Data Residency: Where Financial Data Is Allowed to Sit
Data residency asks four things: where the data sits at rest, where it is processed, where copies go and how long they stay, and who can require it to be produced. The fourth is what people mean by the word, and the first three decide the answer to it. The Reserve Bank of India, at rbi.org.in, states what any of this requires of an Indian regulated lender, and no other body states it.
A firm does not have one answer to where its data is. The firm has one answer for each place the data exists, and the number of places is almost always larger than the number anybody has written down. Every difficulty in the subject starts at that gap. The places a firm can describe are the places it controls, and the places that decide the answer are usually the ones it does not.
What is mechanism here, and what is stated elsewhere
The mechanism is what residency is a property of, why it is hard to establish once a system is running, what a firm has to be able to demonstrate, and what breaks when nobody can answer. Requirements, thresholds, categories of data, permitted places and effective dates are set by the Reserve Bank of India at rbi.org.in for a regulated lender, and by the Securities and Exchange Board of India at sebi.gov.in where the deployer is a market intermediary. The position at those sites is the one that governs, and it is current there and nowhere else.
What is data residency actually asking about?
Start with an ordinary errand. A customer walks into a shop to buy a new mobile connection and hands over a photocopy of an identity document. Where is that photocopy now? Most people answer instantly: in the shop. The instant answer is wrong in an interesting way. The photocopy is in the shop's drawer. The shop also scanned it and sent it to the operator, so a second image sits on the operator's system. The agent who signed the customer up kept a third on his handset. If anybody later says he onboarded a customer he never met, that image is the thing he shows. One document, three holders, and the count came to one.
Data residencyThe set of questions about where data sits, where it is worked on, where copies of it go and who has the power to require it to be handed over. is that ordinary confusion, made formal and applied to a bank. Data residency is not one question with a country as its answer. Data residency is four questions, and only the fourth is the one people mean when they use the word. Number them. 1, where the data sits at rest. 2, where it is processed, and that can be somewhere else entirely. 3, where a copy goes and how long it stays there. 4, who can require it to be produced.
The order matters and it is not the order people ask in. Question 4 is what worries people, so almost everybody asks it first. But question 4 has no independent answer. Question 4 is a consequence of the first three. A firm that has answered only question 1 will still produce a confident answer to question 4, and that confidence is the whole trouble.
Which set of four is what data residency actually asks?
Where does data sit at rest, and why is that the easiest of the four to answer?
At restWhere data is stored when nothing is being done to it. The disk it is written on rather than the machine that read it last. means the data is written down somewhere and nothing is happening to it. Data at rest is the photocopy sitting in the drawer. Question 1 asks about a thing that stays still. A thing that stays still can be pointed at, listed and put in an agreement in one sentence, and that is what makes question 1 the easiest of the four.
Sumeru Bank Limited, an invented lender, runs a retail personal loan intake chain of nine separately built components. Its own store for that chain holds the fourteen fields the reading step pulls off each application, together with the document images those fields were read from. The bank can describe that store precisely, naming the system it belongs to, the team that runs it, who was given read access and who was taken off. The precision is real, and it is precision about one place out of several. A firm in exactly that condition becomes confident it has answered a question it has not.
Question 1 is small for the same reason it is easy. A store the firm operates is a store the firm can inspect. Nothing about being able to inspect it establishes anything about the places that cannot be inspected. Detail on one side of a boundary is not evidence about the other side, and a count of exactly what that mistake cost this bank appears below.
Where is it processed, and can that be somewhere else entirely?
Data in processingWhere the work on data is actually carried out. The store the data comes from and goes back to can be somewhere else. is data something is being done to. The data has been read off the place it was resting, carried to wherever the work happens, worked on, and a result has come back. During that journey the data sits somewhere it sits at no other time, and for the length of the work it can be seen by whoever operates that somewhere.
Think of the photocopy again. The photocopy rests in the drawer. When the agent verifies the customer, he takes it out, holds it up, compares it with the customer's face, and puts it back. In that minute the document is in his hands, not in the drawer, and anyone standing next to him can read it. The drawer clause in the shop's tenancy agreement has nothing to say about that minute.
