Consider the following statements: The Reserve Bank of India’s recent directives relating to ‘Storage of Payment System Data’, popularly known as data diktat, command the payment system providers that 1. they shall ensure that entire data relating to payment systems operated by them are store in a system only in India. 2. they shall ensure that the systems are owned and operated by public sector enterprises. 3. they shall submit the consolidated system audit report to the Comptroller and Auditor General of India by the end of the calendar year Which of the statements given above is/are correct?
Contents14
- A1 only
- B1 and 2 only
- C3 only
- D1, 2 and 3
Show answer
Answer: (A) 1 only
The correct answer is (A) — 1 only.
RBI's data localization directive requires all payment system providers to store their entire payment data within India only.
This is statement 1, and it is correct.
Statement 2 is wrong — the directive does not say the systems must be owned by public sector enterprises.
Private companies can operate them too.
Statement 3 is wrong — the audit report must be submitted to the RBI (not the CAG), and it must be done by CERT-IN empanelled auditors.
Tip: RBI's 'data diktat' = all payment data must be stored in India, but ownership can be private.
RBI's 2018 data localization directive required all payment companies to store Indian users' payment data only within India by October 2018.
The directive came after concerns about foreign payment companies like Visa, Mastercard, and WhatsApp Pay storing Indian payment data overseas, affecting data sovereignty.
The question tests whether students can distinguish between data storage location requirements versus ownership requirements - RBI mandated where data is stored but not who can own the systems.
RBI Data Localization Directive
Science And Technology Storage of Payment System Data data diktat payment system providers
RBI Data Localization Directive: Payment System Data Storage Rules
RBI directive mandates all payment data must be stored only in India
Applies to all payment system providers, regardless of public or private ownership
System audit reports must be submitted to RBI by CERT-IN empanelled auditors
Popularly called 'data diktat' — launched in 2018
The Reserve Bank of India issued the 'Storage of Payment System Data' directive in 2018 to ensure India's data sovereignty in the rapidly growing digital payments sector. This regulation requires complete data localization for all payment transactions.
Key requirement: All payment system data must be stored within India's geographical boundaries — no overseas storage allowed.
Key Provisions vs Common Misconceptions
Aspect | What RBI Actually Requires | Common Wrong Belief |
|---|---|---|
Data Storage | 100% data in India only | Partial data in India is enough |
System Ownership | Private or public — both allowed | Only public sector can operate |
Audit Submission | To RBI by CERT-IN auditors | To CAG by any auditor |
Timeline | By specified deadline (varies) | By calendar year end always |
Who Must Comply
All payment system providers operating in India — banks, payment gateways, wallet companies
Foreign companies like Google Pay, Amazon Pay, PhonePe must store Indian user data locally
Includes card networks, UPI providers, mobile wallets, prepaid instruments
Both domestic and international payment service providers with Indian operations
Why This PYQ Was Asked
UPSC tested whether students understood the exact scope of RBI's data localization rule. The trap was assuming government control over private payment systems (Statement 2) and confusing audit submission authority (Statement 3 — RBI vs CAG).
