Anchal Chhallani | TeamLease RegTech

  • Share On :

Feb 28, 2025


 

What is Data Localization?

 

Data is a collective resource and a national asset over which citizens have a sovereign right. Governments worldwide protect data by imposing certain restrictions and conditions on the storage and processing of data that they do not directly access. Storing data on any device physically located within the boundaries of the nation where such data has been generated is known as ‘data localization.’ Initially, with the advent of the digital age, countries were focusing on ‘digital globalization,’ which allowed cross-border movement of data. This was in stark contradiction to the theory of data localization. However, as the world wide web became wider, nations started departing from the modern ‘free flow of data for innovation’ theory and progressed to protect the nations and their citizens’ strategic interests by adopting the practice of data localization. Restricting and monitoring the free flow of data is essential in order to ensure the privacy and security of the citizens. 

 

Data Localization History in India

 

Data Localization laws in India can be traced back to 1993, when the Public Records Act, 1993 was introduced by the government that prohibited taking public records outside India. With the advent of the internet, the Information Technology (IT) Act, 2000 was enacted. The act defined data as, “a representation of information, knowledge, facts, concepts or instruction which are being prepared or have been prepared in a formalized manner, and is intended to be processed, is being processed or has been processed in a computer system or computer network, and may be in any form (including computer printouts magnetic or optical storage media, punched cards, punched tapes) or stored internally in the memory of the computer.”

 

The IT Act and its allied rules provided a mechanism to protect consumer data, however, it was not as effective dealing with misutilization of data stored and processed outside India. With people becoming aware of their right to privacy, there were various legislative and judicial inventions to acknowledge right privacy as it exists today. It started with an Expert committee being formed in 2012 chaired by Justice A.P. Shah, it prescribed nine national privacy principles.

 

In a landmark ruling in 2017 by the Hon’ble Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India, right to privacy was recognised as a fundamental right under article 21 of the Constitution of India. Later, in 2018, a report by Justice B.N. Srikrishna committee titled ‘A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians’ delved deep into data localisation and security, devising the first data protection legislation in India, the Personal Data Protection Bill, 2018 (‘PDP Bill’).

 

Data localization laws in India

 

India has introduced several regulatory measures mandating the localization of specific data sets. The key data localization laws in India are summarized below: 

 

The Companies Act 2013 and the Companies (Accounts) Rules 2014: 

Section 94 of the Companies Act, read with Sections 88 and 92, require covered organizations to store financial information at the registered office of the company.

 

Section 94 of the (Indian) Companies Act 2013 covers data about: 

  • members for each class of equity and preference shares; 

  • Debenture-holders;

  • other security holders; and 

  • annual returns that the organization filed with the Registrar of Companies. (Section 88, Companies Act.)

 

Section 94 of the Companies Act 2013 applies to: 

  • all companies incorporated under the Companies Act or any prior law; 

  • insurance companies; • banking companies; 

  • electric companies; and 

  • any other companies governed by special laws or designated by the Central Government. (Section 1(4), Companies Act.) 

 

However, a company subject to the Companies Act 2013 and the Companies (Accounts) Rules 2014 may keep a part of its register of members outside of India if either the company's articles of incorporation authorize the foreign register (Section 88(4), Companies Act); or the company stores backups of accounting books maintained in electronic format on servers located in India on a periodic basis (Section 128(3), Companies Act; Rule 3, Accounts Rules).

 

The Reserve Bank of India's Directive 2017-18/153 (April 6, 2018) issued under the Payment and Settlement Systems Act 2007

 

Paragraph 2(i) of the Directive requires covered organizations to store payment data within India. The directive covers payment data, including: 

  • end-to-end transaction details; and

  • information that the system provider collects or processes in carrying out the payment instruction

 

It applies to payment systems providers registered under Section 4 of the PSS Act. Payment systems encompass clearing, payment, or settling services and include transactions involving: 

  • credit cards; 

  • debit cards; 

  • smart cards; 

  • money transfer or similar transactions. (Section 2(i), PSS Act.)

 

However, it permits covered organizations to store copies of payment data outside of India if necessary to complete foreign payment transactions.

The IRDAI (Maintenance of Insurance Records) Regulation, 2015: • Paragraph 3(9) requires covered organizations to store insurance data within India.

It applies to all records, including those in electronic format, pertaining to insurance policies issued and claims made in India and to all insurers

Digital Personal Data Protection Act, 2023

 

The DPDP Act forms the basis for data privacy and protection in India. There are obligations defined for both data fiduciaries and data processors in the Act. It does not require data localization, but it does allow the government to restrict cross-border transfers of personal data to certain countries or territories. Section 16 allows for sector-specific rules to take precedence over the DPDPA. This means that sectors with higher protection and restrictions on data transfer will take precedence. For example, if the DPDP Act does not restrict the processing of your transaction data within India for foreign entities, necessary RBI directives will be applicable to them since it has a higher threshold of restriction.

The DPDPA implemented a whitelist-blacklist mechanism for cross-border data transfers, allowing data flows except to countries restricted by the government. However, the draft rules under DPDPA adopt a layered approach for regulating cross-border data transfers, where a government-appointed committee can impose specific conditions on sharing data with foreign states or entities. This dual-layered framework may conflict with other countries' regulatory obligations, creating additional compliance burdens. Furthermore, new guidelines for significant data fiduciaries (SDFs) restrict the flow of personal and traffic data outside India based on the committee’s recommendations. Rule 22 allows MeitY to request more information to declare SDFs.  The constitution of the proposed committee and the criteria to be followed are also not specified. The lack of clarity around which entities will ultimately be classified as SDFs compounds the uncertainty.

Information Technology Act, 2000, along with Rules and Guidelines

 

The IT Act does not mandate data localization but requires corporations and individuals handling personal data to follow specific practices. Section 67C mandates intermediaries to preserve information as directed by the government. The IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 permit the sensitive data to be transferred beyond the Indian boundaries, given the receiving country also has similar data protection standards. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, impose additional compliance obligations on intermediaries, including furnishing information upon government request, which can be challenging when data is stored in foreign jurisdictions.

 

 

Framework for Adoption of Cloud Services by the SEBI Regulated Entities (REs)

 

The cloud framework was introduced by SEBI on March 6, 2023. It is applicable to regulated entities that use cloud service providers to conduct their businesses. Principle 3 of the Securities and Exchange Board of India's cloud service adoption framework requires cloud service providers to meet data localization requirements. CSPs must store and process data for regulated entities (REs) within data centers that are prescribed by the Ministry of Electronics and Information Technology.

 

The Draft E-commerce Policy (2019)

 

This draft policy mandates that data generated by Indian e-commerce platforms must be stored in India, particularly to safeguard the interests of Indian consumers. The main purpose of the policy is to promote a data-sharing framework that helps domestic innovation and to ensure that foreign companies do not misuse the data of Indian customers. 

 

The Digital Information Security in Healthcare Act (DISHA)

 

The Digital Information Security in Healthcare Act (DISHA) is a proposed law in India that aims to protect the privacy and security of digital health data. It is a policy that requires healthcare providers and other entities to localize sensitive health data in India. DISHA requires that at least one copy of sensitive personal data, such as medical records, be stored in an Indian data center. DISHA requires the explicit consent of the data owner for the processing of sensitive personal data.

 

Data Localization as a concept has both its pros and cons. It has economic benefits as it steers investment in domestic data infrastructure. The Indian data center market is expected to grow rapidly, with investments projected to reach $10 billion by 2025, fueled by the rise of cloud computing, fintech, e-commerce, and social media. It also provides local companies and small businesses a chance to access large volumes of data to support their product development and AI-driven solutions, especially in India's growing fintech and health tech sectors. 

 

However, it also adds to the costs for businesses by requiring them to build and maintain local data storage infrastructures. This can lead to inefficiency and discourage foreign investment, particularly for smaller businesses that may find it difficult to meet the requirements. Despite these challenges, data localization enhances cybersecurity and national security by giving Indian authorities better control over data. It also aligns with the goal of safeguarding citizens' data and ensuring adherence to domestic privacy laws.


  • Share This Blog:
NEW  ·  AI ASSISTANT