RESIDENCY IS A DATA-FLOW DECISION

Know the boundary.
Document the workload.

Practical regulatory context for Indian enterprises evaluating Swiss cloud capacity. RBI, GDPR and Indian data-protection rules are different regimes—not interchangeable compliance badges.

Download review pack
SCOPE BEFORE REGION

Storage is only one part of residency.

Map primary storage, processing, replicas, disaster recovery, backups, logs, keys, administration, support and subprocessors. A Swiss location does not override a payment-data localisation rule; an EU adequacy route does not automatically approve onward India access.

Covered payment data

Assess the RBI Indian-storage requirement and the tightly scoped offshore-processing rules before proposing Swiss-only hosting.

Review payment scope →

Personal-data workloads

Determine DPDP transition status, sector restrictions, GDPR roles and transfer bases separately. Do not infer a universal location mandate.

Review phased requirements →

Website tools

Diagram analysis uses this website’s platform AI. It is not proof of Swiss data residency and must not receive secrets or regulated customer records.

Read processing notice →

RBI · payment-system data

Payment systems and engaged payment-service ecosystem

RBI’s 6 April 2018 Storage of Payment System Data direction and its 26 June 2019 FAQ require covered payment-system data to be stored in India. The FAQ covers RBI-authorised/approved payment-system providers, banks operating in India and payment-service ecosystem entities engaged by them; the authorised/approved provider remains responsible. This is not a blanket rule for all enterprise AI or corporate workloads.

What to assess

  • Include full end-to-end payment/settlement transaction details and information gathered, transmitted or processed as part of payment messages or instructions in the scope assessment.
  • Offshore processing is not categorically barred. The FAQ requires the data to be deleted abroad and brought back to India no later than one business day or 24 hours from payment processing, whichever is earlier; subsequent offshore settlement processing must be near real time.
  • For cross-border transactions, assess the domestic/foreign components under the circular and FAQ. The FAQ allows an additional foreign copy of the domestic component where required; this is not permission to relocate every domestic payment workload.
  • Where applicable, review the required System Audit Report from a CERT-In-empanelled auditor and its coverage, rather than treating a supplier logo or marketing statement as regulatory approval.
DATA RESIDENCY IMPLICATION

A Swiss-only deployment is not a substitute for the Indian storage obligation for covered payment-system data. Map processing, primary storage, replicas, backups, recovery, access and deletion before selecting a region. General AI workloads are not automatically in scope merely because the customer operates in India; embedded payment data may change the analysis.

Procurement evidence

  • Customer’s documented payment-system/data scope determination and responsible regulated entity
  • End-to-end data-field and location map, including foreign copies and support access
  • Contractual region/failover/deletion controls and tested return/deletion evidence
  • Relevant audit report scope, exceptions and regulated-customer approval
Dates, applicability and review boundary
  • Circular: 6 April 2018; official FAQ: 26 June 2019.
  • Original 2018 implementation/reporting dates are historical, not renewed customer deadlines.

The exact customer role, transaction flow and cross-border exception need facts-specific legal review. Recheck later RBI instruments and supervisory requirements; this library does not attest any Aitonomi deployment’s compliance.

RBI · IT outsourcing & cloud governance

Determine the regulated-entity category first

RBI outsourcing directions govern regulated customers and their oversight of providers; they do not confer RBI approval on suppliers. For commercial banks within its scope, the 2025 Managing Risks in Outsourcing Directions are the newer outsourcing instrument. The 2023 IT Outsourcing Direction remains important historical/category context, but should not be presented as the only current rule for every bank. The bank retains accountability.

What to assess

  • Use documented provider and supply-chain diligence covering security, resilience, segregation, legal/regulatory capability, subcontractors and concentration risk.
  • Contracts should preserve bank/RBI access, audit and inspection rights; define incident escalation, data use/location, subcontracting, service levels, remedies and termination.
  • Cross-border outsourcing requires country/jurisdiction risk assessment, enforceable rights and continued access to records. It is not categorically prohibited by these general outsourcing controls.
  • Cloud governance must address shared responsibility, multi-tenancy, multi-location processing and continuous oversight; tested continuity, portability, return, purge and exit arrangements must fit criticality.
DATA RESIDENCY IMPLICATION

India-only storage applies where a separate extant rule requires it. General outsourcing governance does not itself make all banking cloud data India-only. Assess the 2018 payment-data direction, customer category, data classification and any other location or regulatory-access requirement independently.

