Data residency has quietly become one of the most important compliance conversations for AI companies operating in India. As AI training pipelines and inference systems increasingly touch personal data of Indian citizens, understanding data residency is no longer optional. This guide breaks down the different types of data residency obligations Indian AI companies face in 2026, and explains how the right infrastructure partner supports a practical data residency strategy.

Data residency is the question every Indian AI company eventually has to answer honestly: where does your data actually live, and does that location satisfy the law. It sounds simple until you look at how a modern AI pipeline works. Training data, model checkpoints, logs, embeddings, and inference outputs frequently move across multiple systems, and very few teams have a complete map of where every copy of sensitive data physically sits. That gap between assumption and reality is exactly where risk accumulates around data residency.
For a long time, Indian AI startups treated this as a checkbox exercise, something to worry about only if a client asked during procurement. That has changed. With the DPDPA, sector regulators like the RBI, SEBI, and IRDAI, and a growing base of enterprise clients demanding contractual guarantees, AI companies in India now treat data residency as a first-class engineering and legal requirement rather than an afterthought.
The shift has been driven partly by scale and partly by scrutiny. AI companies today are not handling a handful of customer records; they are ingesting millions of interactions, documents, and behavioral signals to train and fine-tune models, and every one of those data points may need to satisfy a specific storage or processing rule. What used to be a conversation reserved for banks and insurers has now spread across fintech, healthtech, edtech, and even early-stage AI startups building consumer-facing products. Founders who once assumed a generic cloud setup was good enough are discovering that enterprise procurement teams, government agencies, and even smaller regulated clients now expect a clear, documented answer about where their data physically resides.
This growing scrutiny also reflects how quickly the regulatory and commercial landscape around India has matured. Cloud providers now market India-specific regions, domestic hosting companies have built compliance-first offerings, and legal teams routinely add data residency clauses to vendor contracts that would have been unusual just a few years ago. For an AI company, ignoring this shift is no longer a viable option, since a single overlooked storage location or an unclear answer during a client audit can quietly derail a deal that took months to close.
This guide walks through the different types of data residency requirements that apply to Indian AI companies today, explains how each affects an AI training or inference pipeline, and gives founders, CTOs, and compliance leads a practical way to evaluate their own infrastructure. By the end, the goal is not just to define data residency in the abstract, but to give you a working framework you can apply directly to your own AI systems, regardless of which sector or stage your company is in.
1. Why Data Residency Has Become a Core Concern for AI Companies in India
Data residency used to be a niche legal term that only came up in RFP documents from large banks. That is no longer the case. As AI companies in India process larger volumes of personal data, data residency has moved from a legal footnote to a boardroom topic discussed alongside product roadmaps and fundraising conversations.
Part of the reason this now sits so high on the priority list is that AI systems are unusually data hungry. A single fine-tuning run might ingest millions of customer interactions, and each could contain personal data that falls squarely within scope. Getting this wrong is not just a legal risk; it can directly affect whether an AI company is even allowed to sign a contract with a regulated enterprise client.
Before scaling any AI training pipeline, map every location where personal data is stored, including logs, backups, and third-party API providers. This map becomes the foundation of your entire data residency strategy.
2. What Data Residency Actually Means for an AI Pipeline
In the simplest terms, this refers to the physical or jurisdictional location where data is stored, processed, and backed up. For AI companies, it spans far more than a single database: training datasets in object storage, model weights derived from that data, vector embeddings used in retrieval systems, and temporary cache files created during inference.
It is worth being precise, because the term is often confused with data localization. Data residency generally refers to a choice or preference about where data sits, while localization is a stricter legal mandate requiring certain data to remain within a country regardless of preference. Indian AI companies need to understand both, since some data types fall under strict localization rules while others carry softer expectations that still hold real contractual weight.
- Choices about where training data lives determine which region’s laws apply if that data is ever breached or subpoenaed.
- The location of model outputs matters when an AI system generates content derived from regulated personal data.
- Backups and disaster recovery copies are frequently overlooked, even though they carry the same legal weight as the primary copy.
- Commitments made in a customer contract can be stricter than what the underlying law technically requires.

3. Type 1: Cross-Border Transfer Rules Under the DPDPA
The Digital Personal Data Protection Act is the broadest framework Indian AI companies must account for. It establishes rules around how personal data of Indian citizens is collected, processed, and transferred, and its cross-border transfer provisions are the clearest expression of data residency obligations in Indian law today.
