Businesses operating across countries routinely move personal data between India and overseas systems. Customer information may be stored by a global cloud provider, employee records may be accessed by an international headquarters, or an Indian business may use SaaS platforms whose infrastructure is located outside the country.
Each of these activities involves cross-border data transfer and requires organizations to understand where the Digital Personal Data Protection (DPDP) Act permits international processing and where additional restrictions may apply.
For businesses, the practical question is therefore whether a particular cross-border data transfer arrangement under the DPDPA is permitted, restricted by another law, or subject to additional controls.
TL;DR
- The DPDP Act, 2023 allows cross-border data transfers but gives the Central Government the power to restrict transfers to specified countries or territories under Section 16.
- Stricter requirements under other Indian laws continue to apply under Section 16(2), including sector-specific data localization and transfer requirements.
- Rule 15 of the DPDP Rules, 2025 provides a framework for restrictions relating to making personal data available to foreign States or entities under their control.
- The DPDPA does not impose blanket data localization for all personal data, although targeted requirements may apply to Significant Data Fiduciaries and regulated sectors.
- Businesses should map international data flows and assess applicable restrictions before transferring personal data outside India.
What Does the DPDPA Say About Cross-Border Data Transfers?
The DPDPA does not establish a blanket prohibition on sending personal data outside India. Section 16 instead gives the Central Government the power to restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India.
This means the DPDPA adopts a conditional approach to the cross border transfer of data. An overseas transfer may be permitted, but organizations must still determine whether a government notification, sector-specific law, or other applicable requirement imposes additional restrictions.
Section 16 — Processing of Personal Data Outside India
Section 16 forms the statutory foundation for cross border data transfer under DPDPA.
Under Section 16(1) of the Digital Personal Data Protection Act, 2023, the Central Government may, by notification, restrict a Data Fiduciary from transferring personal data for processing to a specified country or territory outside India.
This establishes a restriction-based approach to international data transfers. In other words, the DPDPA does not require organizations to obtain prior approval before transferring personal data overseas or limit transfers only to an approved list of countries. As of August 2026, no country or territory has been notified as restricted under Section 16.
However, this does not mean that every overseas transfer is automatically compliant. The organization must separately ensure that the underlying processing has a valid basis under the DPDPA, such as consent under Section 6 or a permitted legitimate use under Section 7. It must also consider any stricter Indian law that applies to the data or the organization.
Section 16(2) — Sectoral and Other Stricter Laws Still Apply
Section 16(2) prevents the general permission for overseas transfers from overriding stricter requirements under other Indian laws.
Section 16(2) of the DPDPA states that Section 16 does not restrict the applicability of any law in force in India that provides a higher degree of protection or greater restriction on transferring personal data outside India.
This is particularly important for businesses operating in regulated sectors. A transfer may be permitted under Section 16 while still being subject to data localization, storage, or transfer restrictions under another applicable law or regulatory framework.
Where a sectoral regulator, such as the Reserve Bank of India (RBI), the Insurance Regulatory and Development Authority of India (IRDAI), or the Securities and Exchange Board of India (SEBI), already requires certain data to remain within India, that requirement continues to apply alongside the DPDPA. Regulated organizations must assess both layers of obligation before assuming a transfer is permissible.
What Do the DPDP Rules, 2025 Say About Cross-Border Transfers?
Rule 15 operationalizes Section 16. It provides that personal data may be transferred outside India, subject to compliance with requirements the Central Government may specify by general or special order, particularly in respect of making such data available to a foreign state, or to a person or entity under its control, or acting as its agency.
- A general order may apply broadly, restricting transfers to an entire country.
- A special order may be narrower in scope, targeting a specific sector, entity, or category of data, such as health data transferred to a particular foreign-government-linked recipient.
Rule 15 does not itself designate any restricted country. It establishes the mechanism the government would use, and its focus is on transfers reaching a foreign state or a state-controlled entity, rather than on ordinary commercial data flows between private organizations.
Is Cross-Border Data Transfer Allowed Under the DPDPA?
Yes. Cross-border data transfer is allowed under the DPDPA, but transfers can be restricted. Section 16 permits the Central Government to restrict transfers to specified countries or territories, while Section 16(2) preserves stricter requirements under other Indian laws.
Businesses should therefore assess every international data flow against three questions:
- Is the destination subject to a restriction issued under the DPDPA framework?
- Does another Indian law impose stricter transfer or localization requirements?
- What personal data is being transferred, who receives it, and for what purpose?
This approach is especially important when businesses depend on international infrastructure, because a single application can involve production servers, backup systems, analytics platforms, subprocessors, and overseas administrative access.
Does the DPDPA Require Data Localization in India?
The DPDPA does not contain a default data localization mandate for general commercial personal data. Many compliance teams confuse cross-border transfer restrictions with data localization, but these two concepts serve distinct regulatory functions.
