish a complaints contactGrievances to be resolved within 90 days.
- Assess high-risk projects — applies at: Significant Data Fiduciaries onlyAnnual.
- Independent audit — applies at: Significant Data Fiduciaries onlyAnnual, by an independent data auditor.
- Check your algorithms — applies at: Significant Data Fiduciaries only
What it costs if you get it wrong
- Fixed maximum fine: ₹250 crore — about $28 millionFailure to take reasonable security safeguards
- Fixed maximum fine: ₹200 crore — about $23 millionFailure to notify a breach
- Fixed maximum fine: ₹200 crore — about $23 millionBreach of children's data obligations
- Fixed maximum fine: ₹150 crore — about $17 millionBreach of Significant Data Fiduciary duties
- Fixed maximum fine: ₹50 crore — about $6 millionAny other provision
Sources
- Official sourcePIB, Government of IndiaDigital Personal Data Protection Rules, 2025
static.pib.gov.in
Breach reporting rules
Official name: Directions under section 70B(6) of the Information Technology Act, 2000 · No. 20(3)/2022-CERT-In · Government rules
India's rules on reporting cyber incidents. You get six hours to report an incident. You must keep 180 days of system logs. Your clocks must be synchronised to Indian government time servers. The rules apply even if you have no office in India, and you still need a named point of contact.
Enforced by Indian Computer Emergency Response Team (CERT-In)
How this country controls where data goes: Approval each time
What you have to do
- Report cyber incidents — within 6 hours
- Keep logs — 6 monthsThe direction says logs must be kept inside India. The regulator's own FAQ is softer. It allows general logs to sit abroad if you can produce them on demand. But it requires financial transaction logs to stay in India.
- Keep data for a minimum period — applies at: Data centres, cloud, VPS and VPN providers — customer records, 5 years after service ends, 5 years
Sources
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions, 28 April 2022
cert-in.org.in
- Official sourceIndian Computer Emergency Response TeamCERT-In FAQs on the Cyber Security Directions, May 2022
cert-in.org.in
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Cyber security rules
Official name: Cybersecurity and Cyber Resilience Framework, control PR.DS.S2 · Held in abeyance by SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 · Regulator directive
A rule that Indian securities-market data must stay in India. It is formally adopted but on hold since 31 December 2024. It has not been withdrawn, and it could be switched back on with no notice. The other cybersecurity controls in the same set of rules still bind you.
Enforced by Securities and Exchange Board of India
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryOn hold at the moment. The regulator can revive it with no public consultation.
Sources
- Official sourceSecurities and Exchange Board of IndiaSEBI — Cybersecurity and Cyber Resilience Framework circulars
sebi.gov.in
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Exact commencement dates — 12 vs 13 November 2026 and 12 vs 13 May 2027
The Rules count from publication; sources differ by one day depending on whether they count from the gazette notification date or the publication date. Plan to the earlier date.
Whether any chairperson or member of the Data Protection Board has been appointed between 1 and 18 August 2026
We can show the posts were empty up to 1 August 2026 from the regulator's own notices. We cannot confirm the position for the days since. Check the regulator's notices before you rely on this.
Full official text and transition period of the Telecommunications (Authorisation) Rules, 2026
Credible trade press reported this in July 2026. We could not find the gazette copy on the department's own site. So we mark the rule medium confidence, and the government link points to the department's homepage rather than to the rule itself.
Whether the IRDAI 2025 regulations expressly repealed the 2015 insurance records regulations
We could not find this on the regulator's site. We cannot confirm it either way. Check with the regulator before you rely on it.
Whether MeitY's cloud empanelment terms impose where data has to be stored in the instrument text
The cloud providers say where the data is stored. We could not confirm it against a government document. Check before you rely on it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.