What is cross-border data transfer under DPDP and how is it regulated

What is cross-border data transfer under DPDP and how is it regulated
Cross-Border

What is cross-border data transfer under DPDP and how is it regulated

Many Indian businesses unknowingly transfer personal data outside India. Here is how the DPDP Act regulates international data flows.

Quick Answer: Under the DPDP Act 2023, personal data of Indian data principals can be transferred to foreign countries only if the destination country is on a government-published 'whitelist' of approved countries. The government has not yet published this list — once notified, transfers to countries not on the list will require additional safeguards or will be prohibited. Until the list is published, the existing IT Act and SPDI Rules framework continues to apply. Cross-border data transfers happen more often than most companies realise: using a US-hosted CRM, sending an email through Google Workspace, storing data on AWS US East, or using a EU-based analytics tool all involve international data transfers. Identify all your cross-border transfers now and assess your readiness for the whitelist regime.

What counts as a cross-border data transfer under DPDP?

A cross-border data transfer occurs when personal data of Indian data principals is transferred to, stored in, or processed in a foreign country. This includes: data stored on cloud servers outside India (AWS US, Azure Europe, GCP Singapore); SaaS tools with servers abroad (US-based CRM, EU-based email platform); API integrations that send data to foreign systems; sharing customer data with a foreign parent company; and offshore delivery centres processing Indian customer data on behalf of an Indian business. If data physically moves to a server outside India, it is a cross-border transfer.

How does the DPDP Act regulate cross-border transfers?

The Act empowers the government to specify countries to which transfer of personal data is permitted. Transfers to approved countries are permitted — either without restriction or with conditions the government specifies for each country. Transfers to non-approved countries are prohibited. The government may also publish a negative list — countries to which transfers are specifically prohibited. The Act also allows certain restricted transfers (perhaps with additional safeguards) for situations where no approved country alternative exists. The flexibility of this system mirrors the EU GDPR's adequacy decision model.

What data localisation requirements exist under DPDP?

The DPDP Act itself does not mandate general data localisation — the approved country list model allows transfers to many countries without requiring a domestic copy. However, sector-specific localisation requirements remain: RBI's payment data localisation (payment data must be stored only in India); SEBI's data localisation for certain capital market data; and IRDAI's insurance data requirements. These sector rules continue to apply regardless of DPDP. For sectors with localisation requirements, maintain a domestic storage infrastructure for the localised data categories even while using cloud systems for other data.

What should companies do now before the approved country list is published?

Prepare: (1) Build a cross-border data transfer inventory — identify every system that transfers Indian personal data outside India, the destination country, and the data categories; (2) Assess which transfers are business-critical vs optional; (3) Identify alternative India-based hosting or processing options for critical transfers; (4) Review your vendor DPAs for cross-border transfer provisions; (5) Build flexibility into your cloud architecture to relocate data processing to India or to approved countries without major re-engineering. Companies with India-hosted alternatives for their SaaS tools will have the smoothest transition when the list is notified.

Are there any current exemptions from cross-border transfer restrictions?

The government can exempt certain cross-border transfers from restrictions. Expected exemptions: transfers necessary for court proceedings or law enforcement assistance (legal mutual assistance); transfers where the data principal has explicitly consented to the specific transfer to a specific country; transfers necessary for the performance of a contract where the other party is in the foreign country; and transfers for public interest purposes. The scope of these exemptions will be defined in the Rules. In the meantime, document the justification for each current cross-border transfer.

What are the penalties for unauthorised cross-border transfers?

Transferring personal data to a non-approved country without a lawful basis is a violation of the Act. The penalty would fall under the general 'breach of any other provision' category — up to ₹50 crore per violation. However, if the transfer results in harm to data principals, higher penalties for inadequate safeguards may also apply. Enforcement of cross-border transfer restrictions is a high priority for regulators globally — GDPR has imposed multi-billion dollar fines for invalid international transfers. Indian enforcement is expected to follow a similar trajectory.

Frequently asked questions

Does using Google Workspace or Microsoft 365 constitute a cross-border transfer?

Yes. If your Google Workspace or Microsoft 365 data is stored on servers outside India — which it typically is unless you have specifically enabled India-region storage — this is a cross-border data transfer. Google and Microsoft both offer India-region storage options for business customers on qualifying plans. Enabling India-region data storage eliminates the cross-border transfer for the data stored in those tools. Review your current data residency settings in each cloud tool and enable India-region storage where available for personal data of Indian principals.

Can an Indian subsidiary transfer data to its foreign parent company?

An Indian subsidiary transferring customer or employee personal data to its foreign parent company is a cross-border transfer subject to DPDP. Intra-group transfers are not exempt by default. Once the approved country list is published, transfers to a parent in an approved country are permitted. For parents in non-approved countries, additional safeguards or restrictions may apply. Internal intra-group DPAs (or data sharing agreements) are needed to document the transfer, the purposes, and the security obligations — even within a corporate group.

If we use a Singapore-based SaaS tool, is that a cross-border transfer?

Singapore is likely to be on India's approved country list given the close economic relationship and Singapore's PDPA (a robust data protection law). However, until the list is formally published, the legal position is uncertain. For SaaS tools in Singapore, check whether the vendor offers an India-region data residency option. If not, document the transfer, assess the risk, and be prepared to migrate to an India-hosted alternative or an approved-country alternative if Singapore is not on the list.

Map your cross-border data transfers

Niti Bharat's DPDP Cross-Border Transfer Assessment identifies all international data flows, assesses readiness for the approved country list, and provides an India-residency migration roadmap.

Start Transfer Assessment
Previous Post Next Post

Get Free DPDP Checklist