DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

India's DPDP Act 2023 does NOT use GDPR-style adequacy decisions. Instead it uses a negative-list (blacklist) model: personal data may generally be transferred out of India unless the Central Government notifies a restriction on a specific country or territory. As of now, no such restriction list has been widely notified, so most transfers are open by default — but that can change, and sector regulators (like the RBI on payment data) can impose their own localisation rules on top. This tracker explains the model and checks how exposed a specific data flow is if a destination is later restricted.

DPDP Adequacy & Restricted-Country Tracker

India does not issue adequacy decisions the way the EU does — it uses a negative list. See exactly how the model works and how exposed your transfers are if a country is later restricted.

Check your transfer exposure under India's negative-list model

How to stay ahead of India's negative-list transfer model

Does India issue DPDP adequacy decisions like the EU?

This is the single most common misconception about Indian data transfers, so it is worth stating plainly: India does not issue DPDP adequacy decisions in the GDPR sense. Under the DPDP Act 2023, personal data may generally be transferred outside India unless the Central Government notifies a restriction on a specific country or territory. This is a negative-list (or blacklist) model — the default is that transfers are permitted, and the government intervenes only to restrict named destinations. There is no white-list of pre-approved 'adequate' countries that a data fiduciary must check against before every transfer.

That design has a practical consequence: most India-outbound flows are open today, but they carry a latent risk. If a destination country you depend on is later added to a restriction list, flows that were compliant can become non-compliant with little notice. Tracking this — and knowing which of your flows would be affected — is exactly what this tracker is built to help with, and what Niti Bharat monitors on behalf of clients with significant cross-border operations.

Sector rules stack on top of DPDP's negative list

Even though DPDP itself is permissive on transfers, it is not the only rule that applies. India's sector regulators impose their own data-localisation and transfer requirements that sit on top of the DPDP negative-list model. The most prominent example is the Reserve Bank of India's directive requiring payment system data to be stored within India — an obligation that applies regardless of what DPDP permits. Companies handling financial, health, or telecom data may face additional sector-specific constraints that are stricter than DPDP's default.

This layering is where many mid-market companies get caught out: they confirm DPDP allows a transfer and stop there, missing an RBI or sector rule that prohibits or localises the same data. Niti Bharat's fixed-price DPDP engagements (₹75K–₹3.2L) map each cross-border flow against both the DPDP negative-list position and any applicable sector regulator rule, so a transfer that looks fine under DPDP is not quietly breaching a localisation directive — well ahead of India's expected May 2027 enforcement date.

Get the India transfer & restricted-country tracker (free)

A living PDF explaining India's negative-list model, the sector localisation rules that stack on top (RBI and others), and a data-flow mapping template to track your own exposure.

Frequently Asked Questions

Has India published a list of restricted countries under DPDP?+
As of now, no broad restricted-country list has been widely notified under the DPDP Act. The mechanism exists — the Central Government can restrict transfers to specific countries — but the default position is that transfers are permitted. This can change, so the practical task is to stay ready to respond if a restriction is notified.
Is India's transfer model the same as GDPR adequacy?+
No. GDPR uses adequacy decisions and safeguards to permit transfers to specific approved destinations. India uses the opposite logic — a negative list — where transfers are open by default unless the government restricts a named country. Treating India as if it uses GDPR-style adequacy leads to the wrong compliance approach.
Do sector rules like RBI localisation override DPDP?+
They operate alongside DPDP, not instead of it. The RBI's payment-data localisation directive, for example, requires payment system data to be stored in India regardless of DPDP's permissive transfer default. If a sector rule is stricter, you must follow the stricter rule — DPDP permission does not excuse a localisation breach.
What should I do if a country I rely on is later restricted?+
Have a data-flow map and an alternate routing plan ready in advance. If a destination is restricted, you will need to know immediately which flows are affected and how to re-route or localise them. Companies without a data map are the most exposed, because they cannot even identify what a restriction would break.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Adjudication OfficerDPDP Applicability by Company Size IndiaDPDP Breach Notification Decision ToolSensitive Personal Data Compliance AuditSee all Reference & Checklists tools →📝 DPDP for Credit Bureaus📝 How to Train Employees DPDP