4 mins

Nasscom Analysis Details DPDP Cross-Border Transfer Mechanisms Against Regional Frameworks

A new Nasscom report contrasts India's DPDP Act with Sri Lanka's data protection law, highlighting critical differences in digital scope and cross-border data transfer models for multinational fintechs.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What happened

Nasscom recently published a comparative analysis of data protection frameworks in South Asia, specifically contrasting India's Digital Personal Data Protection Act, 2023 with Sri Lanka's Personal Data Protection Act. The report highlights fundamental differences in legislative approach, jurisdictional scope, and cross-border data transfer mechanisms. For multinational fintech enterprises operating across the region, these variations directly impact compliance strategies, vendor contract clauses, and the allocation of legal liability.

Does the DPDP Act apply here?

The jurisdictional and material scope of the two laws diverge significantly. India's DPDP Act, 2023 focuses strictly on digital personal data, encompassing data collected online and data collected offline but subsequently digitised. It applies to processing within India and processing outside India connected to offering goods or services to Data Principals in India. In contrast, the Nasscom analysis notes that Sri Lanka's framework does not limit its core regime solely to digital forms. For a fintech General Counsel, this means Indian compliance efforts can exclude purely physical paper trails that are never digitised, whereas Sri Lankan operations require broader lifecycle mapping across all data formats.

Legal implications under DPDP

Under Section 16 of the DPDP Act, India adopts a permitted unless restricted approach for cross-border data transfers. Transfers are generally permitted unless the Central Government restricts transfer to notified countries through a negative list. This aligns well with rapid fintech product cycles and account-aggregator API integrations. Sri Lanka enforces a stricter model requiring explicit data subject consent or formal adequacy rulings under its Section 26. Furthermore, consent is the primary basis for processing under India's Section 4, except where Section 7 legitimate uses apply. The DPDP Rules, 2025 add operational specifics regarding itemised notices and verifiable parental consent, meaning data processors in India face different statutory expectations than their regional counterparts, heavily impacting indemnities and limitation of liability clauses in your vendor contracts.

Could this happen to you

If your enterprise standardises its data handling agreements across South Asia without accounting for these statutory differences, you risk severe contractual and regulatory exposure. A single master service agreement will not suffice. For example, if a cross-border payments vendor suffers a data breach, the DPDP Rules, 2025 mandate intimation to affected Data Principals without delay and a detailed report to the Data Protection Board of India within 72 hours. Sri Lanka enforces different timelines and processor liabilities. If your outside counsel has not tailored your processor indemnities and breach notification workflows to each specific jurisdiction, your legal review burden will skyrocket during an incident, exposing the firm to statutory penalties and immediate RBI scrutiny.

What companies should do in the next 30 days

1. The General Counsel must initiate an immediate audit of all cross-border data transfer flows, generating a mapping report that identifies destinations requiring explicit consent under Sri Lankan law versus those permitted under India's Section 16.

2. Legal and Procurement teams need to review and renegotiate existing vendor contracts, creating a jurisdiction-specific addendum repository to enforce DPDP processor obligations distinct from other regional laws.

3. The Head of Compliance must align the company's breach response playbook with the DPDP Rules, 2025, producing a 72-hour reporting workflow tested against overlapping RBI digital lending guidelines.

4. Product leads must collaborate with Legal to update onboarding flows, ensuring verifiable consent records are maintained where Section 7 legitimate uses do not apply, creating a clear evidence trail for auditor review.

What to watch

Monitor the Central Government for any notifications under Section 16 establishing a negative list of countries restricted from receiving Indian personal data. General Counsels should also watch for the full operationalisation of the Data Protection Board of India, which will set the enforcement tone for breach investigations and processor accountability. There are exactly 256 days remaining until the DPDP hard compliance deadline of 13 May 2027. Use this window to shift from baseline legal review to deploying a privacy-by-design architecture that enhances regulator defensibility. To evaluate your current data transfer and vendor contract exposure, test your systems at freescan.complydp.com.

Sources

Frequently asked questions

How does the jurisdictional scope of India's DPDP Act differ from broader regional laws?

The DPDP Act, 2023 focuses exclusively on digital personal data, including offline data that is subsequently digitised. It applies to processing connected to offering goods or services to Data Principals in India, unlike other regional laws that may cover non-digital processing.

What is the cross-border data transfer mechanism under the DPDP Act?

Under Section 16, India follows a permitted unless restricted model. Cross-border transfers are generally allowed unless the Central Government notifies a specific negative list of restricted countries or territories.

Are we required to obtain consent for all data processing in our fintech apps?

No, consent is the primary basis for processing, except where Section 7 legitimate uses apply. General Counsels must evaluate whether specific RBI-mandated processing falls under legitimate uses before embedding consent flows.

What are the breach notification obligations if our payments vendor is compromised?

Under the DPDP Rules, 2025, you must provide intimation to affected Data Principals without delay. Additionally, a detailed breach report must be submitted to the Data Protection Board within 72 hours.

When is the strict enforcement deadline for the DPDP Act?

Enterprises must achieve full compliance before the hard enforcement deadline on 13 May 2027. Legal teams should focus on updating processor contracts and breach workflows well before this date.