# Aitonomi India — Cloud compliance and data residency

Reviewed: 2026-10-08. Factual procurement orientation, not binding legal advice, regulatory approval, certification or an attestation of Aitonomi controls. Aitonomi AG is an AI deep tech innovation holding. Website/diagram analysis processing is separate from a contracted Swiss neocloud workload.

## RBI · payment-system data

**Scope:** Payment systems and engaged payment-service ecosystem

RBI’s 6 April 2018 Storage of Payment System Data direction and its 26 June 2019 FAQ require covered payment-system data to be stored in India. The FAQ covers RBI-authorised/approved payment-system providers, banks operating in India and payment-service ecosystem entities engaged by them; the authorised/approved provider remains responsible. This is not a blanket rule for all enterprise AI or corporate workloads.

- Include full end-to-end payment/settlement transaction details and information gathered, transmitted or processed as part of payment messages or instructions in the scope assessment.
- Offshore processing is not categorically barred. The FAQ requires the data to be deleted abroad and brought back to India no later than one business day or 24 hours from payment processing, whichever is earlier; subsequent offshore settlement processing must be near real time.
- For cross-border transactions, assess the domestic/foreign components under the circular and FAQ. The FAQ allows an additional foreign copy of the domestic component where required; this is not permission to relocate every domestic payment workload.
- Where applicable, review the required System Audit Report from a CERT-In-empanelled auditor and its coverage, rather than treating a supplier logo or marketing statement as regulatory approval.

**Residency implication:** A Swiss-only deployment is not a substitute for the Indian storage obligation for covered payment-system data. Map processing, primary storage, replicas, backups, recovery, access and deletion before selecting a region. General AI workloads are not automatically in scope merely because the customer operates in India; embedded payment data may change the analysis.

### Procurement evidence
- [ ] Customer’s documented payment-system/data scope determination and responsible regulated entity
- [ ] End-to-end data-field and location map, including foreign copies and support access
- [ ] Contractual region/failover/deletion controls and tested return/deletion evidence
- [ ] Relevant audit report scope, exceptions and regulated-customer approval

### Dates and applicability
- Circular: 6 April 2018; official FAQ: 26 June 2019.
- Original 2018 implementation/reporting dates are historical, not renewed customer deadlines.

**Review boundary:** The exact customer role, transaction flow and cross-border exception need facts-specific legal review. Recheck later RBI instruments and supervisory requirements; this library does not attest any Aitonomi deployment’s compliance.

### Primary sources
- [RBI Storage of Payment System Data circular](https://www.rbi.org.in/scripts/notificationUser.aspx?Id=11244)
- [RBI official FAQs — scope and offshore-processing limits](https://www.rbi.org.in/commonman/english/scripts/FAQs.aspx?Id=2995)

## RBI · IT outsourcing & cloud governance

**Scope:** Determine the regulated-entity category first

RBI outsourcing directions govern regulated customers and their oversight of providers; they do not confer RBI approval on suppliers. For commercial banks within its scope, the 2025 Managing Risks in Outsourcing Directions are the newer outsourcing instrument. The 2023 IT Outsourcing Direction remains important historical/category context, but should not be presented as the only current rule for every bank. The bank retains accountability.

- Use documented provider and supply-chain diligence covering security, resilience, segregation, legal/regulatory capability, subcontractors and concentration risk.
- Contracts should preserve bank/RBI access, audit and inspection rights; define incident escalation, data use/location, subcontracting, service levels, remedies and termination.
- Cross-border outsourcing requires country/jurisdiction risk assessment, enforceable rights and continued access to records. It is not categorically prohibited by these general outsourcing controls.
- Cloud governance must address shared responsibility, multi-tenancy, multi-location processing and continuous oversight; tested continuity, portability, return, purge and exit arrangements must fit criticality.

**Residency implication:** India-only storage applies where a separate extant rule requires it. General outsourcing governance does not itself make all banking cloud data India-only. Assess the 2018 payment-data direction, customer category, data classification and any other location or regulatory-access requirement independently.

### Procurement evidence
- [ ] Current category-specific RBI instrument and customer applicability assessment
- [ ] Provider/subprocessor locations and jurisdiction/right-enforcement assessment
- [ ] Contract extracts for bank/RBI audit, access, incidents and exit
- [ ] Scoped security assurance, BCP/DR tests and portability/deletion evidence

### Dates and applicability
- 2023 IT Outsourcing Direction: issued 10 April 2023, effective 1 October 2023.
- Commercial-bank outsourcing Directions: issued 28 November 2025; specified existing IT agreements transition at renewal or by 10 April 2026, whichever earlier.
- Commercial-bank Cybersecurity, Technology: Risk, Resilience and Assurance Framework: issued 31 July 2026; separate third-party controls also apply.

