🦚 Happy Krishna Janmashtami!

Data Localisation Norms for Banks: A BCP Compliance Guide (2026)

BCP By Ashish Jain · IIBF STORE Editorial · 11 July 2026 · Updated 24 Aug 2026 · 9 min read · 53 views
Data Localisation Norms for Banks: A BCP Compliance Guide (2026)

Every IIBF Banking Compliance Professional (BCP) candidate eventually runs into a deceptively simple exam question: where must a bank's data physically sit? The answer lives in the data localisation norms for banks that RBI has built up since 2018 — rules that decide whether a payment record, a KYC document, or a loan file can ever leave Indian soil, even temporarily, for processing abroad. Get this topic wrong and you lose marks not just on the definition but on the trickier "which exception applies" questions examiners love to set.

This guide breaks down the RBI payment data storage mandate, how it interacts with the newer Digital Personal Data Protection (DPDP) Act, 2023, and where compliance officers most often slip up in practice — exactly the kind of scenario-based question BCP papers now favour.

🌐 What Are Data Localisation Norms for Banks

In the simplest terms, data localisation requires that certain categories of data generated or collected in India be stored on servers physically located within the country, regardless of where the bank, card network, or wallet provider is headquartered. The concept entered Indian banking compliance in a serious way with RBI's April 2018 directive on storage of payment system data, and it has since become a standing topic in every BCP module that touches technology risk or regulatory reporting.

The rule is narrower than many candidates assume. It does not say every byte a bank touches must sit in India — it targets the full end-to-end data of a payment transaction: the originating information, the payment or settlement details, and any related customer data used to complete that transaction. A bank that runs its core banking system through an offshore data centre for non-payment functions is not automatically in breach; the obligation is transaction-specific. This nuance is precisely why the topic pairs so naturally with the compliance issues covered under identification of compliance issues and risks, since misreading the scope of a mandate is itself a classic compliance failure mode.

📜 The RBI Payment Data Storage Mandate

The 2018 directive applies to all system providers — banks, non-bank PSOs, card networks, and prepaid instrument issuers — and required them to ensure that the entire data relating to payment systems operated by them is stored only in India, within a six-month compliance window. Where a transaction has a foreign leg (say, a card used overseas or a cross-border remittance), the data related to the foreign part of that transaction may be processed abroad, but it must be deleted from systems outside India within 24 hours of processing and the resulting data brought back and stored in India.

System providers were also required to submit a Board-approved System Audit Report (SAR), conducted by a CERT-In-empanelled auditor, confirming compliance to the Reserve Bank. Non-compliance has real teeth — RBI has barred at least one major international card network from onboarding new domestic customers over exactly this requirement, a case worth remembering for application-based MCQs.

💡 Exam Tip: If a question describes a foreign transaction leg being processed abroad, the correct answer almost always hinges on the "24-hour deletion" clause — not on whether foreign processing is allowed at all (it is).
Key Concepts — Banking Compliance Professional
Key Concepts — Banking Compliance Professional

🔐 DPDP Act 2023 and Customer Data Protection

Candidates frequently conflate the RBI payment-data mandate with the Digital Personal Data Protection Act, 2023, but the two operate on different logic. The DPDP Act governs personal data generally (not just payment data) and takes a "negative list" approach to cross-border transfer: personal data can be transferred outside India by default, unless the Central Government specifically restricts transfer to a notified country. That is the opposite structure of the RBI mandate, which is a blanket in-India storage requirement for payment data with a narrow, time-bound exception for foreign-leg processing.

For a bank's compliance function, this means running two parallel data-governance tracks: sector-specific RBI localisation duties for payment and settlement data, and DPDP-driven consent, breach-notification, and data-principal-rights obligations for customer personal data more broadly. Banks typically fold both tracks into the same annual compliance risk assessment cycle rather than treating them as separate programmes, since the underlying data often overlaps.

⚠️ Common Mistake: Assuming DPDP overrides or replaces the RBI localisation circular. It does not — sectoral regulator directions continue to apply alongside the DPDP Act; where both apply, the stricter requirement governs.

⚖️ Data Localisation vs Cross-Border Data Flows

The table below is the fastest way to keep the different regimes straight for exam purposes — a favourite trick question is to swap the "mandatory" and "conditional" columns between rows.

