> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# RBI SAR (Data Localization)

> Meet the Reserve Bank of India's data localization and security requirements.

> Meet the Reserve Bank of India's data localization and security requirements.

The Reserve Bank of India (RBI) requires payment system operators and regulated entities to store payment data within India and meet security and audit obligations. The System Audit Report (SAR) and data localization directives ensure that payment data is stored and processed domestically with appropriate safeguards.

<Note>
  These requirements apply to payment system operators, banks, and fintechs handling payment data of Indian customers.
</Note>

## Who needs RBI SAR (Data Localization)?

<CardGroup cols={2}>
  <Card title="Payment operators" icon="credit-card">
    Payment system providers subject to RBI data localization directives.
  </Card>

  <Card title="Indian fintechs and banks" icon="landmark">
    Regulated entities processing payment data within India.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Data localization" icon="database">
    Payment data must be stored within India's borders.
  </Card>

  <Card title="System Audit Report" icon="clipboard-check">
    Independent audit of compliance with RBI directives.
  </Card>

  <Card title="Access and encryption" icon="lock">
    Controls protecting payment data at rest and in transit.
  </Card>

  <Card title="Incident reporting" icon="bell">
    Timely reporting of security incidents to the RBI.
  </Card>
</CardGroup>

## How DSALTA helps with RBI SAR (Data Localization)

<Steps>
  <Step title="Activate RBI SAR">
    Select the RBI framework from the Frameworks page. DSALTA maps localization and security controls.
  </Step>

  <Step title="Review mapped controls">
    Review data storage, access, and audit controls and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather technical evidence.
  </Step>

  <Step title="Approve policies">
    Review and approve data localization and security policies.
  </Step>

  <Step title="Prepare the SAR">
    Organize evidence for the System Audit Report.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What does data localization require?" icon="database">
    Payment data of Indian customers must be stored on systems located within India, with limited exceptions for cross-border transaction processing.
  </Accordion>

  <Accordion title="What is the System Audit Report?" icon="clipboard-check">
    An independent audit demonstrating compliance with RBI's data storage and security directives.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
