data residency
Data Residency for Legal Software: What It Means and Why It Matters in India
Data residency asks one plain question: where does your data physically sit, on a disk, in a named country, inside which vendor's servers, and who can legally reach it from there? For a legal team uploading contracts to a CLM or AI review tool, that question touches three things at once: confidentiality and privilege, any client mandate that names a storage location, and which country's regulators and courts can compel access. Most vendors answer it with a marketing line ("enterprise-grade, secure, global infrastructure") that commits to nothing checkable. (Adira, which publishes this guide, makes contract management software and stores customer data in defined regions. Do not take our word for where; verify it on Adira's security page and get the region named in your Data Processing Agreement, the same way this guide asks you to check any vendor.) Below: what residency actually covers, what Indian law does and does not require, a real sectoral rule that does mandate local storage, and the questions and clause language to use before you sign.
What "data residency" actually covers
Residency is really three separate questions, and a vendor that answers only one has not answered your question.
Where is it stored at rest? The country or region hosting the database, the file storage, and any backup or disaster-recovery copy. A vendor that names one "primary region" and stays silent on backups has told you where the data usually is, not where every copy of it is.
Where is it processed? Storage and processing can sit in different countries. A contract stored in Mumbai can still be sent to a server abroad for an AI summary, a search index, or an OCR step, and back again. If a vendor's AI features call a foundation model provider, that call is a separate data flow, often with its own location and retention window, distinct from where your document rests.
Who else touches it, and from where? Every sub-processor, cloud host, AI model provider, support tool, adds another location and another party with potential access. A residency promise covering only the vendor's own servers, silent on sub-processors, has a gap exactly where data usually leaves the vendor's direct control.
A test you can run: ask the vendor to answer all three, storage, processing, and sub-processors, in one written table with a country name against each row. A vendor that can produce this without hedging has actually thought about residency. One that cannot has probably never been asked.
Why legal teams care about this specifically
Confidentiality and privilege do not evaporate because a document crossed a border, but two practical risks do change with location. First, discovery and government-access rules differ by jurisdiction: a document sitting on a server in a country whose courts or agencies can compel production is exposed to that country's process, on top of India's. Second, many client mandates, especially from regulated counterparties (banks, insurers, government contractors), write a storage location directly into the engagement letter or vendor-approval checklist; a CLM tool that cannot confirm where data sits fails that mandate regardless of how good its AI is.
There is also a risk residency alone does not touch: who a vendor's home jurisdiction can compel, independent of where the server sits. The US CLOUD Act, in force since March 2018, amended the Stored Communications Act so a US-based provider must produce data "within its possession, custody, or control" in response to a valid US warrant, regardless of whether that data is stored inside the US or abroad. A vendor incorporated in the US that stores your contracts in an Indian data centre can still be compelled to hand them over from Washington. Storing data in India closes the "which country's server" gap; it does not by itself close the "which country's company controls it" gap. Ask both questions.
The Indian legal position: what the DPDP Act actually says
Here is where most buyers get the current law wrong. There is a common belief that Indian law requires all personal data to stay in India. That was the direction of the 2018 draft Personal Data Protection Bill (the Justice Srikrishna committee version), which proposed mandatory local storage and, for some categories, a mirrored local copy even where cross-border transfer was allowed. That mirroring requirement did not survive into law. The Digital Personal Data Protection Act, 2023 (DPDP Act), which received presidential assent in August 2023 and whose substantive provisions are now in force following the notified Digital Personal Data Protection Rules, 2025, takes a different and more permissive approach.
Section 16(1) of the DPDP Act states: "The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." (Digital Personal Data Protection Act, 2023, official text)
Read that sentence carefully, because the structure is the opposite of a localisation mandate. It is a negative-list model: transfer of personal data to any country is permitted by default, and the government's power is to restrict transfer to specific countries it later names by notification. As of this writing, the Central Government has not notified any restricted country or territory under Section 16(1), so there is currently no country to which cross-border transfer of personal data is barred under the DPDP Act itself. That can change with a single notification, so this is a fact to recheck periodically, not a permanent conclusion.
