· 8 min read
By Correct Editorial — Compliance Research Desk
Cross-border Data Transfer Rules Explained
Published on: July 29, 2026
For three years, the most common question about India's privacy law from global businesses has been whether it would force data localisation. The answer, now that the Digital Personal Data Protection Rules, 2025 are notified, is substantially no — with three carve-outs that matter enormously in practice.
The Digital Personal Data Protection Act, 2023 takes a permissive default and pairs it with a reserve power. Rule 15 lets data flow; Section 16(1) lets the government stop specific flows later; Section 16(2) preserves every stricter sectoral rule already on the books; and Rule 13(4) allows targeted localisation for Significant Data Fiduciaries. This article explains all four and what to do about them before the regime becomes enforceable on 13 May 2027. For the wider framework, see DPDP Act 2023: An Overview for Businesses.
What Does the Law Actually Permit?
Rule 15 of the DPDP Rules, 2025 states the position in a single sentence:
Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.
Three things follow. Transfer is permitted by default — no transfer impact assessment, no standard contractual clauses, no adequacy finding, and no prior approval is required as a precondition. The only conditionality attaches to requirements the Central Government may specify, and the specific concern flagged is making personal data available to a foreign State or entities under its control. That is a government access concern — the risk that a foreign authority can compel disclosure of Indian residents' data — rather than a general commercial-transfer concern.
Note also what Rule 15 does not do: it does not relieve you of any other obligation. Purpose limitation, security safeguards under Rule 6, breach intimation under Rule 7, and erasure duties all travel with the data. A transfer that is lawful under Rule 15 can still be a Section 8(5) failure if the destination environment is insecure.
What Reserve Power Does Section 16 Give the Government?
Section 16(1) empowers the Central Government to restrict transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be notified. This is a negative list — everything is permitted until a specific destination is named.
As of mid-2026, no country or territory has been notified. Businesses should nonetheless plan for the possibility, because the mechanism is designed for speed: a notification could take effect with little transition. The operational hedge is architectural — know precisely which datasets sit in which jurisdictions, and understand what it would cost to move each one.
The contrast with the EU GDPR is instructive:
| Dimension | India — DPDP Act and Rules | EU — GDPR |
|---|---|---|
| Default position | Transfers permitted | Transfers prohibited unless a basis exists |
| Mechanism | Negative list under Section 16(1) | Adequacy decisions, SCCs, BCRs, derogations |
| Instruments required | None mandated | Standard contractual clauses or equivalent |
| Assessment duty | None specified in the Rules | Transfer impact assessment expected post-Schrems II |
| Core concern | Access by a foreign State | Essential equivalence of protection |
| Sectoral overrides | Expressly preserved by Section 16(2) | Member State and sectoral rules apply separately |
Organisations already running a GDPR transfer programme will find the Indian bar lower. Organisations that built only for India will find it insufficient for Europe. Most Indian SaaS exporters need both.
Where Does Localisation Still Apply?
This is the part that surprises people who read only Rule 15.
1. Section 16(2) preserves stricter laws. The Act expressly states that nothing in Section 16 restricts the applicability of any law in force in India providing a higher degree of protection for, or restriction on, transfer of personal data. Every existing localisation mandate survives intact:
- RBI Storage of Payment System Data, the directive of 6 April 2018, requires payment system operators to store the entire end-to-end payment data only in India, with limited allowance for processing abroad followed by deletion and return within one business day for cross-border legs
- CERT-In directions of 28 April 2022 require ICT system logs to be maintained for 180 days within Indian jurisdiction
- Insurance and securities regulators impose their own record-location and access expectations on regulated entities
- Telecom licence conditions restrict the movement of subscriber information
2. Rule 13(4) targeted localisation for Significant Data Fiduciaries. An SDF must ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes — which will include MeitY officials and may include officials of other ministries — is processed subject to the restriction that that personal data and the traffic data pertaining to its flow are not transferred outside India. No specification has been issued yet, and no SDFs have been notified. But this is the most consequential latent provision in the framework: it permits category-specific localisation for the largest processors without amending the Act.
3. Government access requirements under Rule 15 itself. The requirements the Central Government may specify by general or special order are the third lever, and the one most likely to be exercised first given the drafting emphasis on foreign State access.
Which Transfers Are You Actually Making?
Most organisations underestimate their cross-border footprint by an order of magnitude because they count data centres rather than data flows. A transfer occurs whenever personal data is made accessible from outside India, including:
- Cloud hosting in a non-Indian region, or an Indian region with cross-region replication, backup or disaster recovery abroad
- SaaS tools — CRM, HR information systems, ticketing, email, analytics, marketing automation, e-signature
- Support access where an engineer or agent outside India can view Indian customer records, even without data at rest moving
- Group companies consolidating customer or employee data at a parent or shared-services entity
- AI and analytics vendors processing prompts, documents or logs on foreign infrastructure
- Payment, KYC and fraud vendors with global processing footprints
- Sub-processors of your processors — the layer almost never mapped
Every one of these should appear in a transfer register recording the dataset, the categories of personal data, the receiving entity, the jurisdiction, the purpose, the contractual basis, the security controls, and whether any sectoral localisation applies. The register is the artefact that lets you respond within days if a Section 16(1) notification ever lands. Building it depends on having classified each counterparty correctly — see Data Fiduciary vs Data Processor: Key Differences.
