One Step LawOne Step Law
  • Home
  • Data Privacy
  • Case Commentaries
  • Blockchain
  • Cyber Crime
One Step LawOne Step Law
  • Home
  • Data Privacy
  • Case Commentaries
  • Blockchain
  • Cyber Crime
Search
  • Home
  • Data Privacy
  • Case Commentaries
  • Blockchain
  • Cyber Crime
Follow US
  • Blog
  • Contact
  • Complaint
  • Advertise
One Step Law > Blog > Data Privacy > DPDP Act > Cross Border Data Transfer > Cross-Border Data Transfer Under the DPDP Act, 2023
Cross Border Data TransferData PrivacyDPDP Act

Cross-Border Data Transfer Under the DPDP Act, 2023

Sakshi Srivastava
Last updated: September 1, 2026 1:18 pm
By
Sakshi Srivastava
Share
6 Min Read

In a globally connected digital economy, businesses routinely transfer personal data across national borders. Cloud storage, international payment systems, global HR platforms, customer support services and multinational business operations may all involve personal data moving outside India. The Digital Personal Data Protection Act, 2023 (DPDP Act) provides a framework for regulating such transfers while allowing businesses to operate in an increasingly interconnected digital environment.

Contents
What Does the DPDP Act Say About Cross-Border Transfers?What Do the DPDP Rules, 2025 Provide?What Should Businesses Consider?Conclusion

Unlike some data protection regimes that prescribe detailed adequacy mechanisms or standard contractual clauses for every international transfer, the DPDP Act adopts a comparatively flexible approach to cross-border data transfers.

What Does the DPDP Act Say About Cross-Border Transfers?

The principal provision governing international transfers is Section 16 of the DPDP Act. It provides that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a particular country or territory outside India.

This means that the DPDP Act does not impose a general requirement that all personal data must remain within India. Instead, cross-border transfers are permitted unless a particular destination is restricted by the Central Government, subject to other applicable Indian laws.

Section 16 also expressly recognises that other laws may prescribe a higher degree of protection or impose additional restrictions on the transfer of particular categories of personal data or on particular Data Fiduciaries.

Therefore, organisations cannot assess international transfers under the DPDP Act in isolation. Sector-specific requirements, contractual obligations and other applicable laws may also need to be considered.

What Do the DPDP Rules, 2025 Provide?

The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025, provide additional requirements concerning personal data processed outside India.

Rule 14 provides that where personal data is processed by a Data Fiduciary in India, or outside India in connection with offering goods or services to Data Principals in India, any transfer of such personal data outside India is subject to requirements that the Central Government may specify regarding making that data available to a foreign State, or to a person or entity under the control of, or an agency of, such a State.

This distinction is important. The Rules focus particularly on circumstances in which personal data may become available to foreign governments or entities controlled by them, rather than establishing a blanket prohibition on transferring data overseas.

What Should Businesses Consider?

Businesses routinely using overseas cloud providers, processors or group companies should map where personal data is stored, accessed and transferred.

Organisations should consider:

  • identifying all international data flows;
  • determining whether any transfer is subject to sector-specific restrictions;
  • reviewing contracts with overseas Data Processors;
  • implementing appropriate technical and organisational security measures;
  • assessing whether foreign authorities could obtain access to the data; and
  • maintaining appropriate records of international processing arrangements.

The DPDP framework therefore requires organisations to understand not only where data is transferred, but also who can access it, for what purpose and under what legal framework.

Conclusion

The DPDP Act adopts a relatively flexible approach to cross-border data transfers, rather than imposing blanket data localisation. However, this flexibility does not mean that international transfers can be undertaken without oversight.

Businesses must monitor restrictions notified by the Central Government, comply with other applicable laws and ensure that appropriate contractual and security safeguards are in place.

As international data flows continue to increase, cross-border data governance will become an important part of DPDP compliance. Organisations that proactively map and review their international data transfers will be better positioned to manage regulatory, contractual and privacy risks while continuing to operate effectively in the global digital economy.

TAGGED:Cross Border Data TransferData PrivacyDPDP Act
Share This Article
Facebook Copy Link Print
Previous Article Data Protection Board of India Under the DPDP Act, 2023
Next Article Data Breach Notifications Under the DPDP Act, 2023
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related Posts

Classic Coffee

The Ultimate Guide to Brewing French Press Coffee

Classic Coffee

How to Make a Classic Irish Coffee at Home

Classic Coffee

Brewing the Perfect Pot of Drip Coffee

Classic Coffee

How to Brew the Perfect Cup of Espresso at Home

Classic Coffee

Crafting a Delicious Mocha: Tips and Tricks

Classic Coffee

How to Create a Perfectly Balanced Americano

FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow

You Might Also Like

Sector-Specific Data Privacy: Education and the DPDP Act

6 Min Read

Sector-Specific Data Privacy: Healthcare and the DPDP Act

6 Min Read

KSA PDPL Compliance: Key Obligations for Businesses

6 Min Read

KSA PDPL: Understanding Saudi Arabia’s Personal Data Protection Law

6 Min Read
One Step Law
Embark on a flavorful expedition through the rich history of coffee, from the velvety depths of a perfectly brewed espresso to the luxurious foam of a classic cappuccino.
  • Blog
  • Contact
  • Complaint
  • Advertise
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?