Cross-Border Data Transfers under the DPDP Act, 2023: India’s Negative List Approach Explained

Every time an Indian user books a cab, uses a UPI app, or messages a friend on WhatsApp, personal data quietly crosses borders — stored on a server in Singapore, processed in Ireland, backed up somewhere in the US. Most people never think about this. Regulators have to. Governments want a say over data generated within their borders; businesses want the freedom to move it wherever it gets processed fastest. India’s answer to that tension — the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025 — has only just started taking shape, and it’s worth understanding both what it says and what it deliberately leaves unsaid.

What Do We Mean by “Cross-Border Data Transfer”?

A cross-border transfer happens whenever personal data collected in one country is stored, processed, or accessed in another. It doesn’t need to look dramatic — using a foreign cloud server counts, so does routing customer support through an overseas call centre, so does letting someone abroad remotely access a database sitting in India. Different countries attach different conditions to each of these, which is exactly why a company operating across borders can’t just satisfy one rulebook and call it done.

Why Nations Regulate Data Flows: The Sovereignty Argument

Digital sovereignty is the idea that a state should control the data generated by and about its citizens, much the way it controls its territory or airspace. Three motives usually sit behind this:

National security and law enforcement access — governments would rather not depend on slow mutual legal assistance treaty (MLAT) requests to a foreign court just to get data relevant to an investigation.

Economic self-interest — localisation rules double as industrial policy, nudging global companies to build data centres and create jobs domestically.

Citizen privacy protection — a government may simply not trust the privacy standards of the destination country.

This debate picked up constitutional weight in India after Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, where the Supreme Court held that informational privacy is part of the right to life and personal liberty under Article 21 — meaning any state action touching personal data has to clear the tests of legality, necessity, and proportionality. Every Indian data protection statute since, DPDP included, is built on that foundation.

The DPDP Act and the “Negative List” Approach

Section 16 of the DPDP Act governs cross-border transfers, and it takes a genuinely different route from most global privacy laws. Instead of requiring proof that the destination country offers “adequate” protection — the EU’s approach — or maintaining a positive list of approved jurisdictions, India has gone with a negative list model. Data can go to any country by default. The government only steps in where it specifically restricts a country by notification.

Rule 15 of the DPDP Rules, 2025 (notified 13 November 2025) is what actually operationalises this. It confirms transfer is the default position, and restrictions only bite once a specific notification is issued — a clear break from the far stricter data-localisation drafts floated back in 2019 and 2021. Section 16(2) keeps one safeguard intact: wherever another Indian law demands a higher standard for a particular data category, that stricter law still wins.

As of mid-2026, no country has actually been notified as restricted yet. Several connected pieces are still pending — the criteria for “Significant Data Fiduciaries” under Rule 12, the Data Protection Board of India’s enforcement machinery under Section 27, and the phased rollout timeline the Ministry of Electronics and IT (MeitY) has indicated for the remaining DPDP Rules. Treat this as a transitional compliance landscape, not a finished one.

Sector-Specific Localisation: The RBI’s Payment Data Mandate

The negative-list philosophy doesn’t override localisation mandates that already exist elsewhere. The clearest example is the RBI’s April 2018 directive on the Storage of Payment System Data, which requires payment system operators to store the full data of a payment transaction only in India — a copy can go abroad only for the cross-border leg of a transaction, and only after processing. Payment aggregators, card networks, and wallets have to satisfy this RBI mandate on top of whatever the DPDP framework eventually settles into. The stricter rule governs; that’s just how it works.

Cybersecurity Reporting: The CERT-In Angle

There’s a parallel obligation worth flagging that often gets missed in cross-border discussions: CERT-In’s Directions of 28 April 2022 require service providers, intermediaries, and body corporates to report specified cybersecurity incidents within six hours of becoming aware of them, and to maintain logs for 180 days within Indian jurisdiction. This isn’t a data-transfer rule in the DPDP sense, but it does mean that even where personal data is lawfully transferred abroad for processing, the underlying system logs and incident records often still need to stay accessible within India. Any cross-border compliance mapping is incomplete without checking this alongside Section 16.

The GDPR Comparison: Adequacy, SCCs, and the Schrems Line of Cases

The EU’s GDPR takes the opposite structural approach. Article 45 allows transfer without extra safeguards only where the European Commission has issued an “adequacy decision” for that country. Absent that, exporters lean on tools like Standard Contractual Clauses (SCCs) or Binding Corporate Rules, paired with a transfer impact assessment. It’s worth noting this entire adequacy concept has older roots — the OECD’s 1980 Privacy Guidelines were among the first international instruments to articulate cross-border data flow principles, and much of today’s adequacy and accountability language traces back to that framework.

The EU system was tested hard in Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Case C-311/18) — Schrems II. In July 2020, the CJEU found the EU-US Privacy Shield inadequate against US surveillance practices and struck it down, while keeping SCCs alive, but only if exporters actually assess whether the destination country’s law and practice will let those contractual protections mean something in real life. This followed Schrems I in 2015, which had already taken down the preceding Safe Harbor framework. Read together, both judgments say the same thing twice: a transfer mechanism is only as strong as the surveillance environment on the receiving end, no matter how well the contract is drafted.