Section 16(2) adds an important qualifier: "Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof." In plain terms, the DPDP Act's permissiveness is a floor, not a ceiling. If a different Indian law imposes stricter localisation for your sector, that stricter rule still applies on top of Section 16, it is not overridden by the Act's general permissiveness.
The Digital Personal Data Protection Rules, 2025, notified in November 2025, add one further layer at Rule 15: a Data Fiduciary transferring personal data outside India must meet any requirements the Central Government specifies, by general or special order, concerning making that data available to a foreign state or an entity under a foreign state's control. (Digital Personal Data Protection Rules, 2025, Rule 15) This targets government-to-government access scenarios specifically, not routine commercial cloud hosting, but it is a live condition on cross-border transfer, not a dead letter.
Where the real localisation requirements actually live: sectoral rules
Section 16(2) is not theoretical. The clearest example of a genuine, current, India-only storage mandate sits with the Reserve Bank of India, not the DPDP Act. RBI's circular on Storage of Payment System Data (RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018, dated 6 April 2018) directs: "All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India." (RBI circular on Storage of Payment System Data) The circular defines this to cover the full end-to-end transaction data, from the originating point to the final settlement, and it does allow a copy of the foreign leg of a cross-border transaction to also be stored abroad "if required." System providers had six months to comply and had to report compliance to RBI by 15 October 2018.
This matters for legal and procurement teams for a specific reason: it applies to payment system data, not to contracts, HR files, or general commercial documents, and it binds "system providers" (banks, card networks, payment aggregators, wallets), not every company that happens to be regulated by RBI for other purposes. If your organisation is a bank, NBFC, payment aggregator, or fintech, ask your compliance team whether this circular, or a sector-specific successor rule from RBI, SEBI, or IRDAI, applies to the specific data your legal-tech vendor will handle. It is very unlikely to apply to your CLM or contract-review tool's data unless that tool is processing payment transaction records directly, but "very unlikely" is a question to confirm, not assume.
The myth versus the current position, in short
Myth: "Indian law requires all personal data to be stored only in India." Reality: Section 16(1)'s default rule permits transfer to any country except one the government later notifies as restricted, and none has been notified as of this writing; the 2018 draft Bill's mirroring requirement was dropped before the Act was passed. Myth: "My contract data is automatically covered by a localisation law." Reality: outside a sector-specific rule like RBI's, there is no general statute requiring your contract data to sit on Indian servers, so your vendor contract is doing the work a statute does not. Myth: "If the DPDP Act permits transfer, residency does not matter." Reality: permission to transfer is not a reason to skip due diligence; discovery exposure, sub-processor risk, and a vendor's home-jurisdiction laws remain live questions the Act's permissiveness does not answer for you.
What to ask a vendor, in writing
- "What is the primary storage region for our data, and is it named in the DPA, not only on a website?" A region in a signed document is enforceable; one on a webpage can change without notice.
- "Where are backups and disaster-recovery copies stored, and is that the same region as primary storage?"
- "Does any AI feature send our data to a model provider, in which region, and with what retention?" See Does AI Legal Software Train on Your Contracts? for the training-versus-processing distinction this touches.
- "List every sub-processor and its country, and how you notify customers before adding or changing one."
- "Is our data encrypted at rest and in transit, and who holds the keys, you or a third party?"
- "Is your company subject to a foreign law like the US CLOUD Act that could compel disclosure regardless of storage location, and will you notify us of any such demand where permitted?"
- "Will the storage region and sub-processor list sit inside our signed Data Processing Agreement, naming us as Data Fiduciary and you as Data Processor?" For what else that DPA should cover, see The DPDP Act for Contracts.
