6 min read
DPDP Restricted Countries List: Rules for Cross-Border Data Transfers
Understand how Section 16 of the DPDP Act handles cross-border data transfers, the status of the restricted countries list, and how it impacts global privacy programs.
Last updated:
The Central Government has not yet published a DPDP restricted countries list under Section 16 of the Digital Personal Data Protection Act, 2023. Cross-border transfers of personal data operate on a negative list model. Data flows freely by default. A Data Fiduciary can export data to external jurisdictions unless the government explicitly notifies a specific country or territory. Fiduciaries transfer data globally right now. You do not need to pause operations waiting for an approved whitelist. This approach simplifies the baseline transfer requirement. Section 1 of the Act states that provisions come into force on dates appointed by the Central Government. The government will publish any future restrictions via notification in the Official Gazette. Until that happens, the statute permits data exports to any jurisdiction.
Section 16(2) specifies that the DPDP Act does not override stricter sectoral data localization mandates. The text preserves any law for the time being in force in India that provides a higher degree of protection or restriction on transfers. Certain industries face existing restrictions on data handling. If the Reserve Bank of India requires payment data to stay within India, that rule supersedes the general DPDP permission. Telecom regulations dictate similar local hosting requirements for subscriber records. Your compliance team identifies these sectoral obligations before approving a data transfer. A generic privacy suite fails to flag these local conflicts if it only maps the DPDP baseline. The fiduciary maps every data category against specific industry guidelines. You cannot use Section 16 as a defense if a sectoral regulator penalizes you for exporting regulated data. The DPDP Act operates alongside these localized rules.
Section 3(b) extends the Act to processing outside India. This extraterritorial scope triggers if the processing connects to an activity related to offering goods or services to Data Principals within the territory of India. A foreign company processing this data on a server abroad falls fully under the law. The physical location of the data center does not shield the entity from DPDP requirements. Section 3(a) clarifies that the law covers data collected in digital form or digitized subsequently. Fiduciaries deliver itemised notices and secure valid agreement. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. You establish workflows for Data Principals to exercise their rights across borders. A user in India retains the right to access, correct, or erase their data even if it sits on a processor server in another country. The Act exempts personal data processed for domestic purposes under Section 3(c). It also excludes data made publicly available by the Data Principal.
Global teams manage one program across many jurisdictions. Integrating the DPDP Act requires adjusting standard assumptions. The law relies entirely on the upcoming negative list for international data flows. Fiduciaries avoid complex transfer impact assessments to legalize a transfer under this statute. You still need contracts to enforce Data Processor obligations under Section 8. The fiduciary remains fully liable for the actions of any downstream processor. This strict liability applies regardless of where that processor sits globally. If an external vendor misuses personal data, the Data Protection Board holds the Data Fiduciary accountable. Contracts mandate specific security standards. The agreement prohibits unauthorized sub-processing that might route data into a country eventually placed on the restricted list. Vendor selection requires careful vetting of international data practices.
Cross-border transfers complicate incident response. If your processor in another country suffers a breach, the DPDP Rules, 2025 dictate strict timelines. The fiduciary intimates affected Data Principals without delay. You also submit a detailed report to the Data Protection Board within 72 hours. Distance or time zone differences do not pause this clock. Your international vendors report incidents fast enough to meet this 72-hour window. Update your data processing agreements to reflect this specific requirement. A processor contract that allows 48 hours for breach notification leaves the fiduciary with just 24 hours to investigate and draft the official report. Organizations negotiate legacy vendor agreements to secure tighter communication channels. Fast escalation protocols prevent severe penalties during a foreign vendor breach.
Organizations evaluate their cross-border data flows systematically. 1. Map all cross-border data flows leaving India to external processors to build an exact inventory of what data goes where. 2. Check if any sectoral laws require localization for specific data types in your inventory. 3. Review vendor contracts to confirm they bind processors to DPDP breach notification timelines. 4. Establish a monitoring process to catch the official restricted countries list when the Central Government publishes it. 5. Build data subject rights workflows that retrieve or delete data stored on foreign servers. 6. Verify that the original consent notice covers the exact processing purpose performed by the international vendor. 7. Audit data sets to ensure you exclude data processed for personal or domestic purposes as outlined in Section 3(c).
A common mistake is assuming cross-border data transfers are suspended until the government publishes the list. The opposite is true. The absence of the list means no general DPDP restrictions exist today. A second error is relying on a global privacy tool that forces you to document extensive legal transfer mechanisms for India. This wastes team hours on non-existent legal requirements. Some platforms treat every cross-border flow as a high-risk activity requiring special consent prompts. The DPDP Act requires clear itemised notice. It does not mandate separate consent checkboxes specifically for transferring data abroad. You need tooling that maps exact regulatory requirements. Over-engineering compliance creates unnecessary friction for users. Fiduciaries focus on securing data rather than drafting complex transfer mechanisms.
Exactly 253 days remain until the DPDP hard compliance deadline of 13 May 2027. Teams build a unified data inventory that tracks locations, processors, and cross-border flows. Global platforms claiming India coverage often fail to adapt to the specific negative list model. They miss the 72-hour reporting window to the Data Protection Board. Fiduciaries cannot rely on generic templates designed for other regimes. ComplyDP maps these exact DPDP requirements natively. Visit freescan.complydp.com to evaluate your cross-border data transfer exposure and identify vendor contract gaps.
Sources
Frequently asked questions
Is there a DPDP restricted countries list available right now?
The Central Government has not published a restricted countries list under Section 16 of the DPDP Act. Cross-border transfers are permitted by default until specific countries are notified.
Do we need standard contractual clauses for DPDP compliance?
The DPDP Act does not require specific transfer mechanisms like standard contractual clauses to legalize data exports. Transfers operate on a negative list model. Fiduciaries use valid contracts to bind their Data Processors under Section 8.
How does the DPDP Act treat data transferred to global processors?
Fiduciaries remain fully accountable for data processed externally. They enforce vendor contracts so international processors meet the 72-hour breach reporting window to the Data Protection Board mandated by the DPDP Rules, 2025.
Do sectoral laws affect cross-border data transfers under DPDP?
Yes. Section 16(2) specifies that stricter sectoral laws override the general DPDP permissions. If regulators demand data localization for payment information, those rules apply regardless of the DPDP restricted countries list.
ComplyDP