Consider the following statements: The Reserve Bank of India’s recent directives relating to ‘Storage of Payment System Data’, popularly known as data diktat, command the payment system providers that 1. they shall ensure that entire data relating to payment systems operated by them are store in a system only in India. 2. they shall ensure that the systems are owned and operated by public sector enterprises. 3. they shall submit the consolidated system audit report to the Comptroller and Auditor General of India by the end of the calendar year Which of the statements given above is/are correct?

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2019, Q94

Contents14
UPSC Prelims GS2019Science and Technology
  1. A1 only
  2. B1 and 2 only
  3. C3 only
  4. D1, 2 and 3
Show answer

Answer: (A) 1 only

The correct answer is (A) — 1 only.

RBI's data localization directive requires all payment system providers to store their entire payment data within India only.

This is statement 1, and it is correct.

Statement 2 is wrong — the directive does not say the systems must be owned by public sector enterprises.

Private companies can operate them too.

Statement 3 is wrong — the audit report must be submitted to the RBI (not the CAG), and it must be done by CERT-IN empanelled auditors.

Tip: RBI's 'data diktat' = all payment data must be stored in India, but ownership can be private.

Why this was asked

RBI's 2018 data localization directive required all payment companies to store Indian users' payment data only within India by October 2018.

The directive came after concerns about foreign payment companies like Visa, Mastercard, and WhatsApp Pay storing Indian payment data overseas, affecting data sovereignty.

The question tests whether students can distinguish between data storage location requirements versus ownership requirements - RBI mandated where data is stored but not who can own the systems.

RBI Data Localization Directive

Science And Technology Storage of Payment System Data data diktat payment system providers

RBI Data Localization Directive: Payment System Data Storage Rules

Must know

RBI directive mandates all payment data must be stored only in India

Applies to all payment system providers, regardless of public or private ownership

Good to know

System audit reports must be submitted to RBI by CERT-IN empanelled auditors

Popularly called 'data diktat' — launched in 2018

The Reserve Bank of India issued the 'Storage of Payment System Data' directive in 2018 to ensure India's data sovereignty in the rapidly growing digital payments sector. This regulation requires complete data localization for all payment transactions.

Key requirement: All payment system data must be stored within India's geographical boundaries — no overseas storage allowed.

Key Provisions vs Common Misconceptions

Aspect

What RBI Actually Requires

Common Wrong Belief

Data Storage

100% data in India only

Partial data in India is enough

System Ownership

Private or public — both allowed

Only public sector can operate

Audit Submission

To RBI by CERT-IN auditors

To CAG by any auditor

Timeline

By specified deadline (varies)

By calendar year end always

Who Must Comply

All payment system providers operating in India — banks, payment gateways, wallet companies

Foreign companies like Google Pay, Amazon Pay, PhonePe must store Indian user data locally

Includes card networks, UPI providers, mobile wallets, prepaid instruments

Both domestic and international payment service providers with Indian operations

Why This PYQ Was Asked

UPSC tested whether students understood the exact scope of RBI's data localization rule. The trap was assuming government control over private payment systems (Statement 2) and confusing audit submission authority (Statement 3 — RBI vs CAG).

Exam traps

Trap: Assuming only public sector enterprises can operate payment systems — private companies are allowed

Trap: Confusing CAG with RBI for audit report submission — reports go to RBI, not CAG

Trap: Thinking partial data storage in India is sufficient — directive requires 100% Indian storage

Trap: Mixing up calendar year vs financial year deadlines — specific timelines vary by RBI notifications

Payment Systems in India

Indian Economy payment systems

Payment Systems in India: Types, Regulation & Key Players

Must know

RBI is the primary regulator of all payment systems in India

UPI is India's flagship real-time payment system

Payment systems include cards, digital wallets, bank transfers, and mobile payments

Good to know

NPCI operates major retail payment systems like UPI, RuPay, IMPS

Major Payment Systems

System

Full Form

Purpose

Operated By

Transaction Limit

UPI

Unified Payments Interface

Real-time retail payments

NPCI

₹1 lakh per transaction

RTGS

Real Time Gross Settlement

High-value instant transfers

RBI

Minimum ₹2 lakh

NEFT

National Electronic Funds Transfer

Retail electronic transfers

RBI

No limit

IMPS

Immediate Payment Service

24x7 instant transfers

NPCI

₹2 lakh per transaction

NACH

National Automated Clearing House

Bulk/repetitive payments

NPCI

₹1 crore per transaction

Payment System Categories

# Indian Payment Systems
## Card Payments
- Credit Cards
- Debit Cards
- RuPay
- Visa/Mastercard
- Contactless Cards
## Digital Transfers
- UPI
- RTGS
- NEFT
- IMPS
- Mobile Banking
## Mobile Wallets
- Paytm
- PhonePe
- Google Pay
- Amazon Pay
- Prepaid Instruments
## Institutional
- NACH
- Cheque Clearing
- Government Payments
- Bulk Transfers

