Cross-Border Data Transfer Framework under the Digital Personal Data Protection Act, 2023: Analysing Blacklisting vs. Whitelisting, Regional Adequacy Standards and Global Compliance Alignment
Introduction
The exponential growth of the digital economy has transformed personal data into one of the world’s most valuable resources. Businesses increasingly rely on cloud computing, artificial intelligence, international outsourcing, and global digital platforms, all of which require the seamless movement of data across national borders. Cross-border data transfers facilitate international trade, improve technological innovation, and enable multinational corporations to deliver efficient digital services. At the same time, they expose individuals’ personal data to varying privacy standards, regulatory risks, and cybersecurity threats.
Recognising the need to establish a comprehensive framework for personal data protection, India enacted the Digital Personal Data Protection Act, 2023 (DPDP Act). The legislation seeks to balance an individual’s right to privacy with the legitimate need to process personal data for lawful purposes. Unlike its predecessor, the withdrawn Personal Data Protection Bill, 2019, which proposed extensive localisation requirements, the DPDP Act adopts a comparatively liberal approach towards international data transfers.
One of the most debated aspects of the Act is its framework governing cross-border transfer of personal data. Rather than adopting a traditional “whitelisting” mechanism—where data may only be transferred to jurisdictions recognised as providing adequate protection—the DPDP Act empowers the Central Government to notify countries or territories where transfers may be restricted. This model is generally described as a blacklisting approach. The shift has generated significant debate regarding regulatory certainty, business convenience, privacy protection, and India’s alignment with global data protection standards.
This article examines India’s cross-border data transfer framework under the DPDP Act, 2023 by analysing the blacklisting model, comparing it with international whitelisting and adequacy frameworks, and evaluating its compatibility with global compliance standards.
Understanding Cross-Border Data Transfers
Cross-border data transfer refers to the movement of personal data from one country to another for purposes such as cloud storage, customer support, financial transactions, outsourcing, analytics, healthcare, or digital services. Modern businesses rarely operate within a single jurisdiction. Consequently, personal information often travels across multiple countries before processing is completed.
For example, an Indian e-commerce company may collect customer information in India, store it on servers located in Singapore, process payment data through Ireland, and utilise customer support services operating from the Philippines. Every transfer raises important legal questions regarding applicable privacy laws, governmental access to data, cybersecurity obligations, and enforcement mechanisms.
The DPDP Act acknowledges these commercial realities by permitting international data transfers while retaining governmental oversight over destinations that may pose risks to national interests or data protection objectives.
Legal Framework under the Digital Personal Data Protection Act, 2023
The DPDP Act establishes a rights-based framework regulating the processing of digital personal data. The Act applies where digital personal data is collected within India and also extends to processing outside India where goods or services are offered to individuals located in India.
The legislation identifies key stakeholders including:
- Data Principal
- Data Fiduciary
- Data Processor
- Significant Data Fiduciary
Each stakeholder has distinct rights and obligations regarding the processing and protection of personal data.
Unlike earlier legislative proposals that contemplated mandatory localisation of sensitive personal data, the DPDP Act significantly liberalises international data transfers.
The principal provision governing overseas transfers is Section 16 of the DPDP Act, 2023.
Section 16 provides that the Central Government may, by notification, restrict the transfer of personal data to such countries or territories outside India as it may specify. Consequently, unless a country is specifically prohibited, cross-border transfers remain permissible subject to compliance with the Act.
This legislative choice reflects India’s attempt to balance three competing objectives:
- facilitating international business;
- protecting personal data;
- safeguarding national security and strategic interests.
The Act further clarifies that sector-specific laws imposing additional restrictions, such as those governing banking, insurance, telecommunications, or health data, continue to operate alongside the DPDP framework.
India’s Blacklisting Approach
The DPDP Act introduces what commentators commonly describe as a negative-list or blacklisting model.