Trap: Assuming only public sector enterprises can operate payment systems — private companies are allowed
Trap: Confusing CAG with RBI for audit report submission — reports go to RBI, not CAG
Trap: Thinking partial data storage in India is sufficient — directive requires 100% Indian storage
Trap: Mixing up calendar year vs financial year deadlines — specific timelines vary by RBI notifications
Payment Systems in India
Indian Economy payment systems
Payment Systems in India: Types, Regulation & Key Players
RBI is the primary regulator of all payment systems in India
UPI is India's flagship real-time payment system
Payment systems include cards, digital wallets, bank transfers, and mobile payments
NPCI operates major retail payment systems like UPI, RuPay, IMPS
Major Payment Systems
System | Full Form | Purpose | Operated By | Transaction Limit |
|---|---|---|---|---|
UPI | Unified Payments Interface | Real-time retail payments | NPCI | ₹1 lakh per transaction |
RTGS | Real Time Gross Settlement | High-value instant transfers | RBI | Minimum ₹2 lakh |
NEFT | National Electronic Funds Transfer | Retail electronic transfers | RBI | No limit |
IMPS | Immediate Payment Service | 24x7 instant transfers | NPCI | ₹2 lakh per transaction |
NACH | National Automated Clearing House | Bulk/repetitive payments | NPCI | ₹1 crore per transaction |
Payment System Categories
# Indian Payment Systems
## Card Payments
- Credit Cards
- Debit Cards
- RuPay
- Visa/Mastercard
- Contactless Cards
## Digital Transfers
- UPI
- RTGS
- NEFT
- IMPS
- Mobile Banking
## Mobile Wallets
- Paytm
- PhonePe
- Google Pay
- Amazon Pay
- Prepaid Instruments
## Institutional
- NACH
- Cheque Clearing
- Government Payments
- Bulk TransfersRegulatory Framework
Payment and Settlement Systems Act, 2007 provides legal framework for payment systems
RBI issues licenses and regulates all payment system operators in India
NPCI operates most retail payment infrastructure as an umbrella organization
Data localization rules apply to all payment providers since 2018
Interoperability mandated — users can transact across different payment apps
Data Localization Policies
Science And Technology
Data Localization in India: Policies, Rationale & Global Context
Data localization means storing data within country's geographical boundaries
India has sector-specific data localization rules for payments, telecom, and health
Personal Data Protection Bill proposes broader data localization framework
China and Russia have strict data localization laws, EU allows conditional transfers
Data localization requires companies to store and process citizen data within national borders. Countries adopt this policy for data sovereignty, national security, law enforcement access, and economic benefits like job creation in the domestic IT sector.
India's Sector-wise Data Localization Rules
Sector | Regulator | Key Requirement | Implementation Year |
|---|---|---|---|
Payment Systems | RBI | 100% payment data in India | 2018 |
Telecommunications | DoT/TRAI | Call Detail Records in India | 2014 |
E-commerce | Proposed | User data of Indians in India | Under consideration |
Health Data | Ministry of Health | Health records in India | Proposed in Health Data Policy |
Government Data | MeitY | All govt data in Indian clouds | Under Public Cloud Policy |
Arguments For & Against
For: Better law enforcement access, protection from foreign surveillance, domestic job creation
For: Enhanced cyber security control, prevention of data breaches in foreign jurisdictions
Against: Increased compliance costs, reduced efficiency of global cloud services
Against: Potential trade disputes, reduced innovation due to higher operational costs
Against: May conflict with international trade agreements and digital economy principles

Source: InCountry — The 2021 Data Regulation Recap - InCountry · incountry.com
RBI Regulatory Powers
Indian Economy Reserve Bank of India
RBI's Regulatory Authority: Banking, Payments & Financial System Oversight
RBI Act, 1934 establishes RBI as India's central bank with regulatory powers
RBI regulates banks, NBFCs, payment systems, and foreign exchange
Payment and Settlement Systems Act, 2007 gives RBI authority over payment systems
RBI can issue directives, impose penalties, and revoke licenses
RBI's Regulatory Domains
# RBI Regulatory Powers
## Banking Regulation
- Commercial Banks
- Cooperative Banks
- Regional Rural Banks
- Banking Licenses
## Payment Systems
- UPI
- RTGS/NEFT
- Card Networks
- Mobile Wallets
- Data Localization
## Non-Banking Finance
- NBFCs
- Microfinance
- Housing Finance
- Systemically Important NBFCs
## Foreign Exchange
- FEMA Compliance
- External Commercial Borrowing
- Foreign Investment
- Currency RegulationsRBI's Enforcement Tools
Tool | Used For | Example/Impact | Legal Basis |
|---|---|---|---|
Directives/Guidelines | Policy implementation | Data localization directive | RBI Act Section 35A |
Monetary Penalties | Non-compliance | Fines up to ₹1 crore per day | Banking Regulation Act |
License Revocation | Serious violations | PMC Bank license cancellation | Banking Regulation Act Section 5 |
Business Restrictions | Risk management | PCA framework for weak banks | Banking Regulation Act Section 35A |
Audit Requirements | Compliance monitoring | Special audits, CERT-IN empanelled auditors | Various Acts |
Trap: Confusing RBI with SEBI — RBI regulates banks/payments, SEBI regulates securities markets
Trap: Thinking CAG audits RBI operations — CAG audits RBI itself, but regulated entities report to RBI
Trap: Assuming RBI controls government banking — RBI is banker to government but independent in monetary policy
Trap: Confusing RBI Governor appointment — appointed by Government but has fixed tenure protection