As detailed in recent regulatory analysis of India’s data protection rules, the DPDPA compliance timeline unfolds in phases through 2026 and 2027, and AI companies handling personal data of Indian citizens need a data residency strategy that anticipates the full enforcement deadline rather than waiting until the final phase becomes active.
- The DPDPA allows cross-border transfer by default, but government retains power to notify restricted jurisdictions, directly shaping data residency planning.
- AI companies must track which jurisdictions get added to any future restricted list, since a compliant setup today could require rearchitecting later.
- Consent and purpose limitation requirements under the DPDPA indirectly reinforce this discipline, since companies must know exactly where consented data is processed.
Don’t assume a cloud region labeled ‘India’ automatically means all your data handling is DPDPA-compliant. The DPDPA doesn’t mandate India-only storage by default, but it does require you to know exactly where data moves, since cross-border transfer rules and consent/purpose-limitation obligations still apply. Some services replicate metadata or logs to a global control plane outside India even when primary data appears local, always verify with your provider’s documentation what actually leaves the region.
4. Type 2: Sector-Specific Mandates
Beyond the DPDPA, several Indian regulators impose their own rules that are often stricter and more specific than the general privacy law. AI companies building products for BFSI, healthcare, or insurance clients need to understand these sector rules independently, because general DPDPA compliance does not automatically satisfy them.
4.1 RBI Payment Data Rules
The Reserve Bank of India has long required payment system data be stored exclusively within India. AI companies building fraud detection or credit scoring models touching transaction data must treat this as a hard boundary, not a soft preference, when it comes to data residency.
4.2 SEBI Rules for Capital Markets
SEBI has issued rules requiring regulated entities using cloud service providers to keep regulatory and compliance data within India. AI companies building trading algorithms or market surveillance systems need an architecture that satisfies this requirement independently of general DPDPA compliance.
4.3 IRDAI Rules for Insurance Workloads
The Insurance Regulatory and Development Authority of India imposes its own conditions on where insurance-related data may be processed and stored. AI companies building underwriting or claims-automation tools for insurers should confirm requirements directly with IRDAI guidance.
- Sector-specific rules operate independently from the DPDPA and can be stricter.
- An AI company serving multiple sectors may need different configurations for each client vertical.
- Audits for regulated sectors typically require documented evidence, not just a technical claim of compliance.

5. Type 3: Contractual Requirements from Enterprise Clients
Even where the law does not strictly mandate it, many enterprise clients in India, particularly in banking, government, and healthcare, require data residency as a condition of doing business. This is often called a de facto requirement, since it is not a legal mandate but functions as one through procurement contracts.
According to a detailed 2026 guide on India’s evolving data geography landscape, enterprise clients in regulated industries routinely require Indian data residency as a vendor procurement condition even where general law does not mandate it, which means an AI company can lose enterprise deals purely on this ground even if otherwise fully DPDPA compliant.
- Government procurement contracts frequently include clauses that go beyond what general law requires.
- Enterprise clients in BFSI often ask AI vendors to prove compliance through audit trails and architecture diagrams, not just a policy document.
- Losing an enterprise deal over this gap is more common than losing one over pricing, once a client’s compliance team gets involved.
If you are trying to understand how the right infrastructure partner factors into these contractual conversations, our earlier breakdown of server management service providers walks through what enterprise clients actually look for when evaluating a vendor’s operational maturity, which is often the same lens they apply to data residency claims.
6. Type 4: Cross-Border AI Model Training
A uniquely modern challenge for AI companies is what happens when a model is trained using data that briefly leaves Indian infrastructure, even if the final model or dataset returns. Some training pipelines route data through international GPU clusters for compute availability reasons, and this raises a question older compliance frameworks were never designed to answer clearly.
- Questions around AI training increasingly ask whether data used for training was ever processed outside India, even temporarily.
- Vector databases and embedding stores used in retrieval-augmented generation need their own classification, since embeddings can sometimes reveal underlying personal data.
- AI companies using third-party foundation model APIs must confirm the practices of that provider, since sending prompts containing personal data to an overseas endpoint can trigger the same obligations as storing data abroad directly.