You can mark up a vendor's data-location clause against this checklist for free in Weave, Adira's browser-based contract tool, before you commit to redlines over a call.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| Storage region named specifically ("primary data stored in AWS ap-south-1, Mumbai") | "Enterprise-grade global infrastructure" with no country named | A region you cannot name is a region you cannot verify or hold the vendor to |
| Region commitment is written into the signed DPA | Region is stated only on a marketing or trust-centre page | A webpage can change without notice; only the signed contract binds the vendor |
| Backup and DR locations disclosed alongside primary storage | Vendor answers only for "primary" storage, silent on backups | A backup copy in a different country is still a copy of your confidential data |
| Sub-processors and their countries listed, updated with notice | Vendor will not name its cloud host or AI model provider | You cannot assess a risk you are not told about |
| Vendor discloses which foreign laws (like the CLOUD Act) could reach its data regardless of storage location | Vendor implies India-hosted data is untouchable by any foreign process | Storage location and legal jurisdiction of the company are two different protections |
| Encryption at rest and in transit stated, with key-holder named | "Data is encrypted" with no detail on at rest, in transit, or key ownership | Vague encryption claims cannot be checked or relied on |
| Data-transfer or residency clause references the current DPDP Act and any applicable sectoral rule (RBI, SEBI, IRDAI) by name | Clause references only "applicable law" in general terms | A generic reference does not tell you whether the vendor has actually checked which specific rule applies |
Bad clause versus a better one
Bad: "Vendor may store and process Customer Data in any location Vendor deems appropriate to provide the Services."
What is wrong: it names no region, no backup location, no sub-processor disclosure, and gives the vendor unilateral discretion to move your data anywhere with no notice.
Better: "Vendor shall store Customer Data, including backup and disaster-recovery copies, only within [named region/country], except where a specific feature requires processing in another region, in which case Vendor shall disclose that region, the purpose, and the sub-processor involved in writing before enabling the feature for Customer. Vendor shall maintain and provide on request a current list of all sub-processors and their countries of operation, and shall provide Customer at least 30 days' written notice before adding or changing any sub-processor or storage region. Vendor shall notify Customer of any legal demand from a government or regulator, in India or elsewhere, seeking access to Customer Data, to the extent permitted by law."
What changed: a specific region replaces open discretion, backups are covered explicitly, sub-processor disclosure and notice periods are built in, and a notice obligation for government-access demands closes the CLOUD Act-style gap the bad clause leaves open.
US and global contrast
The comparison runs the other way from what most Indian buyers expect. The US has no single federal data-residency statute; the picture is sector-specific (HIPAA for health data, GLBA for financial data) and otherwise contractual, which is why the CLOUD Act's reach into US-controlled data, wherever stored, matters so much when evaluating a US-headquartered vendor. The EU sits at the strict end: GDPR restricts transfers outside the EU/EEA unless an adequacy decision, Standard Contractual Clauses, or another approved mechanism applies, a more procedural regime than India's. China's Personal Information Protection Law goes further still, requiring local storage and a government security assessment before certain data, including data above defined volume thresholds, can leave the country at all. Against that range, India's DPDP Act sits closer to the permissive end, a negative list rather than localisation-by-default, which makes sectoral rules like RBI's payment-data circular the exception that actually bites, not the general rule.
FAQ
Does Indian law require my contract data to be stored only in India? No, not generally. The DPDP Act's Section 16(1) permits transfer of personal data to any country by default; the government can restrict transfer to a specific country by notification, but has not notified any as of this writing. Unless you are in a sector with its own localisation rule, such as RBI's payment-data circular, there is no general statute requiring your contract data to sit on Indian servers.
If the DPDP Act permits cross-border transfer, why does residency still matter? Because permission to transfer is not the same as a reason to skip due diligence. Discovery exposure in the destination country, sub-processor risk, and a vendor's own home-jurisdiction laws, like the US CLOUD Act, are all real and separate from what the DPDP Act allows.