India’s negative-list model sidesteps this adequacy-assessment burden for now — commercially convenient, but it also means Indian exporters sending data onward into the EU still have to satisfy GDPR separately on that end.

Where India’s Model Sits Globally: The CBPR Comparison

It’s worth placing India’s choice alongside a third model — the APEC Cross-Border Privacy Rules (CBPR) system, now evolving into the Global CBPR Forum, which several Asia-Pacific economies use as a certification-based framework: companies get certified against an agreed set of privacy principles, and that certification is recognised across participating member countries. It’s neither a strict positive list like the EU’s nor a fully open negative list like India’s — more a mutual-recognition club. India hasn’t joined this framework, but as trade negotiations with countries like the US, UK, and EU progress, pressure to align with something closer to CBPR could well shape how India’s restricted-country list eventually gets built.

Reconciling Privacy Protection with International Commerce

India’s IT and BPO sectors exist because data can move freely — a call centre in Bengaluru or a legal process outsourcing unit in Gurugram only functions because foreign clients can lawfully send data here, and Indian firms can send it onward just as easily. A rigid localisation regime would raise compliance costs and disrupt cloud-based delivery overnight. But unrestricted flow isn’t free of risk either — foreign surveillance access, weaker breach-notification standards abroad, and real difficulty enforcing an Indian data principal’s rights once the data has left Indian jurisdiction.

The negative-list approach reads like India trying to have both things at once: trade-friendly default access for a data-services economy worth hundreds of billions of dollars, plus an executive tool to step in if a specific country or platform starts looking genuinely risky. Whether that balance actually holds depends almost entirely on how transparently the government uses its Section 16 notification power going forward.

Practical Compliance Steps for Businesses

Map every cross-border data flow — which categories of personal data leave India, to which countries, through which vendors.

Track sector rules (RBI payment data, CERT-In incident logging, insurance and telecom licence conditions) separately from the general DPDP framework, since Section 16(2) preserves whichever rule is stricter.

Build contract flexibility with cloud vendors so flows can be redirected quickly if a country gets added to a restricted list later.

Consider voluntary alignment with ISO/IEC 27701 — the international standard for privacy information management — as evidence of a working privacy management system; it isn’t mandatory under DPDP, but it helps demonstrate accountability if the Data Protection Board ever comes asking.

Watch for the pending notifications on Significant Data Fiduciaries and restricted countries — both will materially change obligations once issued.

Where data also moves into the EU, keep GDPR-compliant mechanisms (SCCs, transfer impact assessments) running independently of DPDP compliance.

Conclusion

Cross-border data transfer law sits right at the intersection of constitutional privacy rights, national security policy, and the practical reality of a digital economy that ignores borders anyway. India has chosen openness as its default and left itself room to restrict later rather than the other way around. That’s a considered bet on staying integrated into global digital commerce — but for now, it leaves businesses in a genuinely in-between regulatory space, where sector rules, constitutional principles, and an evolving restricted-country list all need tracking together, not separately.

Frequently Asked Questions

Does the DPDP Act require companies to store Indian citizens’ data only within India?

No. There’s no general localisation requirement. Section 16 permits transfer to any country by default unless the government specifically restricts it. Sector rules like the RBI’s payment data mandate are separate, narrower requirements that apply regardless.

What is Rule 15 of the DPDP Rules, 2025?

It’s the provision that operationalises Section 16. It confirms transfer is permitted by default, and restrictions only take effect once the government notifies a specific restricted country or mechanism.

Is India’s approach similar to the GDPR’s adequacy system?

Structurally, it’s the reverse. GDPR restricts transfer unless the destination is assessed as “adequate” or safeguards like SCCs are used. India permits by default and restricts only what it chooses to notify — a negative list model against the EU’s positive list model.

What did the Schrems II judgment decide?

The CJEU held the EU-US Privacy Shield inadequate against US surveillance and struck it down, while keeping SCCs valid subject to a stronger obligation on exporters to check whether the destination country’s actual law and practice would honour those contractual protections.

Does CERT-In’s 2022 Directions affect cross-border data transfer compliance?

Indirectly, yes. Even where personal data itself is transferred abroad lawfully, CERT-In requires cybersecurity incident reporting within six hours and log retention within India for 180 days — a separate obligation that runs alongside, not instead of, DPDP compliance.

Can the government block transfer of data to a specific country at any time?

Yes. Under Section 16 read with Rule 15, the government can restrict or prohibit transfer to a specific country or class of recipients by notification, without being required to give reasons or offer an alternative transfer mechanism.

Ananya Sutradhar
Author: Ananya Sutradhar

Ananya is a second-year law student (B.Com LL.B Hons) with a growing interest in contract law and cyber law. She currently interns at Lawvaani, writing on legal developments in technology and commercial law.