Back to Cross-Border Data Transfer

Negative List Approach

How the DPDPA's negative list approach to cross-border transfers works - allowing data flows by default and restricting specific jurisdictions.

6 min read

The Negative List Concept

The DPDPA's negative list approach means that cross-border data transfers are permitted to all jurisdictions by default. Only jurisdictions that the Central Government explicitly restricts through notification become prohibited destinations. This is the inverse of the GDPR's approach, where transfers are restricted by default and only permitted to 'adequate' jurisdictions or with specific safeguards.

Policy Rationale

The negative list approach reflects India's position as a major data processing and IT services hub. Requiring pre-approval for every cross-border transfer would impose significant operational burdens on the IT/BPO sector, which processes data for clients worldwide. The approach also acknowledges practical realities - modern cloud computing and SaaS platforms involve data processing across multiple jurisdictions, often without the data controller having full visibility into server locations.

Government's Power to Restrict

The Central Government retains the power under section 16(1) to restrict transfers to a country or territory it notifies. The Rules specify no criteria for that decision, and no committee recommends jurisdictions for restriction. Section 16(1) restricts transfer of personal data by a Data Fiduciary. Rule 15 binds the Data Fiduciary and does not extend transfer restrictions to Data Processors or Consent Managers, and no other rule does. In practice a Data Fiduciary cannot avoid a restriction by routing a transfer through a processor: under section 8(1) it remains responsible for processing carried out on its behalf, so contractual flow-down is a practical necessity.

Current Status and Timeline

As of the current date, no jurisdictions have been restricted. Section 16(1) gives the Central Government the power to notify restricted countries; the Rules specify no criteria for that decision, and there is no committee that recommends jurisdictions. Rule 15 is a separate requirement about making data available to a foreign State and comes into force eighteen months after publication of the Rules. Until restrictions are notified, organisations can transfer personal data to any jurisdiction, subject to compliance with all other DPDPA provisions and any applicable sectoral requirements.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.