Cross-Border Data Transfers Under DPDP: What Is Allowed, What May Be Restricted, and How to Prepare

Cross-Border Data Transfers Under DPDP: What Is Allowed, What May Be Restricted, and How to Prepare

Can Indian personal data legally leave the country? Discover the rules for cross border data transfer under DPDP Act, negative lists, and vendor governance.

Sahil Pugalia

Written by

Sahil Pugalia

Date

Read time

4 min

For most companies, data does not respect geography.

A startup in Bengaluru may store its database on cloud servers in Singapore. A SaaS company serving Indian customers may run analytics from Europe. A global platform may process user data across multiple regions.

This is simply how modern digital infrastructure works.

But the Digital Personal Data Protection Act (DPDP Act), 2023, introduces an uncomfortable question: Can the personal data of Indians legally leave the country?

The answer is more flexible than many assume, but that flexibility comes with a catch.

What the DPDP Act Says

The rules for a cross-border data transfer under DPDP act are addressed in DPDP Act Section 16.

The law takes a “negative list” approach. This means personal data can be transferred outside India, except to specific countries that the central government may restrict through notification.

In simple terms:

  • Data transfers are allowed by default.
  • Unless the government places restrictions on specific jurisdictions.

This is a sharp departure from other global privacy frameworks that force companies to rely on pre-approved “whitelists”.

DPDP in a nutshell

What This Means in Practice

For many companies, this provision allows the continued use of global cloud infrastructure without breaking the law.

Take cloud storage as an example. A fintech startup in India may store customer data on cloud servers located in Singapore or Europe. Under the DPDP framework, this is perfectly legal, provided two things are true:

  1. The company complies with the Act’s core obligations.
  2. The destination is not among any countries or territories that may be restricted by future government notification.

But there is a crucial caveat. The startup remains entirely responsible for protecting that personal data, even when it sits on a server 3,000 miles away.

The Accountability Does Not Travel With the Data

One of the hardest truths of the DPDP Act is that accountability does not move with the data. You can outsource the processing. You cannot outsource the liability.

For example, an Indian e-commerce company might use an overseas analytics provider to analyze user behavior. If that analytics provider mishandles the data or causes a breach, the regulatory target is not the overseas vendor. The responsibility under the Act still lies squarely with the Data Fiduciary that collected the data in the first place.

This makes vendor oversight and airtight contractual safeguards non-negotiable.

Sectoral Rules: The Hidden Data Residency Requirements

While the DPDP Act itself allows cross-border transfers broadly, your industry might not. Sector-specific regulations often impose much stricter data residency requirements.

Example: The Financial Sector

RBI data localisation requirements require certain payment-system data to be stored in India and may significantly restrict overseas storage or processing arrangements. So even though the DPDP Act might permit a transfer, companies operating payment systems must still comply with strict Indian data localisation requirements set by the RBI.

Why Governments Care About Data Sovereignty

Data transfer rules exist because sending data across borders creates immediate jurisdictional risks.

Different countries may have:

  • Weaker privacy protections
  • Different surveillance laws
  • Limited enforcement mechanisms

Governments care deeply about data sovereignty; they want the ability to restrict transfers to jurisdictions that pose security or privacy concerns to their citizens. The DPDP Act’s negative list model gives India the ultimate kill switch if a specific data route becomes a risk in the future.

What Companies Should Be Doing Now

Even though a DPDP cross border data transfer remains broadly allowed today, organisations need to prepare carefully.

You cannot govern what you cannot see. The first step is understanding where your personal data actually flows.

Consider a typical digital product. It likely processes data across multiple systems:

  • User signup data stored in India
  • Analytics processed in the United States
  • Customer support systems hosted in Europe
DPDP Network

Without absolute visibility into these flows, companies may struggle to demonstrate compliance during regulatory inquiries, investigations, or assessments. This is why organisations must begin with rigorous data flow mapping, identifying exactly where personal data is stored, which vendors process it, and which countries are involved.

Vendor Governance Becomes Critical

Cross-border data transfers almost always involve third-party service providers. These could include:

  • Cloud infrastructure providers
  • Marketing platforms
  • Analytics tools
  • Customer support systems

Companies must ensure these vendors follow appropriate security safeguards and contractual commitments. Because if the data moves abroad, the responsibility under DPDP remains with the organisation that collected it.

A Balanced Approach to Global Data Infrastructure

The DPDP Act attempts to strike a pragmatic balance.

On one hand, it recognises that modern digital services rely on global infrastructure. On the other, it gives the government the authority to restrict transfers if national interests require it.

For companies, the takeaway is clear. Cross-border data transfers are not banned. But they must be managed responsibly, documented clearly, and monitored carefully.

Because once personal data crosses borders, your compliance responsibilities do not disappear. They simply become more complex.

DPDP allows transfer unless restricted under Section 16 or another applicable law, regulation, or regulatory direction.

The cross-border transfer regime does not come into force immediately. The Government’s notification dated 13 November 2025 activates Section 16 (cross-border transfers) and all operational obligations eighteen months after publication, meaning cross-border transfer compliance becomes fully operational only eighteen months after 13 November 2025.
This means the full compliance framework for cross-border transfers will not be operational until approximately May 2027.

When data crosses borders, compliance doesn’t stop – it gets harder. Regodit helps you stay on top of it.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →