DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

India's DPDP Act 2023 does not mandate GDPR-style Standard Contractual Clauses (SCCs) as a precondition for transferring personal data abroad. Because the Act uses a negative-list model, transfers out of India are generally permitted unless the government restricts a country — so there is no SCC-equivalent adequacy gap to bridge. However, contractual clauses are still strongly advisable: the data fiduciary remains responsible for personal data after it leaves India, so a data processing agreement covering security, breach notification, processing limits and audit rights is essential. This tool checks what contract clauses your specific India transfer actually needs.

Do You Need SCC-Style Clauses for India Transfers?

GDPR needs Standard Contractual Clauses; the DPDP Act works differently. See whether your India cross-border transfers need SCC-style clauses, and what your contracts should cover instead.

Check what contract clauses your India transfer needs

What your India cross-border transfer contract should cover

Does the DPDP Act require Standard Contractual Clauses like GDPR?

No — and this is a frequent point of confusion for companies used to GDPR. Under GDPR, transferring personal data to a country without an adequacy decision requires an approved transfer mechanism, most commonly the Standard Contractual Clauses (SCCs). The SCCs exist to bridge the gap created by GDPR's default restriction on international transfers. The DPDP Act 2023 does not have that default restriction. It uses a negative-list model under which transfers of personal data out of India are generally permitted unless the Central Government notifies a country as restricted. Because there is no adequacy gap to bridge, there is no DPDP requirement for an SCC-equivalent instrument as a precondition to transfer.

That does not mean contracts are optional. The DPDP Act keeps the data fiduciary responsible for personal data even after it is transferred abroad, which makes a robust data processing agreement essential — not to authorise the transfer, but to control it. The right clauses bind the receiving party to purpose limitation, security, breach notification aligned to the DPDP Rules 2025, sub-processor control, deletion and audit rights.

What should India transfer clauses actually contain?

A DPDP-appropriate data processing agreement looks similar in spirit to a GDPR DPA but is framed around DPDP concepts. It should use the Act's terminology (Data Fiduciary, Data Processor, Data Principal), require the receiving party to apply reasonable security safeguards, oblige prompt breach notification so the fiduciary can meet its Board and Data-Principal notification timelines, control sub-processing and onward transfers, and provide for deletion or return of data and for audit and cooperation. For sensitive data — financial, health, children's — or where a party is a Significant Data Fiduciary, the clauses should be tightened, and the agreement should confirm that no sector-specific localisation direction (such as RBI's payment-data rules) restricts the flow.

Companies that already have GDPR SCCs or a GDPR-style DPA are not starting from scratch — those instruments cover much of the ground and can be adapted with an India-specific addendum rather than replaced. Niti Bharat drafts and reviews DPDP-aligned data processing agreements and transfer clauses for IT exporters, GCCs and MNC subsidiaries as part of its fixed-price compliance work, so cross-border relationships are documented and defensible well before the expected May 2027 enforcement date.

Get the India transfer clause checklist (free)

A practical PDF listing the clauses a DPDP-aligned cross-border data processing agreement should contain, plus a guide to adapting existing GDPR SCCs for India transfers.

Frequently Asked Questions

Does the DPDP Act require Standard Contractual Clauses for transfers abroad?+
No. Because the DPDP Act uses a negative-list transfer model, transfers out of India are generally permitted unless a country is restricted by government notification — so there is no SCC-style requirement to authorise a transfer. Contractual clauses are still strongly advisable to control the transfer, but they are not a precondition for it the way GDPR SCCs are.
Can I use my existing GDPR SCCs for India transfers?+
As a starting point, yes. GDPR SCCs cover much of what a DPDP data processing agreement needs, but they are framed around GDPR concepts. It is best to adapt them with an India-specific addendum covering DPDP definitions, breach notification to the Data Protection Board, and monitoring for restricted-country notifications, rather than assuming they suffice unchanged.
If clauses are not required, why bother with a contract at all?+
Because the data fiduciary remains legally responsible for personal data even after it leaves India. Without a contract binding the receiving party to security, breach notification and processing limits, you carry the exposure for their mistakes with no contractual recourse. A data processing agreement controls that risk.
What clauses matter most for sensitive-data transfers?+
For financial, health or children's data, or where a Significant Data Fiduciary is involved, prioritise explicit security standards, tight breach-notification timelines, sub-processor control, deletion/return obligations, and a confirmation that no sector-specific localisation direction (such as RBI's payment-data rules) restricts the transfer.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Does DPDP Apply to Synthetic Data in India?Does the DPDP Act Apply to Foreign Companies?DPDP 90-Day Implementation TrackerWearable & Health-Tracker Data Under DPDP IndiaSee all Reference & Checklists tools →📝 DPDP for Recruitment Staffing📝 What Rights Do Individuals Have DPDP