DPDP Sections • 6 mins
Demystifying Section 16 Of The DPDP Act Cross Border Data Transfers
A definitive guide for General Counsels on managing cross-border data transfer risks under Section 16 of the DPDP Act 2023, ensuring B2B SaaS vendor readiness for enterprise procurement.
Last updated:
Section 16 Of The DPDP Act Explained
For General Counsels and Legal Heads at B2B SaaS companies, cross-border data flows represent a major point of friction in enterprise procurement. Section 16 of the Digital Personal Data Protection Act, 2023 establishes the regulatory framework for transferring digital personal data outside India. Unlike some other global frameworks, India adopts a negative list approach. Cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. This marks a massive shift from earlier localization-heavy drafts, providing regulatory relief to global technology vendors. However, navigating this 'negative list' architecture requires precise contractual and operational alignment, especially for cloud-native organizations that rely on distributed global infrastructure to maintain system availability and reduce latency.
Exact Statutory Text Anchors For Legal Teams
Under Section 16(1), the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. This means you do not need government approval to transfer data to an unlisted country. However, Section 16(2) clarifies that nothing in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data. If your enterprise clients are regulated by the Reserve Bank of India (RBI), strict payment data localization mandates still supersede the baseline DPDP Act. Similarly, if dealing with health or insurance data, sector-specific regulators impose their own territorial constraints. Legal teams must remember that Section 16 does not operate in a vacuum; it acts as a baseline. When assessing procurement risk, General Counsels must map not only the DPDP Act's restricted territories but also overlay any sector-specific regulatory restrictions. Failing to account for these dual layers is a frequent cause of stalled enterprise agreements.
Who This Binds And The Enterprise Procurement Reality
Section 16 directly binds Data Fiduciaries who decide the purpose and means of processing. However, if you are a B2B SaaS provider, you act as a Data Processor. Your enterprise clients, particularly large banks and financial institutions, hold the fiduciary responsibility. They face strict liability under the Act and consequently pass this compliance burden down to you through exhaustive contract clauses. If your SaaS platform relies on offshore sub-processors or global cloud infrastructure, your enterprise deal will stall in procurement limbo unless you can demonstrate compliance and defensibility. When an enterprise sends digital personal data to your environment, they require legally binding assurances that neither you nor your downstream sub-processors will route that data to a country on the Central Government’s restricted list. Without robust back-to-back agreements, your platform represents an unacceptable compliance risk.
How To Comply And Prove Vendor Readiness
Achieving vendor readiness requires translating statutory rules into auditable internal controls. Your outside counsel spend will increase if you attempt to manually negotiate every Data Processing Agreement without a standardized baseline. You must implement specific steps to secure your enterprise contracts and limit your liability.
1. Conduct a privileged review of all global data flows. Legal teams must map exactly where digital personal data is processed, identifying every offshore sub-processor and cloud hosting region. The output artifact is a documented data flow map that satisfies enterprise auditor demands. Crucially, this mapping can exclude data that falls under Section 3(c) exceptions, such as personal data made publicly available by the Data Principal, saving you unnecessary mapping effort.
2. Negotiate clear limitation of liability and indemnity clauses. Update your standard SaaS agreements to clearly delineate liability allocation between fiduciary and processor under the DPDP Rules, 2025. The artifact here is an updated vendor contract playbook. You must ensure flow-down obligations explicitly prohibit sub-processors from engaging entities in restricted territories.
3. Monitor the notified rules for the negative list. Establish an alert mechanism for when the Central Government officially publishes the restricted countries. The artifact is a compliance policy proving you have a mechanism to recall data from restricted territories if required.
4. Standardize Data Processing Agreements (DPAs). Create a definitive Section 16 compliance addendum to your standard DPA. This preemptively answers enterprise client concerns by outlining your exact geographical processing boundaries and notification timelines in the event of backend infrastructure changes.