Does storing data in India protect it from being accessed by a foreign government? Not fully, if your vendor is a foreign company. The CLOUD Act lets US authorities compel a US-based provider to produce data "within its possession, custody, or control" regardless of where that data is physically stored. Storage location and the vendor's home jurisdiction are two separate protections; ask about both.
Is RBI's data-localisation rule relevant to my CLM or contract-review vendor? Almost certainly not, unless your vendor is processing payment transaction data directly. RBI's circular applies to "system providers" handling payment system data specifically, not to general contract or HR data. Confirm with your compliance team if your organisation is a bank, NBFC, or payment company.
What should I actually put in a vendor contract about data residency? A named storage region covering primary storage and backups, a current sub-processor list with countries, advance notice before any region or sub-processor change, and a notice obligation if the vendor receives a government demand for your data. Put all of it in the signed DPA, not just a webpage.
Is choosing an India-only vendor always the safer option? Not automatically. A vendor with weak encryption or poor access controls that stores data only in India is riskier than a well-secured vendor with clear, disclosed multi-region infrastructure. Residency is one control among several, alongside encryption, access management, and sub-processor governance, not a substitute for the others.
This guide gets you to a working understanding of what data residency covers and what current Indian law actually requires, and does not require, on cross-border transfer. It does not tell you which sectoral rules apply to your specific organisation, or whether a particular vendor's contract meets your risk tolerance, both of which depend on facts a lawyer or compliance officer needs to review. This is not legal advice; have counsel review your specific data-processing and cross-border-transfer obligations before you finalise a vendor agreement.
Frequently asked questions
- Does Indian law require my contract data to be stored only in India?
- No, not generally. The DPDP Act's Section 16(1) permits transfer of personal data to any country by default; the government can restrict transfer to a specific country by notification, but has not notified any as of this writing. Unless you are in a sector with its own localisation rule, such as RBI's payment-data circular, there is no general statute requiring your contract data to sit on Indian servers.
- If the DPDP Act permits cross-border transfer, why does residency still matter?
- Because permission to transfer is not the same as a reason to skip due diligence. Discovery exposure in the destination country, sub-processor risk, and a vendor's own home-jurisdiction laws, like the US CLOUD Act, are all real and separate from what the DPDP Act allows.
- Does storing data in India protect it from being accessed by a foreign government?
- Not fully, if your vendor is a foreign company. The CLOUD Act lets US authorities compel a US-based provider to produce data within its possession, custody, or control regardless of where that data is physically stored. Storage location and the vendor's home jurisdiction are two separate protections; ask about both.
- Is RBI's data-localisation rule relevant to my CLM or contract-review vendor?
- Almost certainly not, unless your vendor is processing payment transaction data directly. RBI's circular applies to system providers handling payment system data specifically, not to general contract or HR data. Confirm with your compliance team if your organisation is a bank, NBFC, or payment company.
- What should I actually put in a vendor contract about data residency?
- A named storage region covering primary storage and backups, a current sub-processor list with countries, advance notice before any region or sub-processor change, and a notice obligation if the vendor receives a government demand for your data. Put all of it in the signed DPA, not just a webpage.
- Is choosing an India-only vendor always the safer option?
- Not automatically. A vendor with weak encryption or poor access controls that stores data only in India is riskier than a well-secured vendor with clear, disclosed multi-region infrastructure. Residency is one control among several, alongside encryption, access management, and sub-processor governance, not a substitute for the others.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Section 16, official text - Ministry of Electronics and IT
- Digital Personal Data Protection Rules, 2025, Rule 15 (transfer of personal data outside India), official English text
- RBI Circular RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018, dated 6 April 2018, Storage of Payment System Data - Reserve Bank of India
- CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) - Congressional Research Service overview, Congress.gov
- Cross-Border Data Transfers Under India's Digital Personal Data Protection Act, 2023 - Lexology
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free