An agreement that settles where data is stored has answered question 1 and said nothing about question 2, and the two questions have different people as their answer. At Sumeru Bank one of the nine components, component 2, the liveness check on the selfie image, runs inside a vendor-hosted serviceA component the buyer uses and somebody else runs, changes and measures, reached by sending an input and receiving an output.. The bank sends an image and receives a pass or a fail. The whole exchange is question 2 territory. For the length of the check, the image is being worked on by a party that is not the bank, on machines the bank does not operate.
The agreement says the data is stored in one named place. Does that answer residency?
What does a copy do to the answer?
A copyA second instance of the same data. A copy has its own answer to every residency question and inherits none of the original's answers. is not a smaller version of the original and it is not a weaker claim on the same data. A copy is a second instance of the same thing, with its own answer to every one of the four questions. Where it sits is its own question. Who can see it is its own question. How long it stays is its own question, and that last one is where most firms discover they never decided anything.
Copies are made for good reasons. Nobody stops them. A copy is made so a system can recover after it stops. A copy is made so somebody can investigate a complaint. A copy is made because a supplier keeps a record of what it did, in case the buyer later says it did something else. The supplier's record is a dispute recordA copy a supplier keeps of the work it performed, as its own evidence of what it did. The buyer rarely counts it., made for the supplier rather than for the buyer, and buyers almost never count it.
The reason copies break residency answers is that a copy inherits the data and does not inherit the agreement. A firm that has settled question 1 for the original has settled nothing for the copy, and the copy is frequently held by somebody who was never a party to the sentence that settled it.
Who can require the data to be produced, and why is that the question underneath the others?
ProductionBeing required to hand data over to a party that has the power to require it. The power sits with wherever the data physically is, not with whoever collected it. means somebody with the power to require it says hand that over, and it is handed over. Production is what makes residency feel urgent, and it is what a firm is least able to answer. The power to require production attaches to where the data physically is rather than to who collected it.
The power follows the data. So a firm that knows one of the places its data exists can answer question 4 for one of the places its data exists. The answer will sound complete, and it is complete about that one place. The answer stays silent about every other place without announcing that it is silent.
Question 4 cannot be answered by asking it. Question 4 is assembled from the answers to questions 1, 2 and 3, and it is exactly as good as the weakest of the three. This is why a firm that goes looking for its residency position by reading agreements finds an answer quickly and finds the wrong one. The agreement covers the places the agreement covers.
Why can a firm not answer directly who is able to compel its data?
Where did one selfie image actually exist, for one application?
Now take the abstraction away and follow one object. One applicant at Sumeru Bank starts a personal loan application on a handset and takes a selfie. Component 2 checks that the image belongs to a live human being in front of the camera rather than a photograph of a photograph. Follow that single image and count the places it existed.
Place 1 is the handset it was taken on. Place 2 is the bank's own store. Place 3 is the vendor-hosted service that ran the liveness check. The image had to be sent there for the check to happen. Place 4 is the vendor's own record of the check, kept so that if the bank ever disputes the result the vendor can show what it was given and what it returned. One image, one application, four places, and the arithmetic of the situation was fixed on the day the arrangement was designed rather than on the day anybody thought to ask.
One selfie image, one applicant, one bank, one vendor. How many places does the image exist in?
Why does the count of places grow with the parties rather than with the data?
Here is the part that surprises people who think of this as a storage problem. The image did not get bigger as it travelled. One image stood at place 1 and the same one image at place 4. The number of parties grew instead, and each party that touched the image added at least one place, with one of them adding two to keep a record of its own work.
Run the counterfactual to feel it. If the bank had taken the photograph itself, on its own equipment, in a branch, and checked it with a component it had built, the image would have existed in one place. Add the applicant's handset and it is two. Add a vendor to run the check and it is three. Let that vendor keep the dispute record it needs in order to defend what it did and it is four. A small arrangement with three parties therefore has more places than a very large one with one party, and no amount of data ever changes that.
Which of the four places did the bank have a written answer for?
A written answerA recorded statement of where something is, who gave that statement and when, as distinct from a belief about it held by somebody experienced. is a recorded statement of where a thing is, with a date and a name against it. A written answer is not the same as somebody senior being fairly sure. The distinction sounds pedantic until the day the question is put in a room. A belief cannot be shown to anybody, and on that day the distinction is the only one that matters.
