India
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.
Eight questions about India
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do India's rules apply to my company?
Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.
Sources
- Official sourceMinistry of Electronics and Information TechnologyDigital Personal Data Protection Act, 2023 (Act No. 22 of 2023), section 3
meity.gov.in
Link checked 18 August 2026
Can I store my users' data outside India?
In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.
Two dormant switches could change this overnight. First, the government can populate the blacklist by notification with no consultation. Second, a rule aimed at 'Significant Data Fiduciaries' lets a government committee designate categories of data that may never leave India — the committee has not been formed and no categories named, but the power is unbounded, since the earlier draft law's distinction between ordinary, sensitive and critical data was removed.
Sources
- Official sourceMinistry of Electronics and Information TechnologyDPDP Act 2023, section 16 (restriction on transfer outside India)
meity.gov.in
“The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.”
- Official sourcePress Information Bureau, Government of IndiaDigital Personal Data Protection Rules, 2025 — notification and rule text
static.pib.gov.in
What do I need in place before data leaves India?
Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.
One caveat sits in Rule 15 of the 2025 Rules: the government may set conditions on making personal data available to a foreign state or its agencies. No such order has been issued. Note the drafting targets foreign-government access rather than transfer as such, which makes it a possible future analogue of Europe's resistance to overseas surveillance demands.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 15
static.pib.gov.in
Who enforces the rules in India, and what can they do?
On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.
Sources
- Official sourceMinistry of Electronics and Information TechnologyVacancy circular — Chairperson and Members, Data Protection Board of India, F.No. 2(1)/2026-Pers.I, 6 May 2026
meity.gov.in
- Official sourceMeitY / Digital India CorporationRecruitment for the Board's digital office, 13 July 2026 — evidence the Board was still being staffed
meity.gov.in
How long do I have to keep the data?
There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.
The three-year deletion duty is threshold-based: e-commerce and social media platforms with 20 million or more registered Indian users, and online gaming platforms with 5 million or more. The one-year minimum log retention sits awkwardly against global architectures that expire logs in 30 or 90 days, and is one of the more commonly missed obligations.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 8 and Third Schedule
static.pib.gov.in
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions under section 70B(6) of the IT Act, 28 April 2022 — 180-day log retention
cert-in.org.in
What happens if there is a breach?
Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.
Sources
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions, 28 April 2022 — 6-hour incident reporting
cert-in.org.in
“shall mandatorily report cyber incidents ... to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.”
- Official sourceIndian Computer Emergency Response TeamCERT-In FAQs, May 2022 — clarifies that general logs may sit abroad if producible, but financial transaction logs must stay in India
cert-in.org.in
What trips people up in India?
Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.
Sources
- Official sourceMinistry of Electronics and Information TechnologyDPDP Act 2023, sections 9, 10 and 16(2)
meity.gov.in
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rules 4, 10 and 13, and First Schedule
static.pib.gov.in
What is changing soon in India?
Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.
Watch four dormant switches, any of which can flip with a single notification and no consultation: the blacklist of banned destination countries; the committee that can designate data which may never leave India; the list of organisations designated 'significant'; and the securities regulator's localisation rule, which is formally adopted but held in abeyance since December 2024 and can be revived without warning.
Sources
- Official sourcePress Information Bureau, Government of IndiaDPDP Rules 2025, rule 1(2) — phased commencement
static.pib.gov.in
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
Digital Personal Data Protection Act, 2023
Act of parliament · Act No. 22 of 2023
India's general privacy law. Permissive on cross-border transfer — a blacklist model with an empty blacklist — but heavy on consent, children's protection and, for designated large organisations, in-country accountability. Most of it becomes enforceable on 13 May 2027. Penalties are fixed caps, not a percentage of turnover.
Enforced by Data Protection Board of India — not yet operational
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Nothing required
What it makes you do
- Get consent — from 13 May 2027
- Tell people what you do — from 13 May 2027Must be available in English and the 22 scheduled Indian languages.
- Let people see their data — from 13 May 2027
- Let people correct their data — from 13 May 2027
- Let people delete their data — from 13 May 2027
- Allow a nominee — from 13 May 2027India-specific: a person may nominate someone to exercise their rights on death or incapacity.
- Report breaches to the regulator — within 72 hours, from 13 May 2027
- Tell affected people — from 13 May 2027
- Keep data for a minimum period — 1 year, from 13 May 2027Logs of processing.
- Delete data after a period — applies at: E-commerce and social media with 20m+ Indian users; online gaming with 5m+, 3 years, from 13 May 2027
- Get a parent's consent for children — applies at: under 18, from 13 May 2027
- No tracking or ads to children — from 13 May 2027
- Appoint a data protection officer — applies at: Significant Data Fiduciaries onlyMust be based in India and answerable to the board of directors.
- Publish a complaints contactGrievances to be resolved within 90 days.
- Assess high-risk projects — applies at: Significant Data Fiduciaries onlyAnnual.
- Independent audit — applies at: Significant Data Fiduciaries onlyAnnual, by an independent data auditor.
