Does India require data to stay within Indian borders under DPDP Rules 2025? India does not impose blanket data localisation under the DPDP Act 2023. Rules 16-17 of the DPDP Rules 2025 adopt a whitelist approach: MeitY will publish a list of approved countries to which personal data can be transferred. Transfers to countries not on this whitelist are effectively blocked without adequate safeguards. Certain sectors — especially payments regulated by RBI — face stricter, independent localisation rules that operate separately from DPDP.
Free Tool — No Sign-up Required
India Data Localisation Checker: Does Your Data Need to Stay in India Under DPDP Rules 2025?
Answer 4 quick questions and find out if your cross-border data transfer is compliant — with specific safeguards and next steps.
100% FreeNo data collectedCovers Rules 16-17Enforcement: 13 May 2027
1Data Type
2Destination
3Recipient
4Result
Step 1 — What type of personal data are you transferring?
Select all data categories that apply. Your selection determines what safeguards are required.
Please select at least one data type to continue.
Step 2 — Where is the data going?
Select the transfer destination that best describes your situation.
2
Transfer destination
If you transfer to multiple countries, select the highest-risk destination
Please select a transfer destination to continue.
Step 3 — Who is receiving the data?
The recipient relationship determines what contractual safeguards are required.
3
Recipient type
Please select a recipient type to continue.
Download Cross-Border Transfer Compliance Template
Get our ready-to-use DPA template, Transfer Impact Assessment checklist, and cross-border transfer register — pre-mapped to DPDP Rules 16-17.
✓
Thank you! We'll send your template to the email provided within 2 hours.
Legal disclaimer: This tool provides a preliminary, high-level assessment based on publicly available information about the Digital Personal Data Protection Act, 2023 and DPDP Rules 2025. It does not constitute legal advice and should not be relied upon as such. The MeitY whitelist of approved countries has not yet been published; this tool reflects expected regulatory intent. Please consult a qualified legal professional for advice specific to your situation.
Current Status: India's Cross-Border Data Transfer Rules (DPDP Rules 2025)
India's Digital Personal Data Protection Act 2023 does not mandate blanket data localisation. Instead, the Government has adopted a whitelist (positive list) approach under Rules 16 and 17 of the DPDP Rules 2025: MeitY will notify specific countries to which personal data of Indian residents may be transferred.
Rules 16 and 17 — What They Say
Rule 16
Empowers the Central Government to notify countries/territories to which a Data Fiduciary may transfer personal data. Transfers outside the notified list require additional safeguards determined by the Government.
Rule 17
Permits transfers to certain entities — including government bodies — even without whitelist approval, provided specific conditions are satisfied. Research and public interest transfers are addressed here.
Whitelist Status
As of mid-2026, MeitY has not yet published the final whitelist. The whitelist is expected to include countries with adequacy-equivalent data protection regimes (EU/EEA, UK, Japan, Singapore). Until notification, organisations should treat all cross-border transfers as requiring a robust Data Processing Agreement (DPA) and consider conducting a Transfer Impact Assessment (TIA).
What Safeguards Are Required?
For transfers to whitelisted countries: a Data Processing Agreement (DPA) binding the recipient to DPDP-equivalent obligations is standard practice. For non-whitelisted countries: transfer is effectively blocked unless MeitY provides a specific pathway. A Transfer Impact Assessment evaluates the legal environment of the destination and documents the risks and mitigations.
Important — RBI Payment Data: RBI's data localisation mandate for payment data is separate from DPDP and is more strict. Payment data (card data, transaction data) processed by payment aggregators and system providers must be stored only in India under RBI's Storage of Payment System Data circular (2018, updated 2019). This obligation exists independent of DPDP compliance and is already in force.
Frequently Asked Questions
Does India have strict data localisation under DPDP?
⌄
India does not mandate blanket data localisation under the DPDP Act 2023. Instead, Rules 16-17 of the DPDP Rules 2025 take a whitelist approach: MeitY will publish a list of approved countries to which personal data may be transferred. Transfers to countries not on the whitelist are effectively blocked without adequate safeguards such as a Data Processing Agreement (DPA) with a Transfer Impact Assessment. Certain data — particularly payment data regulated by the RBI — faces stricter, independent localisation requirements that operate separately from DPDP.
Which countries are on India's data transfer whitelist?
⌄
As of mid-2026, MeitY has not published the final whitelist of approved countries under DPDP Rules 2025. The whitelist is expected to include countries with adequate data protection frameworks such as EU/EEA member states, the UK, Japan, Singapore, and similar jurisdictions. Until the whitelist is formally notified, organisations should treat all cross-border transfers as requiring additional safeguards — including robust Data Processing Agreements — regardless of the destination country.
Can I use US-based cloud servers for Indian customer data?
⌄
This depends on whether the US is included in MeitY's approved whitelist, which is yet to be published. For cloud providers like AWS, Google Cloud, or Azure, using an India-region deployment (e.g., ap-south-1 for AWS) keeps data within India and avoids the cross-border transfer question entirely. If you use a non-India region, you will need to ensure the destination country is whitelisted and that appropriate Data Processing Agreements (DPAs) are in place with the cloud provider. Most major cloud providers already offer GDPR-standard DPAs which can be adapted.
What is a Transfer Impact Assessment?
⌄
A Transfer Impact Assessment (TIA) is a documented evaluation of the risks posed by transferring personal data to a foreign country. It analyses: (1) the legal landscape of the destination country — including government surveillance laws and available remedies for data subjects; (2) the contractual safeguards in place such as Standard Contractual Clauses or a Data Processing Agreement; and (3) whether the transfer can proceed safely given those protections. TIAs are required under DPDP Rules 2025 when transferring to countries needing additional safeguards, and are modelled on the GDPR transfer impact assessment framework developed post-Schrems II.
Does DPDP apply to data sent to a parent company abroad?
⌄
Yes. Transfers of personal data from an Indian entity to its foreign parent company or group companies are covered by DPDP Rules 16-17. The fact that the recipient is related to the sender does not provide an exemption. You must ensure the destination country is on MeitY's approved whitelist (once published) and that a Data Processing Agreement is in place. The DPA must bind the parent company to DPDP-equivalent obligations for all personal data received from India. Intra-group data transfer agreements are the standard mechanism used by multinationals to handle this.
Every Sunday
The Sunday DPDP Brief
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.