Procurement evidence

  • Current category-specific RBI instrument and customer applicability assessment
  • Provider/subprocessor locations and jurisdiction/right-enforcement assessment
  • Contract extracts for bank/RBI audit, access, incidents and exit
  • Scoped security assurance, BCP/DR tests and portability/deletion evidence
Dates, applicability and review boundary
  • 2023 IT Outsourcing Direction: issued 10 April 2023, effective 1 October 2023.
  • Commercial-bank outsourcing Directions: issued 28 November 2025; specified existing IT agreements transition at renewal or by 10 April 2026, whichever earlier.
  • Commercial-bank Cybersecurity, Technology: Risk, Resilience and Assurance Framework: issued 31 July 2026; separate third-party controls also apply.

The 2025 commercial-bank definition does not cover every entity category listed in the 2023 instrument. Confirm the customer’s current category-specific directions and amendments with counsel; no provider-specific control effectiveness has been verified here.

India · DPDP & transition requirements

Phased commencement; stricter sector rules remain separate

The DPDP Act, 2023 and final DPDP Rules, 2025 have staggered commencement. On this review date, the institutional and specified initial provisions have commenced, but most operational processing, notice, consent, fiduciary, rights and enforcement duties are scheduled for the later phase. Do not confuse the final rules with the January 2025 draft or represent all core obligations as already operative.

What to assess

  • G.S.R. 843(E) commences specified initial sections on Gazette publication; sections 6(9)/27(1)(d) follow after one year; most core provisions, including section 16 and section 44(2), follow after eighteen months.
  • Final Rules G.S.R. 846(E) similarly stage rules 1, 2 and 17–21 first, rule 4 after one year, and rules 3, 5–16 and 22–23 after eighteen months. Prepare the operational control set without mislabelling its legal start date.
  • Section 16 allows government-notified transfer restrictions rather than a universal India-localisation mandate; Rule 15 permits requirements to be specified for transfers. Rule 13(4) contemplates targeted data-localisation restrictions for specified Significant Data Fiduciary data, not all cloud users.
  • Because the section 44(2) omission of IT Act section 43A is in the deferred phase, the existing IT Act/SPDI framework remains relevant where applicable during transition. Sector-specific residency, retention and outsourcing rules may be stricter.
DATA RESIDENCY IMPLICATION

DPDP alone does not make every personal-data cloud workload India-only. Record actual storage, access, support, backup and subprocessor routes, then assess sector rules, applicable government notifications, possible SDF obligations and transition law. No universal transfer-country permission or absence of later restrictions is guaranteed by this library.

Procurement evidence

  • Dated fiduciary/processor role, purpose and data-category map
  • Current-law and future-phase control mapping with accountable owners
  • Contracts for security, incidents, subprocessors, rights assistance, retention and deletion
  • Legal review of applicable sector rules and live Gazette/transfer notifications
Dates, applicability and review boundary
  • Commencement notification dated 13 November 2025; Gazette upload/publication metadata identifies 14 November 2025.
  • One-year phase: November 2026; eighteen-month operational phase: May 2027, measured from Gazette publication. Confirm the exact legally material day against the authoritative record.
  • Final Rules issued November 2025; December 2025 corrigendum corrected wording, not the stated phased timetable.

Official materials reviewed establish the staged instruments, not a complete live register of every later order. Recheck the current Gazette/MeitY notices before contracting, transfers or deadline reliance; legal applicability is case-specific.

GDPR · EU, Switzerland & onward transfers

Processing roles and routes, not a blanket EU-hosting mandate

GDPR applicability follows establishment and relevant targeting/monitoring activities, not simply company location. The European Commission currently recognises Switzerland as an adequate destination for covered GDPR transfers. That addresses the Chapter V transfer route to Switzerland, not every security, processor-contract or onward-transfer obligation.

