Skip to content

What Storage Compliance Requirements Do Indian Banks Need to Meet Under RBI’s Data Localization Rules

For Indian banks, data compliance used to be mostly straightforward in terms of storing data, running audits, and submitting reports.  Now that outlook has changed significantly.

With the RBI’s Digital Personal Data Protection Act (DPDPA) 2023, and ongoing regulatory pressure on foreign banks operating in India, the compliance requirements around data storage have become more layered, more specific, and considerably harder to manage without the right infrastructure.

If you are a CIO, CISO, or IT Head at an Indian financial institution, this is not just a regulatory note. It is an operational reality that affects how you architect your infrastructure, choose your cloud providers, and manage your data environment every single day.

The RBI's 2018 Directive

According to the India RBI’s 2018 circular DPSS.CO.OD.NO.2785/06.08.005/2017-2018, the instructions were clear that all payment system operators, including banks, non-bank prepaid payment instrument issuers, card networks, and authorized payment system operators, must ensure that the complete end-to-end transaction data relating to payments operated by them is stored exclusively in systems that are located within India. This circular changed everything, and it was not a suggestion. It was a mandate.

And it forced a significant shift in how global payment companies, foreign banks, and domestic financial institutions approached their data infrastructure. Companies like Visa, Mastercard, and PayPal were required to establish local data storage in India, something that had not previously been a requirement.

What Data is Covered:

  • End-to-end transaction details
  • Payment-related information
  • Customer name, mobile number, email address
  • Aadhaar and PAN details
  • Beneficiary details
  • Payment credentials including OTP, PIN, and passwords

What the Rules Say About Processing Abroad

One of the more complex aspects of the RBI permits processing of data abroad but only for the foreign leg of an international transaction. Once that processing is complete, the data must be deleted from overseas systems and brought back to India within 24 hours of payment processing.

This is not simply a technical requirement. To do this, banks have the infrastructure, processes, and monitoring systems in place to track data movement, confirm deletion, and ensure local storage consistently and at scale.

From Apr 2021, the RBI mandatorily required all payment system operators to submit a compliance certificate signed by their CEO on a half-yearly basis confirming adherence to the data localization mandate.

The Digital Personal Data Protection Act 2023 added another layer to an already complex compliance landscape.

Unlike the RBI’s strict localization mandate, which effectively requires all payment data to remain in India, the DPDPA takes a different approach. It permits cross-border data transfers by default, with the Central Government retaining the right to restrict transfers to specific countries through notification. As of August 2026, no country has been formally restricted.

The critical point for Indian banks is that RBI-regulated payment data must remain within India regardless of what the DPDPA permits. The two frameworks operate simultaneously. Banks must comply with both the DPDPA for personal data protection obligations and RBI guidelines for payment system data storage.

This means financial institutions cannot now use DPDPA’s relatively permissive cross-border transfer provisions as a workaround for RBI’s stricter localization requirements. The more restrictive rule applies.

This means banks need compliance architectures that can handle both frameworks simultaneously, tagging data by category, managing transfer restrictions by regulation, and maintaining audit trails that satisfy two different regulatory bodies.

The Challenge for Foreign Banks

Foreign banks operating within India have faced difficulty with the RBI’s localization requirements. In early 2026, the Indian Banks’ Association was in active discussions with the RBI on behalf of foreign banks, communicating that while banks were progressively moving towards local data storage, migrating historical payment data stored in their home jurisdictions since 2018 was proving operationally challenging.

Some foreign banks had already modified their systems to store overseas payment data locally, but the pace of compliance varied significantly across institutions.

How Should the Compliance Infrastructure Look Like?

Getting the Architecture Right – Meeting RBI’s data localization requirements is not simply a legal exercise. It is an infrastructure challenge. Banks that are managing this effectively typically share a few common characteristics:

  • India-region cloud deployments – Using cloud providers with dedicated Indian data centers, such as AWS Mumbai and Hyderabad regions, Microsoft Azure India, and Google Cloud Mumbai, ensures that data residency requirements are met at the infrastructure level.
  • Data classification frameworks – Not all data carries the same compliance obligation. Strong compliance programmes tag data by category and jurisdiction, making it easier to apply the right storage and transfer rules to the right data automatically.
  • Automated deletion and retrieval for cross-border transactions – The 24-hour rule requires banks to track when foreign processing is complete and trigger deletion and local storage automatically. Manual processes cannot do this reliably at scale.
  • CERT-In-aligned audit logging – Producing the System Audit Report that RBI requires demands that your infrastructure generates the right evidence. Audit logging, access records, and storage confirmation need to be built into the architecture from the start, not retrofitted when an audit is approaching.

 

Where Brilyant Can Help

Meeting RBI’s data localisation requirements demands more than policy awareness. It requires infrastructure that is built for compliance from the ground up.

Brilyant works with financial institutions to design and deploy cloud and on-premises infrastructure that meets India’s regulatory data storage requirements, including India-region cloud deployments, data classification frameworks, audit-ready logging, and managed security monitoring through our SOC and NOC capabilities.

If your organization is navigating RBI compliance, assessing your current infrastructure against these requirements, or planning a cloud migration that must account for data localization, our team can help you build an architecture that keeps you compliant without compromising on performance or security.

Frequently Asked Questions

Does RBI’s data localisation rule apply to all banks or only payment companies?

The directive applies to all system providers and system participants in payment systems, including banks, non-bank payment instrument issuers, card networks, and authorized payment operators. Any entity handling payment system data in India falls within scope.

Can Indian banks use international cloud providers for data storage?

Yes, provided those cloud providers have data centers located within India and the data is stored in Indian regions. Most major cloud providers, including AWS, Microsoft Azure, and Google Cloud, have India-based regions that support this requirement.

What happens if a bank fails to comply with RBI’s localisation rules?

The RBI can impose monetary penalties under Section 26 of the Payment and Settlement Systems Act, 2007, up to ₹5 lakh per violation and ₹25,000 per day for continuing violations. In serious cases, the RBI can restrict or revoke payment system authorisation.

How does DPDPA interact with RBI’s data localization requirements?

The two frameworks operate simultaneously. DPDPA governs personal data protection and permits cross-border transfers unless restricted by government notification. RBI’s directive governs payment system data and requires it to remain in India. Banks must comply with both, and where the two conflict, the more restrictive requirement applies.

Get in touch with our infrastructure and compliance specialists to assess your current data storage environment against RBI’s requirements.

Search

Blogs

Search

Please share your details for quick download