Cross-border data transfer under the DPDP Act
Updated 26 Sep 2026 · 5min read · Reviewed by ConsentLo's DPDP audit team
Global cloud platforms and offshore teams move personal data out of India every day. The DPDP Act takes a permissive approach, with important exceptions. Here is how it works.
The default: transfers are allowed
Section 16 of the DPDP Act lets a Data Fiduciary transfer personal data outside India, except to countries or territories that the Central Government restricts by notification. This is often called a negative-list approach, in contrast to the GDPR's adequacy model.
Stricter laws still apply
The Act does not override other laws that give a higher degree of protection or restrict transfers more strictly. Sectoral rules, such as RBI's requirement to store payment system data in India, continue to apply alongside the DPDP Act.
What the DPDP Rules, 2025 add
The Rules allow transfers subject to any requirements the Central Government specifies by order about making personal data available to a foreign State or its agencies. Significant Data Fiduciaries may also have to keep specified personal data in India, based on the recommendations of a Government committee.
A practical transfer checklist
For each transfer outside India, record:
- The destination country and the processor or group company receiving the data.
- Whether the country is on any restricted list.
- Whether a sectoral rule requires the data to stay in India.
- The contract that binds the recipient, and its security safeguards.
- Whether you are, or may become, a Significant Data Fiduciary.
Frequently asked questions
Does the DPDP Act require data localisation?
Not generally. Transfers are allowed except to restricted countries, but sectoral rules and measures for Significant Data Fiduciaries can require some data to stay in India.
Can we use a cloud provider outside India?
Yes, unless the destination is restricted by notification or a sectoral rule requires local storage. Record the transfer and bind the provider by contract.