If your AI pipeline sends prompts containing personal data to a third-party foundation model hosted outside India, that transmission itself may fall within scope of cross-border transfer obligations, even if you never store a permanent copy abroad.
7. Type 5: Backups, Logs, and Disaster Recovery
One of the most commonly missed gaps involves backup copies and operational logs. AI companies often architect their primary database with strict controls, only to discover that automated backup jobs or logging pipelines quietly replicate data to a different region for redundancy.
- Disaster recovery copies must satisfy the same rules as the primary dataset, not a relaxed version of them.
- Application logs that capture request payloads can inadvertently contain personal data, creating an unplanned exposure.
- Monitoring and observability tools hosted on a global SaaS platform can undermine an otherwise solid architecture if left unchecked.
This is exactly the kind of gap that continuous monitoring is designed to catch early. Our detailed guide on 24×7 server monitoring explains how ongoing visibility into infrastructure, including backup jobs and log pipelines, helps teams catch a violation before it becomes a compliance incident rather than after.
8. Type 6: Obligations Tied to Data Subject Rights
The DPDPA grants Indian citizens specific rights over their personal data, including the right to access, correct, and request deletion. Fulfilling these rights requires an AI company to know precisely where every copy of a person’s data resides, which makes location tracking a practical prerequisite for exercising data subject rights.
- A deletion request cannot be fully honored if a company cannot locate every copy that exists.
- AI companies using data for model training face a harder version of this, since personal data may be embedded in model weights rather than stored in a discrete, deletable record.
- Documentation should map not just storage locations but also which AI models were trained on a given dataset.
9. Comparing the Major Types of Data Residency Requirements
| Type | Primary Source | Key Risk |
| Regulatory (DPDPA) | Central government law | Restricted jurisdiction list can change |
| Sector-specific (RBI/SEBI/IRDAI) | Financial and insurance regulators | Stricter than general law, sector audits |
| Contractual (enterprise clients) | Procurement agreements | Deal loss even without legal violation |
| Cross-border AI training | Third-party model APIs, GPU clusters | Transmission itself can trigger obligations |
| Backups and logs | Internal DR and observability tooling | Silent replication outside India |
| Data subject rights | DPDPA individual rights | Incomplete deletion across copies |

10. How Cybersecurity Solutions Support Compliance
Data residency and security are closely linked, even though they are legally distinct. Knowing where data sits is only half the picture; an AI company also needs that location properly secured against unauthorized access, since a location claim means little if the data itself is left exposed.
- Cybersecurity solutions that include encryption at rest and in transit reinforce a company’s posture by ensuring even India-hosted data cannot be trivially exfiltrated.
- Access control and identity management are core cybersecurity solutions that prevent violations caused by an employee or contractor accessing data from an unauthorized location.
- Regular penetration testing, a standard part of most cybersecurity solutions, helps confirm an architecture is not undermined by an overlooked vulnerability.
- Choosing the right cybersecurity solutions is as important as choosing the right region for storage.
- Well-implemented cybersecurity solutions give enterprise clients confidence that location guarantees are backed by real protection.
- Many compliance frameworks now expect cybersecurity solutions and location controls to be documented together, not separately.
- Investing early in cybersecurity solutions is far cheaper than remediating a breach after the fact.
Security posture should always be evaluated alongside storage location during a vendor assessment, and comparing quotes from more than one provider of Cyber Security services before committing budget is a smart practice for any growing AI team. For teams building out a broader security program, our detailed walkthrough of zero trust security principles for India explains how a zero trust architecture naturally reinforces these boundaries by verifying every access request rather than trusting network location alone.
Ready to Secure Your Infrastructure?
Get started with our comprehensive Cyber Security services in India today and experience proactive threat monitoring, vulnerability assessments, and DPDPA-compliant data protection
For AI companies that want a dedicated partner handling this layer, exploring Cyber Security services designed specifically for Indian compliance requirements is a practical way to align obligations with day-to-day security operations, rather than treating the two as separate workstreams handled by different teams.
- Choosing Cyber Security services with experience in Indian regulatory frameworks makes it easier to align technical controls with legal obligations.
- Cyber Security services that include continuous vulnerability scanning help AI companies catch issues before they become audit findings.
- AI companies without dedicated Cyber Security services often discover gaps only after a client compliance review flags them.
- Reliable Cyber Security services also help smaller AI teams meet enterprise-grade expectations without building an internal security function from scratch.
- Cyber Security services covering incident response planning are especially valuable for AI companies handling sensitive training data.
- Evaluating Cyber Security services should be part of any vendor selection process for AI infrastructure, not an afterthought.
- Cyber Security services that offer regular reporting give leadership visibility into risk without requiring deep technical expertise.
- Partnering with established Cyber Security services reduces the operational burden on engineering teams already focused on model development.
- Cyber Security services focused on cloud environments are particularly relevant for AI companies running distributed training pipelines.
- Comprehensive Cyber Security services typically bundle monitoring, patching coordination, and compliance reporting into a single engagement.
- Many enterprise clients now ask AI vendors directly what Cyber Security services they have in place before signing a contract.
- Cyber Security services that specialize in AI workloads understand risks unique to model training and inference that generic providers may miss.
- Choosing Cyber Security services with transparent SLAs helps AI companies set realistic expectations with their own clients.
- Cyber Security services are most effective when reviewed and updated alongside infrastructure changes, not treated as a static setup.
- AI companies scaling quickly often find outsourced Cyber Security services more practical than hiring a full in-house team immediately.
- Cyber Security services with India-based support teams can respond faster during an active incident than an overseas provider.
- Layering Cyber Security services on top of a solid infrastructure foundation gives AI companies a defensible compliance posture.
- Cyber Security services that include employee access audits help prevent internal misuse of sensitive training data.
11. The Role of Server Management Services in Maintaining Compliance
Even the most carefully designed policy falls apart without consistent operational execution. This is where server management services in India become essential, since this is not a one-time architectural decision but an ongoing operational commitment that must survive patches, migrations, scaling events, and staff turnover.
- Server management services in India ensure infrastructure changes, such as adding a new backup target, do not silently break an existing configuration.
- Patch management, a core part of server management services in India, keeps India-hosted servers secure without requiring data to be temporarily routed through an external vendor’s infrastructure for remote diagnostics.
- Server management services in India that include detailed audit logging make it far easier to produce evidence during a client or regulator audit.
- Teams relying on server management services in India can respond faster to a related incident, since local support does not require escalation through an international queue.
- Server management services in India also help smaller AI teams maintain a level of operational discipline that would otherwise require a dedicated in-house ops function.
- Choosing server management services in India with clear SLAs gives compliance teams confidence that infrastructure will not silently drift out of alignment.
- Server management services in India that specialize in AI workloads understand the unique storage and compute patterns involved in training pipelines.
- Regularly auditing server management services in India performance is a useful habit for any AI company scaling its infrastructure footprint.
Server management services in India that combine infrastructure oversight with cybersecurity solutions give AI companies a single accountable partner rather than a fragmented set of vendors. Teams evaluating server management services in India should ask specifically how patching cadence, monitoring, and cybersecurity solutions are coordinated across the same infrastructure.
A well-documented example of how operational gaps become security gaps is the recent cPanel and WHM CVE-2026-41940 authentication bypass vulnerability, a useful reminder that location guarantees mean little if the underlying control panel software managing that infrastructure has an unpatched authentication flaw. Consistent patching discipline is just as much a safeguard as choosing the right region, and it is exactly the kind of task that well-run server management services in India are designed to handle continuously.
For companies that would rather not manage this operational layer internally, dedicated Server Management Services can handle the day-to-day discipline of keeping infrastructure patched, monitored, and aligned with these commitments, freeing engineering teams to focus on the AI product itself.
Ready to Offload Your Server Management?
Get started with our expert Server Management Services in India today and experience 24×7 monitoring, proactive patching, and hands-on support from a dedicated technical team
12. Choosing a Hosting Partner That Understands Data Residency
Not every hosting provider treats this with the seriousness it deserves. Many global platforms advertise an India region without clearly documenting what, if anything, still leaves that region for logging, analytics, or support purposes. Indian AI companies need a hosting partner that can answer these questions with specifics, not marketing language.
- A dependable Web Hosting Company in India should be able to confirm exactly which data categories remain in-country and which, if any, do not.
- A Web Hosting Company in India with DPDPA-aligned data handling policies simplifies the compliance conversation with legal and audit teams.
- Choosing a Web Hosting Company in India with transparent architecture documentation makes audits faster and less stressful.
- A Web Hosting Company in India offering both infrastructure and security services under one roof reduces the coordination overhead of maintaining compliance across multiple vendors.
- Founders comparing options should shortlist a Web Hosting Company in India with a proven uptime and support track record before signing a long-term contract.
- A Web Hosting Company in India with India-based data centres directly addresses latency and compliance concerns simultaneously.
For AI companies evaluating this decision, CloudMinister positions itself as a Web Hosting Company in India built around India-hosted infrastructure, giving AI teams a straightforward path to satisfying these requirements without piecing together a patchwork of global services.
- A Web Hosting Company in India that supports GPU and AI-specific workloads is increasingly valuable as training pipelines grow more demanding.
- Enterprises negotiating long-term contracts should confirm that their Web Hosting Company in India offers clear escalation paths during an incident.
- A Web Hosting Company in India with NVMe-backed storage and predictable INR billing removes two common sources of budgeting uncertainty.
- Startups in their earliest fundraising stages often select a Web Hosting Company in India specifically because of its compliance documentation.
- A Web Hosting Company in India that publishes clear SLAs gives engineering teams confidence when planning production AI workloads.
- Working with a Web Hosting Company in India that understands both traditional hosting and modern AI workloads is increasingly valuable.
- A Web Hosting Company in India offering a clear upgrade path from shared infrastructure to dedicated GPU servers supports teams as they scale.
- Reviews and case studies are a useful way to evaluate a Web Hosting Company in India before signing a long-term contract.
- A Web Hosting Company in India with responsive account management reduces the operational overhead of running production AI infrastructure.
- Compliance teams often prefer a Web Hosting Company in India with extensive audit documentation readily available on request.
- Many Indian AI startups standardize on a single Web Hosting Company in India specifically to simplify their data residency conversations.
- A Web Hosting Company in India that combines hosting, security, and management services under one invoice significantly simplifies procurement.
13. The Growing Scale of Enforcement in India
The pressure behind these requirements is not abstract. According to a 2026 global analysis of data localization laws, over 60 countries now enforce some form of data residency requirement as of 2026, and India is frequently cited among the jurisdictions where sector-specific rules are tightening fastest, particularly in financial services and government-adjacent sectors.
As enforcement matures, AI companies that treated this as a one-time setup task are discovering that the requirement keeps evolving. New sector guidance, updated DPDPA rules, and a deepening base of enterprise clients demanding proof all mean this is an area requiring ongoing attention rather than a single audit checkbox.
14. Building a Practical Framework for Your AI Company
A useful way to approach this is to treat it as a recurring operational discipline rather than a static legal requirement to satisfy once.
- Start by mapping every location where personal data is stored, processed, or transmitted, including third-party AI APIs and backup systems, to establish your current baseline.
- Classify data by sensitivity and regulatory category, since payment data, health data, and general behavioral data may carry different obligations.
- Document your architecture in a form that can be shared with enterprise clients and auditors without exposing sensitive implementation details.
- Review your posture at least twice a year, since DPDPA rules, sector guidance, and enterprise client expectations all continue to evolve.
- Pair your architecture with strong cybersecurity solutions and reliable server management services in India, since location alone does not guarantee protection.
- Building internal awareness around cybersecurity solutions ensures engineering teams treat security as part of everyday development, not a separate afterthought.
- Combining cybersecurity solutions with regular server management services in India reviews keeps both layers of the compliance stack working together instead of drifting apart.
- Teams that invest early in cybersecurity solutions typically spend far less remediating avoidable incidents later in the product lifecycle.
- A quarterly review involving both cybersecurity solutions and server management services in India helps confirm nothing has silently changed since the last audit.
Treat your documentation as a living artifact your compliance and engineering teams update together, not a one-time PDF created for a single audit and then forgotten.

15. Common Mistakes AI Companies Make
Mistake 1: Assuming a Regional Cloud Label Equals Full Compliance
Selecting an India region on a hyperscaler dashboard does not automatically guarantee every byte of data, including logs and telemetry, stays within that region. Always verify claims against actual documentation.
Mistake 2: Ignoring Third-Party AI API Location Practices
Sending prompts containing personal data to an overseas foundation model API can undermine an otherwise solid setup. Always confirm where that provider processes and stores data.
Mistake 3: Overlooking Backup and Log Location
Backup jobs and logging pipelines are among the most common places where a gap quietly appears, since they are often configured separately from the primary database.