Under this approach, international data transfers are generally allowed unless the Government specifically prohibits transfers to certain jurisdictions.
In practical terms:
- every foreign country is presumed permissible;
- restrictions arise only through government notification;
- businesses are not required to demonstrate that the receiving country possesses privacy laws equivalent to India’s legislation.
This represents a significant departure from many international data protection frameworks.
Objectives of the Blacklisting Model
The adoption of the blacklisting approach appears to pursue several policy objectives.
1. Facilitating Ease of Doing Business
India has positioned itself as a global hub for information technology, outsourcing, fintech, software development, and digital services. Excessive restrictions on international data transfers could increase compliance costs and discourage foreign investment.
The blacklisting model simplifies compliance by allowing businesses to transfer personal data without first conducting extensive legal assessments of every destination country.
2. Supporting the Digital Economy
Cloud infrastructure operated by multinational technology companies is geographically distributed. Businesses often cannot determine the precise physical location where data will ultimately be stored.
Permitting transfers by default enables organisations to utilise global cloud infrastructure more efficiently while avoiding unnecessary localisation expenses.
3. Regulatory Flexibility
Instead of permanently recognising countries through adequacy decisions, the Government retains discretion to prohibit transfers whenever geopolitical developments, cybersecurity risks, or national security concerns justify intervention.
Such flexibility may prove valuable where diplomatic relations or cyber threats evolve rapidly.
4. Reducing Administrative Burden
Whitelisting frameworks require regulators to conduct extensive assessments of foreign legal systems before recognising adequate jurisdictions.
The blacklisting model substantially reduces this administrative burden by requiring governmental action only where restrictions become necessary.
Advantages of India’s Framework
Several advantages emerge from the DPDP Act’s approach.
Simplified Compliance
Businesses no longer need to determine whether every receiving country satisfies detailed adequacy standards. Unless a destination has been officially restricted, transfers remain lawful.
Greater Business Certainty
Multinational corporations frequently transfer data among affiliates operating across dozens of countries. A permissive framework reduces legal uncertainty and encourages international investment.
Enhanced Innovation
Artificial intelligence, machine learning, financial technology, and global software development depend upon rapid international data movement. Flexible transfer rules facilitate technological innovation and digital collaboration.
Compatibility with International Commerce
Cross-border trade increasingly depends upon unrestricted data flows. India’s approach aligns with its objective of becoming a leading participant in the global digital economy while avoiding unnecessary barriers to commerce.
Criticisms of the Blacklisting Model
Despite these advantages, the framework has attracted criticism from legal scholars and privacy advocates.
One major concern is the absence of objective criteria governing the Government’s decision to blacklist countries. The Act does not specify whether restrictions will depend upon cybersecurity standards, privacy legislation, human rights protections, reciprocal arrangements, or national security considerations. This broad executive discretion may create uncertainty for businesses planning long-term international operations.
Another criticism relates to the comparatively limited emphasis on the level of protection available in recipient jurisdictions. Under adequacy-based models such as the European Union’s GDPR, regulators evaluate whether foreign legal systems provide protections essentially equivalent to domestic privacy standards before permitting unrestricted transfers. The DPDP Act, however, presumes transfers are permissible unless specifically prohibited. Critics argue that this may result in personal data being transferred to jurisdictions with comparatively weaker privacy safeguards.
Furthermore, the effectiveness of the framework will largely depend on future government notifications and implementing rules. Until clear criteria and procedural safeguards are prescribed, stakeholders may continue to face uncertainty regarding the practical operation of India’s cross-border data transfer regime.
Whitelisting and Regional Adequacy Standards
Unlike India’s blacklisting model, many jurisdictions regulate international data transfers through a whitelisting or adequacy-based framework. Under this approach, personal data may freely flow only to countries that are officially recognised as providing an “adequate level of protection.” Countries that fail to satisfy these standards require additional legal safeguards before data can be transferred.
