Cross-Border Data Transfer Under the DPDP Act (Section 16)
Almost every modern business moves personal data across borders — often without realizing it. A CRM hosted in Singapore, analytics processed in the United States, email delivered through a European provider, backups replicated to a data centre in another region. Each of these is a cross-border transfer of personal data, and each is governed by Section 16 of India's Digital Personal Data Protection (DPDP) Act, 2023.
The good news for Indian businesses is that Section 16 takes a comparatively permissive approach. But "permissive" is not the same as "no obligations." This guide explains what Section 16 actually says, how it differs from the model most global companies know from GDPR, how sectoral localization rules interact with it, and the practical steps every Data Fiduciary should take.
What Section 16 Actually Says
Under the DPDP Act, the entity that decides the purpose and means of processing personal data is the Data Fiduciary, and the individual whose data is processed is the Data Principal. Section 16 governs the transfer of that personal data outside India.
The core rule is a restriction model, sometimes called a negative list. A Data Fiduciary may transfer personal data to any country or territory outside India, except those that the Central Government restricts by notification. In other words, transfers are permitted by default. The government can carve out specific destinations by publishing a notification, and only transfers to those notified countries become restricted.
Two points are worth underlining:
- The default is open. Unless and until a country appears on a restricted list, transfers to it are permitted under Section 16.
- Other laws still apply. Section 16 explicitly preserves any other law in force in India that provides a higher degree of protection or restriction on the transfer of personal data. So a more demanding sector-specific rule sits on top of Section 16, not underneath it.
This is the whole of the Section 16 mechanism at a high level: an open door, with the power reserved for the government to close specific doors.
How This Differs From GDPR Adequacy
If your organization already complies with the EU's General Data Protection Regulation, it is easy to read Section 16 through a GDPR lens and get it exactly backwards.
GDPR uses a whitelist model. Transfers of personal data outside the EEA are, in principle, prohibited unless the destination has an adequacy decision, or the parties put appropriate safeguards in place — Standard Contractual Clauses, Binding Corporate Rules, and so on. The starting assumption is "not allowed unless justified."
The DPDP Act uses a negative list model. The starting assumption is "allowed unless restricted." There is no adequacy assessment to pass and no requirement to execute Standard Contractual Clauses purely to satisfy Section 16. A destination is fine until the Central Government says otherwise.
For a business that ships data out of India, this is materially simpler and generally more permissive than GDPR. But two cautions follow. First, the list of restricted countries can change with a single notification, so a transfer that is compliant today could require rerouting tomorrow. Second, do not assume the reverse: complying with GDPR's transfer rules does not automatically discharge your DPDP obligations, and vice versa. For a fuller side-by-side, see our guide on the DPDP Act versus GDPR.
Localization and Sectoral Rules Still Apply
The most common mistake is to treat Section 16 as the last word on where Indian data may live. It is not. Because Section 16 preserves stricter laws, India's existing sectoral localization requirements remain fully in force.
The clearest example is the Reserve Bank of India's directive on storage of payment system data, which requires that payment data be stored on systems located in India. Payment operators may process a transaction abroad, but the data must be stored domestically, and foreign copies must be handled according to RBI's conditions. Other regulators impose their own constraints in areas such as banking records, insurance, telecom, and certain government and health data.
The practical upshot is a layered analysis. For any given data set you should ask:
- Does Section 16 permit the transfer? Almost always yes, unless the destination is a notified restricted country.
- Does a sectoral law impose a stricter rule? If you are in payments, banking, insurance, telecom, or a regulated sector, a localization or storage-in-India requirement may override the general permissiveness of Section 16.
Section 16 sets the floor. Sector regulators can — and do — raise the ceiling.
A Note on Significant Data Fiduciaries
Some organizations are classified by the Central Government as Significant Data Fiduciaries (SDFs) under Section 10, typically based on the volume and sensitivity of the personal data they process and the risks involved. SDFs carry additional obligations: appointing a Data Protection Officer based in India, commissioning independent data audits, and conducting Data Protection Impact Assessments.
If your organization is, or is likely to be, notified as an SDF, cross-border transfer decisions deserve extra scrutiny and documentation, because your DPIAs and audits will be expected to account for where data flows and why.
Practical Steps for Compliant Transfers
Section 16 is not a heavy compliance burden on its own, but you can only rely on it if you actually know what your data is doing. In practice, the work is about visibility and governance rather than paperwork.
1. Map where your data goes
Build and maintain a data-flow inventory. For each system that touches personal data, record what it holds, which vendor or sub-processor operates it, and in which country the data is stored and processed. Cloud regions, sub-processors of your sub-processors, and backup or disaster-recovery locations are the usual blind spots. You cannot govern a transfer you have not identified.
2. Capture geography at the source
Wherever practical, capture and store the destination geography as part of your processing records — for example, tagging each vendor relationship or data category with the country where data resides. This turns "where does our data go?" from an annual scramble into a live, queryable answer, which is exactly what you will want if the government notifies a restricted country and you need to respond quickly.
3. Govern restricted and high-risk destinations
Put a simple control in place so that if a destination becomes restricted, you can find every affected data flow and reroute or repatriate it. Combine this with your sectoral obligations: flag payment, banking, and other regulated data so that localization rules are enforced regardless of what Section 16 allows.
4. Keep notices and consent honest
Your notice to Data Principals under Section 5, and the consent you collect under Section 6, should reflect reality — including that data may be processed outside India by named categories of processors. Consent must remain free, specific, informed, and unambiguous, and withdrawal must be as easy as giving it. If you tell people their data stays in one place while it is replicated somewhere else, no transfer rule will save you. For the fundamentals, see our guide to consent management under the DPDP Act.
5. Do not forget breach and erasure duties
Cross-border processing does not dilute your Section 8 obligations. You must still maintain reasonable security safeguards, notify the Data Protection Board and affected principals of a personal data breach, and erase personal data once the purpose is served or consent is withdrawn — unless another law requires you to retain it. A vendor abroad holding a stale copy of data you were obliged to erase is your problem, not theirs.
How DPDP Comply Helps
DPDP Comply is built for the Indian regulatory context, so cross-border governance is treated as a first-class part of compliance rather than an afterthought. The platform helps you keep a living record of your processing activities and the vendors involved, capture the geography of where personal data is handled, and maintain the consent and notice trail that makes an international transfer defensible. When you need to demonstrate to the Data Protection Board — or to your own leadership — that you know where personal data goes and how it is governed, that record is already in place.
To see how this fits your organization, explore our cross-border data transfer solution, or get started free and map your first data flows in minutes.
The Bottom Line
Section 16 gives Indian businesses a genuinely simpler cross-border regime than GDPR: transfers are allowed to any country except those the government restricts by notification. But that simplicity is conditional. Sectoral localization rules like the RBI's payment-data directive still bind, the restricted list can change, and your broader duties around consent, security, breach notification, and erasure travel with the data wherever it goes. The organizations that will handle this well are the ones that can answer, at any moment, a single question: where is our data, and who is holding it?
This article is general information, not legal advice.