Skip to content
Make in India OEM · INR-transparent · Pan-India onsite SLATalk to sales: +91 720 794 8743Sign in

Where BFSI AI Compute Must Sit: RBI Localisation Meets DPDP

Buyer's guide Updated 28 Jul 2026 · 6 min read

Overview

The question “where must our AI compute physically sit” has a more precise answer for Indian financial institutions than for most sectors, and it is not primarily answered by the DPDP Act. DPDP takes a comparatively permissive approach to cross-border transfer — as of mid-2026 no restricted-country list had been notified — but sectoral rules are stricter and prevail. The RBI’s payment-data directive requires payment system data to be stored in India, and SEBI and IRDAI impose their own obligations. This article maps which rule governs which data, and what that means for GPU placement.

Where BFSI AI Compute Must Sit: RBI Localisation Meets DPDP
What you’ll learn: how DPDP and sectoral localisation interact, which categories of BFSI data are genuinely constrained, what “processing” means when a model is involved, how to place training, fine-tuning and inference workloads, and what the 2027 enforcement date changes.

Key takeaways

  • DPDP is permissive on transfer — a negative-list model, with no restricted countries notified as of mid-2026.
  • Sectoral rules override — RBI’s payment-data localisation directive is stricter and continues to apply.
  • Model artefacts inherit sensitivity — embeddings, fine-tuned weights and inference traces derive from the underlying data.
  • Inference is the binding case — it touches live customer data continuously, so it is the workload that most clearly belongs in-country.
  • Full DPDP enforcement is expected in 2027, with penalties up to Rs 250 crore — design now, do not retrofit.

Two regimes, not one

DPDP governs personal data broadly and adopts what practitioners describe as a negative-list approach to cross-border transfer: transfers are permitted unless the government notifies restrictions on specific countries. As of mid-2026, no such list had been notified, so DPDP alone does not force localisation.

Sectoral regulation is a separate layer and is not softened by DPDP. The RBI’s directive on storage of payment system data requires the full end-to-end transaction details and related data to be stored only in India. SEBI and IRDAI maintain their own record-keeping and access requirements. A regulated entity must satisfy both frameworks, and where they differ the stricter applies. The practical implication is that a BFSI infrastructure decision should start from the sectoral rule and treat DPDP as an additional, largely orthogonal, obligation.

What counts as the data when a model is involved

This is the question that most often goes unexamined. If a fraud model is trained on transaction records, the resulting weights are a derived artefact of that data. If a RAG system embeds customer correspondence, the vector index encodes it. If an agent produces a trace containing retrieved account details, that trace is customer data. Treating only the source database as regulated, while the derived artefacts travel freely, is a position that is difficult to defend.

The workable stance is to classify by derivation. Anything computed from regulated data inherits its handling requirements until it has been demonstrably de-identified or aggregated beyond re-identification. That covers embeddings, fine-tuned adapters, evaluation datasets, prompt logs and inference traces — and it means the storage tier for those artefacts is in scope, not just the model server.

Placing each workload

Workload Data touched Defensible placement
Production inference on customer data Live regulated data In-country, institution-controlled
RAG index over customer records Derived from regulated data In-country, with the inference tier
Fine-tuning on institutional data Regulated data plus derived weights In-country
Pre-training on public corpora No regulated data Anywhere, including rented capacity
Evaluation on synthetic or public data None, if genuinely synthetic Flexible; document the provenance
Model artefact archive Derived In-country, with retention policy

The pattern is that steady-state, customer-facing inference is the workload with the least flexibility, and it is also the one with the best economics for owned infrastructure because volume is predictable. Experimental and public-data work is the most flexible and the most bursty, which is exactly the profile suited to rented capacity — including India’s subsidised national compute, where empanelled capacity of roughly 38,000 GPUs is reported heading toward around 100,000 by end-2026 at rates near a dollar per GPU-hour.

What the 2027 enforcement date changes

Full DPDP enforcement is expected from May 2027, with penalties reaching up to Rs 250 crore. The date matters less for the transfer question, which is already governed by sectoral rules, than for the security-safeguards and breach-notification obligations that apply regardless of where data sits.

For an AI platform that means three things to build now rather than later: a data inventory that includes model artefacts and inference traces, not just databases; demonstrable access control and encryption covering the GPU platform, where hardware-rooted approaches described in GPU confidential computing strengthen the evidence; and retention policies that actually execute. Retrofitting a data inventory across a deployed AI stack is substantially harder than designing one.

Practical architecture for a bank

A defensible pattern has emerged among Indian institutions. Keep a controlled in-country inference and retrieval estate for anything touching customer data, with the vector index, prompt logs and traces co-located and governed under the same policy. Keep model artefacts derived from institutional data in the same estate, with versioned lineage back to the training data. Use external or rented capacity only for work on public or genuinely synthetic data, and document that boundary so an auditor can see where the line was drawn.

Two supporting controls make this durable. A model registry recording, for each production model, its training data provenance, the jurisdiction it was trained in, and its approval status. And an egress control that prevents regulated artefacts from leaving the estate by accident — the failure mode is rarely a deliberate transfer, it is an engineer copying an index to a laptop or a notebook environment. The design detail is developed in BFSI private AI GPU server controls, with the broader planning frame in on-prem AI for BFSI.

Frequently asked questions

Does DPDP require Indian banks to keep AI compute in India?

Not by itself. DPDP adopts a negative-list approach to cross-border transfer and as of mid-2026 no restricted countries had been notified. What forces localisation for BFSI is sectoral regulation, principally the RBI’s payment-data storage directive.

Do fine-tuned model weights count as regulated data?

Treat them as inheriting the handling requirements of the data they were derived from, unless demonstrably de-identified or aggregated beyond re-identification. The same applies to embeddings, evaluation sets, prompt logs and inference traces.

Which AI workloads can run outside India?

Those touching no regulated data — pre-training on public corpora, evaluation on genuinely synthetic data, and general experimentation. Document the provenance so the boundary is auditable. Anything touching live customer data or artefacts derived from it should stay in-country.

What changes in 2027?

Full DPDP enforcement is expected from May 2027 with penalties up to Rs 250 crore. The most consequential obligations for an AI platform are security safeguards, breach notification and a complete data inventory that includes model artefacts, all of which are far easier to design in than to retrofit.

What is the most common compliance gap in AI deployments?

Uncontrolled egress of derived artefacts. Institutions govern the source database carefully, then allow embeddings, adapters or evaluation extracts to be copied into laptops, notebooks or external tools. Egress controls and a model registry with lineage close that gap.

Ready to deploy?

Talk to an RDP architect about power, cooling and lead time.

Request a Quote
👋 Ask GPU Mart AI — voice & text