Skip to content

Advocate Nitin Kumar Vashista

Home » Blog » DPDP Act Cross-Border Data Transfer: What’s Actually Allowed

DPDP Act Cross-Border Data Transfer: What’s Actually Allowed

DPDP Act Cross-Border Data Transfer What's Actually Allowed

A client called me last month, sounding a bit panicked. “We use an American cloud provider, our support team sits in the Philippines — are we even allowed to send customer data there under this new law?” He’d been putting off asking for weeks, half-expecting the answer to be a long, complicated no.

I get some version of this question almost every week now. And honestly, I get why people are nervous — if your business runs on foreign servers, international vendors, offshore teams, or global SaaS tools (and at this point, whose doesn’t?), the idea of a new data law feels like it’s going to slow everything down.

So here’s the part that usually surprises people: India’s approach to cross-border data transfer under the DPDP Act is actually one of the more relaxed regimes out there, especially compared to the GDPR horror stories most business owners have half-heard about.

 

The Short Answer: Yes, You Can Send Data Abroad

Under Rule 15 of the DPDP Rules, 2025, a Data Fiduciary — the legal term for any business or entity that decides how and why personal data gets processed — is allowed to send personal data outside India. That’s just the default position. No special approval, no extra paperwork, unless the government has specifically said otherwise for a particular country or situation.

Lawyers call this a “negative list” or “blacklist” model, but here’s the plain-English version: every country is fine to send data to, unless the central government has specifically ruled it out. And right now, as of writing this, the government hasn’t formally blacklisted anyone. That could change with a single notification, but today, the door is open.

 

How This Is Different From GDPR

If you’ve ever dealt with GDPR, this probably feels almost too easy — and honestly, that’s the point. GDPR works the opposite way: it’s a “whitelist” system, where you can only send EU data to countries the EU has pre-approved, or you have to bolt on extra legal paperwork like Standard Contractual Clauses just to justify the transfer.

The DPDP Act flips that thinking completely. You don’t have to prove a country is “adequate” or safe enough. The law just assumes the transfer is fine, unless the government has drawn a specific line around a country, a sector, or a type of data. And this wasn’t an accident — India’s economy leans heavily on IT exports, cloud computing, fintech, and outsourcing. A GDPR-style locked-down regime would have hurt the very industries the country depends on.

But the Government Can Still Step In

Don’t read “generally allowed” as “no rules apply, ever.” The government has kept real power here. It can:

  • Block transfers to a specific country entirely
  • Put conditions on how sensitive categories — health records, children’s data — can move to a particular jurisdiction, without touching anything else
  • Impose extra restrictions on what the law calls “Significant Data Fiduciaries” — basically the bigger platforms handling large volumes of data — when it comes to certain government-specified data leaving India

So think of it less as “anything goes” and more as “open by default, with a switch the government can flip for specific cases.” One notification can tighten things for a particular country or data type without touching the rules for everyone else.

The Timeline You Actually Need to Track

This is the part where I lose most clients halfway through explaining it, so let me keep it simple:

  • The government’s notification on 13 November 2025 switched on different parts of the DPDP framework in stages — not everything at once
  • Full compliance on cross-border transfers kicks in roughly 18 months after that date, which puts us around May 2027
  • Consent-related rules become mandatory earlier, from 13 November 2026 — so that deadline arrives first
  • Until DPDP fully takes over, the older 2011 IT Rules (the SPDI Rules) are still technically in force, and they’re actually stricter — they require sensitive personal data to only go to countries offering “comparable” protection

What this really means: you’re standing in a transition period right now. The rules that apply today aren’t quite the rules that’ll apply in 2027, and the businesses that wait until the deadline to figure this out are the ones who’ll be scrambling when it actually lands.

What You Should Actually Do About This Right Now

I know “full enforcement is still a while away” makes this easy to put on the back burner. I’d push back on that a little. A few things worth doing now, not later:

Actually map where your data goes. Almost every client I’ve walked through this with is surprised once we lay it out properly — cloud storage sitting in one country, customer support running from another, analytics tools processing data somewhere else entirely, backups tucked away in a fourth location. You genuinely can’t manage what you’ve never mapped.

Go back and check your vendor contracts. If a cloud provider or SaaS tool is quietly moving your customers’ data across borders on your behalf, your agreement with them needs to say so clearly — including what happens if the government restricts that destination down the line.

Keep a written record. Note down what data goes where, through which vendor, under what safeguards. This isn’t just a compliance checkbox — more and more, enterprise clients and investors are asking these exact questions before they’ll even sign with you.

Be ready to move fast if needed. Because this is a “negative list” system, the government could restrict a specific country with very little warning. If you already know your data flows inside out, you can react in a day. If you don’t, you’ll spend that same day just figuring out what’s even affected.

Why I Wouldn’t Brush This Off

Penalties under the DPDP Act can go up to ₹250 crore for serious violations, and a mishandled cross-border transfer sits squarely in that danger zone. But honestly, the bigger issue isn’t even the fine — it’s that customers, investors, and enterprise partners are increasingly asking about your data practices before they’ll do business with you at all.

If there’s one thing I’d want you to take away from this: cross-border data transfer under the DPDP Act really isn’t the obstacle most people assume it to be. But “generally allowed” doesn’t mean “safe to ignore.” Get it documented and managed now, while there’s still runway — not later, when enforcement has already tightened and you’re playing catch-up.

If you’d like help mapping your cross-border data flows or reviewing your vendor contracts against DPDP Act requirements, this is exactly the kind of work I do with businesses across Delhi NCR through my DPDP Act Compliance Consulting services. If you’d rather have someone on it long-term instead of a one-time review, take a look at DPO services too. Book a free consultation — Advocate Nitin Kumar Vashista, DPDP Act & GDPR Compliance Consultant, Gurgaon.

Leave a Reply

Your email address will not be published. Required fields are marked *