The European Union’s General Data Protection Regulation (GDPR) represents the most developed adequacy framework. Under Article 45 of the GDPR, the European Commission may adopt an adequacy decision after assessing whether a third country’s legal framework provides protection that is essentially equivalent to EU standards. The assessment considers factors such as the rule of law, respect for human rights, independent supervisory authorities, judicial remedies, and effective enforcement mechanisms. Once adequacy is granted, organisations may transfer personal data without requiring additional contractual safeguards.
Where no adequacy decision exists, the GDPR permits transfers through recognised safeguards such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), approved codes of conduct, or certification mechanisms. SCCs are pre-approved contractual clauses issued by the European Commission, whereas BCRs are internal privacy policies adopted by multinational corporate groups for intra-group data transfers. These mechanisms ensure that data subjects continue to enjoy comparable protection even when their data leaves the European Economic Area.
Outside Europe, several regional initiatives have also developed interoperable transfer mechanisms. The APEC Cross-Border Privacy Rules (CBPR) system seeks to facilitate trusted data flows among participating economies through certification-based accountability. ASEAN has introduced Model Contractual Clauses to promote secure data transfers across Southeast Asia, while the Council of Europe’s Convention 108+ encourages harmonised safeguards for international transfers through common legal standards.
These models illustrate an international trend towards balancing free movement of data with robust privacy safeguards through objective regulatory standards.
Blacklisting versus Whitelisting: A Comparative Analysis
| Parameter | India’s Blacklisting Model | Whitelisting / Adequacy Model |
| Default Rule | Transfers are generally permitted unless a country is specifically restricted. | Transfers are prohibited unless the destination country has been recognised as adequate or other safeguards are implemented. |
| Regulatory Burden | Lower initial compliance burden. | Higher compliance due to adequacy assessments and contractual safeguards. |
| Business Flexibility | High flexibility for multinational businesses. | More structured but comparatively restrictive. |
| Privacy Protection | Depends significantly upon governmental restrictions and fiduciary compliance. | Strong emphasis on equivalent legal protection in recipient jurisdictions. |
| Government Role | Restricts transfers through notification. | Conducts detailed adequacy assessments before permitting unrestricted transfers. |
| Commercial Impact | Facilitates global digital commerce. | Prioritises privacy while allowing transfers through recognised mechanisms. |
India’s approach offers greater commercial flexibility and reduces compliance costs, making it attractive for start-ups, software companies, cloud service providers and multinational enterprises. Businesses are generally free to use global infrastructure without undertaking jurisdiction-specific legal assessments.
However, the absence of clearly defined statutory criteria governing blacklisting has attracted criticism. Since the Government possesses broad discretion to identify restricted countries, organisations may face uncertainty regarding future regulatory changes. Investors often prefer transparent legal standards that allow long-term compliance planning.
Conversely, the GDPR’s adequacy framework provides greater legal certainty because decisions are based upon publicly articulated evaluation criteria. Although compliance is more resource-intensive, businesses gain confidence that recognised jurisdictions satisfy internationally accepted privacy benchmarks.
India’s model therefore prioritises economic flexibility, whereas the European model places comparatively greater emphasis upon privacy equivalence.
Global Compliance Alignment
As cross-border data transfers increasingly underpin international commerce, Indian organisations must ensure compliance not only with the DPDP Act but also with foreign regulatory requirements.
Multinational corporations operating in Europe remain subject to the GDPR even while complying with India’s DPDP framework. Consequently, businesses frequently implement multiple compliance mechanisms simultaneously.
Several internationally recognised safeguards remain particularly significant.
Standard Contractual Clauses (SCCs) continue to be the primary legal instrument for transferring personal data from the European Union to jurisdictions lacking adequacy decisions. These clauses impose contractual obligations upon both exporters and importers of personal data and ensure enforceable rights for affected individuals.
