The localisation myth
Earlier drafts of India’s data law contained stronger localisation ideas, including proposals to keep copies of data in India. Those drafts shaped a lasting impression that the final law mandates localisation. The DPDPA as enacted did not take that path.
The result is that many organisations plan for a localisation obligation that the Act does not impose, while overlooking the sector rules that actually do require Indian storage for specific data.
How Section 16 actually works
Section 16(1) allows a Data Fiduciary to transfer personal data for processing to any country or territory outside India, except those the Central Government restricts by notification. This is the opposite of an approved-destinations model: everywhere is permitted until specifically named.
As of 2026, the government has not published such a restriction list. In practice, this makes the DPDPA one of the more open regimes on cross-border transfer, subject to the overriding sector rules below.
The provision that preserves localisation: Section 16(2)
Section 16(2) states that the transfer rule in Section 16(1) does not restrict the application of any other law that provides a higher degree of protection or restriction on transfer. This is the hinge of the whole topic.
It means that where another law or regulator already requires data to stay in India, that stricter requirement is untouched by the DPDPA. The DPDPA sets a permissive baseline; sector law can and does sit above it.
Where Indian storage is still required
Localisation in India comes from specific regulators. The common examples:
| Regulator | Requirement | Data affected |
|---|---|---|
| Reserve Bank of India | 2018 directive, storage only in India | Payment system data |
| Insurance regulator | Records maintained in India | Insurance policy and policyholder data |
| Government / MeitY | Sector or ministry directions where issued | Specified categories |
The practical task is to identify which regulators apply to your business, then layer their storage rules on top of the permissive DPDPA baseline.
How AMLEGALS advises on transfers and localisation
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team maps your data flows against Section 16, identifies which sector regulators impose Indian storage under Section 16(2), and sets out what can be processed abroad and what must stay in India.

