Back to Key Provisions

Cross-Border Data Transfer

Analysis of the DPDPA's approach to cross-border personal data transfers - the negative list mechanism, comparison with GDPR, and practical implications.

8 min read

The DPDPA's Approach to Cross-Border Transfers

Section 16 of the DPDPA adopts a "negative list" approach to cross-border data transfers - personal data may be transferred to any country or territory that has not been specifically restricted by the Central Government through notification. This is fundamentally different from the GDPR's "positive list" (adequacy) approach, where transfers are restricted by default and permitted only to countries deemed adequate or through specific transfer mechanisms. The DPDPA presumes permissibility and restricts only where necessary.

The Negative List Mechanism

Under Section 16(1), the Central Government may, by notification, restrict the transfer of personal data to specific countries or territories. Until such notifications are issued, transfers are permitted to all jurisdictions. As of the current date, no countries have been placed on the restricted list. This means cross-border transfers are currently unrestricted under the DPDPA, though this could change as the Government exercises its notification powers. Rule 15 of the DPDP Rules does not establish a committee or a list; it is a separate requirement about making personal data available to a foreign State. The decision to restrict a country rests with the Central Government under section 16(1).

Rule 15: A Separate Requirement, Not a Committee

Rule 15 of the DPDP Rules 2025 does not create a committee, a list, or a set of evaluation criteria. It adds a separate requirement: a Data Fiduciary transferring personal data outside India must meet such requirements as the Central Government may specify, by general or special order, in respect of making that data available to a foreign State, or to an entity under its control or acting as its agency. Rule 15 sets out no requirements itself and creates no evaluating body, and it comes into force eighteen months after publication of the Rules. The power to restrict transfers to a particular country sits in section 16(1) of the Act, which lets the Central Government, by notification, restrict transfer to a country or territory it notifies. The Rules specify no criteria for that decision, and no committee recommends jurisdictions for restriction.

Practical Implications for Organisations

The current permissive regime means organisations can continue cross-border data flows without specific transfer mechanisms. However, prudent compliance requires: 1. Monitoring government notifications for any new restrictions 2. Maintaining contractual safeguards with overseas processors 3. Ensuring the Data Fiduciary's obligations (security, breach notification, erasure) extend to overseas processing 4. Documenting cross-border transfer decisions as part of accountability Organisations should not assume the current permissive regime will continue indefinitely. Building in contractual protections now provides resilience against future restrictions.

Comparison with GDPR Transfer Mechanisms

The GDPR provides multiple transfer mechanisms: • Adequacy decisions (Article 45) • Standard Contractual Clauses (Article 46(2)(c)) • Binding Corporate Rules (Article 47) • Derogations for specific situations (Article 49) The DPDPA's approach is simpler but less granular. While the DPDPA does not mandate SCCs, BCRs, or formal adequacy assessments, section 8(1) of the Act makes the Data Fiduciary responsible for compliance even where processing is carried out by a Data Processor (including one abroad), and section 8(2) requires that such engagement take place only under a valid contract. The Act does not impose an equivalent-protection standard on the overseas processor. In addition, Section 16(2) of the Act preserves any other Indian law imposing stricter transfer restrictions, so sectoral rules (e.g., RBI/SEBI localisation) apply on their own terms and are not overridden by the DPDPA. For organisations subject to both GDPR and DPDPA, maintaining GDPR-compliant transfer mechanisms will satisfy the more relaxed DPDPA requirements.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.