6 mins

The Localization Myth: Cross-Border Transfers Under Section 16

Debunking the myth that the DPDP Act bans cross-border data transfers. General Counsel learn how Section 16 establishes a negative list, freeing B2B SaaS vendors to close enterprise deals without onshore server mandates.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

The myth circulating among enterprise procurement teams is that personal data governed by the Digital Personal Data Protection Act, 2023 cannot leave India. Legal departments frequently stall B2B SaaS agreements. They assume total data localization is the baseline legal requirement, forcing vendors to absorb high infrastructure costs to keep servers onshore. Confusion often traces back to older privacy bill drafts and sectoral mandates that demand local storage. Procurement officers misinterpret these earlier requirements as current law. They issue broad vendor questionnaires demanding proof of physical servers located entirely within the country. This practice slows international software providers trying to close deals.

Articles from legal publishers like Mondaq track how the legislative debate shifted from local storage mandates to a negative list model. Analysts at Kalp Systems note that organizations still wrongly expect complete restrictions on international transfers. Legal teams read old analyses and reject vendor contracts out of caution. The ITIF reported in June 2025 that the DPDP Act establishes a blacklist approach. The framework allows personal data to flow to any country except those restricted by the Central Government. The January 2025 draft rules add nuance to this framework. Vidhi Legal Policy observes that these rules empower the government to create a list of specific types of personal data subject to tighter controls. Despite this complication, the baseline default remains permissive.

Section 16(1) of the DPDP Act establishes a restriction framework rather than a localization mandate. The Central Government may restrict the transfer of personal data by a Data Fiduciary to specific notified countries or territories. This mechanism creates a negative list. The law permits cross-border data flows to any unlisted destination without individual transfer permits. DPO-India explains that the Act allows data to move to most nations while restricting those on the government-notified prohibited list. B2B vendors only need to verify that their server host countries are absent from the Central Government notification.

The DPDP Act does not erase existing sectoral mandates. Section 16(2) plainly states that the statute does not override any other law providing a higher degree of protection or restriction on data transfers. A Data Fiduciary complies with both. If the Reserve Bank of India requires payment data to remain domestic, a fintech company obeys that localization rule. Health data regulations may impose stricter geographic boundaries. The DPDP Act provides a baseline standard. Legal teams need to track sector-specific regulations alongside the 2025 DPDP Rules. A SaaS platform handling financial records cannot use Section 16(1) to bypass Reserve Bank directives.

Sending data abroad does not remove it from the scope of the DPDP Act. Under Section 3(b), the law applies to processing digital personal data outside India if that processing is for an activity related to offering goods or services to Data Principals within the country. A cloud provider in Singapore hosting profiles for an Indian e-commerce platform remains subject to DPDP obligations. The offshore entity has to honor rights requests and breach notification duties. The physical location of the server changes the geography but not the regulatory burden. Companies exporting data require binding contracts to impose these obligations on their foreign sub-processors.

A Data Fiduciary requires a valid legal basis to transfer data out of the country. Section 4 specifies that processing requires a lawful purpose. Consent is the main basis except where Section 7 legitimate uses apply. A company cannot move data across borders just because a country is missing from the negative list. The Data Fiduciary needs the Data Principal consent or a valid statutory exemption. Notice documents accurately reflect these offshore processing activities. The Central Government negative list dictates where data cannot go, while Section 4 outlines why a company can process it at all. Vendors map every cross-border data flow to a specific legal ground.

General Counsel at large enterprises evaluate vendor readiness through strict indemnity clauses. When a B2B SaaS company cannot explain its cross-border data flows, the enterprise procurement process halts. Legal heads need clear documentation showing exactly where data travels. Mapping this geography reduces outside counsel spend during contract negotiations. Companies skip waiting for government pre-approval to route data to unlisted territories. Data Fiduciaries can freely transfer personal data to any unlisted nation, so legal teams should avoid conflating the negative list with foreign whitelists. A transparent data architecture speeds up the vendor approval pipeline. Sales teams equipped with clear data transfer assessments close deals without friction.

Legal leaders rely on specific evidence artifacts for cross-border flows. They document the geographic locations of all sub-processors. Data processing agreements need updates to explicitly forbid transfers to any country the Central Government places on the negative list. Legal teams attach indemnification provisions that trigger if a vendor breaches this geographic boundary. A Data Fiduciary holds the primary responsibility for the actions of its Data Processors under the Act. An enterprise audits its supply chain to map exactly which jurisdictions touch the data. Contracts specify that the primary vendor assumes full liability if a fourth-party sub-processor routes data through a restricted territory.

Failing to monitor these cross-border boundaries carries heavy financial risks. The DPDP Act assigns stiff penalties for processing personal data in violation of the statute. If a vendor transfers data to a country on the negative list, the Data Fiduciary faces regulatory action. The Data Protection Board of India has the authority to investigate these unauthorized transfers. Organizations cannot use a vendor technical error as an excuse for violating Section 16. Procurement teams integrate ongoing geographic monitoring into their annual vendor risk assessments. A one-time check during onboarding falls short. The Central Government can update the restricted list, which requires businesses to adapt their data routing immediately.

Many software providers rely on multi-region cloud architectures. A single SaaS application might process login credentials in one country and store analytics backups in another. General Counsel map every individual node in this network. The DPDP Act holds the Data Fiduciary accountable for the entire lifecycle of the personal data. If an analytics module routes data through a newly restricted territory, the primary vendor severs that connection. Legal departments require software vendors to provide a 30-day notice before adding a new foreign sub-processor. This window allows the Data Fiduciary to verify that the new destination complies with Section 16(1), the 2025 draft rules, and sector-specific laws under Section 16(2).

General Counsel review their data supply chain using this compliance checklist.

1. Map all jurisdictions where B2B SaaS vendors host or process personal data.

2. Confirm consent forms or Section 7 legitimate uses cover these international transfers.

3. Revise vendor contracts to require immediate notification if they route data through newly restricted territories.

4. Audit sub-processors against any sector-specific localization laws preserved by Section 16(2).

5. Establish a contract termination clause tied to unauthorized geographic transfers.

Stalled enterprise deals cost software vendors revenue. Legal teams require precise documentation showing exactly where offshore data travels. Check your vendor readiness gaps today at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act require all personal data to stay in India?

No. Section 16(1) allows the Central Government to restrict transfers to specific countries. Unless a destination is on that negative list, cross-border transfers are permitted.

How do sector-specific data localization rules interact with the Act?

Section 16(2) preserves stricter data transfer laws. If a financial regulator demands localization for specific data types, businesses comply with those sector rules alongside the DPDP Act.

Does our B2B SaaS platform need government approval to transfer data abroad?

The Act does not require pre-approval for unlisted countries. General Counsel update vendor contracts to prohibit transfers only to restricted territories.

What legal grounds do we need for cross-border processing?

Consent is the main basis except where Section 7 legitimate uses apply. A company needs a valid legal ground to process the data, regardless of where the server is located.

Do businesses need a one-time check for cross-border data transfer compliance?

No. The Central Government may update the restricted country list at any time under Section 16(1). Organizations need ongoing geographic monitoring to ensure vendors do not route data through newly restricted territories.