Section 16 of the DPDPA permits the transfer of personal data to any country or territory outside India, except those restricted by the Central Government through notification. This 'negative list' approach allows data flows by default unless specifically prohibited. The negative-list power sits in section 16(1); Rule 15 of the DPDP Rules 2025 adds a separate requirement about making personal data available to a foreign State, and does not itself create or administer the restricted list.
This is fundamentally different from the adequacy-based frameworks used by the EU and other jurisdictions. The DPDPA does not require Data Fiduciaries to conduct transfer impact assessments, implement Standard Contractual Clauses, or obtain specific authorisation before transferring data abroad. However, Section 8(1) makes the Data Fiduciary liable for any Data Processor abroad, so contractual safeguards (effectively 'Indian SCCs') are needed to ensure overseas processors adhere to DPDPA standards.