Data Localization & Cross-Border Data Flows: DPDPA vs GDPR
Analyzing data localization requirements and cross-border transfer rules under the DPDPA, and how they interact with GDPR standards.
Data Localization Mandates in India
Data localization involves storing and processing personal data within the national boundaries of India. While the general DPDPA framework allows cross-border data transfers to countries unless specifically blacklisted by the government, sectoral regulators (like RBI, SEBI, and IRDAI) impose strict localization requirements.
Q: What are the RBI requirements for payment data localization?
The Reserve Bank of India (RBI) mandates that all payment data (including card details, transaction history, and credentials) must be stored exclusively on servers located in India. While data can be processed abroad during a transaction, it must be purged from foreign servers within 24 hours.
Cross-Border Transfers & Global Frameworks
For international companies operating in India, comparing the DPDPA with GDPR is essential. GDPR utilizes Adequacy Decisions, Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs) to govern cross-border transfers. The DPDPA takes a blacklist approach, allowing transfers to most countries unless restricted, but places a high emphasis on Data Fiduciary accountability.
Q: Who is considered a Data Processor under the DPDPA?
Any third-party vendor, IT consultant, or cloud service provider that processes personal data on behalf of a Data Fiduciary is a Data Processor. Fiduciaries must execute data processing agreements ensuring processors implement strong security measures and report breaches immediately.
Compliance Warning
Even if the DPDPA permits a cross-border transfer, the Data Fiduciary remains entirely liable for any data breaches or non-compliance committed by the foreign Data Processor.
Book a Personalised Walkthrough
Interested in the Data Governance frameworks? Speak to a specialist to get a custom roadmap for your systems.