Home / Act 2023 / Sec. 16
Sec. 16 · Chapter IV · DPDP Act 2023

Cross-border transfer

India picked the opposite lever from the GDPR. Under Section 16, cross-border transfer of personal data is permitted by default. The Central Government may restrict specific countries by notification. As of September 2026, no country has been restricted.

Verified 8 Sep 2026 DPDP Act 2023, Sec. 16 + Rule 15 6 min read No restricted countries yet

01What Section 16 says

Section 16(1) says the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India. Section 16(2) preserves any higher standard already imposed by another Indian law.

Read plainly: transfers are permitted unless specifically restricted. This is what commentary calls the "negative-list" or "blacklist" model. It is the inverse of the GDPR model, which prohibits transfers unless an adequacy decision or a Standard Contractual Clause covers the transfer (the "whitelist" or adequacy model).

Digital Personal Data Protection Act, 2023, Section 16. Gazette of India, 11 August 2023.

02Rule 15 mechanics

Rule 15 of the DPDP Rules 2025 restates the default: personal data processed by a Data Fiduciary may be transferred outside India unless restricted.

The Rule adds one operational point. Where a country has been notified as restricted, the Data Fiduciary must ensure it does not transfer personal data to that country. The Rule does not prescribe technical mechanisms (Standard Contractual Clauses, Binding Corporate Rules), because none are required under a negative-list model. Rule 15 takes effect on 14 May 2027 along with the other substantive Rules.

Rule 15 DPDP Rules 2025 (effective 14 May 2027).

03The SDF-specific override (Rule 12(4))

Rule 12(4) creates a second lever, targeted at Significant Data Fiduciaries only.

Under Rule 12(4), the Central Government may notify specific categories of personal data that Significant Data Fiduciaries process, and require those categories to remain in India. This is a targeted localisation obligation that runs parallel to Section 16 and applies to SDFs alone.

No such data category has been notified as of September 2026. Financial identifiers, health identifiers, biometric identifiers, and payment authentication data are the categories most often flagged in industry consultation. If your organisation is likely to be designated an SDF, plan for the possibility that at least one high-sensitivity category will need to remain in India.

Rule 12(4) DPDP Rules 2025 (effective 14 May 2027). Read with Sec. 10 SDF.

04The sectoral overlays that still apply

Section 16(2) preserves any higher standard imposed by another Indian law. This means sectoral rules on data localisation continue to bind you on top of DPDP. In practice, these are the four you must not overlook.

RBI

Payment system data

RBI directive dated 6 April 2018 requires payment system data to be stored only in India. Copies abroad are permitted for foreign-leg processing but must be brought back within 24 hours.

SEBI

Broker and MII data

SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) requires trading and settlement data to be stored on primary and DR servers located in India.

IRDAI

Insurance policyholder data

IRDAI Information and Cyber Security Guidelines require critical policyholder data to be stored on servers located in India.

DoT

Telecom subscriber data

Unified Licence conditions require subscriber data to be stored in India, with limited processing abroad under safeguards.

05Reading the tea leaves on which restrictions come first

Nothing here is notified yet. But MeitY's consultation papers and the pattern of restrictions under sector regulators give a sense of which lever is likely to move first.

The obvious first candidate is any country under active strategic tension. This is the national-security lever and is the easiest for the Government to justify politically.

Next is the reciprocal-protections angle, essentially the reverse of what the EU does with its adequacy decisions. If a country's data protection framework does not offer Indian Data Principals comparable safeguards, the Government may restrict transfers to it. This is the slower path because it needs a policy justification, but it is the one MeitY has hinted at most often.

The fastest lever, though, is not against a country at all. Rule 12(4) lets the Government notify specific data categories that Significant Data Fiduciaries must keep inside India. Financial data, health data, biometric identifiers. That restriction can be issued without naming a country and would take effect immediately for designated SDFs.

06What you should do today

Even under a negative-list default, prudent Data Fiduciaries map their cross-border data flows now. Section 16 lets the Government restrict a country overnight, and Rule 15 will only take 18 months notice at most.

Three practical steps:

  1. Inventory your cross-border data flows. Which personal data categories cross which borders, via which processor, for which purpose. This is the ROPA (Record of Processing Activities) obligation under Section 8(3).
  2. Layer sectoral obligations on top. If you are BFSI, health, or telecom, your sectoral regulator already restricts specific data categories. Map those to your data flows.
  3. Build a country switch. Design your processor contracts and infrastructure so you can lift and shift a specific data category out of a specific country within 30 days. That is the shortest reasonable notice period the Central Government has signalled.
Practical steps per industry commentary; not a Government or Board direction.
Map your cross-border data flows. dcomply ships a Cross-Border Transfer module that maps flows and flags any category that would be affected by a restriction. See how →