4 min read
Cross-Border Data and Processor Liability: Comparing India's DPDP Act and Sri Lanka's PDPA
An analysis of the structural differences between India's DPDP Act, 2023 and Sri Lanka's PDPA, focusing on cross-border data transfers, processor liability, and contracting obligations for General Counsels.
Last updated:
What Happened
Nasscom published a comparative analysis detailing the structural and regulatory differences between India's Digital Personal Data Protection Act, 2023, and Sri Lanka's Personal Data Protection Act. The report examines jurisdictional scope, data processor obligations, and cross-border transfers. It states that India restricts its core regime to digital personal data and offline data that is subsequently digitised.
Sri Lanka regulates the processing of personal data broadly without limiting its scope to digital formats. India uses a permitted unless restricted model for cross-border data flows. Sri Lanka requires a formal government determination of equivalent protection under Section 26 or explicit data principal consent for offshore transfers.
Does The DPDP Act Apply Here
Applicability dictates contract structure and liability allocation for General Counsels. The DPDP Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. It directly governs data collected offline and later digitised.
The Act does not apply to non-personal data or anonymised corporate intellectual property. Contractual indemnities must map precisely to this specific digital scope to limit unnecessary outside counsel spend. Organisations embedding privacy-by-design architecture early will face less compliance friction during vendor onboarding.
Legal Implications Under DPDP
Section 16 of the Act governs cross-border data transfers. It permits the free flow of data to jurisdictions outside India unless the Central Government restricts transfer to notified countries or territories. Legal teams must draft vendor agreements anticipating potential negative-list notifications. Data processing under Section 4(1) requires a lawful purpose, relying on valid consent or Section 7 legitimate uses.
The Nasscom report details how these laws diverge on processor obligations. Accountability under the Indian framework remains strictly with the Data Fiduciary, as vendors hold no direct statutory liability under the Act. Contractual indemnity clauses and audit rights are the sole mechanism for fiduciaries to enforce downstream compliance.
Could This Happen To You
If your enterprise shares personal data with regional vendors, the regulatory burden falls entirely on your organisation. Regulators will not pursue the vendor. The Data Protection Board of India will demand evidence of verifiable consent or legitimate use documentation during an inquiry. Should a vendor suffer a breach, the Rules, 2025 require the Indian Data Fiduciary to intimate affected Data Principals without delay and submit a detailed report to the Board within 72 hours.
An inability to produce itemised notices, processing logs, and vendor breach notification records destroys regulator defensibility. Penalties reach 250 crore rupees per instance. Legal heads must secure broad audit rights and strict 24-hour breach reporting clauses in all processor contracts to defend against enforcement actions.
What Companies Should Do In The Next 30 Days
1. Legal teams must audit cross-border data transfer agreements to document the physical location of vendor servers.
2. Update processor contracts to include strict indemnity clauses and mandatory 24-hour breach notification timelines.
3. Review the legal basis for processing offshore data to ensure operations rely on valid consent or documented Section 7 legitimate uses.
4. General Counsels should initiate privacy-by-design reviews for new digital products to reduce future litigation risk.
What To Watch
General Counsels should monitor the Central Government for any Section 16 negative list notifications restricting cross-border transfers. The Data Protection Board will begin setting enforcement precedents once operationalised under the Rules, 2025. Exactly 255 days remain until the 13 May 2027 hard deadline. Assess your current vendor agreements and consent records using the evaluation tool at freescan.complydp.com to determine immediate exposure.
Sources
Frequently asked questions
How does the DPDP Act regulate cross-border data transfers?
Section 16 permits transfers outside India unless the Central Government restricts specific countries. Legal teams must monitor government notifications for any restricted jurisdictions and update vendor contracts accordingly.
Does the DPDP Act impose direct liability on data processors?
No. The Act places compliance obligations solely on the Data Fiduciary. General Counsels must rely on commercial contracts, audit rights, and indemnity clauses to enforce data protection standards on downstream vendors.
What happens if an offshore vendor suffers a data breach?
The Indian Data Fiduciary retains the legal obligation to manage the incident. Under the Rules, 2025, the fiduciary must notify affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.
Is consent required for all cross-border data processing?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Organisations must document their lawful purpose under Section 4(1) before transferring personal data to regional partners.
ComplyDP