DPDP Cross-Border Data Transfer: How Section 16 Actually Works
Section 16 permits transfers outside India by default, subject to country restrictions by notification. Rule 15, sectoral overlays, and six compliance steps.
On This Page
Store customer data in an Indian cloud region and run analytics in a European one, and you are transferring personal data outside India. Under Section 16 of the DPDP Act 2023, that transfer is now a regulated act. The regulation is lighter than most compliance teams assume, and less predictable than they would like.
What Section 16 Says
The section is two sub-sections long. The first carries the model:
“The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.” (Section 16(1))
India has chosen a negative-list approach. Transfers are permitted by default, to every jurisdiction. The Central Government holds the power to restrict specific countries by notification. A transfer becomes unlawful only when the destination is notified.
As of July 2026, no restriction notification has been issued. That is not a reason to ignore the section. The power exists, it can be exercised at any time, and a notification may arrive with a short window to reroute data flows.
Rule 15: The Operative Layer
The DPDP Rules 2025 operationalise Section 16 through Rule 15:
“Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.” (Rule 15)
Read it carefully. The rule’s concern is not the transfer itself but access by foreign States and their agencies. The government can specify requirements, by general or special order, governing when transferred data may be made available to a foreign government or entities under its control. No such order has been published as of July 2026. When one arrives, it will bind every Data Fiduciary transferring data abroad, which is why the transfer inventory in the steps below is the preparation that matters.
Sectoral Mandates Are the Stricter Layer
The DPDP framework does not dilute sectoral data localisation. For regulated finance, the binding constraints predate the Act:
- RBI payment data localisation. RBI’s 2018 directive requires payment system data to be stored only in India. That is a storage mandate, not a transfer restriction, and it is stricter than anything in Section 16. It continues to apply to banks, NBFCs, and payment system operators.
- Other sectoral instruments. Securities and insurance regulators impose their own record-keeping and localisation expectations on the entities they supervise.
The operating rule for a regulated entity: your compliance baseline is the stricter instrument. Section 16 sets the general floor; your sector regulator usually sets the real constraint. The RBI-DPDP conflict framework covers how sectoral mandates and DPDP obligations bind the same records.
Where the Risk Sits for SaaS and Cloud-First Companies
For a SaaS company, cross-border transfer is not an edge case. It is the operating model.
Cloud regions. Primary storage in AWS Mumbai keeps data in India. Cross-region replication, disaster recovery to Singapore, or a global CDN caching personal data moves it out.
Third-party processors. The analytics stack, the email provider, the support desk: each may process personal data outside India. The Data Fiduciary remains responsible for processing done on its behalf, so a vendor’s hosting decision is your compliance surface.
Distributed teams. Engineers outside India with production database access constitute a transfer surface. Access controls and logging are mitigations, not exemptions.
B2B processing. If you process Indian clients’ data as a processor, the Section 16 obligation sits with your client, and their contracts will push the compliance requirement down to you.
DPDP vs GDPR on Transfers
| Dimension | GDPR | DPDP Act |
|---|---|---|
| Default position | Restricted unless adequacy or safeguards proven | Permitted unless the country is restricted by notification |
| Mechanism | Adequacy decisions, SCCs, BCRs | Government notification under Section 16(1); requirements under Rule 15 |
| Sensitive data | Special categories with stricter transfer rules | No separate category; all personal data treated alike |
| Sectoral overlap | Limited | Significant: RBI and other sectoral localisation mandates sit on top |
The DPDP model is simpler to operate and harder to predict. GDPR compliance is slow to establish and stable afterwards. Section 16 compliance is trivial today and can change with one gazette notification. The full GDPR comparison covers the other axes.
Six Steps Before Enforcement
Penalty enforcement is expected from May 2027; the compliance timeline has the full sequence. Six steps put cross-border flows in order inside that window.
- Map every cross-border flow. Systems, cloud regions, processors and their hosting locations, and overseas access. The data inventory is the foundation; a transfer you have not mapped is a transfer you cannot defend.
- Identify your sectoral constraints first. If RBI localisation or another sectoral mandate applies, it is the baseline. Section 16 analysis comes second.
- Audit processor contracts. Location commitments, sub-processor disclosure, region-lock options, and breach notification obligations aligned with the 72-hour framework.
- Apply technical safeguards. Encryption in transit and at rest, minimum-necessary access for overseas teams, audit logs on cross-border access events.
- Prepare for a restriction notification. Identify the alternative region for each critical system, and assign an owner to monitor gazette notifications. A restriction with a short window is the scenario to have rehearsed.
- Document every transfer. Destination, purpose, safeguards, and basis, in a record reviewed whenever a vendor or geography changes. This is the artefact an inquiry will ask for.
What a Violation Costs
A transfer to a restricted jurisdiction breaches Section 16 and falls in the residual tier of the penalty Schedule, up to Rs 50 crore. The Act’s headline Rs 250 crore tier belongs to security safeguard failures under Section 8(5), not to transfer violations. The exposure that compounds the penalty is evidentiary: an entity that cannot show where its data went, and under what safeguards, has no defence to present.
Where ConsentOS Fits
Cross-border compliance rests on knowing where personal data goes and being able to prove the basis for each flow. The ConsentOS Data Inventory portal records each data category with its systems and processors, consent records tie every category to the purpose it was collected for, and the conflict-of-law documentation register holds the statutory basis where a sectoral mandate governs a record. When a restriction notification arrives, the entities that respond in days rather than quarters will be the ones with this map already built.
Run the Gap Assessment to score your position, cross-border flows included.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
DPDP Act vs GDPR: 5 Key Differences for MNCs Operating in India
Both laws protect personal data. They differ in scope, consent models, penalty structures, and cross-border transfer rules. This is what multinational companies operating in India need to know.
7 min read
Industry GuidesDPDP Compliance for SaaS Companies in India (2026)
Most SaaS companies are both: Data Fiduciary for their own customer data, Data Processor for client data. What each role demands under the DPDP Act 2023.
12 min read
Industry GuidesRBI-DPDP Retention Conflict: KYC Erasure Rules for Indian Fintechs
The RBI and PMLA mandate five-year KYC retention. The DPDP Act requires erasure on request. For Indian fintechs and NBFCs, these obligations are in direct conflict. This article explains the Legal Obligation Override framework that resolves both simultaneously.
9 min read
Implementation GuidesBuild a Personal Data Inventory for DPDP Compliance (India 2026)
Step-by-step guide to auditing and documenting personal data flows for India's DPDP Act. The data inventory is the foundation of every DPDP compliance programme.
12 min read