What are the DPDP Act rules on cross-border data transfers? The DPDP Act 2023 permits cross-border transfer of personal data to countries or territories notified by the Central Government. By default, transfers to non-notified countries are restricted. The government may restrict transfers to specific countries on grounds of national security or public interest. Organisations that transfer personal data internationally — including to cloud providers, parent companies, or offshore processing centres — must verify that the destination country is on the approved list or obtain specific government permission.
The DPDP Act permits transfers by default — with traps: blacklisted destinations, sectoral localisation, and paperwork gaps. Answer 3–4 questions per data flow.
A one-page decision tree PDF + the transfer-register Excel we use in assessments: every flow, destination, mechanism and contract reference in one place.
Section 16 of the DPDP Act 2023 takes the opposite approach to GDPR: transfers of personal data outside India are permitted by default, except to countries the Central Government restricts by notification (a blacklist, versus Europe's adequacy whitelist). Two big caveats: stricter sectoral laws — like the RBI's payment-data localisation mandate — continue to prevail, and your privacy notice and processor contracts must still reflect every flow.
A transfer register: every outbound flow, its destination country, the legal capacity (fiduciary or processor), the contract that binds the recipient, and the notice disclosure. Most companies have the flows but not the register — which is the gap this worksheet closes.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.