Cross-border data protection
Your data can leave India. The law where it lands decides what happens next.
Section 16 of the DPDP Act permits transfer to any country the Central Government has not restricted, and no restricted list has been notified. That makes the receiving jurisdiction, not DPDP, the binding constraint on most Indian cross-border processing.
The India position
A negative list, and it is empty.
DPDP does not run an adequacy or a positive-instrument model. Section 16 permits transfer to any country except those the Central Government restricts by notification. Rule 15 sets out how such a restriction would be framed if one is ever issued — but as of this review, none has been.
The exception that matters more in practice is Rule 13(4): the Government can direct a Significant Data Fiduciary to keep specified personal data, and any traffic in it, inside India entirely. That power is narrow, discretionary, and aimed at SDFs — not a general localisation rule.
None of this displaces the sectoral rules that were already in force. The RBI's payment data localisation mandate — system data on payment transactions stored only in India — survives DPDP untouched, and it binds fintech and lending regardless of what Section 16 permits.
What this means for you
- DPDP itself is rarely the blocker on an outbound transfer.
- The receiving country's law sets the real obligation — consent standard, breach window, DPO seat.
- Sectoral India rules apply independently of where the data goes.
Jurisdictions
Where we work, stated plainly.
We do not claim the same depth everywhere. The three groups below carry different weight on the page because they carry different weight in fact.
Where we practise
India
DPDP Act, 2023
Data Protection Board of India
European Union
GDPR (Regulation 2016/679)
EDPB & Member State DPAs
United Arab Emirates
Federal Decree-Law No. 45 of 2021
UAE Data Office
Where we have delivered
Singapore
Personal Data Protection Act 2012
Personal Data Protection Commission
Saudi Arabia
Personal Data Protection Law
Saudi Data & AI Authority
United Kingdom
UK GDPR & Data Protection Act 2018
Information Commissioner's Office
Where we advise on exposure
Head-to-head comparisons
In development
The cross-border transfer checker.
Name the destination country and the data category, and get back the DPDP position, the receiving jurisdiction's requirement, and the gap between them. Not live yet — join the list to be notified when it ships.
Know where your data goes. Know what follows it there.
Operating across sectors? See sector pages →
General information, not legal advice.