Back to Cross-Border Data Transfer
Transfer Mechanism Under DPDPA
Understanding Section 16's permissive approach to cross-border data transfers - the negative list mechanism, Rule 15 (consolidated under the November 2025 Rules), and its implications.
7 min read
Section 16 Framework
Section 16 of the DPDPA permits the transfer of personal data to any country or territory outside India, except those restricted by the Central Government through notification. This 'negative list' approach allows data flows by default unless specifically prohibited. The final notified Rules (November 2025) consolidate the cross-border transfer framework under Rule 15.
This is fundamentally different from the adequacy-based frameworks used by the EU and other jurisdictions. The DPDPA does not require Data Fiduciaries to conduct transfer impact assessments, implement Standard Contractual Clauses, or obtain specific authorisation before transferring data abroad. However, Section 8(1) makes the Data Fiduciary liable for any Data Processor abroad, so contractual safeguards (effectively 'Indian SCCs') are needed to ensure overseas processors adhere to DPDPA standards.
The Permissive Approach
The DPDPA's approach provides operational flexibility to organisations - particularly in the IT/BPO and SaaS sectors where cross-border data flows are integral to business operations. Until the Central Government notifies restricted jurisdictions, transfers to all countries remain permissible. Rule 15 sets out the criteria the Government must use to restrict a country (reciprocity, security, and other factors), and the 18-month transition period for these provisions ends in May 2027.
This approach was a deliberate policy choice, moving away from the data localisation provisions that featured in earlier iterations of the Bill (the 2019 Bill required storage of a 'serving copy' in India and prohibited transfer of 'critical personal data').
Continuing Obligations
While cross-border transfer itself does not require additional safeguards, all other provisions of the DPDPA continue to apply regardless of where data is processed. This includes consent requirements, security safeguards (R.6), breach notification (R.7), data retention limits (R.8), and children's data protections (R.9-12).
The Data Fiduciary remains liable for processing carried out by its Data Processors abroad. Contractual arrangements with overseas processors should address compliance with the DPDPA's requirements.
Sectoral Data Localisation Requirements
While the DPDPA itself is permissive, sectoral regulators may impose separate data localisation requirements. The RBI's 2018 directive requires payment system data to be stored exclusively in India. SEBI and IRDAI have their own requirements for financial and insurance data.
Organisations must navigate both the DPDPA framework and applicable sectoral requirements, applying the stricter standard where they overlap.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