**Review boundary:** The 2025 commercial-bank definition does not cover every entity category listed in the 2023 instrument. Confirm the customer’s current category-specific directions and amendments with counsel; no provider-specific control effectiveness has been verified here.

### Primary sources
- [RBI Commercial Banks — Managing Risks in Outsourcing Directions, 2025](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13139)
- [RBI IT Outsourcing Master Direction, 2023](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12486)
- [RBI commercial-bank cybersecurity framework, 2026](https://rbi.org.in/scripts/NotificationUser.aspx?Id=13643&Mode=0)

## India · DPDP & transition requirements

**Scope:** Phased commencement; stricter sector rules remain separate

The DPDP Act, 2023 and final DPDP Rules, 2025 have staggered commencement. On this review date, the institutional and specified initial provisions have commenced, but most operational processing, notice, consent, fiduciary, rights and enforcement duties are scheduled for the later phase. Do not confuse the final rules with the January 2025 draft or represent all core obligations as already operative.

- G.S.R. 843(E) commences specified initial sections on Gazette publication; sections 6(9)/27(1)(d) follow after one year; most core provisions, including section 16 and section 44(2), follow after eighteen months.
- Final Rules G.S.R. 846(E) similarly stage rules 1, 2 and 17–21 first, rule 4 after one year, and rules 3, 5–16 and 22–23 after eighteen months. Prepare the operational control set without mislabelling its legal start date.
- Section 16 allows government-notified transfer restrictions rather than a universal India-localisation mandate; Rule 15 permits requirements to be specified for transfers. Rule 13(4) contemplates targeted data-localisation restrictions for specified Significant Data Fiduciary data, not all cloud users.
- Because the section 44(2) omission of IT Act section 43A is in the deferred phase, the existing IT Act/SPDI framework remains relevant where applicable during transition. Sector-specific residency, retention and outsourcing rules may be stricter.

**Residency implication:** DPDP alone does not make every personal-data cloud workload India-only. Record actual storage, access, support, backup and subprocessor routes, then assess sector rules, applicable government notifications, possible SDF obligations and transition law. No universal transfer-country permission or absence of later restrictions is guaranteed by this library.

### Procurement evidence
- [ ] Dated fiduciary/processor role, purpose and data-category map
- [ ] Current-law and future-phase control mapping with accountable owners
- [ ] Contracts for security, incidents, subprocessors, rights assistance, retention and deletion
- [ ] Legal review of applicable sector rules and live Gazette/transfer notifications

### Dates and applicability
- Commencement notification dated 13 November 2025; Gazette upload/publication metadata identifies 14 November 2025.
- One-year phase: November 2026; eighteen-month operational phase: May 2027, measured from Gazette publication. Confirm the exact legally material day against the authoritative record.
- Final Rules issued November 2025; December 2025 corrigendum corrected wording, not the stated phased timetable.

**Review boundary:** Official materials reviewed establish the staged instruments, not a complete live register of every later order. Recheck the current Gazette/MeitY notices before contracting, transfers or deadline reliance; legal applicability is case-specific.

### Primary sources
- [DPDP Act 2023 — official Act text](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)
- [G.S.R. 843(E) — primary phased commencement notification](https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf)
- [Final DPDP Rules 2025 — Gazette G.S.R. 846(E)](https://egazette.gov.in/WriteReadData/2025/267650.pdf)
- [MeitY final rules and corrigendum listing](https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa)
- [India Code — IT Act, including section 43A](https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf)

## GDPR · EU, Switzerland & onward transfers

**Scope:** Processing roles and routes, not a blanket EU-hosting mandate

GDPR applicability follows establishment and relevant targeting/monitoring activities, not simply company location. The European Commission currently recognises Switzerland as an adequate destination for covered GDPR transfers. That addresses the Chapter V transfer route to Switzerland, not every security, processor-contract or onward-transfer obligation.

- Article 28 requires an appropriate controller/processor contract, documented instructions, sufficient guarantees and authorisation for subprocessors.
- Article 32 requires risk-appropriate technical and organisational safeguards. Article 35 DPIA duties arise for processing likely to create high risk; they are not a universal checklist for every cloud workload.
- Switzerland’s EU adequacy route does not automatically cover a subsequent disclosure or access route to India. Where Chapter V criteria apply, assess the onward exporter/importer and an applicable transfer basis; Article 46 safeguards may be needed, and Article 49 derogations are limited exceptions.
- Swiss FADP can apply independently to the Swiss exporter. Confirm the current Swiss adequacy list and applicable safeguards rather than inferring Swiss-law transfer status from the EU decision.