What Should Contracts and Architecture Look Like?
Although the Rules mandate no specific transfer instrument, prudent practice converges on a familiar set of terms, and enterprise procurement in India is already demanding them:
- Location transparency — a named list of processing and storage locations, with notice before any change
- Sub-processor register and approval rights, with equivalent flow-down obligations
- Rule 6 security schedule — encryption, access control, logging and monitoring, backups, and one-year log retention
- Government access clause — the vendor's obligations on receiving a foreign lawful-access demand, including notice where legally permitted and a commitment to challenge overbroad requests
- Breach notification to you within a window shorter than 72 hours, so you can meet your own obligation under Rule 7
- Deletion and return on termination, evidenced
- Assistance with rights requests within your 90-day grievance window under Rule 14(3)
- Localisation contingency — an obligation to support migration to an Indian region if a notification under Section 16(1) or a specification under Rule 13(4) requires it
On the architecture side, the cheapest insurance is jurisdictional optionality: keep Indian personal data in a logically separable store, prefer providers with Indian regions, avoid hard-coding foreign endpoints into core flows, and confirm that backups and disaster-recovery copies obey the same rules as primary storage. Teams shipping models should also read our guide to AI compliance under the DPDP Act, since training and inference pipelines are among the least-mapped transfer paths.
What Is the Exposure If You Get It Wrong?
There is no dedicated cross-border entry in the Schedule to the Act, which means most transfer failures fall under the residuary head of up to ₹50 crore for breach of any other provision of the Act or Rules. But transfer failures rarely stay in their own lane. If an overseas environment is inadequately secured, the exposure escalates to ₹250 crore under Section 8(5); if a breach in that environment is not intimated correctly, a further ₹200 crore head opens under Section 8(6). An SDF that ignores a Rule 13(4) localisation specification faces the ₹150 crore head under Section 10.
Sectoral consequences are often faster and more painful than the Board's. Non-compliance with the RBI payment data directive has historically resulted in supervisory action restricting the onboarding of new customers — a commercial penalty measured in lost growth rather than rupees. Section 33(2) also directs the Board to weigh mitigation and its timeliness, so a documented remediation plan started before enforcement carries real value.
A Practical Checklist
- Build the transfer register — every dataset, every jurisdiction, every sub-processor, refreshed quarterly.
- Separate the sectoral layer — identify which datasets are already subject to RBI, CERT-In, IRDAI or telecom localisation, and treat those as a hard constraint independent of DPDP.
- Assess your SDF likelihood — if volume and sensitivity make notification plausible, model the cost of localising your highest-risk categories now.
- Repaper vendor contracts with location, sub-processor, government access, and migration clauses.
- Confirm backups and logs obey the same jurisdictional rules as primary data.
- Run a notification drill — if a country were restricted tomorrow, how long would migration take, and what would break?
- Report to the board annually on cross-border concentration risk.
India has chosen openness with a switch on the wall. The businesses that will handle a future flick of that switch calmly are the ones that mapped their flows in 2026. More Indian regulatory explainers are available at Correct Learn, including our DPDP compliance roadmap and our primer on the Consent Manager framework.
References
- Gazette of India — The Digital Personal Data Protection Act, 2023 — Section 16 on processing of personal data outside India and the Schedule of penalties.
- Digital Personal Data Protection Rules, 2025 — notified text — Rule 13(4) and Rule 15 on localisation and cross-border transfer.
- MeitY — Explanatory Note to the DPDP Rules, 2025 — Official explanation of the transfer provisions.
- Reserve Bank of India — Storage of Payment System Data directive dated 6 April 2018 and related FAQs.
- Indian Computer Emergency Response Team (CERT-In) — Directions dated 28 April 2022 on log retention within Indian jurisdiction.
- Ministry of Electronics and Information Technology — Nodal ministry notifications on the DPDP framework.
- India Code — Consolidated statutory text with commencement annotations.
- Press Information Bureau — Government communications on the DPDP Rules and implementation timeline.
Frequently asked questions
- Can Indian businesses transfer personal data outside India?
- Yes. Rule 15 of the DPDP Rules, 2025 permits transfer outside India by default, subject to any requirements the Central Government specifies by general or special order regarding making that data available to a foreign State or an entity under its control.
- Has India notified any restricted countries under Section 16?
- Not as of mid-2026. Section 16(1) empowers the Central Government to restrict transfers to notified countries or territories, but no such notification has been issued. This is a negative-list approach, unlike the GDPR adequacy model.
- Does the DPDP Act override sectoral data localisation rules?
- No. Section 16(2) expressly preserves any law providing a higher degree of protection or restriction on transfers. The RBI payment system data directive of April 2018 and other sectoral requirements continue to apply in full.
- When can a Significant Data Fiduciary be required to localise data?
- Rule 13(4) requires a Significant Data Fiduciary to ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes, along with the traffic data pertaining to its flow, is not transferred outside India.