International data transfer is integral to the operation of multinational companies and Indian businesses using global technology infrastructure. Personal data is transferred through cloud services, SaaS platforms, and other sources.

The Digital Personal Data Protection Act, 2023 (DPDP Act) provides the principal framework for cross-border data transfer. This makes it important for the organization to understand whether it can transfer information or which restriction is applied.

What is Cross-Border data transfer?

Cross-border data transfer means moving personal data between countries. Since data protection laws vary by region, these transfers must follow applicable privacy regulations and security standards to keep data safe during transfer and storage.

 

What does the DPDPA say about Cross-Border data transfers?

Section 16 of the DPDP Act explains when and how personal data can be transferred or processed outside India. It gives the government the power to restrict transfers to certain countries or territories.

Transfers are allowed by default – a “blacklist” approach

The DPDPA generally allows personal data to be transferred outside India.

Section (16): The Central Government can restrict a Data Fiduciary from transferring personal data to certain countries or territories outside India.

It means that the country is specifically restricted by the government. A Data Fiduciary is permitted to transfer data. Means DPDP Act follows a “blacklist” model: countries can be prohibited rather than every country needing prior approval.

Other stricter Indian laws still apply

Section 16(2): Section 16 does not override any Indian Law which provides stronger or stricter requirements for transferring personal data outside India.

So, if a specific law, for example, a law governing banking or health data, has stricter cross-border transfer requirements. These stricter norms will continue apply.

Special Exemption under Section 17(1)(d)

There is also an important exemption for data belonging to people outside India.

If the personal data relates to an individual outside India, and the data is processed under a contract between a person in India and a person outside India.

Then chapter || and ||| and Section 16 of the DPDPA generally do not apply to that processing.

It is applicable to the outsourcing/BPO arrangements, where an Indian organization processes the personal data of foreign individuals for an overseas organization.

How to Ensure Cross-Border Data Transfer Compliance Under the DPDPA?

Organisations can achieve cross-border compliance by going beyond the basic checks like restricted countries and maintaining controls on the data flow.

The below steps can be undertaken by the organisation to ensure that there is compliance with cross-border transfer of data under the DPDPA-

Mapping of international data flows: It is essential to understand what personal data is shared and transferred outside the jurisdiction of the company domain, for what purpose, and which third parties have access to it.

Check for restrictions: The organisation must review the latest government notification (Section 16) for any restrictions specified on the transfer of personal data to a particular country or territory before sharing personal data.

Review of vendors: The company must have a standard operating procedure for overseas vendors to ensure that personal data is collected, processed, stored, accessed, and protected appropriately. In addition, the organisation needs to periodically evaluate such vendors to check compliance with these procedures.

Limiting access: The organisation should mandate that overseas vendors and employees have access to only the personal data required to perform their specific tasks. Also, the data access should be revoked when it is no longer required.

Enhancing security measures: Organisation should implement appropriate data security and protection measures like access control, encryption of data, authentication, monitoring, and secure data-transfer mechanisms.

Updating contracts: Contracts with overseas vendors should include terms and conditions related to data protection, security, and breach notification, among others.

Maintaining documentation: The organisation must maintain sufficient documentation related to international transfers, including the processing of personal data, reasons for transferring the data, vendors, countries, and methods and mechanisms used for protecting personal data.

Constant revision of requirements: Data privacy laws and regulations governing cross-border data transfer are subject to changes; hence, companies must be alert to the new requirements issued by the government or sector-specific regulatory authorities.

Conclusion

Cross-border data transfers are now a normal part of how many businesses operate, but moving personal data between countries requires careful planning. India’s DPDPA provides a framework for international data transfers while allowing the government to place restrictions where required. Businesses also need to consider other applicable laws, sector-specific requirements, and the practices of their overseas vendors.

A clear understanding of where data goes, who can access it, and how it is protected can make cross-border data management easier. By regularly reviewing data flows, vendors, contracts, security measures, and regulatory changes, organisations can reduce unnecessary risks and keep their international data practices aligned with applicable requirements.

FAQs

Ques: Does the DPDPA ban sending personal data outside India?

Ans: No, Transfers are allowed unless the Central Government restricts a specific country or territory.

Ques: Is DPDPA cross-border data transfer the same as GDPR?

Ans: No, GDPR requires specific safeguards for international transfers, while the DPDPA generally allows transfers unless restricted.

Ques: Do businesses need government approval to transfer data abroad?

Ans: Generally, no. Businesses need to check government restrictions and other applicable Indian laws.

Ques: What happens if data is transferred to a restricted country?

Ans: It may result in a violation of the applicable transfer restriction and regulatory action.

Ques: Does using an international cloud provider count as a cross-border transfer?

Ans: It can, especially when personal data is stored, accessed, or processed outside India.

Kajal Mourya

I'm a Content Strategist specializing in compliance, fintech, identity verification, and cybersecurity. I simplify complex regulations into practical, research-backed content that helps businesses make informed decisions, improve digital trust, and stay ahead of evolving industry and compliance requirements.