5 min read
Section 16 Explained: Managing Cross-Border Data Transfers Under the DPDP Act
A definitive guide for privacy leaders on Section 16 of the DPDP Act, detailing the negative list approach to cross-border data transfers, sectoral overrides, and operational compliance strategies.
Last updated:
Section 16 of the Digital Personal Data Protection Act, 2023 governs how organizations handle cross-border data flows. Unlike European frameworks that restrict transfers by default, the DPDP Act permits international data movement unless the Central Government explicitly adds a destination country to a restricted list. This negative list approach allows global companies to maintain their existing data architecture, provided they can immediately sever data pipelines if a jurisdiction is subsequently restricted by government notification.
Statutory Text and Legal Anchors
Section 16(1) of the DPDP Act establishes that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. Section 16(2) provides a vital caveat for regulated industries. It states that this baseline permission does not restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection or restriction on the transfer of personal data outside India.
Territorial Scope and the GDPR-to-DPDP Delta
For global privacy teams managing one program across regimes, this section represents a major structural shift. European laws demand complex transfer impact assessments and approved contractual clauses before data can move. In contrast, the DPDP framework operates on a completely different premise. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. However, under Section 16, transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. This eliminates heavy, upfront transfer approvals but requires continuous monitoring of government notifications.
Operationalizing the DPDP Rules 2025
The DPDP Act provides the structural rules for transfers, but the DPDP Rules, 2025 define the operational mechanics and accountability. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The itemised notices mandated by the Rules must clearly explain the purposes of processing, regardless of whether that processing occurs in Mumbai or Frankfurt. Furthermore, if data transferred to a foreign processor is compromised, the incident response clock is absolute. Fiduciaries must ensure an intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025.
Sectoral Overrides in Practice
Section 16(2) ensures that the DPDP Act does not dilute existing sectoral localization mandates. For example, financial institutions governed by the Reserve Bank of India must already store payment systems data locally. The DPDP Act's general permission to transfer data does not override these RBI guidelines. Legal leads must maintain a precise legal mapping to ensure that while general consumer data might flow freely across borders, highly regulated datasets remain restricted by their specific sectoral laws.
Vendor Risk Management and Processor Contracts
Section 16 significantly alters how organizations approach third-party risk management. When a Data Fiduciary engages a Data Processor, the contract must explicitly account for the negative list mechanism. Fiduciaries must demand transparency regarding sub-processors and their geographical locations. If a primary processor routes data through a country that is suddenly notified as restricted by the Central Government, the fiduciary remains fully accountable for the violation. Therefore, vendor contracts must include immediate termination or data-rerouting clauses that can be activated the moment a government notification is published.
Step-by-Step Remediation for Global Fiduciaries
1. Map all international data destinations. The Privacy Lead must build a dynamic data flow map documenting every country where internal systems or third-party processors store or access digital personal data. The required evidence artifact is a real-time topology map or updated processing register tied to specific vendor contracts.
2. Cross-reference sectoral localization laws. The Legal Lead must evaluate whether specific data sets, such as banking records, are subject to existing Indian laws requiring strict local storage. The required evidence artifact is a legal matrix appending sectoral requirements to the primary data flow record.
3. Establish a restrictive notification response protocol. The Compliance and IT Teams must jointly design a technical workflow to halt data transfers immediately if the Central Government notifies a new country on the restricted list. The required evidence artifact is a tested incident response playbook detailing vendor suspension protocols and alternative processing routes.
Financial Penalties and Cross-Sectional Impact
Failing to halt transfers to a restricted jurisdiction exposes the organization to severe regulatory action. While the DPDP Act's Schedule does not list a separate penalty exclusively for Section 16, illegal transfers constitute a breach of general Data Fiduciary obligations, carrying financial penalties up to INR 250 crore. The Data Protection Board of India will scrutinize the volume of data illegally transferred and the speed of the fiduciary's response. Section 16 also heavily impacts Section 8 vendor management obligations, as fiduciaries are ultimately liable if a downstream processor independently routes data into a newly restricted territory.
Deadline Pressure and Next Steps
Global privacy teams evaluating tooling must act decisively to ensure they can produce evidence on demand for regulatory audits. Existing generic multi-law suites often lack the specific architecture to handle Indian sectoral overrides or rapid negative list compliance. Exactly 257 days remain until the DPDP hard compliance deadline of 13 May 2027. Building a reliable cross-border data transfer strategy requires immediate visibility into your global vendor ecosystem.
Assess whether your current global privacy architecture can seamlessly handle the transition from European models to the Indian requirements. Check whether your current setup satisfies this one section with a free scan framed as a section-level gap check at freescan.complydp.com to close your compliance gaps before the deadline.
Sources
Frequently asked questions
Does the DPDP Act require us to sign standard contractual clauses for international transfers?
No. Under the DPDP Act, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. This negative list approach means standard contractual clauses designed for European regimes are not a statutory requirement for transferring data out of India, though standard vendor processing contracts are still required under Section 8.
How does Section 16 impact our global privacy program across multiple regimes?
Managing one program across regimes requires understanding the GDPR-to-DPDP delta. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. You do not need upfront regulatory approval to move data globally, but you must build workflows to instantly halt transfers if a destination country is notified as restricted.
What happens if our foreign processor suffers a security incident?
If a vendor outside India experiences a breach involving personal data governed by the Act, the Data Fiduciary remains entirely accountable. This requires an intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours, per the Rules, 2025.
Are there any situations where data localization is required under Indian law?
Yes. Section 16(2) specifies that the DPDP Act does not override other Indian laws that impose higher restrictions on data transfers. For example, sectoral regulators like the Reserve Bank of India enforce strict data localization for payment systems, which must be followed alongside DPDP obligations.
What is the penalty for transferring data to a restricted country?
Violating Section 16 is a major breach of Data Fiduciary obligations. The Data Protection Board can levy financial penalties up to INR 250 crore under the Schedule, weighing factors such as the volume of data illegally transferred to the restricted jurisdiction and the duration of the violation.
ComplyDP