**Residency implication:** GDPR is not a universal EU-only-hosting requirement. Adequate destinations and appropriate safeguards can support lawful transfers, but customer contracts, sector rules and risk assessments may restrict locations or remote access. Include support, administration, replicas, backups and onward processing in the route map.

### Procurement evidence
- [ ] Article 28 DPA, current subprocessor identities/locations and authorisation process
- [ ] Controller/exporter/importer and territorial/Chapter V analysis for each onward route
- [ ] Applicable SCC module, transfer-risk assessment and supplementary measures where required
- [ ] Scoped security evidence and DPIA determination for the actual processing

### Dates and applicability
- GDPR: Regulation (EU) 2016/679.
- Switzerland adequacy: Commission Decision 2000/518/EC and current Commission adequacy listing reviewed on 8 October 2026.
- EDPB Article 3/Chapter V guidelines adopted 14 February 2023; processor-chain opinion adopted 7 October 2024.

**Review boundary:** No Aitonomi-specific architecture, processing purpose, DPA or transfer mechanism was supplied. The Swiss Annex 1 text was not fully exposed by available extraction, so a definitive Swiss-FADP destination finding is not asserted. This is procurement orientation, not a GDPR certification or binding legal opinion.

### Primary sources
- [GDPR — official EUR-Lex legal text](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)
- [European Commission — current adequacy decisions](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en)
- [EDPB — Article 3 and Chapter V guidelines](https://www.edpb.europa.eu/system/files/2023-02/edpb_guidelines_05-2021_interplay_between_the_application_of_art3-chapter_v_of_the_gdpr_v2_en_0.pdf)
- [Swiss FDPIC — cross-border transfer guidance](https://www.edoeb.admin.ch/en/cross-border-transfer-of-personal-data)

## India · CERT-In logs & incident handling

**Scope:** Targeted ICT logs and provider records, not all workload content

CERT-In’s 28 April 2022 Directions require specified cyber incidents to be reported within six hours and covered ICT logs to be enabled and securely retained for a rolling 180 days. Applicable data-centre, VPS, cloud and qualifying VPN providers have a separate prescribed customer-record retention duty of five years after cancellation/withdrawal, or longer where law requires.

- Map Annexure I incident types and the six-hour trigger from noticing an incident or being informed; outsourced hosting does not automatically remove a covered entity’s duties.
- Retain covered ICT-system logs for at least a rolling 180 days, with time synchronisation, secure access and a workable incident/production process.
- For applicable providers, map the specified identity, address/contact, hire period, IP, onboarding, purpose and ownership records and the five-year post-cancellation requirement. This is not retention of all customer workload content for five years.
- Directions clause (iv) specifies Indian-jurisdiction logs; FAQ Q35 discusses foreign storage if logs can be produced in reasonable time, while Q36 addresses providers serving Indian users and Indian-jurisdiction logs/financial-transaction records. Obtain a reconciled legal/control assessment, not blanket permission for offshore-only logging.

**Residency implication:** Separate log jurisdiction and provider-held subscriber records from production data residency. Offshore-only logging should not be assumed sufficient merely because a FAQ discusses foreign copies. The applicability and allocation of duties depend on the actual entity role, service and data flows.

### Procurement evidence
- [ ] Clause-by-clause customer/provider control ownership and incident-escalation playbook
- [ ] Log-category inventory, 180-day retention configuration, secure production/export and jurisdiction evidence
- [ ] Applicable customer-record fields, validation and five-year post-cancellation controls
- [ ] Time synchronisation and tested six-hour classification/escalation workflow

### Dates and applicability
- Directions issued 28 April 2022; stated general effect 60 days later.
- 27 June 2022 notice extended qualifying MSMEs and specified customer-validation fields to 25 September 2022, not every obligation.
- Official CERT-In index reviewed on 8 October 2026; case-specific applicability and later instruments still need verification.

**Review boundary:** The FAQ explains rather than amends the law. Its foreign-storage nuance must be assessed alongside the express Directions and other applicable sector rules. No Aitonomi-specific logs, records or reporting arrangements were verified.

### Primary sources
- [CERT-In Directions under IT Act section 70B(6)](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf)
- [CERT-In official FAQ — May 2022](https://www.cert-in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf)
- [CERT-In limited extension notice — June 2022](https://www.cert-in.org.in/PDF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf)
- [CERT-In official Directions index](https://www.cert-in.org.in/Directions70B.jsp)
