India's DPDP Act 2023 does NOT use GDPR-style adequacy decisions. Instead it uses a negative-list (blacklist) model: personal data may generally be transferred out of India unless the Central Government notifies a restriction on a specific country or territory. As of now, no such restriction list has been widely notified, so most transfers are open by default — but that can change, and sector regulators (like the RBI on payment data) can impose their own localisation rules on top. This tracker explains the model and checks how exposed a specific data flow is if a destination is later restricted.
India does not issue adequacy decisions the way the EU does — it uses a negative list. See exactly how the model works and how exposed your transfers are if a country is later restricted.
This is the single most common misconception about Indian data transfers, so it is worth stating plainly: India does not issue DPDP adequacy decisions in the GDPR sense. Under the DPDP Act 2023, personal data may generally be transferred outside India unless the Central Government notifies a restriction on a specific country or territory. This is a negative-list (or blacklist) model — the default is that transfers are permitted, and the government intervenes only to restrict named destinations. There is no white-list of pre-approved 'adequate' countries that a data fiduciary must check against before every transfer.
That design has a practical consequence: most India-outbound flows are open today, but they carry a latent risk. If a destination country you depend on is later added to a restriction list, flows that were compliant can become non-compliant with little notice. Tracking this — and knowing which of your flows would be affected — is exactly what this tracker is built to help with, and what Niti Bharat monitors on behalf of clients with significant cross-border operations.
Even though DPDP itself is permissive on transfers, it is not the only rule that applies. India's sector regulators impose their own data-localisation and transfer requirements that sit on top of the DPDP negative-list model. The most prominent example is the Reserve Bank of India's directive requiring payment system data to be stored within India — an obligation that applies regardless of what DPDP permits. Companies handling financial, health, or telecom data may face additional sector-specific constraints that are stricter than DPDP's default.
This layering is where many mid-market companies get caught out: they confirm DPDP allows a transfer and stop there, missing an RBI or sector rule that prohibits or localises the same data. Niti Bharat's fixed-price DPDP engagements (₹75K–₹3.2L) map each cross-border flow against both the DPDP negative-list position and any applicable sector regulator rule, so a transfer that looks fine under DPDP is not quietly breaching a localisation directive — well ahead of India's expected May 2027 enforcement date.
A living PDF explaining India's negative-list model, the sector localisation rules that stack on top (RBI and others), and a data-flow mapping template to track your own exposure.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.