Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

est of the sovereignty, integrity, defence and security of India. While the DPDP Act does not stipulate any requirement to seek approval for international transfers of data per se, it does give the govern - ment wide powers to impose any restrictions on such transfer as it may notify through delegated legislation. Accordingly, the government can always impose the obligation to seek approval for transferring data internationally. Please see 5.5 Recent Developments regarding develop - ments under the Draft DPDP Rules. 5.3 Data Localisation Requirements There are no data localisation requirements under the SPDI Rules. There are no specific data localisation require - ments under the DPDP Act, but such require - ments can be introduced through delegated legislation or rules. The CERT-IN Directions mandate enabling the logs of all ICT systems and maintaining them securely for a rolling period of 180 days within the Indian jurisdiction. As per the FAQs to the CERT-IN Directions, these logs can be stored outside India if they can be presented to the CERT-IN within a reasonable time. Sectoral Laws There are data localisation or access require - ments under sectoral laws, some of which are identified below. Banking The RBI has a soft data localisation mandate under the Circular on Storage of Payment Data and the associated FAQs, according to which authorised payment system providers are required to store the entire payment data in

systems located in India. However, for cross- border transaction data consisting of a foreign component and a domestic component, a copy of the domestic component may also be stored abroad, if required. Insurance The Insurance Regulatory and Development Authority of India (Maintenance of Information by the Regulated Entities and Sharing of Informa - tion by the Authority) Regulations 2025 require that records related to policies issued and claims made in India shall be held in data centres locat - ed and maintained within the country. Securities In the Cloud Services Framework, SEBI has mandated that data including logs and any other data/information pertaining to regulated entities in any form stored in the cloud must reside in India; in the case of foreign investors, the regu - lated entities must keep the original data/trans - actions/logs and make them available and easily accessible in legible and usable form in India. A data localisation mandate had also been intro - duced in the Cybersecurity and Cyber Resilience Framework by SEBI in respect of regulated enti - ties’ regulatory data as well as data in human/ application readable form if the data centre is operated outside India. However, after receiving pushback regarding this mandate, SEBI issued a clarification on 31 December 2024 and put the data localisation requirement on hold until fur - ther notice. Telecom The UL requires a licensee to not transfer any subscriber-related accounting information (except for international roaming/billing) and user information (except pertaining to foreign

202 CHAMBERS.COM

Powered by