Cloud & Infrastructure

Data Localisation Requirements in India for Cloud

Affix Center · · 6 min read

Data Localisation Requirements in India for Cloud - Affix Center

"Is our data allowed to leave India?" It sounds like a simple question, but most IT heads find there is no single answer. Data localisation requirements in India for cloud setups come from several places: the data protection law, sectoral regulators such as RBI and SEBI, CERT-In directions and, for government work, specific contract and hosting conditions. Each one covers different data and asks for different things.

The risk is that organisations either ignore the issue, and end up with backups, logs or analytics copies sitting in overseas regions, or overcorrect and assume everything must stay in India even when it need not. Both are costly. This guide sets out the main rules as they stand, and then shows how to translate them into practical cloud design decisions. It is general guidance, not legal advice, so confirm your position with your legal and compliance team.

The Main Sources of Localisation Rules

Digital Personal Data Protection Act and Rules

The Digital Personal Data Protection Act, 2023 does not impose a blanket localisation rule. Section 16 allows personal data to be transferred outside India, but the Central Government may restrict transfers to specified countries. It also states that any other Indian law providing a higher degree of protection or restriction on transfers continues to apply.

The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with an eighteen-month period for phased compliance. They add two points relevant to cloud planning:

  • Transfers abroad must meet any requirements the Central Government specifies about making personal data available to a foreign State or entities under its control.
  • Significant Data Fiduciaries must ensure that personal data specified by the Central Government, on the recommendation of a committee, is not transferred outside India, along with the traffic data relating to its flow.

RBI rules on payment data

RBI's April 2018 circular on storage of payment system data requires payment system providers to store the entire data relating to payment systems operated by them in a system only in India. Processing abroad is permitted in limited cases, but the data must be brought back and stored in India, and deleted from overseas systems within the timelines RBI has set.

SEBI cloud framework

SEBI's framework for adoption of cloud services by regulated entities, issued in March 2023, requires that data of regulated entities resides and is processed within the legal boundaries of India. Brokers, depositories, mutual funds and other SEBI-regulated entities must design their cloud use around this.

CERT-In directions

The CERT-In directions of April 2022 require service providers, intermediaries, data centres, body corporates and government organisations to maintain logs of their ICT systems securely for a rolling period of 180 days within Indian jurisdiction. This is often overlooked when logs are shipped to a monitoring tool hosted overseas.

Government and PSU contracts

Government departments and PSUs usually set hosting conditions in their tenders and policies, often requiring data to be hosted in India with approved providers. Always check the specific contract, RFP and departmental policy.

Which Data Is Actually Affected?

The first practical step is to classify your data. Localisation rules apply to specific kinds of data, so you need to know what you hold and where it flows.

  1. Inventory your systems. List applications, databases, file stores, backups, logs and analytics platforms.
  2. Classify the data. Personal data, payment data, regulated financial data, government data, logs, and general business data.
  3. Map the flows. Note where each data set is stored, processed, backed up and replicated, including third-party SaaS tools.
  4. Match the rules. For each data set, note which requirement applies based on your sector and contracts.
  5. Record decisions. Keep a short register explaining where each data set lives and why. Auditors and regulators will ask.

Designing Your Cloud Setup for Data Localisation Requirements

Once you know which data must stay in India, the cloud design choices become clearer. The major public cloud providers operate regions in India, including Mumbai, so localisation is usually achievable. The detail is in the configuration.

Regions and replication

  • Deploy regulated workloads only in Indian regions.
  • Check default settings for backups, snapshots and cross-region replication. Disaster recovery copies should also stay in India where the rules require it, for example by pairing two Indian regions.
  • Use organisation-level policies to block resource creation in non-approved regions.

Logs and monitoring

  • Store security and system logs in India for at least the period CERT-In requires.
  • If you use an overseas monitoring or SIEM service, confirm where it stores data, or keep a primary copy in India.

SaaS and third-party tools

Email, CRM, helpdesk and analytics tools often store data outside India by default. Review each one, ask vendors for data residency options, and update contracts to reflect where data will be held.

Encryption and access

Localisation is about location, but security still matters. Encrypt data at rest and in transit, manage keys carefully, and restrict administrative access. Support staff located abroad accessing data in India can raise questions, so document who can access what. Our cybersecurity services team can help set up access controls and monitoring that fit these rules.

Common Gaps We See

  • Production data in Mumbai, but automated backups replicating to Singapore or Europe
  • Application logs sent to a monitoring tool hosted outside India
  • Developers copying production data to test environments in other regions
  • Customer support tools with personal data stored abroad by default
  • No written record of localisation decisions for audit

Most of these can be fixed with configuration changes and vendor reviews, without rebuilding applications.

A Simple Action Plan

Meeting data localisation requirements in India for cloud workloads is easier as a short, planned exercise than as a scramble before an audit. A practical sequence for the next few months:

  1. Assign an owner. One person, usually from IT or compliance, should own the data inventory and localisation register.
  2. Complete the inventory and classification described above, starting with systems that hold personal, payment or regulated data.
  3. Review cloud configurations for regions, backups, replication and logging, and fix anything that breaks your rules.
  4. Review vendor contracts for SaaS and managed services, and ask for written data residency commitments where needed.
  5. Track the phased DPDP timelines and any notifications from the Central Government on transfer restrictions or restricted data categories.
  6. Repeat the review at least once a year and whenever you add a major system or vendor.

Frequently Asked Questions

Does the DPDP Act require all personal data to stay in India?

No. It allows transfers abroad, subject to restrictions the Central Government may notify. Stricter sectoral rules and localisation duties for certain data held by Significant Data Fiduciaries still apply.

Can payment data be processed outside India?

RBI allows limited processing abroad, but the data must be stored only in India and brought back within the timelines RBI has specified.

Do logs need to be stored in India?

Under the April 2022 CERT-In directions, logs of ICT systems must be maintained for a rolling 180 days within Indian jurisdiction.

Is hosting in an Indian cloud region enough?

Not always. You must also check backups, replication, logs, SaaS tools, contracts and who has access to the data.

How Affix Center Can Help

Affix Center helps organisations in Mumbai and across India review where their data lives and design cloud and infrastructure setups that meet their sector's rules. We can map data flows, review region and backup settings, and fix gaps in logging and third-party tools.

To review your cloud setup against data localisation requirements, speak with our team.