Regulated and government workloads
These rules most often decide where Indian workloads run and how they are logged. This is general information, not legal advice; your compliance team or auditor confirms what applies.
- Payments: RBI requires payment system data to be stored only in India, so payment workloads stay in Indian regions
- Logs: CERT-In directions require system logs to be kept for 180 days within India and specified incidents reported within six hours
- Securities and insurance: SEBI and IRDAI set their own expectations for cloud use by regulated entities
- Government: departments generally use cloud services empaneled by MeitY
- Personal data: the DPDP Act allows transfers abroad except to countries the government restricts, but sector rules can be stricter
