Skip to the content
Global Data RulesData governance rules, country by country

India

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in India — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

You can send Indian data almost anywhere under India's general privacy law. The government can ban named countries, and so far it has banned none. But some industries are strict. Payments data, insurance records and telecom network data must stay inside India. The main law is passed, but most of it only becomes enforceable in May 2027. The regulator has no members yet.

Data governance in India

The eight things that decide how you handle data about people in India. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, the law reaches you even if you have no office in India. It applies to any organisation anywhere in the world that handles Indians' data. It applies where you do so in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.

Where the data is allowed to live

Yes, and freely. India uses a banned-country list. The government may name countries you cannot send data to. As of today it has named none. Six industries are the exception, and they are covered below.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

There is nothing to sign, no government approval and no standard contract. India's general law needs no paperwork to send personal data abroad. The only question is whether the country is on the banned list, and no country is. Industry rules override this completely.

Ways to send data out:
Nothing required

The regulator, and whether it actually acts

The Data Protection Board of India is meant to enforce, but nobody is enforcing yet. The Board legally exists. As of August 2026 it has no chairperson and no members. The government advertised the five posts in May 2026 and advertised again in June. They were still empty in August. Industry regulators are fully active. The central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.

How long you must keep it — and when to delete it

There are minimum keeping times and a duty to delete. From May 2027 you must keep logs of how you use data for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last used the service. You must warn the user 48 hours first.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are two deadlines, and this catches almost everyone out. You have SIX HOURS to report a cyber incident to India's national cyber agency. That is one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and the affected people without delay. You then file a detailed report within 72 hours.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Four things catch people out. (1) A child is anyone under 18. India has no lower age for digital consent, unlike Europe. Targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company worth about 2.3 million US dollars, so a foreign company cannot be one. (3) If you are named a 'significant' organisation, your data protection officer must be based in India and answer to the board. (4) The general law expressly keeps stricter industry rules in place. Its relaxed transfer rules give you nothing if you touch payments, insurance or telecom.

What you have to do here:
Get a parent's consent for children · No tracking or ads to children · Appoint a data protection officer

What's changing next

Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable. The government has publicly refused to delay it or to exempt startups. Some time before then the Board should get its members. Enforcement starts at that point.

What to do: Diarise 13 November 2026 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data must stay in the country

Official name: Storage of Payment System Data · RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-18 · Regulator directive

In forceNo — it stays put

All payment system data must be stored in a system only in India. No mirror abroad is permitted. Only the foreign leg of a cross-border transaction may be stored overseas. For those, a copy of the domestic part may also be held abroad.

In force since 15 October 2018

Enforced by Reserve Bank of India

How this country controls where data goes: Not allowed

Telecoms

Telecoms data must stay in the country

Official name: Telecommunications (Authorisation) Rules, 2026 · Government rules

In forceNo — it stays put

India's newest and strictest rule on keeping data in the country. Every system of a telecommunication network must sit inside India. So must all data, logs and information that go with it. No copies may be routed, shared or made available outside India. Remote access from abroad needs government permission first.

In force since 20 July 2026

Enforced by Department of Telecommunications

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Insurance

Insurance data rules

Official name: IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025 · Directly binding regulation

In forceNo — it stays put

Records of all policies issued and all claims made in India must be held in data centres located and maintained in India only.

In force since 3 January 2025

Enforced by Insurance Regulatory and Development Authority of India

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Digital Personal Data Protection Act, 2023 · Act No. 22 of 2023 · Act of parliament

Partly in forceYes — store it anywhere

India's general privacy law. It is relaxed about sending data abroad. The government can ban named countries, and it has banned none. It is heavy on consent and children's protection. Organisations named as large must also answer for their data from inside India. Most of the law becomes enforceable on 13 May 2027. Penalties are fixed caps, not a percentage of turnover.

In force since 13 November 2025In force now, but not enforced until 13 May 2027

That is a long gap: the duty is real law today, but no penalty can follow until 13 May 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Data Protection Board of India — not yet operational

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Nothing required

Breach reporting rules

Official name: Directions under section 70B(6) of the Information Technology Act, 2000 · No. 20(3)/2022-CERT-In · Government rules

In forceA copy must stay

India's rules on reporting cyber incidents. You get six hours to report an incident. You must keep 180 days of system logs. Your clocks must be synchronised to Indian government time servers. The rules apply even if you have no office in India, and you still need a named point of contact.

In force since 28 June 2022

Enforced by Indian Computer Emergency Response Team (CERT-In)

How this country controls where data goes: Approval each time

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Securities

Cyber security rules

Official name: Cybersecurity and Cyber Resilience Framework, control PR.DS.S2 · Held in abeyance by SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 · Regulator directive

SuspendedNo — it stays put

A rule that Indian securities-market data must stay in India. It is formally adopted but on hold since 31 December 2024. It has not been withdrawn, and it could be switched back on with no notice. The other cybersecurity controls in the same set of rules still bind you.

Enforced by Securities and Exchange Board of India

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Exact commencement dates — 12 vs 13 November 2026 and 12 vs 13 May 2027

    The Rules count from publication; sources differ by one day depending on whether they count from the gazette notification date or the publication date. Plan to the earlier date.

  • Whether any chairperson or member of the Data Protection Board has been appointed between 1 and 18 August 2026

    We can show the posts were empty up to 1 August 2026 from the regulator's own notices. We cannot confirm the position for the days since. Check the regulator's notices before you rely on this.

  • Full official text and transition period of the Telecommunications (Authorisation) Rules, 2026

    Credible trade press reported this in July 2026. We could not find the gazette copy on the department's own site. So we mark the rule medium confidence, and the government link points to the department's homepage rather than to the rule itself.

  • Whether the IRDAI 2025 regulations expressly repealed the 2015 insurance records regulations

    We could not find this on the regulator's site. We cannot confirm it either way. Check with the regulator before you rely on it.

  • Whether MeitY's cloud empanelment terms impose where data has to be stored in the instrument text

    The cloud providers say where the data is stored. We could not confirm it against a government document. Check before you rely on it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.