India's DPDP Act 2023 lets you transfer personal data abroad — except to countries the government restricts. DPDP Comply models that negative list, flags transfers to restricted destinations, and captures the visitor's country by geolocation so you can govern and evidence it.
Controls, geo capture and audit — not legal blocking
What is Section 16?
Section 16 of the DPDP Act 2023 takes a negative-list approach to cross-border data transfer: a data fiduciary may transfer personal data outside India to any country except those the Central Government restricts by notification. That is notably more permissive than the GDPR's adequacy whitelist — and it means your controls should model a short list of restricted destinations, not an allow-list of approved ones.
Want the full breakdown of Section 16 and how to operationalize it? Read the guide
How it works
DPDP Comply gives you the pieces to map, govern and prove cross-border transfers — the restricted list, the transfer register, geo capture, and the audit trail behind it.
A maintained list of restricted destinations, keyed on ISO country codes, mirrors Section 16's negative-list model: transfers stay open by default, and only countries on the list are treated as restricted.
Register each cross-border transfer per project — destination country, third party, purpose, data types and legal basis. Any transfer to a restricted country is automatically flagged for review.
The platform captures the visitor's country from edge geolocation, and consent records carry country and region as ISO-code fields — surfaced in analytics as a geographic breakdown, so you can see where your data principals actually are, not where you assume they are.
Flagged transfers, a geographic breakdown of consent by country, and a tamper-evident audit trail give you a defensible, inspection-ready record of how transfers are governed.
A transfer declared to a restricted country is flagged automatically — so you can review and evidence it, rather than discover it in an audit. DPDP Comply surfaces the flag and the geo; it does not silently block traffic on your behalf.
Two models, one difference
If you are used to GDPR-style data localization thinking, Section 16 inverts the default. Here is the contrast your controls need to reflect.
Section 16 permits transfer of personal data to any country except those the Central Government notifies as restricted. Open by default, with a short negative list — not an allow-list.
The EU permits transfers only to countries on an approved adequacy list, or with additional safeguards in place. Closed by default; you must justify each destination up front.
Sectoral localization still applies on top. Even where Section 16 permits a transfer, stricter sector rules — such as the RBI's payment-data localization mandate — can require certain data to remain in India. Map those over the negative list, not instead of it.
Why it matters
Section 16 keeps cross-border transfer permissive, but a data fiduciary still has to know where personal data goes, why, and to whom. DPDP Comply gives you that visibility: a per-project register of transfers checked against the restricted-countries list, plus the visitor's country captured by geolocation, so a restricted destination is flagged and recorded rather than missed.
This is a governance and evidence layer — controls, geo capture and a tamper-evident audit trail — not automatic legal blocking and not a legal determination. This is general information about the DPDP Act 2023, not legal advice; confirm your specific obligations, including any sectoral localization rules, with qualified counsel.
FAQ
Section 16 lets a data fiduciary transfer personal data outside India to any country except those the Central Government restricts by notification. It is a negative-list, or restrict-by-exception, model — generally more permissive than the GDPR's adequacy whitelist. Stricter sectoral rules, such as the RBI's requirements for payment data, still apply on top of Section 16.
Under the GDPR, a transfer to a country outside the EU is allowed only if that country is on an approved adequacy list or you put additional safeguards in place. DPDP Section 16 flips the default: transfers are permitted everywhere except to countries the government specifically notifies as restricted. DPDP Comply models this directly with a restricted-countries list rather than an allow-list.
You declare each cross-border transfer per project — the destination country, third party, purpose, data types and legal basis. The platform checks the destination against a maintained list of restricted countries and flags any transfer to a restricted destination for review. It is a governance and evidence control, not automatic legal blocking of traffic.
Yes. The platform captures the visitor's country from edge geolocation, consent records carry country and region as ISO-code fields, and analytics show a geographic breakdown of consent by country. That lets you see where your data principals actually are and evidence how transfers are governed.
No. DPDP Comply gives you controls, geo capture and an audit trail to help you map and evidence transfers, but it does not make legal determinations. This page is general information, not legal advice — confirm your obligations, including any sectoral localization rules, with qualified counsel.
Declare where personal data goes, flag restricted destinations against Section 16's negative list, and keep a defensible record of every one — all in DPDP Comply.
Get Started — It's FreeNo credit card required · Setup in under 10 minutes