AMLEGALS — Strategic Lawyering
DPDPA transfers · Localisation

Data localisation in India: what the DPDPA does and does not require

Data localisation is one of the most misunderstood parts of Indian data law. The common assumption is that the DPDPA forces data to stay in India. It does not. The real picture is a liberal transfer rule in the Act, with specific storage requirements that come from sector regulators.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 3 min read

A gold map outline of India with data streams flowing outward and back on a dark navy background
Short answer

The Digital Personal Data Protection Act, 2023 is not a data localisation law. Section 16 permits the transfer of personal data outside India, except to countries or territories that the Central Government may restrict by notification. This is a negative-list or blacklist model: transfers are allowed unless a destination is specifically restricted, rather than allowed only to approved destinations. Section 16(2) preserves stricter requirements under other laws, which is the key provision. It means that where a sector regulator already requires data to be stored in India, that requirement continues. The clearest example is the Reserve Bank of India’s 2018 directive requiring payment system data to be stored only in India. So localisation in India is driven by sector regulators, not by the DPDPA itself. An organisation should therefore separate two questions: what the DPDPA allows for cross-border transfer generally, and what any applicable sector regulator requires for storage.

  • Data localisation
  • Cross-border transfer
  • Section 16
  • RBI
  • Data residency
  • Sector rules
DPDPA model
Negative list: transfer allowed unless destination is restricted
Provision
Section 16, transfers outside India
Sector rules survive
Section 16(2) preserves stricter laws
Example
RBI 2018 payment data storage in India

The localisation myth

Earlier drafts of India’s data law contained stronger localisation ideas, including proposals to keep copies of data in India. Those drafts shaped a lasting impression that the final law mandates localisation. The DPDPA as enacted did not take that path.

The result is that many organisations plan for a localisation obligation that the Act does not impose, while overlooking the sector rules that actually do require Indian storage for specific data.

How Section 16 actually works

Section 16(1) allows a Data Fiduciary to transfer personal data for processing to any country or territory outside India, except those the Central Government restricts by notification. This is the opposite of an approved-destinations model: everywhere is permitted until specifically named.

As of 2026, the government has not published such a restriction list. In practice, this makes the DPDPA one of the more open regimes on cross-border transfer, subject to the overriding sector rules below.

The provision that preserves localisation: Section 16(2)

Section 16(2) states that the transfer rule in Section 16(1) does not restrict the application of any other law that provides a higher degree of protection or restriction on transfer. This is the hinge of the whole topic.

It means that where another law or regulator already requires data to stay in India, that stricter requirement is untouched by the DPDPA. The DPDPA sets a permissive baseline; sector law can and does sit above it.

Where Indian storage is still required

Localisation in India comes from specific regulators. The common examples:

Sector localisation requirements that continue under Section 16(2)
RegulatorRequirementData affected
Reserve Bank of India2018 directive, storage only in IndiaPayment system data
Insurance regulatorRecords maintained in IndiaInsurance policy and policyholder data
Government / MeitYSector or ministry directions where issuedSpecified categories

The practical task is to identify which regulators apply to your business, then layer their storage rules on top of the permissive DPDPA baseline.

How AMLEGALS advises on transfers and localisation

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team maps your data flows against Section 16, identifies which sector regulators impose Indian storage under Section 16(2), and sets out what can be processed abroad and what must stay in India.

Questions and answers

Data Localisation in India: common questions

Does the DPDPA require data to be stored in India?

No. Section 16 permits transfer outside India except to destinations the government may restrict. The DPDPA itself is not a localisation law.

What is the negative-list model?

Transfers are allowed to all destinations except those specifically restricted by government notification, rather than allowed only to pre-approved destinations.

Why do people still talk about localisation?

Because sector regulators impose it. Section 16(2) preserves stricter laws, so rules like the RBI 2018 payment data directive continue to require Indian storage.

Which data must stay in India?

Data covered by a sector requirement, most clearly payment system data under the RBI 2018 directive, and other categories where a regulator directs Indian storage.

Has the government restricted any countries?

As of 2026 no restriction list has been published under Section 16(1), so transfers are broadly permitted subject to sector rules.

Contact

Map your transfers and storage

Share where your data is processed. The AMLEGALS data privacy team will set out what can move abroad and what must stay in India.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Data Localisation in India: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Data Localisation in India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Data Localisation in India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Data Localisation in India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Data Localisation in India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Data Localisation in India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Data Localisation in India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Data Localisation in India · DPDPA Exposure Assessment