Binding Corporate Rules (BCRs) facilitate intra-group transfers among multinational corporations by establishing uniform privacy standards applicable across all affiliated entities. Once approved by the relevant supervisory authority, BCRs provide an efficient mechanism for continuous international data transfers.
The OECD Privacy Guidelines promote principles including accountability, transparency, purpose limitation, data quality, and security safeguards. Although non-binding, these principles have significantly influenced national privacy legislation worldwide and continue to shape international regulatory cooperation.
Similarly, Convention 108+ represents the only legally binding international treaty dedicated to data protection and cross-border transfers. It encourages interoperable privacy frameworks and trusted international data flows among participating jurisdictions.
India’s DPDP framework demonstrates increasing alignment with these global developments by permitting cross-border transfers while preserving governmental authority to impose targeted restrictions where necessary. Rule 15 of the DPDP Rules further empowers the Central Government to prescribe specific requirements relating to transfers to foreign States or entities under their control, reflecting an evolving, risk-based approach.
Practical Challenges for Indian Businesses
Despite its comparatively liberal framework, several implementation challenges remain.
First, uncertainty surrounding future government notifications may complicate compliance planning. Organisations investing in long-term cloud infrastructure may be required to reconfigure data architecture if important jurisdictions are subsequently restricted.
Secondly, businesses operating across multiple jurisdictions must simultaneously comply with different regulatory frameworks. For instance, an Indian technology company serving European customers may need to satisfy both the DPDP Act and GDPR requirements, including SCCs or other recognised safeguards.
Thirdly, highly regulated sectors such as banking, insurance, healthcare and telecommunications remain subject to sector-specific localisation or confidentiality obligations that operate independently of the DPDP Act. Section 16 itself preserves the applicability of laws imposing a higher degree of protection or additional restrictions.
Finally, increasing reliance on artificial intelligence, machine learning and global cloud infrastructure requires organisations to maintain sophisticated governance mechanisms, vendor due diligence, cybersecurity controls and continuous monitoring of international regulatory developments.
Recommendations
To enhance the effectiveness of India’s cross-border transfer framework, several measures merit consideration.
First, the Central Government should publish objective criteria governing blacklisting decisions. Transparency regarding the factors considered—such as privacy legislation, cybersecurity standards, reciprocity and national security—would improve regulatory certainty.
Secondly, India may consider adopting a hybrid framework combining its existing blacklisting model with voluntary adequacy partnerships for trusted jurisdictions. Such an approach could facilitate international trade while strengthening confidence in India’s privacy ecosystem.
Thirdly, sector-specific guidance should clarify how the DPDP Act interacts with financial, healthcare, telecom and other regulatory regimes. Harmonisation would reduce compliance complexity for businesses operating across multiple sectors.
Finally, organisations should adopt internationally recognised privacy governance frameworks, including comprehensive data mapping, contractual safeguards, vendor risk assessments, privacy impact assessments and robust cybersecurity practices. Alignment with global best practices will enable Indian businesses to participate more effectively in international digital markets.
Conclusion
The Digital Personal Data Protection Act, 2023 marks a significant evolution in India’s approach to regulating cross-border data transfers. By replacing strict localisation proposals with a predominantly blacklisting framework, the legislation seeks to balance privacy protection with economic growth, technological innovation and international digital trade.
India’s approach offers considerable commercial flexibility and reduces compliance burdens for organisations engaged in global business. Nevertheless, the framework’s long-term success will depend upon transparent implementation, well-defined governmental criteria, and continued harmonisation with evolving international privacy standards.
As digital commerce becomes increasingly borderless, regulatory interoperability rather than complete uniformity will likely define the future of global data governance. India’s challenge lies in preserving national sovereignty and protecting individual privacy while remaining an attractive destination for international investment and cross-border digital innovation. If implemented with transparency, accountability and predictable regulatory guidance, the DPDP framework has the potential to position India as a leading participant in the emerging global data governance ecosystem.