Skip to main content
Compliance Areas

DPDP Cross-Border Data Transfer: How Section 16 Actually Works

Section 16 permits transfers outside India by default, subject to country restrictions by notification. Rule 15, sectoral overlays, and six compliance steps.

9 min read
On This Page

Store customer data in an Indian cloud region and run analytics in a European one, and you are transferring personal data outside India. Under Section 16 of the DPDP Act 2023, that transfer is now a regulated act. The regulation is lighter than most compliance teams assume, and less predictable than they would like.

What Section 16 Says

The section is two sub-sections long. The first carries the model:

“The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.” (Section 16(1))

India has chosen a negative-list approach. Transfers are permitted by default, to every jurisdiction. The Central Government holds the power to restrict specific countries by notification. A transfer becomes unlawful only when the destination is notified.

As of July 2026, no restriction notification has been issued. That is not a reason to ignore the section. The power exists, it can be exercised at any time, and a notification may arrive with a short window to reroute data flows.

Rule 15: The Operative Layer

The DPDP Rules 2025 operationalise Section 16 through Rule 15:

“Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.” (Rule 15)

Read it carefully. The rule’s concern is not the transfer itself but access by foreign States and their agencies. The government can specify requirements, by general or special order, governing when transferred data may be made available to a foreign government or entities under its control. No such order has been published as of July 2026. When one arrives, it will bind every Data Fiduciary transferring data abroad, which is why the transfer inventory in the steps below is the preparation that matters.

Sectoral Mandates Are the Stricter Layer

The DPDP framework does not dilute sectoral data localisation. For regulated finance, the binding constraints predate the Act:

  • RBI payment data localisation. RBI’s 2018 directive requires payment system data to be stored only in India. That is a storage mandate, not a transfer restriction, and it is stricter than anything in Section 16. It continues to apply to banks, NBFCs, and payment system operators.
  • Other sectoral instruments. Securities and insurance regulators impose their own record-keeping and localisation expectations on the entities they supervise.

The operating rule for a regulated entity: your compliance baseline is the stricter instrument. Section 16 sets the general floor; your sector regulator usually sets the real constraint. The RBI-DPDP conflict framework covers how sectoral mandates and DPDP obligations bind the same records.

Where the Risk Sits for SaaS and Cloud-First Companies

For a SaaS company, cross-border transfer is not an edge case. It is the operating model.

Cloud regions. Primary storage in AWS Mumbai keeps data in India. Cross-region replication, disaster recovery to Singapore, or a global CDN caching personal data moves it out.

Third-party processors. The analytics stack, the email provider, the support desk: each may process personal data outside India. The Data Fiduciary remains responsible for processing done on its behalf, so a vendor’s hosting decision is your compliance surface.

Distributed teams. Engineers outside India with production database access constitute a transfer surface. Access controls and logging are mitigations, not exemptions.

B2B processing. If you process Indian clients’ data as a processor, the Section 16 obligation sits with your client, and their contracts will push the compliance requirement down to you.

DPDP vs GDPR on Transfers

DimensionGDPRDPDP Act
Default positionRestricted unless adequacy or safeguards provenPermitted unless the country is restricted by notification
MechanismAdequacy decisions, SCCs, BCRsGovernment notification under Section 16(1); requirements under Rule 15
Sensitive dataSpecial categories with stricter transfer rulesNo separate category; all personal data treated alike
Sectoral overlapLimitedSignificant: RBI and other sectoral localisation mandates sit on top

The DPDP model is simpler to operate and harder to predict. GDPR compliance is slow to establish and stable afterwards. Section 16 compliance is trivial today and can change with one gazette notification. The full GDPR comparison covers the other axes.

Six Steps Before Enforcement

Penalty enforcement is expected from May 2027; the compliance timeline has the full sequence. Six steps put cross-border flows in order inside that window.

  1. Map every cross-border flow. Systems, cloud regions, processors and their hosting locations, and overseas access. The data inventory is the foundation; a transfer you have not mapped is a transfer you cannot defend.
  2. Identify your sectoral constraints first. If RBI localisation or another sectoral mandate applies, it is the baseline. Section 16 analysis comes second.
  3. Audit processor contracts. Location commitments, sub-processor disclosure, region-lock options, and breach notification obligations aligned with the 72-hour framework.
  4. Apply technical safeguards. Encryption in transit and at rest, minimum-necessary access for overseas teams, audit logs on cross-border access events.
  5. Prepare for a restriction notification. Identify the alternative region for each critical system, and assign an owner to monitor gazette notifications. A restriction with a short window is the scenario to have rehearsed.
  6. Document every transfer. Destination, purpose, safeguards, and basis, in a record reviewed whenever a vendor or geography changes. This is the artefact an inquiry will ask for.

What a Violation Costs

A transfer to a restricted jurisdiction breaches Section 16 and falls in the residual tier of the penalty Schedule, up to Rs 50 crore. The Act’s headline Rs 250 crore tier belongs to security safeguard failures under Section 8(5), not to transfer violations. The exposure that compounds the penalty is evidentiary: an entity that cannot show where its data went, and under what safeguards, has no defence to present.

Where ConsentOS Fits

Cross-border compliance rests on knowing where personal data goes and being able to prove the basis for each flow. The ConsentOS Data Inventory portal records each data category with its systems and processors, consent records tie every category to the purpose it was collected for, and the conflict-of-law documentation register holds the statutory basis where a sectoral mandate governs a record. When a restriction notification arrives, the entities that respond in days rather than quarters will be the ones with this map already built.

Run the Gap Assessment to score your position, cross-border flows included.

Know where you stand on DPDP compliance

Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.