India chairs the 18th BRICS Summit on September 12-13 in New Delhi, and a shared payment system for the bloc is on the agenda. The pitch writes itself: India already runs the world's most-cited instant-payments network, and the host nation is the one showing up with working rails. BRICS leaders spent their 2025 Rio de Janeiro summit tasking finance ministers and central bank governors to keep building a Cross-Border Payments Initiative aimed at payments that are fast, low-cost, accessible, efficient, transparent and safe. ThePrint reports that whatever payment system emerges from this week's talks would be shaped by member countries' data protection regimes, including India's own DPDP Act and RBI's circulars. Read that as a footnote and the story is India arriving at its own summit with the answer already built.
It is worth slowing down on that framing. India is not arriving with a blank-slate proposal. It is arriving with a domestic rulebook that already treats payment data as something to be kept close, and a newer, broader law that gives its government the power to decide, country by country, where personal data may travel at all. Indian regulation gives a payment system exactly one business day, 24 hours, to delete foreign-processed transaction data and bring it home. Any BRICS-wide settlement layer that clears a leg outside India inherits that clock the moment it touches an Indian account.
The rule already bolted to every rupee transaction
This is not a new instinct dusted off for the summit. Since April 2018, the Reserve Bank of India has required every payment system provider to store the entire data relating to the payment systems it operates only in India. The rule does not ban foreign processing outright. It permits it, but on a tight leash: if any part of a transaction is processed abroad, the RBI's own FAQ requires that data to be deleted from the foreign system and brought back to India within one business day or 24 hours of processing, whichever is earlier. Eight years on, that is still the baseline every payment rail touching India has to satisfy, and it predates BRICS's own cross-border payments push by seven years.
A second, broader lever just switched on
A newer instrument sits alongside it, and it reaches further than payments alone. Section 16 of India's Digital Personal Data Protection Act, 2023 lets the central government restrict, by notification, the transfer of personal data by any data fiduciary to a specified country or territory outside India. That is a general-purpose power over where Indian personal data may flow, not a payments-specific rule, and it is still being switched on: the government notified the Digital Personal Data Protection Rules on 14 November 2025, operationalising the Act with an eighteen-month phased compliance window that runs into 2027. As BRICS leaders sit down in New Delhi this week, the machinery behind India's own cross-border data power is roughly ten months into an eighteen-month rollout, not yet fully in force.
Two regimes, one country, converging on the same week.
Neither rule was written with BRICS in mind. Both now sit directly in the path of any settlement layer the summit agrees to build.
| Rule | What it requires | In force since |
|---|---|---|
| RBI payment-system data circular | All data relating to a payment system stored only in India | April 2018 |
| RBI cross-border processing FAQ | Data processed abroad deleted and repatriated within 24 hours | April 2018 |
| DPDP Act, Section 16 | Government may restrict, by notification, transfer of personal data to a named country | August 2023 |
| DPDP Rules, 2025 | Operationalises the Act; eighteen-month phased compliance window | Notified November 2025 |
Source: Reserve Bank of India, RBI FAQs, Digital Personal Data Protection Act, 2023, Press Information Bureau.
Bilateral already works. Multilateral is the harder problem
India is not short of proof that cross-border payments can be made to work under this exact rulebook. UPI is now live for acceptance or remittances in more than eight countries, including the UAE, Singapore, Bhutan, Nepal, Sri Lanka, France, Mauritius and Qatar. Every one of those was negotiated as its own bilateral arrangement, each partner agreeing to whatever data-handling terms let a UPI transaction clear on its soil while satisfying India's storage and repatriation rules on this end. The volume moving through those links is no longer trivial: the value of India's cross-border UPI transactions rose from Rs 19.7 crore in FY24 to Rs 258.53 crore in FY25, and had already reached Rs 169.29 crore in just the first four months of FY26, per data placed before Parliament. That is real, fast-growing traffic clearing India's 24-hour repatriation clock bilaterally, not a rule tested on a rounding error. A BRICS-wide rail is a different kind of problem: one standard, agreed once, that has to satisfy India's localisation regime and four or more other countries' rules simultaneously, rather than one bespoke deal at a time. What scales bilaterally does not automatically scale multilaterally, and the summit's own framing, per ThePrint, is that the shared system "would be shaped by" India's data regime, not exempted from it.
