Legal News

Allahabad High Court: No 2-Year Gap for Second Maternity Leave

India·Briefly Analysis⏱️ 3 min read

Summary

  • Indian law does not require non-financial sector companies to store all personal or business data exclusively in India.
  • Non-BFSI organisations must comply with specific statutes, sectoral regulations, contractual undertakings, or directions that may require data storage, backup, access, or production within India.
  • Lawyers advising non-BFSI organisations should help them inventory and govern their data effectively to ensure compliance with Indian law.

What's at Stake for Non-BFSI Organisations

While Indian law does not impose an obligation on non-financial sector companies to store all personal or business data exclusively in India, specific statutes, sectoral regulations, contractual undertakings, or directions may necessitate data storage, backup, access, or production within the country.

The evolving data localisation framework in India presents a nuanced landscape for non-banking and financial institutions (non-BFSI) organisations. While Indian law does not require these entities to store all personal and business data exclusively within the country, specific statutes, sectoral regulations, contractual undertakings, or directions may necessitate data storage, backup, access, or production in India. This means that non-BFSI firms must navigate a complex web of requirements, ensuring they comply with relevant laws and regulations while also maintaining data governance practices.

In this context, it's essential for lawyers advising non-BFSI organisations to help them inventory and govern their data effectively. By doing so, these entities can ensure they are prepared to localise specific datasets when required under Indian law.

The Role of Indian Data Protection Laws

Indian data protection laws, including the Information Technology Act 2000 and the SPDI Rules 2011, regulate specified sensitive personal data or information. These laws permit overseas transfer of such data when the recipient maintains the same standard for data protection as required under the SPDI Rules. The Digital Personal Data Protection Act 2023 adopts a broadly similar approach, allowing overseas transfer subject to certain conditions.

While these laws do not impose an obligation on non-BFSI companies to store all personal or business data exclusively in India, they do require compliance with sectoral regulations and contractual undertakings. This means that non-BFSI firms must carefully review their data storage practices to ensure they meet the necessary requirements.

The Practical Implications

In light of the evolving data localisation framework, non-BFSI organisations in India should take proactive steps to address potential compliance risks. This includes conducting thorough data inventories, implementing robust governance practices, and ensuring that contractual undertakings are in place to facilitate data storage and transfer.

By taking these steps, non-BFSI firms can ensure they are prepared to meet the requirements of Indian law and maintain their data governance practices effectively.

Practical Implications

Lawyers advising non-BFSI organisations in India should ensure they inventory and govern their data, comply with sectoral rules, and be prepared to localise specific datasets when required under Indian law.

Source

Source: Original reporting via Leading Questions

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Wansom is AI and can make mistakes.