At Sumeru Bank the count was one out of four, being 25.0 per cent. Place 2, the bank's own store, had a written answer. Places 1, 3 and 4 did not, so three of the four places one image existed in were outside anything the bank had recorded, being 75.0 per cent. The reason is not carelessness and it is worth being precise about. When the arrangement behind component 2 was assessed, the assessment asked what data leaves the buyer, where it lands and what happens to it there. The assessment got as far as what data leaves, and no further.
Half an answer to the one question that touched the data is what produced three unrecorded places, and the half that was missing was the half about the other party's machines rather than the bank's own. The bank asked properly in month 11 and had an answer in six weeks. During those six weeks the chain kept running, and there was no reason to stop it. Component 2 sees every application. At the bank's own rate of 500 applications a working day across the roughly thirty working days of a six week wait, that is about 15,000 more images making the same journey, an arithmetic consequence of the locked rate rather than a separate measurement.
A firm can describe its own store in precise detail. What does that establish about the other places?
How far does the question reach across everything the bank runs?
A bank does not run one arrangement. One image in one application is the right place to learn the mechanism and the wrong place to stop. When Sumeru Bank swept for uses of this kind of technology in month 10 it found fourteen in use. Four of those fourteen were bought from somebody else rather than built inside the bank, being 28.6 per cent, and three of those four sat outside the register entirely.
Now add the awkward one. The register records built or bought for each use case as a whole. Eight of the intake chain's nine components were built by the bank, so the register records the whole chain as built. The ninth, component 2, runs inside somebody else's service. So the count of places where the residency questions cross a boundary the bank does not control is five of the fourteen, being 35.7 per cent, and one of those five is invisible in the field that was supposed to record exactly that. This is arithmetic on the bank's own counts rather than a new measurement, and it is the reason a residency review that reads the register alone finds four and misses one.
A register records bought or built for each use as a whole. Why can that field understate where residency questions arise?
What does a retention schedule cover, and what does it usually miss?
A retention scheduleThe written statement of what a firm keeps and for how long, usually organised by the kind of record rather than by the place it is stored. is the written statement of what is kept and for how long. The schedule answers the second half of residency question 3, the how long they stay part, and it is the artefact most firms point at when asked. Have a look at what it actually covered here.
Sumeru Bank's schedule covered 12 of the 14 fields the reading step pulls off each application, being 85.7 per cent. The coverage figure looks decent, and it is the figure that would get quoted. Of the two stores holding images the schedule covered nothing at all: neither the store holding the document images, arriving at four per file and 34,400 a month, nor the store holding the selfie image from every one of the 10,000 monthly applications. Counted as items that hold data, the schedule reaches 12 of 16, being 75.0 per cent, arithmetic on the bank's own counts rather than a second measurement.
Schedules miss image stores for a structural reason rather than a careless one: a schedule is written field by field because fields are what a data record lists, and the documents and images the fields were read from are not fields. Think of the drawer at home where the household paperwork accumulates. Somebody decided what to do with the electricity bills. The box of photographs on top of the cupboard was never on the list of things a decision was being made about, and nobody ever decided anything about it.
A retention schedule covers 12 of 14 fields. What is most likely to be missing?
How does a firm find out where its own data is?
Agreements are written down and searching them feels like work, so the instinct is to start there. The instinct produces a fast wrong answer every time. An agreement can only describe the places it covers, and the places that break a residency position are the places no agreement mentions. Counting has to come before reading, and the count has to include the places the firm does not control.
Five numbered steps, and the order is the whole of the method. Step 1, list every place the data exists, including the ones nobody at the firm operates: the device it was captured on, every party it is sent to, and every party those parties send it to. Step 2, name the holder of each place, as an organisation rather than as a system. Step 3, put the same four questions to every holder, in the same words, and never accept an answer to question 1 as an answer to the set. Step 4, record each answer as an answer, with the date it was given and the name of who gave it. Step 5, write down what remains unknown, as a named gap with somebody accountable for closing it. A gap that is written down behaves completely differently from a gap that is merely unmentioned.
