27 May 2026  ·  DPDPA & IT Compliance

Cross-Border Data Transfers Under the DPDPA 2023

Back to Blog

In an era of globalised business operations and cloud computing, the rules governing cross-border transfers of personal data are of critical importance. The DPDPA 2023 adopts a nuanced approach that balances India's data sovereignty interests with the practical realities of international commerce.

The Cross-Border Transfer Framework Under DPDPA

The Digital Personal Data Protection Act, 2023 permits the transfer of personal data outside India, subject to restrictions that the Central Government may notify from time to time. Section 16 of the Act empowers the Government to restrict transfers to certain countries or territories, effectively creating a whitelist or blacklist approach to cross-border data flows. Until such restrictions are notified, organisations may transfer personal data internationally, provided they comply with all other obligations under the Act — including obtaining valid consent and implementing adequate security safeguards.

Contrast with the Previous Draft Bills

Earlier drafts of India's data protection legislation — the Personal Data Protection Bill, 2019 and the Data Protection Bill, 2021 — had proposed stringent data localisation requirements, mandating that certain categories of sensitive and critical personal data be stored exclusively within India. The DPDPA 2023 represents a significant departure from this approach, adopting a more flexible framework that prioritises enabling cross-border data flows while reserving the Government's power to impose restrictions where necessary for national security or public interest. This shift has been broadly welcomed by the technology and business community.

Implications for Multinational Organisations

For multinational organisations that transfer personal data from India to overseas affiliates, cloud service providers, or data processors, the DPDPA's cross-border transfer provisions have important practical implications. Organisations must ensure that their data transfer agreements and privacy notices accurately reflect the countries to which data may be transferred. They must also monitor Government notifications regarding restricted territories and be prepared to adjust their data flows accordingly. Intra-group data transfer agreements and standard contractual clauses — familiar concepts from GDPR compliance — may serve as useful models for structuring compliant cross-border transfers under the DPDPA.

Data Localisation Requirements for Specific Sectors

While the DPDPA itself does not impose blanket data localisation requirements, several sector-specific regulations in India continue to mandate local storage of certain categories of data. The Reserve Bank of India requires payment system data to be stored exclusively in India. The Insurance Regulatory and Development Authority and the Securities and Exchange Board of India have issued similar directives for their respective sectors. Organisations operating in these regulated sectors must navigate the intersection of the DPDPA's cross-border transfer framework and these sector-specific localisation mandates, which may require maintaining separate data infrastructure for regulated data categories.

Practical Steps for Compliance

Organisations engaged in cross-border data transfers should take several practical steps to ensure compliance. First, conduct a data mapping exercise to identify all personal data flows across borders, including transfers to cloud service providers and third-party processors. Second, review and update privacy notices to disclose cross-border transfers and the countries involved. Third, ensure that data processing agreements with overseas processors include appropriate contractual protections. Fourth, establish a monitoring mechanism to track Government notifications regarding restricted territories and respond promptly to any changes. Finally, document all cross-border transfer decisions as part of your broader data governance framework.

Cross-border data transfer compliance is a complex area that requires ongoing monitoring as Government notifications evolve. Our advocates can assist your organisation in structuring compliant data transfer arrangements and staying ahead of regulatory developments.

Consult Our Advocates

Advocacy A Law Firm  ·  DPDPA & IT Compliance

Advocacy A Law Firm

Your trusted advocates for corporate, civil, and compliance matters across India.

Legal Compliance

Udyam Registration

UDYAM-UP-09-0043193

GST No.

09CHFPK34641ZK

Office Hours

Mon – Sat  ·  10:00 AM – 6:00 PM IST

Data Privacy & Compliance Notice

Advocacy A Law Firm is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Digital Personal Data Protection Act, 2023 (DPDPA) (India). Any personal information you provide through this website — including your name, email address, and contact details — is collected solely for the purpose of responding to your legal enquiries and will not be shared with third parties without your explicit consent. You have the right to access, rectify, or request deletion of your personal data at any time by contacting us at [email protected]. By submitting the contact form on this website, you consent to the processing of your personal data for the stated purpose.

Copyright © 2026 Advocacy A Law Firm — All Rights Reserved.