Regulatory Framework

Payment and Settlement Systems Act, 2007 provides legal framework for payment systems

RBI issues licenses and regulates all payment system operators in India

NPCI operates most retail payment infrastructure as an umbrella organization

Data localization rules apply to all payment providers since 2018

Interoperability mandated — users can transact across different payment apps

Data Localization Policies

Science And Technology

Data Localization in India: Policies, Rationale & Global Context

Must know

Data localization means storing data within country's geographical boundaries

India has sector-specific data localization rules for payments, telecom, and health

Good to know

Personal Data Protection Bill proposes broader data localization framework

China and Russia have strict data localization laws, EU allows conditional transfers

Data localization requires companies to store and process citizen data within national borders. Countries adopt this policy for data sovereignty, national security, law enforcement access, and economic benefits like job creation in the domestic IT sector.

India's Sector-wise Data Localization Rules

Sector

Regulator

Key Requirement

Implementation Year

Payment Systems

RBI

100% payment data in India

2018

Telecommunications

DoT/TRAI

Call Detail Records in India

2014

E-commerce

Proposed

User data of Indians in India

Under consideration

Health Data

Ministry of Health

Health records in India

Proposed in Health Data Policy

Government Data

MeitY

All govt data in Indian clouds

Under Public Cloud Policy

Arguments For & Against

For: Better law enforcement access, protection from foreign surveillance, domestic job creation

For: Enhanced cyber security control, prevention of data breaches in foreign jurisdictions

Against: Increased compliance costs, reduced efficiency of global cloud services

Against: Potential trade disputes, reduced innovation due to higher operational costs

Against: May conflict with international trade agreements and digital economy principles

Global data localization landscape — China, Russia have strict rules, India has sector-specific approach
Global data localization landscape — China, Russia have strict rules, India has sector-specific approach

Source: InCountry — The 2021 Data Regulation Recap - InCountry · incountry.com

RBI Regulatory Powers

Indian Economy Reserve Bank of India

RBI's Regulatory Authority: Banking, Payments & Financial System Oversight

Must know

RBI Act, 1934 establishes RBI as India's central bank with regulatory powers

RBI regulates banks, NBFCs, payment systems, and foreign exchange

Good to know

Payment and Settlement Systems Act, 2007 gives RBI authority over payment systems

RBI can issue directives, impose penalties, and revoke licenses

RBI's Regulatory Domains

# RBI Regulatory Powers
## Banking Regulation
- Commercial Banks
- Cooperative Banks
- Regional Rural Banks
- Banking Licenses
## Payment Systems
- UPI
- RTGS/NEFT
- Card Networks
- Mobile Wallets
- Data Localization
## Non-Banking Finance
- NBFCs
- Microfinance
- Housing Finance
- Systemically Important NBFCs
## Foreign Exchange
- FEMA Compliance
- External Commercial Borrowing
- Foreign Investment
- Currency Regulations

RBI's Enforcement Tools

Tool

Used For

Example/Impact

Legal Basis

Directives/Guidelines

Policy implementation

Data localization directive

RBI Act Section 35A

Monetary Penalties

Non-compliance

Fines up to ₹1 crore per day

Banking Regulation Act

License Revocation

Serious violations

PMC Bank license cancellation

Banking Regulation Act Section 5

Business Restrictions

Risk management

PCA framework for weak banks

Banking Regulation Act Section 35A

Audit Requirements

Compliance monitoring

Special audits, CERT-IN empanelled auditors

Various Acts

Exam traps

Trap: Confusing RBI with SEBI — RBI regulates banks/payments, SEBI regulates securities markets

Trap: Thinking CAG audits RBI operations — CAG audits RBI itself, but regulated entities report to RBI

Trap: Assuming RBI controls government banking — RBI is banker to government but independent in monetary policy

Trap: Confusing RBI Governor appointment — appointed by Government but has fixed tenure protection