Where does a firm start when finding out where its data is?
The error that gets made, and what it costs
The wrong reading is that residency is a question about a country, answered once, in an agreement. Residency is a question about places, and the count of places is what a firm gets wrong. Sumeru Bank could describe its own store precisely and had never counted the handset, the vendor's service or the vendor's record of the check, so three of the four places one image existed in sat outside everything it had written down.
Nothing had gone wrong and no customer was harmed. The bank could not answer question 4 at all on the day somebody asked. Who can require this to be produced depends entirely on where it is, and the bank knew where one of four instances of that image was. Six weeks later it knew about two more.
The cost was six weeks of being unable to answer a question about its own customer's photograph, during which about 15,000 more images made the same journey, and the fix was a question the bank could have put before signing rather than in month 11.
Where does the answer to any of this come from, and where does it not?
Everything above is mechanism. Mechanism is teachable, it does not change when a circular is issued, and it is the same in every jurisdiction: data has places, places have holders, holders have obligations, and the power to require production attaches to the place. Not one sentence of it settles what is permitted.
Permission is a different kind of statement entirely, and it comes from one kind of source. For a regulated lender in India, the Reserve Bank of India states the position on where financial and customer data may sit, how it may be processed, what may be copied and what must be produced, and publishes that position at rbi.org.in. Where the deployer is a market intermediary rather than a lender, the equivalent position is stated by the Securities and Exchange Board of India at sebi.gov.in. Both bodies state the position, and the position is current only at their own sites. A summary made anywhere else is only as current as the day it was written.
International material on the same subject exists. The Bank for International Settlements publishes at bis.org on how supervisors internationally think about data held outside a firm and outside its jurisdiction, and that material gives the shape of the argument. The international discussion describes a range of approaches. The position that applies to an Indian regulated lender is stated by an Indian authority, at that authority's own site.
Who states the position?
For an entity it regulates, the Reserve Bank of India states every requirement about where financial or customer data may sit, where it may be processed, what copies may exist, how long they may be kept and who may require them to be produced, and publishes that position at rbi.org.in. Where the deployer of such an arrangement is a market intermediary, the equivalent position is stated by the Securities and Exchange Board of India at sebi.gov.in. Material on how supervisors internationally frame the subject is published by the Bank for International Settlements at bis.org.
The current position on requirements, thresholds, permitted and prohibited places, categories of data, retention periods and effective dates is stated at the issuing body's own site, and a copy held anywhere else is only as current as the day it was made.
Where does the actual rule on any of this come from?
How does a controller, an auditor or a household actually use this?
The same four questions are used differently by a controller, an auditor and a household. Take the three in turn. A controller inside a firm uses them as a counting instrument rather than a policy. Once a quarter, for one arrangement, she lists the places, names the holders, and marks each place as answered or unanswered with a date. The output is not a position; the output is a count, and a count that moves in the wrong direction is the earliest signal available that an arrangement has changed underneath.
An auditor or a reviewer from outside uses them as a probe. The useful move is not to ask whether the firm complies. The answer to that is always yes, and it is always sincere. The useful move is to pick one object, one selfie image say, and follow it. Ask how many places this single object exists in, and then ask to see the written answer for each place. The shape of the failure is never a wrong answer and is almost always a missing one.
And a household uses the same instinct without the vocabulary. When somebody hands over a photocopy of an identity document, the useful question is not whether the shop is trustworthy. The useful question is how many copies now exist, who has each one, and whether anybody ever decided when they get destroyed. The last question usually turns out to have no answer, the same finding Sumeru Bank made about its image stores, reached from a drawer instead of a data store.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | Published position for a regulated lender on where financial and customer data may sit, how it may be processed, what may be retained and what may be required to be produced | rbi.org.in |
| Securities and Exchange Board of India | The equivalent published position where the deployer of such an arrangement is a market intermediary rather than a lender | sebi.gov.in |
| Ministry of Corporate Affairs | Material on what a board is accountable for where an arrangement affects customers | mca.gov.in |
| Bank for International Settlements | Material on how supervisors internationally frame data held outside a firm and outside its jurisdiction | bis.org |
Sumeru Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
