Special provisions

Cross-border data transfer under the DPDP Act (section 16)

Audience: founders, engineering and infrastructure leads, vendor managers · Last reviewed: October 2026

Most Indian businesses already send personal data abroad: cloud hosting, email tools, analytics, support desks and payment partners often run outside India. This guide explains what the DPDP Act, 2023 and the DPDP Rules, 2025 actually say about cross-border transfers, what they do not say, and what to put in place now.

The DPDP Act does not ban transfers abroad and does not set up an adequacy or standard-contract system. Instead, it gives the Central Government a power to restrict transfers by notification, and leaves stricter sector laws in place.

What the law says

Section 16: the restriction power

Section 16(1) says the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India that it notifies. Any such notification must be laid before Parliament (section 41). The Act itself does not list any restricted country, so the starting point is that transfers are allowed unless a notification restricts them. Check the official resources and the Gazette for any notification before relying on this.

Section 16(2) adds that nothing in section 16 limits any other Indian law that gives a higher degree of protection for, or a restriction on, transfers of personal data outside India. If your sector regulator or another law already restricts where certain data can go, that restriction continues to bind you.

Rule 15: requirements about foreign States

Rule 15 states that personal data processed under the Act may be transferred outside India, subject to the Data Fiduciary meeting any requirements the Central Government specifies, by general or special order, about making that data available to a foreign State, or to a person or entity under the control of, or an agency of, such a State. The Rules do not themselves set out those requirements; they would come through a separate order.

Rule 13(4): localisation for Significant Data Fiduciaries

A Significant Data Fiduciary must take measures so that personal data specified by the Central Government, on the recommendation of a committee it constitutes, is processed subject to the restriction that the data and the traffic data about its flow are not transferred outside India (Rule 13(4) and 13(5)). This only applies to entities notified as Significant Data Fiduciaries under section 10, and only to the data specified. See Significant Data Fiduciary explained.

When the transfer rules apply

  • Commencement. Section 16 and Rule 15 are in the eighteen-month phase, i.e. eighteen months from 13 November 2025 (section 1(2) commencement note; Rule 1(4)).
  • Foreign processing of Indian users' data. The Act applies to processing outside India if it is connected with offering goods or services to Data Principals in India (section 3(b)). A foreign company serving Indian customers is inside scope.
  • Exemptions. Section 16 does not apply in the situations listed in section 17(1), such as processing necessary to enforce a legal right or claim (section 17(1)(a)), or processing in India of personal data of people outside India under a contract with a person outside India (section 17(1)(d)), which is relevant to outsourcing and back-office work for foreign clients. Sections 8(1) and 8(5) still apply in those cases.

Your responsibility does not travel with the data

Section 8(1) makes the Data Fiduciary responsible for complying with the Act for processing done by it or on its behalf by a Data Processor, irrespective of any contract to the contrary. A foreign vendor is still your Data Processor, so you remain answerable for its security and deletion behaviour.

  • You may engage a Data Processor only under a valid contract (section 8(2)).
  • That contract should include reasonable security safeguards (Rule 6(1)(f)).
  • You must protect data processed on your behalf by a Data Processor (section 8(5)).
  • On withdrawal of consent you must cause your Data Processors to stop processing (section 6(6)), and on erasure you must cause them to erase (section 8(7)(b)).
  • A Data Principal can ask for the identities of all Data Fiduciaries and Data Processors you shared her data with (section 11(1)(b)), so you need an accurate list, including foreign vendors.

Read: vendor and processor checklist

Practical cross-border checklist

  1. Map transfers. For each system, record what personal data it holds, where it is stored, and from where it is accessed (including support staff abroad). Our data mapping guide shows how.
  2. Check sector rules. Ask whether any other law that applies to you restricts transfers of some data (section 16(2)). If it does, that rule is the binding one.
  3. Review contracts. Make sure every foreign processor contract covers security safeguards, deletion and stopping processing on instruction (sections 8(2), 8(5), 8(7)(b); Rule 6(1)(f)).
  4. Plan for a notification. Know which vendors you would need to move, and how quickly, if a country you rely on were notified under section 16(1).
  5. Track government-access requirements. Watch for any order under Rule 15 about making data available to foreign States, and ask key vendors how they handle such requests.
  6. If you could be an SDF, design for keeping specified data and traffic data in India (Rule 13(4)).
  7. Publish an honest subprocessor list. It helps with access requests under section 11(1)(b); see how to write a subprocessor list page.

What happens if you get it wrong

The Schedule to the Act does not have a separate line for section 16. A breach of a provision not listed elsewhere falls under item 7, with a penalty that may extend to fifty crore rupees. If a transfer goes wrong because of weak security, item 1 (reasonable security safeguards under section 8(5)) may extend to two hundred and fifty crore rupees. The Board imposes penalties only after an inquiry and a hearing, considering the factors in section 33(2). See DPDP penalties explained.

How this differs from GDPR

Teams used to the EU GDPR expect adequacy decisions and standard contractual clauses. The DPDP Act has neither. Its model is a government power to restrict transfers to notified places, combined with stricter sector rules and SDF localisation. Read more in DPDP vs GDPR.

Frequently asked questions

Is cross-border data transfer allowed under the DPDP Act?

Yes, unless restricted. Section 16(1) lets the Central Government restrict transfers to countries or territories it notifies, and Rule 15 permits transfers subject to any requirements it specifies about making data available to foreign States. The Act itself does not list any restricted country.

Does the DPDP Act require data localisation?

Not as a general rule. Rule 13(4) requires Significant Data Fiduciaries to keep personal data specified by the Central Government, and the traffic data about its flow, within India. Other sector laws with stricter transfer rules also continue to apply under section 16(2).

Does the DPDP Act have standard contractual clauses like GDPR?

No. The Act and Rules do not prescribe standard contractual clauses or adequacy decisions. You still need a valid contract with each Data Processor (section 8(2)) that provides for reasonable security safeguards (Rule 6(1)(f)).

When do the cross-border provisions apply?

Section 16 and Rule 15 come into force eighteen months after 13 November 2025, under the commencement notification noted at section 1(2) and Rule 1(4).

Does section 16 apply to Indian companies processing foreign customers' data?

Section 17(1)(d) disapplies section 16, along with most of Chapters II and III, where a person based in India processes personal data of people outside India under a contract with a person outside India. Sections 8(1) and 8(5) on responsibility and security still apply.

Practical next step

Build a one-page transfer register: every system and vendor, where it stores or accesses data, and the contract that covers it. Then check what your public site sends to third parties.

Advertisement