Post

Navigating Cross-Border Data Transfers: India's Negative-List Approach Under DPDPA Section 16

Navigating Cross-Border Data Transfers: India's Negative-List Approach Under DPDPA Section 16

As of September 2026, the Digital Personal Data Protection Act, 2023 (DPDPA) is firmly entrenched in India’s legal landscape, reshaping how personal data is handled. A critical aspect of this new regime, particularly for India’s globally integrated digital economy, is the framework governing cross-border transfers of personal data. Unlike many international counterparts, the DPDPA adopts a distinctive “negative-list” model under Section 16, offering both unique opportunities and compliance challenges for Data Fiduciaries.

The Default Permissibility: A Paradigm Shift

Under Section 16(1) of the DPDPA, the default position for cross-border transfers of personal data is one of permissibility. This means that a Data Fiduciary is generally allowed to transfer personal data outside India, unless such a transfer is restricted by the Central Government. This approach stands in stark contrast to models like the European Union’s GDPR, which operates on a “positive-list” system, requiring an adequacy decision or specific transfer mechanisms (like Standard Contractual Clauses or Binding Corporate Rules) before data can leave the EU. India’s model simplifies the initial hurdle for transfers, promoting a more fluid flow of data by default.

The Central Government’s Prerogative: Defining the Negative List

The core of India’s cross-border transfer mechanism lies in the power vested in the Central Government. Section 16(2) of the DPDPA empowers the Central Government to notify “such country or territory as may be prescribed” to which a Data Fiduciary shall not transfer personal data. While the Act itself does not explicitly detail the criteria for such prescriptions, it is understood that factors such as national security, data protection standards in the recipient jurisdiction, reciprocal arrangements, and India’s strategic interests would inform these decisions. The DPDP Rules, now in effect, have provided further clarity on the procedural aspects of this notification, including the process for public consultation, though the specific criteria often remain subject to executive discretion.

This negative-list model places a significant onus on Data Fiduciaries to stay abreast of government notifications. Unlike a static list of “adequate” countries, the negative list could be dynamic, potentially changing based on geopolitical shifts or evolving data protection landscapes globally. Businesses must therefore establish robust monitoring mechanisms to ensure continuous compliance.

Sectoral Overlays and Interplay with Existing Regulations

While the DPDPA provides the overarching framework, Data Fiduciaries must also consider existing and evolving sectoral regulations that may impose additional restrictions or requirements on cross-border data transfers. For instance, the Reserve Bank of India (RBI) has historically mandated data localisation for payment system data, requiring that all data relating to payment systems be stored only in India. This requirement, while not directly prohibiting transfer, often necessitates a primary storage in India, impacting how financial data is managed and then potentially transferred under DPDPA. Similarly, regulators like SEBI for securities markets and IRDAI for the insurance sector may introduce specific norms for the handling and transfer of sensitive financial and health data, respectively.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, particularly for Significant Social Media Intermediaries, also require certain data retention in India, which could influence the overall data architecture and transfer strategies of such entities. The DPDPA’s Section 16 operates in conjunction with these specific sectoral requirements, meaning a transfer might be permissible under DPDPA but still restricted by an RBI or SEBI directive.

Challenges and Future Considerations

The negative-list model, while offering initial flexibility, presents certain challenges. The potential for a dynamic list requires continuous vigilance from Data Fiduciaries. Transparency in the Central Government’s decision-making process for adding countries to the negative list will be crucial for businesses to anticipate and plan. Furthermore, the interplay between the DPDPA’s general permissibility and specific sectoral data localisation or transfer restrictions needs careful navigation. Businesses must ensure their data mapping exercises comprehensively cover all applicable laws and regulations. Any non-compliance with Section 16, leading to unauthorised transfer to a prohibited country, could attract significant penalties under Section 33 of the DPDPA.

Practical Takeaway

Indian businesses, General Counsels, and Data Protection Officers must move beyond a passive understanding of cross-border transfers. The DPDPA’s negative-list model demands proactive engagement. Develop comprehensive data inventories that meticulously map all cross-border data flows, identifying the nature of data, recipient jurisdictions, and the legal basis for transfer. Implement robust internal processes to continuously monitor notifications from the Central Government regarding prohibited countries or territories. Review and update data transfer agreements to include clauses that allow for immediate cessation of transfers if a jurisdiction becomes prohibited. Finally, engage with legal counsel to understand the nuanced interplay between DPDPA Section 16 and specific sectoral regulations (RBI, SEBI, IRDAI), ensuring a holistic and agile compliance strategy.

This post is licensed under CC BY 4.0 by the author.