Data localization requires personal data to be created, processed, or stored exclusively within physical servers located inside India. Cross-border transfer restrictions, by contrast, allow personal data to leave the country freely while reserving the sovereign right to block transfers to specific blacklisted nations.
The DPDPA relies on this restriction-based approach rather than mandatory localization for cross border data protection. However, specific sectors within India still enforce absolute data localization through their own specialized regulatory frameworks.
When Can Data Localization or Transfer Restrictions Apply?
Significant Data Fiduciaries and Cross-Border Data Transfers
The DPDP Rules introduce a targeted localization mechanism for Significant Data Fiduciaries (SDFs). Rule 13(4) requires an SDF to ensure that personal data specified by the Central Government, based on a committee's recommendations, and the traffic data relating to its flow are not transferred outside India.
This is a targeted requirement rather than a universal localization rule. SDFs should therefore design data architectures that can accommodate India-only processing or storage for categories that may subsequently be specified.
Cross-Border Data Transfers and Sector-Specific Regulations
Section 16(2) means organizations must assess the DPDPA alongside other Indian laws and regulatory directions. This is particularly relevant in sectors where regulators have already established data storage or transfer requirements.
Businesses should consider additional requirements applicable to:
- Financial Services: Non-banking financial companies (NBFCs) and credit bureaus face strict data residency guidelines enforced by financial watchdogs.
- Healthcare: Patient health records and electronic medical logs require localized storage to safeguard sensitive health metrics under national health digital frameworks.
- Telecommunications: Telecom infrastructure logs and subscriber call detail records (CDRs) are bound by strict local storage rules under the Telecommunications Act.
- Government & Public Sector: Public sector agencies and government contractors handling citizen records are barred from storing data in offshore cloud facilities.
- Critical Infrastructure: Operators of critical national infrastructure, such as power grids and transportation networks, must maintain all operational data within domestic boundaries.
Banking and payments
The RBI's Storage of Payment System Data requirements are an important example of sector-specific localization. Payment-system data must be stored in systems located in India, although certain cross-border transactions can have a foreign component stored abroad. The RBI also permits payment processing outside India subject to conditions, including bringing the relevant data back to India within the prescribed timeframe.
A payment business therefore cannot rely only on the general DPDPA position when evaluating an overseas processor or cloud architecture.
Insurance
Insurance businesses should separately assess applicable IRDAI requirements relating to data storage, security, outsourcing, and technology operations. Where those requirements impose greater restrictions on overseas processing or storage, they continue to apply alongside the DPDPA framework.
Other regulated sectors should similarly evaluate their own regulatory requirements before approving international processing arrangements.
What Are the DPDPA Exemptions Relevant to Cross-Border Processing?
The negative list approach keeps routine compliance with DPDP cross border data transfer rules relatively straightforward, though certain categories of processing fall outside the ordinary restriction framework. Based on the DPDPA's structure and prevailing practitioner guidance, these commonly include processing that is:
- Necessary to establish, exercise, or defend a legal right or claim
- Carried out by Indian courts, tribunals, or regulatory bodies performing judicial or quasi-judicial functions
- Required for the prevention, detection, investigation, or prosecution of offences in India
- Conducted in respect of data principals located outside India, under a contract with a person located outside India
- Connected to a court-approved merger, amalgamation, demerger, or other corporate restructuring
- Necessary to assess the financial status of a loan defaulter, subject to applicable disclosure laws
These exemptions are most relevant to legal and M&A teams handling litigation, regulatory inquiries, or corporate restructuring involving cross-border data privacy.
How Should Businesses Comply With Cross-Border Data Transfer Requirements?
A practical DPDP compliance program should combine legal analysis with visibility into where personal data is collected, stored, accessed, and transferred. Before approving a cross border data transfer, businesses should assess both the DPDP Act requirements and any stricter obligations that apply to their industry or data.
- Map international data flows: Identify the data collected in India, processing locations, cloud regions, subprocessors, backup locations, and overseas access paths.
- Classify the transfers: Distinguish ordinary international processing from flows involving regulated data, SDF requirements, foreign-State access, or sector-specific restrictions.
- Review vendors and contracts: Check data-processing terms, subprocessor locations, security obligations, audit rights, deletion provisions, and change-notification requirements.
- Assess localization requirements: Determine whether RBI, IRDAI, government contracts, or other applicable rules require specified data to remain in India.
- Monitor regulatory changes: Track Central Government notifications and sectoral directions that could change permitted destinations or impose additional controls.
- Maintain evidence: Document data-flow assessments, vendor reviews, transfer decisions, approvals, and technical safeguards to support ongoing compliance.
Because non-compliance with applicable DPDP obligations can result in significant financial consequences, organizations should also understand the penalties under the DPDP Act and incorporate regulatory risk into their data-transfer governance.
