Cross-Border Transfer and Data Localisation
Reading module · approx 12 min
The DPDP Act's approach to cross-border data transfer is a significant departure from the earlier Data Protection Bill's strict localisation requirements. The Act adopts a whitelist model, with the government designating countries to which transfer is permitted.
The transfer framework
Under the DPDP Act, personal data may be transferred to countries or territories outside India that the central government notifies as permitted destinations. The government may impose conditions on such transfers and may restrict transfer to specific countries based on bilateral agreements, adequacy assessments, or national security considerations.
Until the government notifies the whitelist of permitted countries, practitioners should monitor MeitY guidance and the DPDP Rules for interim positions on cross-border transfer. In the meantime, organisations with existing cross-border data flows should document those flows, identify the data types and destinations involved, and prepare to adjust as the Rules are notified.
What the Act does not say
The DPDP Act does not mandate data localisation for most categories of personal data. This is a significant policy departure from previous drafts of the legislation. However, sector-specific data localisation requirements under other laws continue to apply: RBI's payment data localisation requirements; SEBI requirements for market-related data; IRDAI requirements for insurance data; and CERT-In requirements for logs and records.
Data Processing Agreements for cross-border transfers
When a Data Fiduciary transfers personal data to a Data Processor outside India, the Data Fiduciary remains responsible for ensuring the Processor meets DPDP Act standards. A Data Processing Agreement (DPA) is therefore essential for cross-border outsourcing arrangements. The DPA should bind the foreign Processor to DPDP-equivalent obligations on security, breach notification, and Data Principal rights assistance.
Practical steps for cross-border compliance
Until Rules are notified, organisations should: map their cross-border data flows (what data, to which countries, for which purposes); assess whether existing standard contractual clauses or binding corporate rules can be adapted for DPDP compliance; monitor government notifications for the whitelist of permitted countries; and establish contractual mechanisms with foreign processors to ensure DPDP-equivalent protections.
Module 5 covers the Data Protection Board of India — the enforcement authority under the Act — and the penalty regime.