Mistake 4: Treating This as a Legal-Only Concern
This is as much an engineering and operational challenge as a legal one. Without server management services in India actively enforcing the architecture, and without cybersecurity solutions protecting it, even a well-written policy can drift out of compliance. Data residency, in practice, is upheld by daily operational discipline far more than by a document sitting in a compliance folder.
Mistake 5: Underestimating How Cybersecurity Solutions and Data Residency Intersect
Some AI companies treat cybersecurity solutions and data residency as entirely separate workstreams owned by different teams. In practice, the two constantly overlap, since a properly secured environment is what makes a data residency guarantee meaningful in the first place.
Mistake 6: Not Revisiting After Scaling
A setup that worked for a small pilot project can break down entirely once an AI company scales to multiple regions, more data sources, and larger enterprise clients. This is precisely the stage where server management services in India and updated cybersecurity solutions become necessary rather than optional.
Key Takeaways
- Data residency for Indian AI companies spans regulatory law, sector-specific mandates, contractual obligations, and technical realities of AI training pipelines.
- The DPDPA is the broadest framework, but sector regulators like the RBI, SEBI, and IRDAI often impose stricter rules independently.
- Enterprise clients frequently demand guarantees that go beyond what the law technically requires, making this a real business risk.
- Backups, logs, and third-party AI APIs are common blind spots where violations quietly occur.
- Strong cybersecurity solutions and dependable server management services in India are essential to keeping an architecture intact over time, not just at initial setup.
- Choosing a Web Hosting Company in India that understands data residency in detail removes significant compliance risk for AI companies operating at scale.
Ready to Talk to Our Team?
Reach out today and experience fast, India-based support, transparent pricing, and infrastructure guidance tailored to your business needs
Conclusion
Data residency is no longer a peripheral legal concept for Indian AI companies; it is core to how AI products are architected, sold, and operated. Understanding the different types of data residency requirements, from the DPDPA’s cross-border rules to sector-specific mandates and contractual expectations from enterprise clients, gives AI teams the clarity needed to build systems that hold up under scrutiny.
What makes this topic genuinely difficult is that it sits at the intersection of law, engineering, and vendor management, and very few companies have a single team responsible for all three. A legal team might understand the DPDPA in detail but have little visibility into where backup jobs actually replicate data. An engineering team might have full control over infrastructure but no clear picture of which client contracts carry stricter obligations than the law itself requires. Closing that gap is what separates AI companies that pass enterprise audits smoothly from those that scramble to answer basic questions when a client’s compliance team finally asks.
As enforcement deepens through 2026 and beyond, Indian AI companies that pair a clear data residency framework with strong cybersecurity solutions and consistent server management services in India will be far better positioned to win enterprise deals, pass regulatory audits, and avoid the kind of quiet drift that turns into an expensive compliance problem later. Treated seriously and revisited often, this becomes a competitive advantage rather than a constant source of anxiety.
Ultimately, the companies that get ahead on this front are not the ones that treat it as a one-time legal exercise, but the ones that build ongoing habits around it: mapping data flows regularly, choosing infrastructure partners who understand the nuances involved, and revisiting their architecture as regulations and client expectations evolve. Data residency, approached this way, stops being a recurring source of last-minute panic and becomes simply part of how a well-run AI company operates.
Frequently Asked Questions
What is data residency and why does it matter for AI companies in India?
It refers to the physical or jurisdictional location where data is stored and processed. It matters because training data, model outputs, and logs often contain personal data subject to the DPDPA and sector-specific rules.
Is data residency the same as data localization?
No. Data residency generally refers to a chosen or preferred storage location, while data localization is a stricter legal mandate requiring certain data to remain within a country’s borders regardless of preference.
Do all Indian AI companies need to worry about this, or only large enterprises?
Any AI company processing personal data of Indian citizens should have a data residency plan, regardless of size. Smaller companies often face the same enterprise client demands as larger competitors.
How do server management services in India help with data residency?
They ensure that ongoing changes to infrastructure, such as patches, backups, and monitoring configurations, do not silently break an established architecture.
Can using a third-party AI model API affect my data residency compliance?
Yes. Sending personal data to an overseas AI model API can trigger the same obligations as storing that data abroad directly, even without a permanent copy being retained.