Cross-Border Data Transfer Examples for Indian Businesses
Indian Company Using a Global Cloud or SaaS Provider
An Indian retail organization using a globally hosted CRM or ERP platform routinely stores customer names, contact details, and purchase history on servers located outside India, a straightforward instance of processing of personal data outside India. This is permitted by default under the DPDPA, provided the organization has a valid data processing agreement in place and discloses the arrangement in its privacy notice.
The scale of this pattern is reflected in the growth of India-based cloud infrastructure itself: Google Cloud opened its second Indian region in Delhi-NCR in July 2021 to offer low-latency infrastructure and support data residency for domestic organizations.
However, many Indian businesses continue to rely on international SaaS hosting for primary workloads, relying on contractual and technical safeguards to ensure cross border data privacy compliance.
Indian Subsidiary Sharing Data With Global Headquarters
Indian arms of multinational technology companies frequently share user data with their global group entities for centralized processing, and this pattern has drawn direct regulatory scrutiny in India.
In November 2024, the Competition Commission of India imposed a penalty of Rs. 213.14 crore on Meta in connection with WhatsApp's 2021 privacy policy, which had made the sharing of user data collected in India with other Meta group companies a condition of continued access to the service.
While this was a competition law finding rather than a DPDPA enforcement action, it illustrates the level of regulatory attention that intra-group, cross-border data sharing arrangements can attract. It also underscores why a compliant intercompany transfer agreement and clear data flow documentation are essential even where no DPDPA restriction currently applies to the destination.
Regulated Business or SDF With Localization Requirements
Regulated financial entities operating in India must obey sector-specific storage directives that override general DPDPA permissions under Section 16(2).
In March 2023, the Securities and Exchange Board of India issued its Framework for Adoption of Cloud Services by SEBI Regulated Entities, establishing mandatory data residency rules that require cloud data centers hosting market infrastructure, depositories, and mutual funds to be physically located within India.
Similarly, the Reserve Bank of India has maintained strict enforcement over payment data localization and inter-entity operational boundaries, as reflected in its early 2024 directives halting operations at Paytm Payments Bank due to persistent supervisory concerns.
Where a financial institution is also classified as a Significant Data Fiduciary and subject to localized data restrictions under DPDPA Rule 13(4), it must navigate multi-layered localization mandates alongside sector-specific regulations.
How miniOrange Helps
Meeting DPDP cross-border data transfer requirements is not a one-time legal exercise. It requires ongoing visibility into where personal data resides, who can access it, and whether it crosses a border that now carries a compliance obligation.
miniOrange's DPDP Compliance Solution supports this through data discovery and classification tools that map personal data across cloud, SaaS, and on-premise systems, enabling organizations to identify which data sets warrant cross-border scrutiny. The platform also provides consent and notice management, DPIA and RoPA documentation, and breach management workflows aligned with DPDPA timelines.
For organizations with additional sector-specific obligations, such as BFSI or healthcare entities also subject to RBI or IRDAI requirements, miniOrange's legal advisory and DPO-as-a-service offerings support the development of a defensible, audit-ready compliance posture around cross-border data flows.
Conclusion
Cross-border data flows are integral to how modern Indian businesses operate, with personal data moving through cloud platforms, SaaS providers, global vendors, and group infrastructure. India’s DPDP Act brings these activities within a defined data protection framework, making cross border data privacy an increasingly important part of compliance.
The real challenge is maintaining visibility into where personal data goes, who can access it, and what restrictions apply. By mapping data flows, evaluating third parties, and monitoring regulatory changes, organizations can manage cross border data transfer requirements with greater confidence and build a privacy program that remains adaptable as India’s data protection landscape evolves.
FAQs
1. Is cross-border transfer of personal data allowed under the DPDPA?
Yes. Section 16 allows personal data to be transferred outside India, while permitting the Central Government to restrict transfers to specified countries or territories. Stricter requirements under other Indian laws can continue to apply.
2. Is data localization mandatory for all companies under the DPDPA?
A: No, the DPDPA does not mandate universal data localization for all companies. Personal data can be transferred internationally unless the Central Government explicitly restricts a specific country or sector rules apply.
3. What is the difference between cross-border data transfer and data localization?
Cross border data transfer refers to moving or processing personal data outside India. Data localization requires specified data to be stored or processed within India. A business can therefore be subject to transfer restrictions without being required to localize every category of personal data.
4. Do sector-specific localization requirements still apply?
Yes. Section 16(2) expressly preserves Indian laws that provide greater protection or impose greater restrictions on overseas transfers. The RBI's payment-system data requirements are one example.
5. Are Significant Data Fiduciaries subject to additional requirements?
Potentially. The DPDP Rules provide for specified personal data and related traffic data to be kept from being transferred outside India where required by the Central Government.
6. What should businesses check before transferring personal data overseas?
Businesses should map the relevant data flow, identify the destination and recipient, review vendor and subprocessor arrangements, check sector-specific localization requirements, assess applicable government restrictions, and document the resulting compliance decision.



Leave a Comment