DPDP cross-border data transfer
under section 16 and Rule 15.
How India's negative-list model for international transfers works, what Rule 15 and the Significant Data Fiduciary rule add, which sectoral localisation rules still bite, and how it compares with GDPR Chapter V.
Last updated Published by TryTrustableNot legal advice
How does the DPDP Act regulate cross-border data transfer?
The DPDP Act permits transfers of personal data outside India by default. Section 16 lets the Central Government restrict transfers to specific countries or territories by notification, and preserves any other Indian law that restricts transfers more strictly. There is no adequacy test and no mandatory contract template.
Section 16 of the Act has two sub-sections:
- 16(1), the negative list. The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as it notifies. Everything not notified is open
- 16(2), stricter laws survive. Nothing in section 16 limits any law in force in India that gives a higher degree of protection for, or restriction on, transfers of personal data outside India, for any data, Data Fiduciary or class of either
A notification under section 16 has to be laid before each House of Parliament under section 41, so a restriction will be visible. As of 28 September 2026 we have found none. The DPDP regulatory tracker will record one if it appears.
One exemption matters to Indian outsourcing businesses. Under section 17(1)(d), Chapter II (except section 8(1) and 8(5)), Chapter III and section 16 do not apply to personal data of people outside India processed in India under a contract with a person outside India. Security safeguards and accountability still apply; notice, consent, rights and the transfer power do not.
What does Rule 15 of the DPDP Rules require?
Rule 15 confirms that personal data may be transferred outside India, subject to one condition. The Data Fiduciary must meet any requirements the Central Government specifies, by general or special order, for making that data available to a foreign State, or to a person or entity under the control of, or an agency of, such a State.
Read Rule 15 for what it targets: access by foreign governments, not ordinary commercial transfers to a cloud region or a support centre abroad. It commences on 13 May 2027 with the other substantive rules. Until the Government issues an order under it, there is nothing further to comply with, but an order could arrive with little notice and could be special, aimed at one Data Fiduciary. A company that receives foreign government data requests should already know who handles them and on what basis.
Will Significant Data Fiduciaries have to keep data in India?
Some of it, possibly. Rule 13(4) requires a Significant Data Fiduciary to ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes, is not transferred outside India, together with the traffic data about its flow. Nothing has been specified yet.
Under Rule 13(5), the committee must include officials from MeitY and may include officials from other ministries. That makes the localisation list a Government decision, not a statutory category, and it applies only to Data Fiduciaries notified as significant. The Significant Data Fiduciary guide covers who gets notified.
Proposed, not in force. In January 2026, Business Standard reported that MeitY had proposed shortening the eighteen-month window for Significant Data Fiduciaries. Commentary on the same stakeholder consultation describes proposals to bring the cross-border provisions (Rule 13(4) and Rule 15) into force immediately, with comments sought by 4 February 2026. As of 28 September 2026 no amending notification has been published, so Rules 13 and 15 still commence on 13 May 2027.
Which sectoral data localisation rules still apply?
Section 16(2) keeps every stricter Indian law in force, so sector regulators' localisation rules sit on top of the DPDP Act. The best known is RBI's April 2018 directive on storage of payment system data, which requires payment system operators to store the entire data about the payment systems they operate only in India.
RBI's circular of 6 April 2018 (RBI/2017-18/153) gave system providers six months to comply, and covers the full end-to-end transaction details, including customer data, credentials and payment instructions. RBI's FAQs on the directive add two points that decide most architecture questions:
- There is no bar on processing payment transactions abroad, but the data must then be deleted from the foreign systems and brought back to India within one business day or 24 hours of processing, whichever is earlier
- For a cross-border transaction with a foreign and a domestic leg, a copy of the domestic component may also be stored abroad if required
Other regulators set their own storage conditions for their sectors. Check yours before assuming the DPDP default applies: the Act is the floor, not the ceiling. For fintechs, the fintech compliance guide puts the RBI, CERT-In and DPDP requirements side by side.
How does DPDP compare with GDPR Chapter V?
