Cross-border transfer
India picked the opposite lever from the GDPR. Under Section 16, cross-border transfer of personal data is permitted by default. The Central Government may restrict specific countries by notification. As of September 2026, no country has been restricted.
01What Section 16 says
Section 16(1) says the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India. Section 16(2) preserves any higher standard already imposed by another Indian law.
Read plainly: transfers are permitted unless specifically restricted. This is what commentary calls the "negative-list" or "blacklist" model. It is the inverse of the GDPR model, which prohibits transfers unless an adequacy decision or a Standard Contractual Clause covers the transfer (the "whitelist" or adequacy model).
02Rule 15 mechanics
Rule 15 of the DPDP Rules 2025 restates the default: personal data processed by a Data Fiduciary may be transferred outside India unless restricted.
The Rule adds one operational point. Where a country has been notified as restricted, the Data Fiduciary must ensure it does not transfer personal data to that country. The Rule does not prescribe technical mechanisms (Standard Contractual Clauses, Binding Corporate Rules), because none are required under a negative-list model. Rule 15 takes effect on 14 May 2027 along with the other substantive Rules.
03The SDF-specific override (Rule 12(4))
Rule 12(4) creates a second lever, targeted at Significant Data Fiduciaries only.
Under Rule 12(4), the Central Government may notify specific categories of personal data that Significant Data Fiduciaries process, and require those categories to remain in India. This is a targeted localisation obligation that runs parallel to Section 16 and applies to SDFs alone.
No such data category has been notified as of September 2026. Financial identifiers, health identifiers, biometric identifiers, and payment authentication data are the categories most often flagged in industry consultation. If your organisation is likely to be designated an SDF, plan for the possibility that at least one high-sensitivity category will need to remain in India.
04The sectoral overlays that still apply
Section 16(2) preserves any higher standard imposed by another Indian law. This means sectoral rules on data localisation continue to bind you on top of DPDP. In practice, these are the four you must not overlook.
Payment system data
RBI directive dated 6 April 2018 requires payment system data to be stored only in India. Copies abroad are permitted for foreign-leg processing but must be brought back within 24 hours.
Broker and MII data
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) requires trading and settlement data to be stored on primary and DR servers located in India.
Insurance policyholder data
IRDAI Information and Cyber Security Guidelines require critical policyholder data to be stored on servers located in India.
Telecom subscriber data
Unified Licence conditions require subscriber data to be stored in India, with limited processing abroad under safeguards.
05Reading the tea leaves on which restrictions come first
Nothing here is notified yet. But MeitY's consultation papers and the pattern of restrictions under sector regulators give a sense of which lever is likely to move first.
The obvious first candidate is any country under active strategic tension. This is the national-security lever and is the easiest for the Government to justify politically.
Next is the reciprocal-protections angle, essentially the reverse of what the EU does with its adequacy decisions. If a country's data protection framework does not offer Indian Data Principals comparable safeguards, the Government may restrict transfers to it. This is the slower path because it needs a policy justification, but it is the one MeitY has hinted at most often.
The fastest lever, though, is not against a country at all. Rule 12(4) lets the Government notify specific data categories that Significant Data Fiduciaries must keep inside India. Financial data, health data, biometric identifiers. That restriction can be issued without naming a country and would take effect immediately for designated SDFs.
06What you should do today
Even under a negative-list default, prudent Data Fiduciaries map their cross-border data flows now. Section 16 lets the Government restrict a country overnight, and Rule 15 will only take 18 months notice at most.
Three practical steps:
- Inventory your cross-border data flows. Which personal data categories cross which borders, via which processor, for which purpose. This is the ROPA (Record of Processing Activities) obligation under Section 8(3).
- Layer sectoral obligations on top. If you are BFSI, health, or telecom, your sectoral regulator already restricts specific data categories. Map those to your data flows.
- Build a country switch. Design your processor contracts and infrastructure so you can lift and shift a specific data category out of a specific country within 30 days. That is the shortest reasonable notice period the Central Government has signalled.