Data categoryStorage ruleForeign leg allowed?
Payment system data (RBI, 2018 circular)Full data stored only in India✅ Yes, but foreign copy deleted within 24 hrs
KYC / customer identification recordsPrimary storage in India; DR backup permitted abroad✅ Yes, for disaster recovery only
General personal data (DPDP Act, 2023)No blanket localisation; negative-list approach✅ Yes, unless country is notified/restricted
Data to a notified/restricted country under DPDPTransfer prohibited❌ No
Process & Framework — Banking Compliance Professional
Process & Framework — Banking Compliance Professional

🧭 Building a Compliance Checklist for Banks

In practice, a compliance officer verifying localisation adherence works through a short but strict checklist: mapping every payment data flow end-to-end, confirming vendor and cloud contracts contain explicit India-storage clauses, verifying the 24-hour foreign-leg deletion logs, and ensuring the annual System Audit Report reaches the Board before submission to RBI. These checks routinely surface alongside other supervisory themes — inspection teams reviewing the RBI supervisory framework for a bank will almost always pull the data-localisation SAR as part of the same review cycle, and larger banks often examine it in the same board pack that tracks the large exposures framework and other prudential returns.

Because data-handling failures are themselves a category of operational and regulatory risk, most banks route localisation findings straight into their compliance risk assessment register rather than tracking them separately — a linkage the BCP syllabus tests directly. Customer-facing disclosure of how data is stored and used also ties back to the bank's obligations under regulatory guidelines on customer service, since transparency about data practices is now treated as part of fair customer treatment, not a purely technical IT matter.

📌 Remember: The System Audit Report is Board-approved before it goes to RBI — a detail examiners like to test by asking "who approves the SAR" rather than "who prepares it."

Recent RBI reports on payment system oversight also reference localisation compliance as a recurring supervisory finding; candidates preparing this topic should skim the summaries in recent important reports of RBI for the latest enforcement examples, since BCP papers increasingly draw case-based questions from real supervisory actions rather than only from the bare text of the circular.

In Practice — Banking Compliance Professional
In Practice — Banking Compliance Professional

🧠 Practice MCQs: Data Localisation Norms for Banks

Q1. Under RBI's payment data storage mandate, data relating to the foreign leg of a transaction may be processed abroad, but the copy stored outside India must be deleted within: (a) 6 hours (b) 24 hours (c) 48 hours (d) 7 days

Answer: (b) — The foreign-leg data must be deleted from the overseas system within 24 hours of processing.

Q2. Which document must system providers submit to RBI to demonstrate compliance with the payment data storage circular? (a) Statutory Audit Report (b) System Audit Report (SAR) by a CERT-In empanelled auditor (c) Annual Report to shareholders (d) Suspicious Transaction Report

Answer: (b) — A Board-approved System Audit Report from a CERT-In-empanelled auditor must be submitted to RBI.

Q3. The Digital Personal Data Protection Act, 2023 governs cross-border transfer of personal data using which approach? (a) Blanket ban on all transfers (b) Prior RBI approval for every transfer (c) A negative list of restricted countries (d) Mandatory localisation of all personal data

Answer: (c) — DPDP allows transfers by default except to countries specifically notified/restricted by the Central Government.

Q4. RBI's 2018 data storage directive primarily applies to: (a) All bank IT systems without exception (b) Only foreign banks operating in India (c) System providers handling payment system data (d) Only cooperative banks

Answer: (c) — The mandate targets banks, non-bank PSOs, card networks and PPI issuers handling payment system data specifically.

Q5. Who must approve a bank's System Audit Report before it is submitted to RBI under the data localisation framework? (a) The IT vendor (b) The bank's Board (c) The customer (d) NPCI

Answer: (b) — The SAR must be Board-approved prior to submission to the Reserve Bank.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does data localisation mean a bank cannot use any foreign cloud provider?

No. It means payment system data must be stored only in India; foreign cloud infrastructure can still be used for other functions as long as in-scope payment data resides on Indian servers.

Is the RBI data localisation mandate the same as the DPDP Act's data protection rules?

No. RBI's mandate is a sector-specific, payment-data-only storage requirement, while the DPDP Act, 2023 governs personal data broadly with a more permissive cross-border transfer regime.

What happens if a payment system provider fails to comply with localisation norms?

RBI can restrict the provider from onboarding new customers or take other supervisory action until compliance, as has happened with at least one major card network.

Do KYC records fall under the same localisation rule as payment data?

KYC and customer records are expected to be primarily stored in India, with disaster-recovery backups permitted abroad — a related but distinct requirement from the payment-data mandate.

Data localisation is one of those BCP topics that rewards precision over memorised definitions — know the 24-hour exception, know who approves the SAR, and know where RBI's rule ends and the DPDP Act begins. For more detail on the full text of the circular, see RBI's Storage of Payment System Data directive. Ready to test yourself? Browse more topics under the Banking Compliance Professional tag hub, or jump straight into a CAIIB or JAIIB mock test to see how this topic is actually examined.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading