Back to Cross-Border Data Transfer
Negative List Approach
How the DPDPA's negative list approach to cross-border transfers works - allowing data flows by default and restricting specific jurisdictions.
6 min read
The Negative List Concept
The DPDPA's negative list approach means that cross-border data transfers are permitted to all jurisdictions by default. Only jurisdictions that the Central Government explicitly restricts through notification become prohibited destinations.
This is the inverse of the GDPR's approach, where transfers are restricted by default and only permitted to 'adequate' jurisdictions or with specific safeguards.
Policy Rationale
The negative list approach reflects India's position as a major data processing and IT services hub. Requiring pre-approval for every cross-border transfer would impose significant operational burdens on the IT/BPO sector, which processes data for clients worldwide.
The approach also acknowledges practical realities - modern cloud computing and SaaS platforms involve data processing across multiple jurisdictions, often without the data controller having full visibility into server locations.
Government's Power to Restrict
The Central Government retains the power to restrict transfers to specific jurisdictions based on factors including: the legal framework of the recipient country, international agreements, security of data, and the nature and sensitivity of data.
The restriction power extends to Data Fiduciaries, Consent Managers, and Data Processors - meaning that even processors handling data on behalf of Indian entities must comply with any notified restrictions.
Current Status and Timeline
As of the current date, no jurisdictions have been restricted. Under the final notified Rules (November 2025), Rule 15 provides the criteria the Central Government must use to notify a restriction, while a separate 'committee' recommendation process applies specifically to Significant Data Fiduciaries. The general restriction power rests with the Central Government, and Rule 15 comes into force approximately 18 months after the notification of the Rules (~May 14, 2027).
Until restrictions are notified, organisations can transfer personal data to any jurisdiction, subject to compliance with all other DPDPA provisions and any applicable sectoral requirements.
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
