Back to Cross-Border Data Transfer

Transfer Mechanism Under DPDPA

Understanding Section 16's permissive approach to cross-border data transfers: the negative list under section 16(1), the separate Rule 15 requirement, and its implications.

7 min read

Section 16 Framework

Section 16 of the DPDPA permits the transfer of personal data to any country or territory outside India, except those restricted by the Central Government through notification. This 'negative list' approach allows data flows by default unless specifically prohibited. The negative-list power sits in section 16(1); Rule 15 of the DPDP Rules 2025 adds a separate requirement about making personal data available to a foreign State, and does not itself create or administer the restricted list. This is fundamentally different from the adequacy-based frameworks used by the EU and other jurisdictions. The DPDPA does not require Data Fiduciaries to conduct transfer impact assessments, implement Standard Contractual Clauses, or obtain specific authorisation before transferring data abroad. However, Section 8(1) makes the Data Fiduciary liable for any Data Processor abroad, so contractual safeguards (effectively 'Indian SCCs') are needed to ensure overseas processors adhere to DPDPA standards.

The Permissive Approach

The DPDPA's approach provides operational flexibility to organisations, particularly in the IT/BPO and SaaS sectors where cross-border data flows are integral to business operations. Until the Central Government notifies restricted jurisdictions, transfers to all countries remain permissible. Section 16(1) empowers the Central Government to notify restricted countries, and the Rules set out no criteria for that decision. The eighteen-month transition period for Rule 15 runs from publication of the Rules. This approach was a deliberate policy choice, moving away from the data localisation provisions that featured in earlier iterations of the Bill (the 2019 Bill required storage of a 'serving copy' in India and prohibited transfer of 'critical personal data').

Continuing Obligations

While cross-border transfer itself does not require additional safeguards, all other provisions of the DPDPA continue to apply regardless of where data is processed. This includes consent requirements, security safeguards (R.6), breach notification (R.7), data retention limits (R.8), and children's data protections (R.10-12). The Data Fiduciary remains liable for processing carried out by its Data Processors abroad. Contractual arrangements with overseas processors should address compliance with the DPDPA's requirements.

Sectoral Data Localisation Requirements

While the DPDPA itself is permissive, sectoral regulators may impose separate data localisation requirements. The RBI's 2018 directive requires payment system data to be stored exclusively in India. SEBI and IRDAI have their own requirements for financial and insurance data. Organisations must navigate both the DPDPA framework and applicable sectoral requirements, applying the stricter standard where they overlap.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.