Who actually needs this coalition
There is also a size question underneath the payments question. India's economy accounts for about 8.2 percent of world GDP on a purchasing power parity basis in 2025, up from 7.9 percent in 2024. China alone accounts for about 19.6 percent, more than double India's share. The gap widens once the rest of the founding coalition is added in. Russia accounts for about 3.4 percent of world GDP on the same basis, Brazil about 2.4 percent, and South Africa about 0.5 percent, a combined 6.3 percent that, stacked alongside China's 19.6 percent, puts roughly a quarter of world GDP in the rest of the founding coalition against India's 8.2 percent alone. India is chairing the summit and setting the agenda, but it is not the coalition's economic center of gravity, which cuts against reading India's caution as a small country protecting itself. It is the country with by far the strictest data instincts in the room using its chair to insist those instincts get respected, even though the room's largest economy sits elsewhere, and the rest of the room combined outweighs it by three to one.

The honest objection
The strongest case against reading any of this as friction is that payment-system data and general personal data are policed by two different regimes for a reason. RBI already occupies the payment-systems field under its own long-standing mandate, and Section 16 is a general tool the government need never point at a BRICS settlement rail specifically. On that reading, whatever the two ministries agree to build could simply be engineered to satisfy the RBI's localisation and repatriation rule alone, leaving the DPDP transfer power an unused background threat that never has to fire, and the summit's payments initiative proceeds without the two laws ever actually colliding.
That case holds only if the settlement layer never needs a foreign processing leg at all, which is precisely the design constraint a shared multi-country rail exists to remove. The moment a transaction clears through a partner country before reaching an Indian account, RBI's repatriation clock starts, and the DPDP Act's transfer-restriction power exists as a standing feature of Indian law, not a switch that has to be flipped before it shapes how counterparties negotiate. Engineers can route around one rule. They cannot design around the fact that both rules exist and both answer to the same government hosting the talks.
The Signal
The consensus read treats this week's summit as India cashing in on its payments credibility. The more useful read is that India is testing, in public, whether its own data instincts are compatible with the thing it is asking the rest of BRICS to build. Watch what the summit actually produces: a framework that lets processing happen anywhere and simply repatriates data on India's 24-hour clock would prove the two regimes can coexist. If it instead quietly routes every leg through India-based infrastructure to avoid the question entirely, that would prove they cannot, and that India's data law, not its diplomacy, set the design. A payment system this careful over where a byte may rest is not being built by a country in a hurry.
Reporting basis: the framing that a BRICS payment system would be shaped by India's DPDP Act and RBI circulars is per ThePrint's reporting, the only outlet in this account of the summit's agenda. India's 2018 data-localisation requirement and its one-business-day repatriation rule for foreign-processed payment data are both from the Reserve Bank of India, via its original circular and its own published FAQ on that circular. The Digital Personal Data Protection Act's Section 16 transfer-restriction power is from the Act's Gazette text as published by the Ministry of Electronics and Information Technology, and the eighteen-month phased compliance window is from the Ministry's notification of the DPDP Rules, 2025, as reported by the Press Information Bureau. The BRICS Cross-Border Payments Initiative language is from the Rio de Janeiro Declaration, as reproduced by the Press Information Bureau. UPI's live cross-border markets are per a Press Information Bureau release, and the value of those cross-border UPI transactions is per Business Standard's reporting of figures placed before Parliament in a Lok Sabha reply. India's, China's, Russia's, Brazil's and South Africa's shares of world GDP at purchasing power parity are from the IMF's World Economic Outlook database, for India, China, Russia, Brazil and South Africa. The comparisons and combined totals between those countries' shares are The Signal's calculation from those figures.



