Back to articles
DPDP Act

Cross-Border Data Transfers Under the DPDP Act

The DPDP Act flips the model — transfers are allowed by default, except to notified 'negative-list' countries. Here's how to prepare.

April 2, 2025 8 min read Vrushali Borade

The Negative-List Model

Section 16 of the DPDP Act takes a strikingly permissive approach to cross-border data transfers. Unlike GDPR, which prohibits transfers unless adequacy, standard contractual clauses or binding corporate rules apply, the DPDP Act permits transfers to any country by default — except those the Central Government specifically notifies as restricted.

As of publication, no country has been placed on the negative list, meaning transfers to the United States, European Union, Singapore, United Kingdom and elsewhere are permitted without additional formalities under the DPDP Act itself. This is likely to be temporary; a notified list is widely expected during 2025-26.

Sectoral Localisation Overlays

The permissive DPDP position does not displace sector-specific data localisation. The Reserve Bank of India's 2018 directive requires payment system data to be stored only in India. IRDAI mandates that insurance policyholder data be maintained in India. SEBI's cloud framework restricts where regulated entities may host trading and demat data.

MeitY's earlier draft e-commerce rules and the CERT-In 2022 directions on log retention add further overlays. A financial services or health-tech company must therefore reconcile the DPDP Act's permissive default with the stricter sectoral position — and where they conflict, the sectoral rule prevails.

Your inter-company data-sharing agreements, standard contractual clauses and vendor DPAs should reference both the DPDP Act and the applicable sectoral rules, and should include audit-right, sub-processor notification and breach-notification clauses that satisfy both regimes.

Maintain a Live Transfer Register

Best practice — and, we anticipate, forthcoming Rules requirement — is to maintain a live 'data transfer register' listing every third-party processor and sub-processor, its physical processing location, the categories of personal data shared, the lawful basis, the contractual safeguards in place, and the date of the last vendor risk assessment.

For a typical SaaS business the register will include cloud infrastructure (AWS, GCP, Azure regions), CRM (Salesforce, HubSpot), analytics (Mixpanel, Amplitude), email (SendGrid, Postmark), support (Zendesk, Intercom), and payment (Stripe, Razorpay). Each row should be reviewed at least annually and whenever a vendor is added, removed or changes its processing location.

Practical Steps to Take Now

Run a vendor inventory this quarter. Update your Data Processing Agreements to reflect the DPDP Act's definitions and to bind sub-processors to equivalent obligations. Flag any transfers into jurisdictions likely to appear on a future negative list — historically these are countries where India has strategic security concerns — and design a fallback processing location for each.

If you are a Significant Data Fiduciary or expect designation, plan for an Indian primary or hot-standby region for regulated data categories.

Cross-BorderTransfersLocalisation

Have questions on this topic?

Book a confidential consultation with Vrushali Borade.

Book Consultation