Back to Cross-Border Data Transfer
GDPR Comparison - Cross-Border Transfers
A detailed comparison of the DPDPA's negative list approach with the GDPR's adequacy framework for cross-border data transfers.
7 min read
Fundamental Architectural Difference
The GDPR and DPDPA take opposite default positions on cross-border transfers. The GDPR restricts transfers by default and permits them to 'adequate' jurisdictions or with specific safeguards. The DPDPA permits transfers by default and restricts them only to notified jurisdictions.
This means that under the GDPR, an organisation must actively establish a legal basis for each transfer. Under the DPDPA, transfers flow freely unless and until a jurisdiction is restricted - although Section 16(2) clarifies that the DPDPA does not override stricter sectoral laws (e.g., RBI payment data localisation), so transfers do not truly 'flow freely' for all industries. See the consent framework for how consent requirements differ between the two laws.
Adequacy Decisions vs Negative List
The European Commission evaluates foreign jurisdictions and grants 'adequacy' decisions recognising equivalent data protection. Currently, about 15 jurisdictions have adequacy status. All other transfers require additional safeguards.
India's approach requires the Government to identify only problematic jurisdictions. This is administratively simpler but places less emphasis on ensuring adequate protection in recipient countries. That said, under Section 8(1) of the DPDPA, a Data Fiduciary is still responsible for ensuring that any Data Processor (even one located abroad) complies with the Act. This creates an implicit adequacy requirement via contract, even if the country itself is not blacklisted.
Transfer Safeguards Comparison
The GDPR provides multiple transfer mechanisms: adequacy decisions, SCCs, BCRs, codes of conduct, certification mechanisms, and derogations. Each has specific requirements and documentation obligations.
While the DPDPA does not name SCCs or BCRs, Rule 12 and Rule 15 of the 2025 Rules require Significant Data Fiduciaries to verify contractual safeguards for overseas transfers as part of the annual audit. In addition, the Rule 12 DPIA for SDFs must assess risks arising from processing, which inherently covers cross-border transfer risks. The framework reduces compliance burden compared with the GDPR but is not without safeguard expectations.
Practical Implications for Dual-Compliance
Organisations processing data subject to both the GDPR and DPDPA must comply with both frameworks simultaneously. For transfers from India, the DPDPA's permissive approach means minimal additional steps in most cases - but where a sectoral regulator (like SEBI or RBI) mandates local storage, the negative-list approach does not provide a 'safe harbor' under Section 16(2). For transfers from the EU to India, GDPR requirements (including SCCs or other safeguards) continue to apply.
India does not currently have an EU adequacy decision, meaning that GDPR-compliant transfers from Europe to India require SCCs or other appropriate safeguards regardless of the DPDPA's approach. The penalties for non-compliance differ significantly between the two frameworks.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
