DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Under the DPDP Act 2023, transferring personal data outside India is generally permitted — the Act uses a negative-list model, meaning transfers are allowed unless the Central Government notifies specific countries or territories as restricted. This is the opposite of GDPR's positive adequacy model. However, sector-specific rules (for example RBI directions on payment data, or SDF-specific requirements) can still restrict or localise certain data, and you remain fully responsible for the security and lawful basis of the data even after it leaves India. This checker assesses your specific transfer against these factors and flags where the real risk lies.

Cross-Border Data Transfer Risk Checker (DPDP Act)

Wondering whether you can legally move personal data abroad under the DPDP Act? Answer a few questions and get a tailored read on your cross-border transfer risk.

Check your cross-border transfer risk

Before transferring personal data out of India — a DPDP checklist

Can you legally transfer personal data abroad under the DPDP Act?

For most companies, the answer is yes. The DPDP Act 2023 adopts a negative-list approach to cross-border transfers: personal data may generally be transferred outside India, and the Central Government retains the power to notify specific countries or territories to which transfers are restricted. This is a deliberate departure from the GDPR model, where transfers are restricted by default and only permitted where an adequacy decision or an approved safeguard exists. Under the DPDP Act, absent a restricted-country notification, the transfer rule itself does not block sending data abroad.

That relative openness comes with two important caveats. First, sector-specific rules can still restrict or localise particular categories of data — the clearest example being RBI directions requiring certain payment data to be stored in India, which apply independently of the DPDP transfer rule. Second, transferring data abroad does not transfer away your responsibility for it: the data fiduciary remains accountable for the security, lawful basis and proper handling of the data even after it leaves the country.

What actually creates cross-border transfer risk under the DPDP Act?

Because the baseline permission is broad, the real risk in a cross-border transfer usually comes from three places rather than the transfer rule itself. The first is data type: sensitive categories such as financial, health and children's data can attract sector-specific restrictions and heightened obligations even when general data flows freely. The second is contractual control: because you remain responsible for the data after it leaves India, the absence of a DPDP-aligned data processing agreement with the receiving party is a genuine exposure, especially for third-party vendors and cloud providers who may onward-transfer. The third is your own status — Significant Data Fiduciaries and regulated entities face additional DPIA, audit and localisation obligations that raise the bar.

Niti Bharat helps Indian companies — IT exporters, GCCs and MNC subsidiaries in particular — assess and document their cross-border transfers so they are defensible: mapping which data goes where, confirming no restricted-country or sector direction applies, and putting the right data processing agreements in place. This work is fixed-price (₹75,000–₹3.2 lakh depending on scope) and designed to be completed well before the expected May 2027 enforcement date.

Get the cross-border transfer readiness pack (free)

A practical PDF covering how to document a DPDP-compliant cross-border transfer, a DPA clause checklist, and the sector rules (RBI and others) that can override the general permission.

Frequently Asked Questions

Does the DPDP Act ban transferring personal data outside India?+
No. The DPDP Act uses a negative-list model — transfers of personal data outside India are generally permitted, and the government may notify specific countries or territories as restricted. Absent such a notification, the transfer rule itself does not prohibit sending data abroad.
Is the DPDP transfer rule the same as GDPR adequacy?+
No — it is essentially the opposite. GDPR restricts transfers by default and permits them only via adequacy decisions or approved safeguards (a positive-list approach). The DPDP Act permits transfers by default and restricts only notified countries (a negative-list approach).
Do RBI payment-data rules still apply under the DPDP Act?+
Yes. Sector-specific rules such as RBI's payment-data storage directions operate independently of the DPDP transfer rule. Even where the DPDP Act would permit a transfer, a sector regulator can still require certain data to be stored or localised in India.
Am I still responsible for data after it leaves India?+
Yes. As the data fiduciary you remain accountable for the security, lawful basis and proper handling of personal data even after it is transferred abroad. This is why a DPDP-aligned data processing agreement with the receiving party is essential.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Data Fiduciary Obligations CheckerData Processing Legitimacy CheckerData Processor vs Fiduciary CheckerChildren's Data Consent Kit DPDP IndiaSee all Calculators tools →📝 DPDP Penalty Amount📝 DPDP Penalty Data Breach India