NEWS ANALYSIS • 4 min read
Nasscom Analyzes DPDPA vs Sri Lanka: Navigating Cross-Border Transfers and EdTech Scope
A Nasscom analysis compares India's DPDP Act with Sri Lanka's data protection law, highlighting critical differences in cross-border data transfers, territorial scope, and verifiable parental consent obligations for enterprises.
Last updated:
What happened
Nasscom recently published a comparative analysis of data protection frameworks across South Asia, focusing on structural and operational distinctions between India's Digital Personal Data Protection Act, 2023, and Sri Lanka's Personal Data Protection Act. The report highlights that India designed a framework specifically for the scale and complexity of its digital economy. In contrast, Sri Lanka adopted a model heavily influenced by European standards. The analysis outlines key differences in material scope, data processor obligations, and mechanisms for cross-border data transfers.
Does the DPDP Act apply here?
For an EdTech Head of Compliance, understanding material scope is the first step in risk assessment. The Nasscom analysis notes that India's DPDPA focuses strictly on digital personal data, including offline data that is subsequently digitized. Sri Lanka regulates personal data more broadly, regardless of format. The territorial scope of the DPDP Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. If your learning platform digitizes physical enrollment forms or operates offshore servers to serve students in India, the Act applies fully.
Legal implications under DPDP
The two laws diverge significantly on core processing principles. Under Section 4 of the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Cross-border data flows present another major operational difference, as Section 16 of the DPDP Act adopts a permitted unless restricted approach. Transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. The Nasscom report contrasts this with Sri Lanka, which mandates formal regulatory approvals or explicit consent for offshore transfers.
Could this happen to you
Consider a scenario where your EdTech enterprise relies on offshore analytics vendors to process student engagement data. If a vendor experiences a security incident, the DPDP Rules, 2025 require you to provide breach intimation to affected Data Principals without delay, alongside a detailed report to the Data Protection Board within 72 hours. An auditor or the DPBI will immediately ask for your RoPA, DPIA, and proof of vendor oversight. If you cannot produce this evidence pack, your enterprise faces severe penalty ceilings reaching up to 250 crore rupees per instance.
EdTech compliance heads face additional complexities under Rule 10 workflows. Processing children's data requires verifiable parental consent and strictly prohibits behavioral tracking. If your offshore vendor relies on algorithms that track minors, your board holds the regulatory risk. Generic GRC tools often fail to capture complex Parental Tokens or age-gating mechanics. Your control owner must be able to produce specific consent artefacts that prove parental authorization, rather than relying on standard terms of service agreements.
What companies should do in the next 30 days
1. Map cross-border data flows. The Head of Compliance should update the RoPA to list all offshore cloud providers and sub-processors, ensuring readiness if the Central Government publishes a negative list under Section 16.
2. Audit parental consent mechanics. The Chief Product Officer must review user onboarding to ensure verifiable parental consent is collected and behavioral tracking of minors is disabled, producing an evidence pack for legal review.
3. Test incident response timelines. The control owner for security must run a tabletop exercise to prove the team can compile a DPBI-ready breach report within the 72-hour window mandated by the DPDP Rules, 2025.
What to watch
Exactly 260 days remain until the 13 May 2027 hard deadline. EdTech compliance and legal leaders should monitor MeitY for upcoming notifications regarding restricted territories for cross-border transfers. Ensure your compliance architecture can handle both itemised notices and verifiable parental consent without breaking the user experience. Check your current control gaps and audit readiness at freescan.complydp.com.
Sources
Frequently asked questions
How does the DPDP Act handle data processed outside India?
The DPDP Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. Section 16 allows these cross-border transfers unless the Central Government explicitly restricts specific countries.
What is the financial risk of failing to manage offshore vendor breaches?
Data Fiduciaries are fully responsible for their Data Processors under the DPDP Act. Failing to secure personal data or report a breach to the DPBI within 72 hours can result in penalties up to 250 crore rupees.
Do we need parental consent for students using our EdTech platform?
Yes, processing children's data requires verifiable parental consent under the DPDP Act and Rules, 2025. Platforms must also ensure that behavioral tracking and targeted advertising directed at children are completely disabled.
What evidence will the DPBI ask for during a compliance audit?
The DPBI will expect a comprehensive evidence pack, including an updated RoPA, relevant DPIA records, and valid consent artefacts. For EdTech platforms, this means producing specific logs of verifiable parental consent rather than just generic terms of service agreements.
Are we required to get consent for every type of data processing?
Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legitimate uses include scenarios like medical emergencies or compliance with legal judgments, but standard commercial processing still relies heavily on valid consent.
ComplyDP