Skip to the content
Global Data RulesData governance rules, country by country

India

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Waking up

India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.

Eight questions about India

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do India's rules apply to my company?

Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.

High confidenceNational rules

Can I store my users' data outside India?

In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.

High confidenceDepends on your industryBlocklist

What do I need in place before data leaves India?

Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.

High confidenceNothing requiredBlocklist

Who enforces the rules in India, and what can they do?

On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.

High confidenceWaking up

How long do I have to keep the data?

There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.

High confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What trips people up in India?

Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.

High confidenceGet a parent's consent for childrenNo tracking or ads to childrenAppoint a data protection officerRegister or notify

What is changing soon in India?

Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.

High confidencePartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

Digital Personal Data Protection Act, 2023

Act of parliament · Act No. 22 of 2023

Partly in forceYes — store it anywhere

India's general privacy law. Permissive on cross-border transfer — a blacklist model with an empty blacklist — but heavy on consent, children's protection and, for designated large organisations, in-country accountability. Most of it becomes enforceable on 13 May 2027. Penalties are fixed caps, not a percentage of turnover.

In force since 13 November 2025But only enforceable from 13 May 2027

Enforced by Data Protection Board of India — not yet operational

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Nothing required

High confidence

Directions under section 70B(6) of the Information Technology Act, 2000

Government rules · No. 20(3)/2022-CERT-In

In forceA copy must stay

India's cyber incident regime. Six hours to report an incident, 180 days of system logs, and clocks synchronised to Indian government time servers. Applies extraterritorially — a company with no presence in India still needs a named point of contact.

In force since 28 June 2022

Enforced by Indian Computer Emergency Response Team (CERT-In)

Transfer model: Approval each time

High confidence

Industry rules4 rules

Storage of Payment System Data

Regulator directive · RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-18 · Payments

In forceNo — it stays put

All payment system data must be stored in a system only in India. No mirror abroad is permitted. Only the foreign leg of a cross-border transaction may be stored overseas, and for those a copy of the domestic component may also be held abroad.

In force since 15 October 2018

Enforced by Reserve Bank of India

Transfer model: Not allowed

High confidence

Telecommunications (Authorisation) Rules, 2026

Government rules · Telecoms

In forceNo — it stays put

The newest and sharpest localisation rule in India. Every system of a telecommunication network and all associated data, logs and information must sit inside India, and no copies may be routed, shared or made available outside India. Remote access from abroad needs prior government permission.

In force since 20 July 2026

Enforced by Department of Telecommunications

Transfer model: Not allowed

Medium confidence

IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025

Directly binding regulation · Insurance

In forceNo — it stays put

Records of all policies issued and all claims made in India must be held in data centres located and maintained in India only.

In force since 3 January 2025

Enforced by Insurance Regulatory and Development Authority of India

Transfer model: Not allowed

Medium confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Exact commencement dates — 12 vs 13 November 2026 and 12 vs 13 May 2027

    The Rules count from publication; sources differ by one day depending on whether they count from the gazette notification date or the publication date. Plan to the earlier date.

  • Whether any chairperson or member of the Data Protection Board has been appointed between 1 and 18 August 2026

    We can evidence vacancy up to 1 August 2026 from the regulator's own notices, but cannot prove a negative for the days since.

  • Full official text and transition period of the Telecommunications (Authorisation) Rules, 2026

    Reported by credible trade press in July 2026; we have not yet located the gazette copy on the department's own site. The rule is therefore marked medium confidence and the government backlink is to the department's homepage rather than the instrument.

  • Whether the IRDAI 2025 regulations expressly repealed the 2015 insurance records regulations

    Not located on the regulator's site.

  • Whether MeitY's cloud empanelment terms impose data residency in the instrument text

    Residency is described by the cloud providers rather than quoted from a government document we could open.

60-day cadence: India has four dormant switches (transfer blacklist, restricted-data committee, significant-organisation designations, the suspended securities rule) that can each flip with a single notification and no consultation. Anything longer than 60 days risks the site asserting a permissive position that has already been reversed.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.