On this page
- Layer 1: Section 16(1), restriction by notification
- Layer 2: Rule 15, data made available to a foreign State
- Layer 3: stricter Indian law still applies
- Significant Data Fiduciaries: a localisation duty
- Processing abroad and the Act
- The reverse case: foreign clients’ data processed in India
- Checking each transfer
- Transfers already running
- Common questions
- In the news
- Sources
Using a cloud region outside India, an overseas email platform or a group company’s shared HR system sends personal data abroad. The Digital Personal Data Protection Act, 2023 does not ban this. It lets the Central Government restrict it. A Data Fiduciary is the person or business that decides why and how personal data is processed. Three layers apply to every transfer it makes: Section 16 of the Act, Rule 15 of the DPDP Rules, 2025, and any other Indian law that is stricter. A fourth applies to Significant Data Fiduciaries.
Layer 1: Section 16(1), restriction by notification
Section 16(1) says the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to any country or territory outside India that it notifies.
The model is a restriction list. Transfers are not limited to approved countries; instead, the government can name countries or territories to which transfers are restricted. For you, that means:
- No list of “safe” countries exists in the Act or the Rules for you to rely on.
- The position can change by notification. A destination that is unrestricted when you sign a contract can be notified later.
Before relying on any destination, check the Gazette for notifications under Section 16(1), and re-check on a schedule you set.
Layer 2: Rule 15, data made available to a foreign State
Rule 15 confirms that personal data processed under the Act may be transferred outside India, subject to one restriction. The Data Fiduciary must meet any requirements the Central Government specifies, by general or special order, about making that data available to a foreign State. The same applies to any person or entity under the control of such a State, and to any of its agencies.
Rule 15 does not itself list those requirements; they come from orders. So each transfer raises two questions. Could the data be made available to a foreign State or a body it controls? Has an order been issued that applies? Record whether each recipient is a foreign State, or controlled by or an agency of one, so you can answer the second question when orders appear.
Layer 3: stricter Indian law still applies
Section 16(2) preserves any other law in force in India that gives a higher degree of protection for, or restriction on, transfers of personal data outside India. Section 16 does not limit such a law. If a sector law, or a regulation or direction with the force of law, requires data to stay in India or sets conditions on transfers, that requirement continues alongside the Act.

Significant Data Fiduciaries: a localisation duty
Rule 13(4) adds a duty for Significant Data Fiduciaries. The Central Government may specify personal data, on the recommendations of a committee it constitutes. A Significant Data Fiduciary must take measures to ensure that such data, and the traffic data about its flow, is not transferred outside India. This applies only to notified Significant Data Fiduciaries and only to data the government specifies.
Processing abroad and the Act
Section 3(b) applies the Act to processing outside India when it is connected with offering goods or services to Data Principals in India. Moving that processing offshore does not end your obligations. For other offshore processing, such as staff data hosted abroad, the text is not explicit, so take advice.
Your responsibility for vendors also travels with the data. Section 8(1) keeps you responsible for processing done on your behalf by a Data Processor, and Section 8(5) requires reasonable security safeguards for that processing. Where Section 8(2) applies, you need a valid contract with the processor; see what goes in a Data Processing Agreement.
The reverse case: foreign clients’ data processed in India
Section 17(1)(d) covers a person based in India who processes the personal data of Data Principals not within India, under a contract with a person outside India. For that processing, Chapter II (other than Sections 8(1) and 8(5)), Chapter III and Section 16 do not apply. Security safeguards and overall responsibility still do.
Checking each transfer
- Log each transfer activity, not just each vendor: the data, destination, recipient, purpose and contract.
- Check Section 16(1). Has the destination country or territory been notified? Record the date you checked.
- Check Rule 15. Could the data be made available to a foreign State or a body it controls, and does any general or special order apply?
- Check other law. Does any sector law that binds you set a stricter rule (Section 16(2))?
- If you are a notified Significant Data Fiduciary, check whether the data is specified under Rule 13(4).
- Re-check on a cycle, and whenever a new notification or order is published. The interval is your choice; the Act does not set one.
A transfer you have never checked should count as unchecked, not as permitted.
Transfers already running
Sections 3, 8, 16 and 17, and Rules 13 and 15, apply from 13 May 2027 (clause (c) of G.S.R. 843(E); Rule 1(4)). Transfers already running on that date are covered from then, so the register should be ready before it.
Common questions
Can I transfer personal data outside India?
Yes, unless the Central Government has restricted transfers to that country or territory by notification. Any other Indian law that gives a higher degree of protection still applies.
Which countries can I transfer personal data to?
The Act and Rules name no permitted destinations. The Act works the other way: the government may restrict transfers to the countries it notifies.
What do the Rules add about transfers?
You may transfer data subject to meeting requirements the Central Government may set, by general or special order, about making the data available to a foreign State or to any person or body under its control.
Do Significant Data Fiduciaries have extra transfer duties?
Yes. They must make sure that personal data the Central Government specifies, and the traffic data about its flow, is not transferred outside India.
Does the Act apply to a foreign company that sells to people in India?
Yes, when it processes digital personal data outside India in connection with offering goods or services to people in India.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 10: Data leaving India, in the toolkit
- The free duties list, every duty in plain words
In the news
- The DPDP cross-border transfer rules aren't live yet; so why are contracts being redrafted as if they are?
A practitioner column separating what the law requires now from what starts on 13 May 2027 for transfers abroad.
- DPDP Rules: How Section 16 Governs Data Transfers Abroad
Explainer on how the Act and the Rules govern transfers abroad, the layers we describe.
- Government notifies DPDP rules, sets 18-month roadmap for data protection regime
Early press report that also touches on localisation and transfers abroad.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 3(b)Processing outside India linked to offering goods or services in India
- Section 8(1)Responsible for processing by a Data Processor
- Section 8(2)Processor engaged for activities related to offering goods or services: only under a valid contract
- Section 8(5)Security safeguards
- Section 16(1)Restriction on transfers to notified countries or territories
- Section 16(2)Stricter Indian law continues to apply
- Section 17(1)(d)Foreign Data Principals' data processed in India under a foreign contract
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 13 and 15 in force eighteen months from publication
- Rule 13(4)Significant Data Fiduciaries: specified data not transferred outside India
- Rule 15Requirements, by general or special order, about making data available to a foreign State
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 3, 8, 16 and 17 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


