AMLEGALS — Strategic Lawyering
Back to Documents
Framework

Cross-Border Data Transfer Assessment

Documenting compliance with Section 16 requirements for international data flows

Section 16Rule 15

Personal data can flow across borders, but not without guardrails. Section 16 permits transfers to countries not restricted by the Central Government. Before you transfer, you must assess the destination and document your compliance basis.

The Negative List Approach

DPDPA takes a negative list approach to cross-border transfers. Data can flow to any country unless the Central Government has specifically restricted transfers to that country. This is different from GDPR adequacy decisions. Until restrictions are published, transfers are generally permitted.

Transfer Assessment Process

Even without a restricted list, prudent practice requires assessment before transfer. Where is the data going? What protections exist in that jurisdiction? Can you enforce contractual safeguards? This assessment demonstrates due diligence.

Key Points
  • Destination country identification
  • Legal framework in destination
  • Contractual protections in place
  • Enforcement mechanisms available
  • Risk assessment documentation

Contractual Safeguards

Regardless of destination country status, your contracts with overseas recipients should include DPDPA-aligned protections. Purpose limitations. Security requirements. Breach notification. Sub-processing controls. These contractual safeguards travel with the data.

Monitoring for Changes

The Central Government may restrict transfers to specific countries at any time. You must monitor for such announcements and be prepared to halt or reroute data flows if restrictions are imposed.

Essential Clauses

Transfer Inventory

Section 16

List of all cross-border transfers and destinations

Destination Assessment

Section 16

Analysis of each destination legal framework

Contractual Protections

Section 16

DPDPA-aligned clauses in transfer agreements

Restriction Monitoring

Section 16

Process for tracking government restrictions

Contingency Planning

Section 16

Response plan if destination becomes restricted

Data Principal Notification

Section 5

How transfers are disclosed in privacy notices

Implementation Steps

1

Inventory all data flows crossing Indian borders

2

Identify destination countries for each transfer

3

Research legal frameworks in each destination

4

Review existing contracts for DPDPA alignment

5

Update contracts to include required protections

6

Document assessment rationale for each transfer

7

Establish monitoring for government restriction announcements

8

Develop contingency plans for potential restrictions

Frequently Asked Questions

Need This Document Drafted?

Understanding the requirement is the first step. Having it implemented correctly is what protects your organization. Our team drafts DPDPA-compliant documents tailored to your specific operations.

Get in Touch

DPDPA Cross Border Transfer Assessment: questions and answers

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Cross Border Transfer Assessment?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Cross Border Transfer Assessment under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Cross Border Transfer Assessment under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Cross Border Transfer Assessment?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Cross Border Transfer Assessment rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Cross Border Transfer Assessment?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Cross Border Transfer Assessment · DPDPA Exposure Assessment