Data localisation in India has become a key consideration for organizations adopting cloud-based enterprise software. As the data protection and industry-specific regulations continue to evolve, businesses must ensure that their software providers can meet data residency, security, and compliance requirements from the very beginning.
Today, data localisation is no longer just a compliance checkbox, it has become a critical factor in enterprise software procurement. Before selecting or renewing a software solution, organizations increasingly evaluate where their data will be stored, how it will be processed, and whether the platform aligns with India's regulatory expectations.
This guide explains India's data localisation landscape, the key regulations that affect enterprise software, and the practical steps organizations can take to build a secure, compliant, and future-ready technology stack.
The Indian data localisation landscape is pretty complex. India does not have one law that says all data must be stored in the country. Instead there are different rules that apply. For example there is a law to protect peoples personal data and separate rules for banks, government computer systems and different industries like defence, healthcare and telecom. Companies that work in two or three of these areas have to follow all the rules at the time.
There are three ideas that people often get mixed up:
Over the ten years Indias approach to data localisation has changed. At first there were ideas to make rules like the ones in Europe but now the approach is more relaxed. The new Digital Personal Data Protection Rules from 2025 say that data can be sent abroad unless the government says no. This is a change from the old idea that all data had to be stored in the country. However there are still rules for certain areas like payments, government purchases and health data. For companies buying software the main law is the baseline. The rules, for their specific industry are often more important.
Financial services have strict rules in India. The Reserve Bank of India (RBI) said in a circular in April 2018 that all payment system operators must store all payment data on servers in India. This includes customer details like name, mobile number and email address. It also includes Aadhar card number, PAN, beneficiary details and payment credentials like One Time Password (OTP) PIN and passwords.
The RBI requires system providers to submit a compliance certificate every six months, signed by the CEO or Managing Director. They also need a System Audit Report certified by a CERT-In empanelled auditor.
These regulations have important implications for software companies that provide solutions to banks, Non-Banking Financial Companies (NBFCs), payment aggregators, and insurers.
The RBIs rules on outsourcing and cloud computing also apply to third-party vendors and sub-processors not the regulated entity. A bank cannot avoid its obligations by outsourcing.
Their rules are stricter than the Digital Personal Data Protection (DPDP) Act. Will continue to apply alongside it. Section 16(2) of the DPDP Act preserves any sectoral rule already in force.The rules will keep operating in parallel, with DPDP than being absorbed by it. RBI and DPDP will work together to regulate payment data in India.The RBI directives and BFSI obligations will ensure that payment data is stored and processed securely in India.
The Digital Personal Data Protection Act and the Digital Personal Data Protection Act rules are being introduced in stages. The Digital Personal Data Protection Act and the Digital Personal Data Protection Act rules are going to affect how companies handle data. The Data Protection Board of India is already in place. Companies have to register their consent managers after one year. They also have to follow some rules like giving notice keeping data safe telling people if there is a breach and following rules for transferring data to countries. These rules will start eighteen months after the notification in November 2025.
The Digital Personal Data Protection Act says that personal data can be sent to any country unless the government says no.. The government has not made a list of countries where data cannot be sent. So companies do not know which countries are off-limits. The Digital Personal Data Protection Act rules say that some companies will have restrictions, on sending personal data outside India. If there is a breach these companies have to tell the Data Protection Board. They can also be fined a lot of money up to ₹200 crore if they do not follow the rules.
For companies that buy or make software the Digital Personal Data Protection Act has some implications. They should map out where their data is going even if the rules are not being enforced yet. This is important because they need to know which vendors and cloud regions are handling data of people in India. The Digital Personal Data Protection Act may not require companies to keep data in India. It does not mean they have no restrictions. They should be able to move their data out of a country if the government says they cannot send data there anymore.
Companies should also keep an eye on which companies are named as Significant Data Fiduciaries. These companies will have rules to follow for handling personal data. The Digital Personal Data Protection Act and the Digital Personal Data Protection Act rules are going to change how companies handle data so they need to be prepared. They should know what the Digital Personal Data Protection Act and the Digital Personal Data Protection Act rules say about -border transfers and Significant Data Fiduciaries.
In addition to the RBI guidelines and the DPDP Act, sectors such as defence, healthcare, and telecom have specific data localisation requirements that enterprise software vendors should not overlook.
1. Defence and government procurement.Government departments, PSUs, nationalised banks and defence-linked agencies can generally only procure cloud services from providers empanelled under MeitY's MeghRaj initiative.Empanelment requires that cloud services offered are hosted within India and that data is limited within the boundaries of India, alongside independent audits by the Standardisation Testing and Quality Certification directorate against standards such as ISO 27001, 27017 and 27018. Empanelled hyperscaler regions (for example, Mumbai and Hyderabad for AWS, or Mumbai and Delhi-NCR for Google Cloud and several Indian providers) exist specifically to satisfy this requirement, but empanelment is granted service-by-service and expires periodically, so a vendor being "MeitY empanelled" in general does not guarantee that the specific module an enterprise wants to deploy is in scope. Sensitive defence and intelligence workloads frequently sit on separate, more restrictive procurement paths altogether.
2. Healthcare
India does not yet have a single binding healthcare-data-localisation statute in force, but the direction is consistent across the frameworks that do exist. The long-discussed Digital Information Security in Healthcare Act framework has proposed that at least one copy of sensitive personal data such as medical records be kept in an Indian data centre. Separately, the Ayushman Bharat Digital Mission's Health Data Management Policy sets consent, storage and access rules for any platform that integrates with ABHA-linked health records, and the DPDP Act's general obligations apply on top of that, treating health data as a category warranting particular care. Enterprise health-tech and hospital-management software vendors should expect Indian data residency for clinical records to become a hard requirement rather than a best practice, and should build for it now.
