India’s nuanced approach to data localisation demands targeted compliance strategies for organisations

India’s evolving data localisation rules require non-BFSI organisations to adopt a granular compliance framework, focusing on specific datasets like Aadhaar and cyber-security logs, rather than a blanket localisation mandate.

India’s data-localisation rules are often treated as an all-or-nothing proposition, but the better reading is more nuanced: for most non-BFSI organisations, the issue is not whether every dataset must remain in India, but which records must be stored, backed up or kept accessible from Indian systems, and under what legal or contractual framework. Bar and Bench’s analysis says companies should build a governance model that separates sensitive categories of information and matches each one to the relevant rule set, rather than assuming a single blanket obligation applies across the board.

That distinction matters most for Aadhaar-related data. According to the piece, private entities cannot use Aadhaar authentication as a routine know-your-customer tool, and where Aadhaar information is handled lawfully, it must be segregated and managed under the Unique Identification Authority of India’s framework. UIDAI says it is the statutory authority created under the Aadhaar Act, 2016, and it oversees the legal and operational framework for Aadhaar data.

The same principle of targeted compliance applies to cyber-security logs. The CERT-In directions issued in April 2022 require service providers, intermediaries, data centres, body corporates and government organisations to maintain ICT system logs securely for 180 days within Indian jurisdiction. The directions also impose other obligations on certain providers, while CERT-In’s FAQs have been read as allowing some operational flexibility so long as logs can be produced when required. Separate industry guidance notes that organisations must also be ready to report specified cyber incidents to CERT-In within six hours of becoming aware of them.

Companies also need to factor in the Companies Act, 2013. Bar and Bench notes that where electronic books of account are kept outside India, they must remain accessible in India, and companies must maintain a daily back-up on servers located in India. Taken together, these rules point away from a simplistic localisation debate and towards a more granular compliance strategy: map the dataset, identify the governing rule, and then decide whether the obligation is storage, access, segregation or back-up.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.