Cross border transfer of personal data
In short
India takes a restriction based approach rather than an adequacy based one. Section 16(1) permits a Data Fiduciary to transfer personal data outside India except to a country or territory that the Central Government restricts by notification. There is no requirement to establish adequacy or to put standard contractual clauses in place as a condition of transfer under the Act.
Rule 15 adds one condition: the Data Fiduciary must meet such requirements as the Central Government may specify, by general or special order, in respect of making personal data available to a foreign State, or to a person or entity under the control of or an agency of such a State.
01The three layers to check
| Layer | Source | Effect |
|---|---|---|
| General permission | Section 16(1) | Transfer permitted unless the destination is restricted by notification |
| Government orders | Rule 15 | Requirements specified by general or special order, aimed at availability to a foreign State or entities under its control |
| Sectoral law | Section 16(2) | Nothing in Section 16 restricts the application of any other law that provides a higher degree of protection or restriction on transfer |
Section 16(2) is the provision that most affects regulated entities. A permissive position under DPDP does not displace RBI storage requirements for payment system data, or any other sectoral localisation obligation. Where both apply, the stricter one governs.
02The separate restriction on Significant Data Fiduciaries
Rule 13(4) is a different mechanism and should not be read together with Section 16. It obliges a Significant Data Fiduciary to ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes, and the traffic data pertaining to its flow, is not transferred outside India.
This is a category based localisation restriction attaching to designated entities, not a country based one. Its scope depends on a specification that has not yet been published.
03What to do before the position settles
The work that holds its value whatever the notifications say is data flow mapping. Specifically: which personal data leaves India, to which entity, in which country, under what contract, hosted by whom, and mirrored where.
For a global capability centre or captive processing arrangement, add one column: whether the entity acts as Data Fiduciary or Data Processor for each flow. That single column changes who owes the notice, who owes the breach intimation, and who answers the Data Principal.
04Common questions
Which countries are restricted?
The Act works by exception, so a country is restricted only if it is notified. Verify the current position against Central Government notifications before relying on any list.
Are standard contractual clauses required?
The Act does not impose an SCC style mechanism as a condition of transfer. Contractual controls remain necessary for security safeguards under Rule 6 and for allocating breach obligations.
Does DPDP override RBI localisation requirements?
No. Section 16(2) preserves other laws that impose a higher degree of protection or restriction on transfer.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.