munotes®

Data Localisation and Cross-Border Data Flows

Chapter Ninety

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

Pages 564 to 570 of 948

In one line

Data localisation means three quite different things, India has moved from proposing the strictest form to enacting the most permissive, and the hard requirements that survive are in a banking direction and a cyber security direction rather than in any statute.

The three degrees

Get these apart before anything else, because the word "localisation" is used for all three and they are not the same.

Mirroring, the weakest. A copy must be kept in India. The data may still be transferred and processed anywhere. The purpose is access: a regulator or investigator can obtain the copy without a treaty request.

Conditional or restricted transfer, the middle. Data may leave, but only on conditions: an adequacy finding, contractual safeguards, consent, or the approval of an authority. This is the European model under Chapter V of the GDPR, and chapter 700 works it.

Hard localisation, the strongest. The data must be stored and processed only in India and may not be transferred at all. This is the model China applies to the personal information and important data of critical information infrastructure operators under article 37 of the Cybersecurity Law. Chapter 720.

An answer that says "India requires data localisation" without saying which of the three is talking about nothing.

What actually binds in India today

One: the Reserve Bank of India's payment data direction.

The direction of 6 April 2018, on storage of payment system data, requires all payment system providers to ensure that the entire data relating to payment systems operated by them is stored in a system only in India. The data covered is comprehensive: end-to-end transaction details, and information collected, carried or processed as part of the message or payment instruction. Compliance was required within six months.

The clarification that followed permitted processing abroad where the transaction is foreign, provided the data is brought back to India within a short period and deleted from the foreign systems. So the operative model is hard localisation of storage with a narrow processing carve-out.

Why the Reserve Bank of India did it. Unfettered supervisory access. Its stated reason was the need for unrestricted access to payment data for supervisory purposes, given the growth of payment systems and the fact that much of the data was stored abroad.

Two: the CERT-In direction of 28 April 2022, direction (iv). Logs of all information and communication technology systems must be enabled and maintained for a rolling 180 days, and maintained within the Indian jurisdiction. Chapter 770. That is hard localisation of one narrow class of data, imposed by a direction issued under section 70B(6).

Three: sectoral rules. The insurance regulator requires policyholder records to be held in India; the Department of Telecommunications imposes conditions through licences; and the Ministry of Health's electronic health record standards contemplate storage in India.

munotes.in564

The rest of this chapter

Module one is free. The rest of LL.M. Intellectual Property and Information Technology Semester 3 is part of the bundle.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

See the semester for ₹798 Already bought it? Sign in

Or just the notes: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!