In a globally connected digital economy, businesses routinely transfer personal data across national borders. Cloud storage, international payment systems, global HR platforms, customer support services and multinational business operations may all involve personal data moving outside India. The Digital Personal Data Protection Act, 2023 (DPDP Act) provides a framework for regulating such transfers while allowing businesses to operate in an increasingly interconnected digital environment.
Unlike some data protection regimes that prescribe detailed adequacy mechanisms or standard contractual clauses for every international transfer, the DPDP Act adopts a comparatively flexible approach to cross-border data transfers.
What Does the DPDP Act Say About Cross-Border Transfers?
The principal provision governing international transfers is Section 16 of the DPDP Act. It provides that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a particular country or territory outside India.
This means that the DPDP Act does not impose a general requirement that all personal data must remain within India. Instead, cross-border transfers are permitted unless a particular destination is restricted by the Central Government, subject to other applicable Indian laws.
Section 16 also expressly recognises that other laws may prescribe a higher degree of protection or impose additional restrictions on the transfer of particular categories of personal data or on particular Data Fiduciaries.
Therefore, organisations cannot assess international transfers under the DPDP Act in isolation. Sector-specific requirements, contractual obligations and other applicable laws may also need to be considered.
What Do the DPDP Rules, 2025 Provide?
The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025, provide additional requirements concerning personal data processed outside India.
Rule 14 provides that where personal data is processed by a Data Fiduciary in India, or outside India in connection with offering goods or services to Data Principals in India, any transfer of such personal data outside India is subject to requirements that the Central Government may specify regarding making that data available to a foreign State, or to a person or entity under the control of, or an agency of, such a State.
This distinction is important. The Rules focus particularly on circumstances in which personal data may become available to foreign governments or entities controlled by them, rather than establishing a blanket prohibition on transferring data overseas.
What Should Businesses Consider?
Businesses routinely using overseas cloud providers, processors or group companies should map where personal data is stored, accessed and transferred.
Organisations should consider:
- identifying all international data flows;
- determining whether any transfer is subject to sector-specific restrictions;
- reviewing contracts with overseas Data Processors;
- implementing appropriate technical and organisational security measures;
- assessing whether foreign authorities could obtain access to the data; and
- maintaining appropriate records of international processing arrangements.
The DPDP framework therefore requires organisations to understand not only where data is transferred, but also who can access it, for what purpose and under what legal framework.
Conclusion
The DPDP Act adopts a relatively flexible approach to cross-border data transfers, rather than imposing blanket data localisation. However, this flexibility does not mean that international transfers can be undertaken without oversight.
Businesses must monitor restrictions notified by the Central Government, comply with other applicable laws and ensure that appropriate contractual and security safeguards are in place.
As international data flows continue to increase, cross-border data governance will become an important part of DPDP compliance. Organisations that proactively map and review their international data transfers will be better positioned to manage regulatory, contractual and privacy risks while continuing to operate effectively in the global digital economy.
