Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

1–10 of 180 posts

Re: India bans MasterCard from adding new customers

#5
So, the reason is that the entirety of the customer data must be stored locally in India, rather than on a server located elsewhere[0]? Does anyone know why the rule in India is so much stricter than the equivalent GDPR rule[1], which allows transfer of data outside the EU in various circumstances (basically if it's assured that it won't lead to the data being subject to much laxer standards of protection)?

According to the article, the banks are saying the reason it's much stricter than the equivalent EU data residency requirements is to ensure the Indian government can spy on customer data. Is there a more reasonable, less malicious reason they may have written the requirements this way?

[0] https://rbi.org.in/CommonPerson/english/Scripts/FAQs.aspx?Id...

[1] https://gdpr.eu/article-44-transfer-of-personal-data/

Re: India bans MasterCard from adding new customers

#6
post #4

I can't make out if these rules are specific to India. Doesn't the EU have the same data residency rules as well? Why are Mastercard and Amex struggling with this?

The Indian rule seems to require all data be stored strictly inside India, without any of it being stored outside the country. The EU permits data to be transferred outside the EU under a number of circumstances: e.g. if the other country has equivalent data protection laws, if the non-EU company you're transferring the data to has promised to abide by the EU rules, stuff like that. Take this with a grain of salt, of course, because I'm not a lawyer, but that's how I understand it.

Re: India bans MasterCard from adding new customers

#8
post #3

Is this hard to implement for MasterCard? Otherwise, it seems reasonable to me, but I'm not that knowledgeable in this area.

Yes, it is. You either need to entirely fork your operation to have it operate entirely within India, or be extremely careful with how you store your data, and store the data only in India, but process it in other data centers without ever having it touched disk. Which I believed means you can never even log the data.

Re: India bans MasterCard from adding new customers

#9
post #2

FYI, American Express and Diners Club have already been banned from adding new customers in India due to the same thing. https://www.reuters.com/article/india-banking-american-expre...

> the subscriptions are now required to be paid monthly by people

I have a bunch of subscriptions (App Store, JetBrains, AWS etc.,) which continue to seamlessly go through without me having to explicitly authorise each month.

I suspect there is a fine print/subtext to that subscriptions rule that isn't accessible to public.

Re: India bans MasterCard from adding new customers

#10
post #5

So, the reason is that the entirety of the customer data must be stored locally in India, rather than on a server located elsewhere[0]? Does anyone know why the rule in India is so much stricter than the equivalent GDPR rule[1], which allows transfer of data outside the EU in various circumstances (basically if it's assured that it won't lead to the data being subject to much laxer standards of protection)? According…

If I was running a large country, I'd want transactions to be entirely local for national security reasons. Generally, in the event of a world war, I wouldn't want it to be trivial for other countries to remotely cut off my whole economy.
Post reply on HN