New Delhi: At the upcoming BRICS Summit in New Delhi under India’s chairship, member nations are expected to discuss cross‑border payments and related data safeguards as the bloc seeks to build an interoperable, resilient payments architecture, while respecting national data sovereignty.
While BRICS (Brazil, Russia, India, China, and South Africa) may design interoperable platforms to bypass the SWIFT mechanism (Standardised International Messaging Network for Banks and Financial Institutions—which currently handles cross-border payments) and settle payments directly in local currencies, India’s participation would be shaped by strict compliance with its localisation regime.
India’s payments-related data are handled by Digital Personal Data Protection Act, 2023, and rules and regulations laid down by the Reserve Bank of India from time to time.
Will India need to modify its regulatory framework, particularly DPDP Act obligations and RBI circulars on data localisation, to participate in any BRICS payments system, and what those changes would mean to India’s payments-related data protection regime?
“Whilst the RBI data localisation circular still remains, DPDPA dropped this. There is, therefore, no impediment for modifications to be done with respect to financial data too,” senior advocate N.S. Nappinai told ThePrint.
Cross‑border payments require coordination between multiple banking systems, compliance with diverse regulatory regimes and settlement across different currencies.
Currently, it is handled by SWIFT. It provides the secure, standardised infrastructure across the globe to communicate payment instructions. When an Indian bank needs to send dollars to a foreign bank, SWIFT transmits the encrypted message that tells the banks how to settle the transaction.
The BRICS discussions in recent years—from creating a shared digital settlement platform to exploring alternatives to SWIFT (standardised international messaging network for banks and financial institutions)—are driven by a desire for financial sovereignty and smoother local‑currency trade.
The 18th BRICS Summit will be held from 12-13 September in New Delhi. Whatever BRICS‑level payment system emerges from these discussions would be shaped by the member-countries’ local data protection regimes, including India’s own robust DPDP Act, 2023, and RBI circulars.
“Municipal laws (a country’s domestic or national laws) will always prevail over international covenants or undertakings. RBI’s circular being under delegated legislation is easier to modify than parliament enacted laws. With DPDPA not mandating data localisation, India is not restrained from aligning with BRICS if it deems fit,” Nappinai explained.
“If India decides to align, then it would have to modify its municipal or local laws to reflect its international undertakings. Apart from this requirement, nothing else would stand in the way of implementation of its undertakings.”
Also read: Payment systems, BRICS expansion & bilateral meets. What to expect as Modi heads to Russia
BRICS & cross‑border payments
Last year, at the BRICS Leaders’ Declaration, the bloc set out a clear vision for reshaping global payments and data governance under the Cross‑Border Payments Initiative.
The declaration underscored its role as a cornerstone for building fast, low‑cost, accessible, efficient, transparent and safe cross‑border payments system—a framework designed to strengthen trade and investment flows both within BRICS and with other nations.
Equally significant was the bloc’s articulation of a data governance vision. BRICS reaffirmed the need for a principle‑based, interoperable framework that balances respect for national data sovereignty with mutually agreed cross‑border data flows. The declaration emphasised ethical data practices, protection of personal privacy and alignment of national regulations to ensure trust and interoperability.
RBI and data localisation
With the rapid expansion of India’s digital payments ecosystem, the Reserve Bank of India in a circular dated 5 April 2018 underscored the need to safeguard payment system data through global best practices and continuous monitoring.
The RBI circular requires that all end‑to‑end transaction data be stored exclusively in India. If both payer and payee are in India, the entire transaction data (customer info, account details, credentials, logs) must be stored only in India.
In terms of a cross-border payment with an Indian counterpart, data like customer data, payment sensitive data , transaction data like timestamps, origin/destination system information must be stored in India.
The overseas component like beneficiary’s bank abroad, foreign regulator requirements may be stored abroad if necessary.
There is no bar on processing of payment transactions outside India. However, the data shall be stored only in India after the processing.
In case the processing is done abroad, the data should be deleted from the systems abroad not later than the one business day or 24 hours from payment processing, whichever is earlier. The complete end‑to‑end transaction details must be stored in India and subsequent activities such as settlement or chargeback must likewise ensure that the data resides domestically.
DPDP Act and cross‑border data transfers
Section 16 of the DPDP Act empowers the Central government to restrict cross‑border transfers of personal data. Importantly, the provision itself does not speak of mandatory data localisation; it only sets out a framework for government‑controlled restrictions.
The DPDP framework adds another layer by imposing obligations on data fiduciaries. A Data Fiduciary is an entity that collects the personal data with consent. Even when transfers are permitted, fiduciaries must ensure that contractual safeguards are in place with foreign processors, maintain records of transfers and uphold the rights of data principals.
In effect, the DPDP Act ensures accountability for transfers, while RBI ensures localisation of payment data.
Any new cross‑border payment system proposed by BRICS will inevitably have to align with India’s domestic regulatory framework, particularly the RBI rules on data localisation and cross border payments.
Prasanth Sugathan, Legal Director at Software Freedom Law Center, India said, “It seems the plan is to achieve interoperability through technical standards. However, there could be challenges when it comes to settlement and Foreign exchange conversion. This route could be easier to comply with the data localisation requirement of the RBI.”
Asked if BRICS will need a formal treaty structure to govern cross-border payments, he added, “The practical and faster option will be to avoid treaties, and to opt for MoUs and shared standards. An example that can be relied on for this is making UPI work in the UAE by means of shared technical standards.”
However, he said that conflicting legal regimes can pose a challenge to creating a payment system that operates across nations.
“Even when DPDP Act becomes operational when it comes to issues relating to data localisation, sectoral laws that provide higher standards will prevail. However, we have seen successes in making UPI work across various countries even with the strict data localisation requirements mandated by RBI. There will, of course, be challenges in navigating the data sovereignty regimes of Russia and China.”
Also read: The evolution of BRICS, an odd grouping born out of a 2001 Goldman Sachs paper