3. Telecom
Telecom licence conditions in India have long required that certain subscriber and traffic data tied to national security and law enforcement access be held domestically, and this pattern of telecom-metadata localisation is common internationally as well. For enterprise software serving telecom operators billing platforms, CRM, network analytics this means subscriber identity and call/traffic metadata typically cannot be processed or stored on infrastructure outside India, even where other, less sensitive operational data can be.
Meeting data localisation and compliance requirements is much easier with a proactive strategy than reacting after a regulatory inquiry. A practical approach includes the following five steps:
Organize data into categories such as payment data, healthcare records, telecom subscriber information, personal identifiable information (PII), and non-personal operational data before deciding where it should be stored or processed. Since a single enterprise application often handles multiple types of data, each governed by different regulatory requirements, proper classification is essential for ensuring compliance
Organizations in the BFSI, government, defence, and healthcare sectors should deploy applications in India-based cloud regions from the outset to simplify compliance and avoid costly migrations later. For government departments and Public Sector Undertakings (PSUs), it is advisable to use MeitY-empanelled cloud service providers to meet procurement and regulatory requirements.
Vendor and sub-processor agreements should specify data location, deletion timelines for any data legitimately processed abroad, audit rights, and breach-notification obligations that match or exceed what DPDP and sector regulators require.
Data protection regulations, RBI guidelines, and MeitY empanelment requirements continue to evolve. Instead of treating compliance as a one-time exercise, organizations should build the capability to regularly monitor regulatory changes, update data flows, and migrate workloads quickly when needed. This proactive approach ensures long-term compliance and reduces business risk.
For the most sensitive workloads payment credentials, defence-linked systems, core health records many Indian enterprises are choosing to keep systems of record on-premise or in a sovereign private cloud, and use public cloud only for less sensitive, elastic workloads. Our on-premise deployment hub covers the architecture patterns for this in more detail.
If your organisation operates in BFSI, RBI's payment-data circular is non-negotiable and should be treated as the floor, not the ceiling, of your compliance programme see our BFSI sector guide for what this means for banking and NBFC software procurement specifically. Public sector and defence-linked buyers should also review our dedicated pages on government and defence procurement requirements, which go deeper into empanelment and audit expectations than this overview can.
As enterprises strengthen their data localisation strategies, internal communication platforms must follow the same compliance standards as other business-critical applications. Many organizations continue to rely on global messaging platforms that store or process sensitive business data outside India, creating governance and regulatory challenges.
Troop Messenger addresses these concerns with its On-Premise Deployment, enabling organizations to host their entire communication infrastructure within their own data center or private cloud. This gives enterprises complete ownership of their messaging data while supporting India's evolving data residency and compliance expectations.
For organizations operating in regulated industries such as BFSI, healthcare, government, defense, and telecom, Troop Messenger offers several advantages:
As more Indian enterprises adopt hybrid and sovereign cloud strategies, deploying an on-premise business messaging platform like Troop Messenger helps organizations maintain regulatory compliance while ensuring secure, uninterrupted collaboration across teams.
Data localisation in India is evolving rapidly, driven by the Digital Personal Data Protection (DPDP) Act, RBI regulations, MeitY guidelines, and sector-specific requirements for industries such as healthcare, telecom, and defence. As these regulations continue to develop, organizations must move beyond viewing compliance as a one-time requirement and instead build long-term strategies that support changing legal and business needs.
To stay compliant, enterprise IT and procurement teams should classify data based on its sensitivity, understand the regulatory obligations applicable to each category, and choose software vendors that offer flexible deployment options, including on-premise, hybrid, or India-based cloud infrastructure where required. Organizations that proactively plan their data architecture, strengthen vendor contracts, and continuously monitor regulatory updates will be better positioned to maintain compliance, reduce risk, and adapt confidently as India's data localisation landscape continues to evolve.
No. India does not have one law that says all data must be stored in India. The rules are different for sectors. For example the Reserve Bank of India says that payment system data must be stored in India. The government and defence also have their rules for storing data. The DPDP Act has an approach that allows data to be sent outside India unless a specific country is restricted. Healthcare and telecom companies have their rules too. Companies need to check what rules apply to their type of data.
The Reserve Bank of India says that payment system operators must store all data related to payment systems in India. This includes things like transaction details, customer names and payment credentials. There is one exception that allows some data to be stored outside India if it is part of a -border transaction. If data is processed outside India it must be deleted from the system within one business day.
No it has not. The DPDP Act actually allows data to be sent outside India unless the government says that a specific country is restricted. Now there is no list of restricted countries. Companies should still plan for how they will handle data transfers because the rules may change in the future.
Only government companies need to use cloud providers that are approved by the Ministry of Electronics and Information Technology. This approval ensures that the cloud providers services are hosted in India and meet standards. Private companies do not need to use approved cloud providers. Some choose to do so anyway.
Not yet, but it is likely that this will be required in the future. Some proposed laws, like the Digital Information Security in Healthcare Act say that health records should be stored in India. The Ayushman Bharat Digital Mission also has rules, about how health data should be
stored. The DPDP Act treats health data as sensitive. Companies that handle health data should plan to store it in India even if it is not required by law yet.
