Home Courses DPDP Act 2023 Compliance Module 4
Module 4 of 6 — DPDP Act 2023 Compliance

Cross-Border Transfer and Data Localisation

Reading module · approx 12 min

The DPDP Act's approach to cross-border data transfer is a significant departure from the earlier Data Protection Bill's strict localisation requirements. The Act adopts a whitelist model, with the government designating countries to which transfer is permitted.

The transfer framework

Under the DPDP Act, personal data may be transferred to countries or territories outside India that the central government notifies as permitted destinations. The government may impose conditions on such transfers and may restrict transfer to specific countries based on bilateral agreements, adequacy assessments, or national security considerations.

Until the government notifies the whitelist of permitted countries, practitioners should monitor MeitY guidance and the DPDP Rules for interim positions on cross-border transfer. In the meantime, organisations with existing cross-border data flows should document those flows, identify the data types and destinations involved, and prepare to adjust as the Rules are notified.

What the Act does not say

The DPDP Act does not mandate data localisation for most categories of personal data. This is a significant policy departure from previous drafts of the legislation. However, sector-specific data localisation requirements under other laws continue to apply: RBI's payment data localisation requirements; SEBI requirements for market-related data; IRDAI requirements for insurance data; and CERT-In requirements for logs and records.

Sector-specific localisation Even though the DPDP Act does not impose general data localisation, Indian businesses must comply with sector-specific requirements. RBI's payment system data rules require that all payment system data be stored exclusively in India. SEBI rules require certain market data to be maintained domestically. These rules continue in parallel with the DPDP Act and are not superseded by it.

Data Processing Agreements for cross-border transfers

When a Data Fiduciary transfers personal data to a Data Processor outside India, the Data Fiduciary remains responsible for ensuring the Processor meets DPDP Act standards. A Data Processing Agreement (DPA) is therefore essential for cross-border outsourcing arrangements. The DPA should bind the foreign Processor to DPDP-equivalent obligations on security, breach notification, and Data Principal rights assistance.

Practical steps for cross-border compliance

Until Rules are notified, organisations should: map their cross-border data flows (what data, to which countries, for which purposes); assess whether existing standard contractual clauses or binding corporate rules can be adapted for DPDP compliance; monitor government notifications for the whitelist of permitted countries; and establish contractual mechanisms with foreign processors to ensure DPDP-equivalent protections.

Module 5 covers the Data Protection Board of India — the enforcement authority under the Act — and the penalty regime.