What to assess

  • Article 28 requires an appropriate controller/processor contract, documented instructions, sufficient guarantees and authorisation for subprocessors.
  • Article 32 requires risk-appropriate technical and organisational safeguards. Article 35 DPIA duties arise for processing likely to create high risk; they are not a universal checklist for every cloud workload.
  • Switzerland’s EU adequacy route does not automatically cover a subsequent disclosure or access route to India. Where Chapter V criteria apply, assess the onward exporter/importer and an applicable transfer basis; Article 46 safeguards may be needed, and Article 49 derogations are limited exceptions.
  • Swiss FADP can apply independently to the Swiss exporter. Confirm the current Swiss adequacy list and applicable safeguards rather than inferring Swiss-law transfer status from the EU decision.
DATA RESIDENCY IMPLICATION

GDPR is not a universal EU-only-hosting requirement. Adequate destinations and appropriate safeguards can support lawful transfers, but customer contracts, sector rules and risk assessments may restrict locations or remote access. Include support, administration, replicas, backups and onward processing in the route map.

Procurement evidence

  • Article 28 DPA, current subprocessor identities/locations and authorisation process
  • Controller/exporter/importer and territorial/Chapter V analysis for each onward route
  • Applicable SCC module, transfer-risk assessment and supplementary measures where required
  • Scoped security evidence and DPIA determination for the actual processing
Dates, applicability and review boundary
  • GDPR: Regulation (EU) 2016/679.
  • Switzerland adequacy: Commission Decision 2000/518/EC and current Commission adequacy listing reviewed on 8 October 2026.
  • EDPB Article 3/Chapter V guidelines adopted 14 February 2023; processor-chain opinion adopted 7 October 2024.

No Aitonomi-specific architecture, processing purpose, DPA or transfer mechanism was supplied. The Swiss Annex 1 text was not fully exposed by available extraction, so a definitive Swiss-FADP destination finding is not asserted. This is procurement orientation, not a GDPR certification or binding legal opinion.

India · CERT-In logs & incident handling

Targeted ICT logs and provider records, not all workload content

CERT-In’s 28 April 2022 Directions require specified cyber incidents to be reported within six hours and covered ICT logs to be enabled and securely retained for a rolling 180 days. Applicable data-centre, VPS, cloud and qualifying VPN providers have a separate prescribed customer-record retention duty of five years after cancellation/withdrawal, or longer where law requires.

What to assess

  • Map Annexure I incident types and the six-hour trigger from noticing an incident or being informed; outsourced hosting does not automatically remove a covered entity’s duties.
  • Retain covered ICT-system logs for at least a rolling 180 days, with time synchronisation, secure access and a workable incident/production process.
  • For applicable providers, map the specified identity, address/contact, hire period, IP, onboarding, purpose and ownership records and the five-year post-cancellation requirement. This is not retention of all customer workload content for five years.
  • Directions clause (iv) specifies Indian-jurisdiction logs; FAQ Q35 discusses foreign storage if logs can be produced in reasonable time, while Q36 addresses providers serving Indian users and Indian-jurisdiction logs/financial-transaction records. Obtain a reconciled legal/control assessment, not blanket permission for offshore-only logging.
DATA RESIDENCY IMPLICATION

Separate log jurisdiction and provider-held subscriber records from production data residency. Offshore-only logging should not be assumed sufficient merely because a FAQ discusses foreign copies. The applicability and allocation of duties depend on the actual entity role, service and data flows.

Procurement evidence

  • Clause-by-clause customer/provider control ownership and incident-escalation playbook
  • Log-category inventory, 180-day retention configuration, secure production/export and jurisdiction evidence
  • Applicable customer-record fields, validation and five-year post-cancellation controls
  • Time synchronisation and tested six-hour classification/escalation workflow
Dates, applicability and review boundary
  • Directions issued 28 April 2022; stated general effect 60 days later.
  • 27 June 2022 notice extended qualifying MSMEs and specified customer-validation fields to 25 September 2022, not every obligation.
  • Official CERT-In index reviewed on 8 October 2026; case-specific applicability and later instruments still need verification.

The FAQ explains rather than amends the law. Its foreign-storage nuance must be assessed alongside the express Directions and other applicable sector rules. No Aitonomi-specific logs, records or reporting arrangements were verified.

Translate the controls into an architecture review.

Use a redacted diagram for sizing, then verify processing locations, contractual terms and control evidence in a scoped engagement. No tool here issues a compliance certificate.