Penalties And Regulator Defensibility
Failing to govern cross-border transfers exposes the Data Fiduciary to severe financial risk. Under the Schedule to the DPDP Act, general non-compliance with the provisions of the Act or Rules attracts a penalty of up to Rs 50 crore. When determining the exact fine, the Data Protection Board of India will weigh aggravating factors, such as the volume of data transferred and whether the breach of Section 16 led to a loss of data control. The reputational damage of an unauthorized data transfer often exceeds the statutory fines. As a SaaS vendor, if your infrastructure routes regulated enterprise data through a restricted territory, the fiduciary will likely terminate the contract for cause. Demonstrating regulator defensibility means having undeniable proof - through audit logs and finalized DPAs - that your transfer mechanisms strictly adhere to the negative list and any superseding sectoral mandates.
How Section 16 Interacts With Other Core Provisions
Section 16 must be read alongside Section 3, which defines the territorial scope of the Act. The Act covers digital personal data processed within India, and processing outside India if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India (Section 3(b)). If your platform is hosted offshore but targets individuals within India, DPDP jurisdiction automatically attaches. It also interacts closely with Section 8, which mandates that a Data Fiduciary may only engage a Data Processor under a valid contract. Your enterprise clients use Section 8 as the legal basis to mandate and audit your Section 16 cross-border transfer compliance. Furthermore, Section 1(2) dictates that provisions may come into force on different dates, requiring Legal Heads to stay vigilant regarding when the specific restricted country notifications are formally activated in the Official Gazette.
Deadline Pressure For Legal Decision Makers
The window to update contracts and map data flows is closing rapidly. Exactly 288 days remain until the DPDP hard compliance deadline of 13 May 2027. Enterprise procurement cycles often take six to nine months. If you wait to map your cross-border transfers, your SaaS deals will face insurmountable delays during vendor onboarding next year. Preparing early guarantees that your sales organization will not lose strategic deals due to preventable legal bottlenecks.
Next Steps For Securing Enterprise Deals
Stop letting enterprise contracts stall over DPDP compliance ambiguities. You can reduce legal review burden and provide immediate safe harbour assurances to your enterprise clients by auditing your cross-border data flows today. Run a definitive gap assessment on your current data transfer mechanisms at freescan.complydp.com to ensure you are fully vendor-ready. Proactive mapping of your cloud infrastructure ensures that when the Central Government finally notifies the restricted list under Section 16, your organization is positioned to seamlessly adapt without disrupting critical enterprise operations.
Sources
Frequently asked questions
Does Section 16 require us to localize all data in India?
No. The DPDP Act adopts a negative list approach. Cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. However, under Section 16(2), stricter sectoral localization rules that provide for a higher degree of restriction, such as those from the RBI for payment data, remain in effect and supersede the baseline DPDP provisions.
How does cross-border data transfer impact B2B SaaS procurement?
Enterprise clients act as Data Fiduciaries and are legally liable for where their data is processed. Under Section 8, they must use valid contracts to govern Data Processors. They will block SaaS procurement if you cannot provide a clear, documented map of offshore sub-processors to prove data is not routed to restricted territories under Section 16.
What happens if a sub-processor transfers data to a restricted country?
General non-compliance under the Act carries penalties up to Rs 50 crore. The Data Protection Board of India may hold the fiduciary accountable for the unauthorized transfer, triggering severe contractual indemnity claims and potential termination for cause against your SaaS company.
How should General Counsels handle consent for cross-border transfers?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Your itemised notices under the DPDP Rules, 2025 must outline the processing purposes clearly, ensuring Data Principals in India understand how their data is handled globally across your vendor supply chain.
When must we finalize our cross-border data mapping?
Exactly 288 days remain until the DPDP hard compliance deadline of 13 May 2027. Given long enterprise procurement cycles, legal teams must finalize data flow mapping and sub-processor inventories immediately to avoid stalled deals and ensure continuous regulator engagement defensibility.
ComplyDP