DPDPA Section 16: Unpacking India's Negative-List Approach to Cross-Border Data Transfers
The Digital Personal Data Protection Act (DPDPA), 2023, has fundamentally reshaped India’s data privacy landscape. Among its most distinctive provisions is Section 16, which governs the cross-border transfer of personal data. Unlike many global frameworks that mandate explicit permission or complex mechanisms for such transfers, the DPDPA adopts a “negative-list” model, signaling a pragmatic and trust-based approach to international data flows. As of July 2026, understanding this framework is critical for every Indian business operating in an interconnected world.
The DPDPA’s Permissive Stance on Cross-Border Transfers
Section 16 of the DPDPA stipulates that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to “such countries or territories outside India as it may deem fit.” The crucial implication here is that, in the absence of such a notification, cross-border transfers are generally permissible. This stands in stark contrast to frameworks like the European Union’s GDPR, which requires an “adequacy decision” for data transfers to third countries or the implementation of specific safeguards like Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). India’s approach prioritizes ease of business and global data flow, placing the onus on the government to identify and restrict problematic jurisdictions rather than requiring prior approval for all transfers.
As of today, July 26, 2026, the Central Government has yet to issue a notification establishing a negative list of countries or territories. This means that, from a DPDPA perspective, Indian data fiduciaries can transfer personal data to any country, provided they adhere to all other obligations under the Act. These obligations include ensuring data principal consent where required (Section 7), adhering to purpose limitation (Section 6), and implementing reasonable security safeguards to prevent data breaches (Section 8). The underlying principle is that data fiduciaries remain accountable for the protection of personal data, regardless of its geographical location (Section 9).
Navigating Sectoral Overlays and Existing Restrictions
While DPDPA Section 16 offers a broadly permissive framework, it is imperative for Indian businesses to remember that the DPDPA operates alongside, and often defers to, specific sectoral regulations. Section 4(2) of the DPDPA clarifies that its provisions are in addition to, and not in derogation of, any other law for the time being in force. This means that existing data localization or residency requirements imposed by sectoral regulators continue to apply.
For instance, the Reserve Bank of India (RBI) has long mandated that payment system data be stored only in India, with specific requirements for foreign leg processing. Similarly, the Securities and Exchange Board of India (SEBI) has issued guidelines on data residency for market intermediaries. The Insurance Regulatory and Development Authority of India (IRDAI) also has norms concerning the handling and storage of policyholder data. These specific directives, often predating the DPDPA, impose stricter conditions on cross-border transfers for particular types of data. Therefore, a financial institution or an insurance provider cannot simply rely on the absence of a DPDPA negative list; they must first comply with their respective regulator’s mandates. Any future DPDPA negative list or accompanying rules are likely to either incorporate or explicitly refer to these existing sectoral restrictions.
Anticipating the Negative List: What Lies Ahead?
The eventual publication of a negative list by the Central Government remains a key anticipated development. The criteria for inclusion on such a list are not yet formally defined, but they could encompass a range of factors. These might include countries with inadequate data protection laws, those known for lax enforcement, jurisdictions posing national security risks, or even those engaged in adversarial geopolitical actions.
Businesses should prepare for the possibility that the negative list could be dynamic, subject to amendments based on evolving international relations, technological advancements, or assessments of data protection regimes globally. This necessitates continuous monitoring of government notifications and proactive risk assessments of their international data processing activities.
Practical Takeaway
For Indian businesses, General Counsels, and Data Protection Officers, the current landscape under DPDPA Section 16 presents both opportunity and responsibility. While the absence of a negative list currently allows for greater flexibility in cross-border data transfers, it does not absolve fiduciaries of their fundamental obligations.
Key actions for businesses include:
- Data Mapping: Conduct thorough data mapping to identify all personal data collected, where it is stored, and where it is transferred.
- Sectoral Compliance: Prioritize compliance with specific data localization or residency mandates from regulators like RBI, SEBI, and IRDAI, which supersede the general DPDPA provisions on transfers.
- Robust Contracts: Implement comprehensive data processing agreements with overseas recipients, ensuring they contractually commit to DPDPA principles, including security safeguards, purpose limitation, and assistance with data principal rights requests.
- Monitor Notifications: Stay vigilant for any notifications from the Central Government regarding the negative list, and be prepared to adapt data transfer strategies accordingly.
- Risk Assessment: Regularly assess the data protection posture of recipient countries and entities, even if they are not on a negative list, to mitigate reputational and compliance risks.
By proactively addressing these areas, Indian enterprises can leverage the DPDPA’s flexible cross-border transfer model while ensuring robust data protection and compliance.