- Check your algorithms — applies at: Significant Data Fiduciaries only
What it costs if you get it wrong
- Fixed maximum fine: ₹250 crore — about $28 millionFailure to take reasonable security safeguards
- Fixed maximum fine: ₹200 crore — about $23 millionFailure to notify a breach
- Fixed maximum fine: ₹200 crore — about $23 millionBreach of children's data obligations
- Fixed maximum fine: ₹150 crore — about $17 millionBreach of Significant Data Fiduciary duties
- Fixed maximum fine: ₹50 crore — about $6 millionAny other provision
Sources
- Official sourcePIB, Government of IndiaDigital Personal Data Protection Rules, 2025
static.pib.gov.in
Directions under section 70B(6) of the Information Technology Act, 2000
Government rules · No. 20(3)/2022-CERT-In
India's cyber incident regime. Six hours to report an incident, 180 days of system logs, and clocks synchronised to Indian government time servers. Applies extraterritorially — a company with no presence in India still needs a named point of contact.
Enforced by Indian Computer Emergency Response Team (CERT-In)
Transfer model: Approval each time
What it makes you do
- Report cyber incidents — within 6 hours
- Keep logs — 6 monthsThe direction says logs must be maintained within Indian jurisdiction; the regulator's own FAQ softens this, allowing general logs abroad if producible on demand, but requires financial transaction logs to stay in India.
- Keep data for a minimum period — applies at: Data centres, cloud, VPS and VPN providers — customer records, 5 years after service ends, 5 years
Sources
- Official sourceIndian Computer Emergency Response TeamCERT-In Directions, 28 April 2022
cert-in.org.in
- Official sourceIndian Computer Emergency Response TeamCERT-In FAQs on the Cyber Security Directions, May 2022
cert-in.org.in
Industry rules4 rules
Storage of Payment System Data
Regulator directive · RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-18 · Payments
All payment system data must be stored in a system only in India. No mirror abroad is permitted. Only the foreign leg of a cross-border transaction may be stored overseas, and for those a copy of the domestic component may also be held abroad.
Enforced by Reserve Bank of India
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryOffshore processing is allowed, but data must be deleted abroad and returned to India within 24 hours or one business day, whichever is earlier.
- Independent auditSystem Audit Report by a CERT-In empanelled auditor.
Sources
- Official sourceReserve Bank of IndiaStorage of Payment System Data, 6 April 2018
rbi.org.in
“All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India.”
Link checked 18 August 2026
Telecommunications (Authorisation) Rules, 2026
Government rules · Telecoms
The newest and sharpest localisation rule in India. Every system of a telecommunication network and all associated data, logs and information must sit inside India, and no copies may be routed, shared or made available outside India. Remote access from abroad needs prior government permission.
Enforced by Department of Telecommunications
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNo exemption or proviso. Covers cloud-hosted telecom network providers, internet exchange points and satellite gateway operators.
- Keep logs — 6 monthsAudit trail of remote access, held in India.
Sources
- Official sourceDepartment of TelecommunicationsDepartment of Telecommunications — Telecommunications (Authorisation) Rules, 2026
dot.gov.in
IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025
Directly binding regulation · Insurance
Records of all policies issued and all claims made in India must be held in data centres located and maintained in India only.
Enforced by Insurance Regulatory and Development Authority of India
Transfer model: Not allowed
What it makes you do
- Keep the data in the country
Sources
- Official sourceInsurance Regulatory and Development Authority of IndiaIRDAI — Maintenance of Information by Regulated Entities Regulations, 2025
irdai.gov.in
Cybersecurity and Cyber Resilience Framework, control PR.DS.S2
Regulator directive · Held in abeyance by SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 · Securities
A localisation requirement for Indian securities-market data that is formally adopted but suspended since 31 December 2024. It has not been withdrawn, and could be switched back on without notice. Other cybersecurity controls in the same framework remain binding.
Enforced by Securities and Exchange Board of India
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryCurrently suspended. Revivable by the regulator without public consultation.
Sources
- Official sourceSecurities and Exchange Board of IndiaSEBI — Cybersecurity and Cyber Resilience Framework circulars
sebi.gov.in
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Exact commencement dates — 12 vs 13 November 2026 and 12 vs 13 May 2027
The Rules count from publication; sources differ by one day depending on whether they count from the gazette notification date or the publication date. Plan to the earlier date.
Whether any chairperson or member of the Data Protection Board has been appointed between 1 and 18 August 2026
We can evidence vacancy up to 1 August 2026 from the regulator's own notices, but cannot prove a negative for the days since.
Full official text and transition period of the Telecommunications (Authorisation) Rules, 2026
Reported by credible trade press in July 2026; we have not yet located the gazette copy on the department's own site. The rule is therefore marked medium confidence and the government backlink is to the department's homepage rather than the instrument.
Whether the IRDAI 2025 regulations expressly repealed the 2015 insurance records regulations
Not located on the regulator's site.
Whether MeitY's cloud empanelment terms impose data residency in the instrument text
Residency is described by the cloud providers rather than quoted from a government document we could open.
60-day cadence: India has four dormant switches (transfer blacklist, restricted-data committee, significant-organisation designations, the suspended securities rule) that can each flip with a single notification and no consultation. Anything longer than 60 days risks the site asserting a permissive position that has already been reversed.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.