Cross border data transfers under DPDP
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Yes, by default. Rule 15 permits transfer subject to requirements the Central Government may specify by order about making personal data available to any foreign State or entities under its control, and section 16 lets the government restrict transfers to notified countries. No such restriction is on file on this site as of its verification date. Any Indian law with stronger transfer protection continues to apply, and localisation can reach Significant Data Fiduciaries for specified data.
Teams arriving from GDPR expect adequacy decisions and standard clauses. This framework is built differently: open by default, with government levers.
The default is permission
"Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State."
Read the structure: transfer is permitted, and the condition is meeting whatever requirements the government specifies by order about exposure to foreign states and their entities. Watching for such orders is the operational duty this creates.
The second lever: notified country restrictions
Section 16 of the Act lets the Central Government restrict transfers to notified countries or territories. No country notification is on file on this site as of its verification date; the mechanism exists whether or not it has been used.
Two additions worth knowing
Stricter Indian laws survive: section 16(2) preserves any law giving higher protection or stronger restriction for particular data or fiduciaries. And Significant Data Fiduciaries can face localisation for government specified data under Rule 13(4), including the traffic data about its flow.
What to do
If your processors are offshore, put room for these controls into contracts now; the vendor and processor checklist includes it. Coming from GDPR, see the transfer row of the gap checker for what not to assume.
Related tool
Vendor and Processor Checklist
Identify DPDP relevant actions for your vendors and Data Processors.
Open
Related tool
DPDP vs GDPR Gap Checker
If you have a GDPR program, find the DPDP specific areas that need separate review.
Open
Sources cited on this page
- [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 15, p. 30. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 16, p. 11. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, (4), p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Localisation restrictions for Significant Data Fiduciaries on government specified data.