The two regimes start from opposite ends. The GDPR prohibits transfers outside the EEA unless a Chapter V mechanism applies, such as an adequacy decision or standard contractual clauses. The DPDP Act permits transfers unless the Government restricts a destination, and leaves stricter sectoral laws in place.
| DPDP Act 2023 and Rules 2025 | GDPR Chapter V | |
|---|---|---|
| Default | Transfer permitted (s.16(1), Rule 15). | Transfer prohibited unless Chapter V is complied with (Art. 44). |
| Country decisions | Negative list: the Government may notify restricted countries or territories. None notified as of 28 Sep 2026. | Positive list: the Commission's adequacy decisions (Art. 45). |
| Contractual route | None required for the transfer itself. Processor contracts under s.8(2) and Rule 6(1)(f) still apply. | Standard contractual clauses, binding corporate rules and other safeguards (Arts. 46–47). |
| Exceptions | Not needed while transfers are open. S.17(1)(d) disapplies s.16 for foreign nationals' data processed in India under a foreign contract. | Derogations for specific situations, such as explicit consent or contract necessity (Art. 49). |
| Foreign government access | Rule 15: requirements the Government sets on making data available to a foreign State or its agencies. | Art. 48: a foreign court or authority's order is enforceable only under an international agreement. |
| Localisation | For SDFs, data specified on a committee's recommendation stays in India (Rule 13(4)). Sectoral rules such as RBI 2018 survive (s.16(2)). | No general localisation; member-state sectoral rules exist. |
| Transfer impact assessment | Not required. | Expected in practice for SCC transfers, following the CJEU's Schrems II judgment. |
| Penalty head | Breach of s.16 falls under the ₹50 crore catch-all. | Up to €20 million or 4% of worldwide turnover (Art. 83(5)(c)). |
Summary for orientation. Section, rule and article numbers are given so each cell can be checked against the Act, the Rules and the GDPR on EUR-Lex.
The asymmetry matters for Indian companies serving Europe. Sending data out of India is mostly open. Receiving EU data in India is governed by the GDPR's rules, which usually means standard contractual clauses and a transfer assessment on the European side. The DPDP to GDPR mapping lines up the rest of the two regimes.
What should you do about cross-border transfers now?
Map where personal data leaves India, check each flow against your sector's localisation rules, put security obligations in every processor contract, and set up a way to notice a section 16 notification, a Rule 15 order or a Rule 13(4) specification the day it is published. None of those requires waiting for May 2027.
1. Map the flows. Every processor, sub-processor, cloud region and support location that receives personal data. Automated data discovery finds the data and maps how it crosses borders; tag managers on your own site are a flow too, and the free scan lists where they send data.
2. Apply the stricter law first. Payment data, and any other data a sector regulator has told you to store in India, is decided by that rule, not by section 16.
3. Contract for safeguards. Section 8(1) keeps you responsible for what your processors do, wherever they are. The DPDP data processing agreement template covers security, breach notice and erasure.
4. Keep a way to switch a destination off. A negative list can grow overnight. Know which flows would stop if a country were notified, and how fast you could move them.
Related guides: children's data and verifiable parental consent, Significant Data Fiduciary duties, data retention and erasure, how the Data Protection Board works and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.
The things people ask us
Can personal data be transferred outside India under the DPDP Act?
Yes. Section 16 lets a Data Fiduciary transfer personal data to any country unless the Central Government restricts transfers to that country by notification. We have found no such notification as of 28 September 2026. Stricter sectoral rules, such as RBI's payment data storage directive, still apply on top.
Is there a blacklist of countries under DPDP section 16?
Not yet. Section 16(1) lets the Central Government notify countries or territories to which transfers are restricted, which is why the model is called a negative list. As of 28 September 2026 we have found no notification under it. Any such notification must be laid before Parliament under section 41.
Do I need standard contractual clauses to send data out of India?
The DPDP Act does not require them. Transfers are allowed unless restricted, with no adequacy test or mandated clauses. You still need a valid contract with any Data Processor under section 8(2), and Rule 6 requires that contract to provide for reasonable security safeguards. Sending EU data into India is a separate question under the GDPR.
Does RBI require payment data to stay in India?
Yes. RBI's directive of 6 April 2018 requires payment system operators to store the entire data relating to payment systems they operate only in India. RBI's FAQs allow processing abroad, but the data must be deleted there and brought back within one business day or 24 hours, whichever is earlier. Section 16(2) of the DPDP Act keeps such stricter laws in force.
Will Significant Data Fiduciaries have to localise data?
Possibly, for specified data. Rule 13(4) requires a Significant Data Fiduciary to keep personal data specified by the Central Government, on a committee's recommendation, and the related traffic data, inside India. No such data has been specified yet. January 2026 reporting said MeitY proposed bringing this forward; that proposal was not notified as of 28 September 2026.
What does Rule 15 of the DPDP Rules require?
Rule 15 allows transfer outside India subject to one restriction: the Data Fiduciary must meet any requirements the Central Government sets, by general or special order, for making personal data available to a foreign State or an entity it controls. It commences on 13 May 2027. It targets foreign government access, not ordinary commercial transfers.
See where your site sends data before anyone agrees.
The free scan names every third-party request your pages make before consent, and where it goes. It is the quickest cross-border map you can draw.