Where your data is stored is as important as how well it is protected. Across the world, regulators are introducing data localisation requirements to make sure sensitive information remains within national borders, improving oversight, resilience and data sovereignty. India’s financial sector is no exception in this case.
As part of its Cybersecurity and Cyber Resilience Framework (CSCRF), the Securities and Exchange Board of India (SEBI) introduced a data localisation requirement that would require regulated entities to host data relating to the Indian securities market within India. However, before the requirement became enforceable, SEBI issued a circular on 31 December 2024 placing the mandate in abeyance. In simple words, the requirement exists within the framework but is not currently mandatory.
That decision continues to shape compliance planning today. Firms must understand what the data localisation requirement originally intended, why SEBI paused it, which CSCRF obligations remain fully enforceable and how to prepare if the mandate is reinstated in the future.
This blog explains the current regulatory position, the practical implications for regulated entities and the steps BFSI compliance teams should take while the requirement remains on hold.
What data localisation under SEBI CSCRF actually covers
SEBI introduced CSCRF through circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 Aug 2024. Inside the Protect function’s Data Security family, there is control PR.DS.S2, the Data Localisation standard. It was written to require regulated entities to host data connected to Indian securities market operations within India’s legal boundaries.
The scope was broad by design. It broadly applied to data relating to Indian securities market operations. Any regulated entity relying on overseas hosting arrangements would probably have needed architectural changes to satisfy localisation requirement.
Why the requirement moved into abeyance
Four months after the original circular, SEBI changed course. Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 which was dated 31 Dec 2024, extended certain compliance timelines and added a short but important note. Based on feedback received on the data localisation provisions, SEBI decided the standard needed further consultation and placed PR.DS.S2 in abeyance until further notification.
That pause has been held since. Subsequent CSCRF updates, including the technical clarification circular issued in Aug 2025, continued to list Data Localisation as in abeyance rather than reinstating it. No compliance deadline has been announced for PR.DS.S2, and no timeline for a decision has been published either.
What stays binding under SEBI CSCRF despite the pause
Abeyance applies narrowly to the geographic hosting requirement. Every other data-related control in CSCRF remains active and auditable. Regulated entities should still budget effort and evidence for:
- Data classification: Sorting information into Public, Internal, Confidential and Restricted tiers remains a core CSCRF expectation.
- Encryption at rest and in transit: The framework’s baseline encryption standard, PR.DS.S1, continues to apply to systems handling regulated data.
- Data loss prevention monitoring: Continuous DLP coverage for critical systems is still required under the Detect function.
- Log management and database activity monitoring: Centralised logging and database monitoring remain part of the audit evidence SEBI expects.
- Secure data disposal: Retention and disposal practices must still align with SEBI’s record-keeping requirements.
- Asset inventory and software bill of materials: Maintaining an accurate inventory of applications and their components stays mandatory for critical systems.
How this fits with the DPDP Act and CERT-In requirements
The Digital Personal Data Protection Act, 2023 (DPDP Act), takes a different route on cross-border data than the paused SEBI standard did. Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025, follow a blocklist approach. Personal data can move outside India by default, barring only transfers to countries the government specifically restricts, and no such list exists yet.
That lighter-touch model may be part of why SEBI wants more time before finalising its own position. Separately, CERT-In’s log retention rule asks regulated entities to keep certain logs within India for 180 days. That obligation sits outside CSCRF and is unaffected by the abeyance.
How BFSI compliance teams should plan while the mandate is paused
A few things that BFSI compliance teams should plan when the mandate is paused:
- Do not list Data Localisation as binding in internal audit scopes or IT committee reports this cycle.
- Do not exclude it from long-term architecture planning. Keep cloud contracts flexible enough to accommodate reactivation.
- Document the abeyance in compliance records, citing circular 2024/184, so audit evidence reflects the current status.
- Monitor SEBI’s circular page for a notification, since SEBI has not given long lead times for similar changes before.
- Treat the binding data controls above as the real audit priority for this cycle.
Conclusion
Data Localisation under SEBI CSCRF is one of the most closely watched provisions in India, precisely because it is paused. The underlying control, its evidence requirements and its potential return all deserve a place in compliance planning, even while the mandate itself stays inactive. Every other CSCRF data control, from classification to encryption to asset inventory, continues to need audit-ready evidence today.
It’s important to build that evidence base and stay prepared for a possible reactivation of Data Localisation Under SEBI CSCRF. It needs a compliance programme that tracks every binding control alongside the paused one. CyberNX’s SEBI CSCRF framework consulting services help regulated entities run gap assessments, build a compliance roadmap and keep CSCRF evidence audit-ready, irrespective of if there’s abeyance or not. Connect with our experts to build a compliance architecture that is prepared for both outcomes.
Data Localisation Under SEBI CSCRF FAQs
What is PR.DS.S2 under SEBI CSCRF?
PR.DS.S2 is the CSCRF Data Security standard that would require regulated entities to host data related to Indian securities market operations within India. It sits in the framework’s Protect function.
Is data localisation currently mandatory under SEBI CSCRF?
No. SEBI placed the standard in abeyance through circular 2024/184 dated 31 Dec 2024, and subsequent CSCRF updates have not reinstated it.
Does the DPDP Act require data localisation?
No. The DPDP Act and its 2025 Rules allow personal data to move outside India by default, restricting only transfers to countries the government specifically notifies, and no such list exists yet.
What should regulated entities prioritise instead of localisation right now?
Data classification, encryption, DLP monitoring, log management, secure disposal and asset inventory remain binding and should form the current audit priority.




