AMLEGALS — Strategic Lawyering
HomeCross Border Transfers

Cross Border Transfers Under the DPDPA

The architecture foreign companies must build before the notification arrives

Anandaday Misshra|12 min
“The absence of a restricted country notification today is not permission to transfer without documentation. It is an interval. Use it.”
01

Why the negative list changes everything

Most data protection regimes use a positive list. The regulator identifies countries that provide adequate protection and permits transfers to those jurisdictions. GDPR adequacy decisions work this way. APEC CBPR recognition works this way.

The DPDPA inverts this architecture. Section 16 empowers the Central Government to notify countries to which transfers are restricted. Until such notification, transfers to all countries are permitted. After notification, transfers to restricted countries require specific Government authorisation or must cease.

This creates a compliance paradox. The absence of restrictions today does not relieve the documentation obligation today. An organisation that treats current permissibility as permanent will find itself scrambling to construct transfer governance on the day the Government exercises its Section 16 authority. The time to build the architecture is before the notification, because after it, the time is gone.

The negative list can be activated by executive notification at any time. Pre notification preparation is the only defensible position.

02

The data flow map is the first document the Board will examine

Before any cross border compliance architecture can be constructed, every data flow involving Indian personal data must be mapped. This is not preparatory. It is foundational.

The map must identify every category of personal data collected from Indian data principals, every jurisdiction where that data is processed, stored, or accessed, every third party and sub processor that handles the data, the legal basis for each transfer, and the contractual architecture governing each flow.

For multinational operations, the mapping exercise reveals uncomfortable realities. Cloud infrastructure spans jurisdictions by configuration, not by legal design. SaaS platforms route data through regions determined by load balancing, not by regulatory requirement. Customer support teams access Indian personal data from Manila, Dublin, and Austin without awareness that each access point carries a DPDPA obligation.

The map is the diagnostic. Without it, every subsequent compliance investment is built on assumption. Assumptions do not produce compliance undertakings in Board proceedings.

Cloud infrastructure does not respect jurisdictional boundaries. Your data flow map reveals where your compliance obligations actually are, not where you assume them to be.

03

Section 8(2) and the DPA that GDPR SCCs cannot replace

Every transfer to a processor outside India requires a Data Processing Agreement compliant with Section 8(2). The distinction matters: GDPR Standard Contractual Clauses do not satisfy this requirement.

The DPA must contain the specific purposes for which data is processed, mapped to the consent notice under Rule 3. It must impose the obligation to process data only on the Data Fiduciary's instructions. It must require reasonable security safeguards under Section 8(5). It must mandate breach notification to the Data Fiduciary without delay. And it must require data deletion upon completion of the processing purpose or upon withdrawal of consent.

For foreign companies with hundreds of vendor relationships, this means a systematic DPA remediation programme. Every existing vendor contract must be audited against Section 8(2). Every DPA must be reconstructed on DPDPA terms. Every sub processor must be identified and brought within the contractual chain. The organisations that attempt to use a single global DPA template will find that it satisfies the requirements of no jurisdiction fully, and the requirements of the DPDPA not at all.

Legacy DPAs constructed solely for GDPR do not satisfy Section 8(2) of the DPDPA. The structural differences — particularly in processor obligation architecture and consent-flow requirements — make remediation a necessity, not a discretionary exercise.

04

When the breach occurs in Frankfurt but the obligation arises in India

A data breach affecting Indian personal data triggers Section 8(6) notification obligations, regardless of where the breach occurs. If a Frankfurt data centre suffers a breach exposing personal data of Indian users, the notification obligation under the DPDPA begins the moment the breach is detected. Rule 7 prescribes the form and manner of notification.

The cross border dimension creates a coordination challenge. The breach response team in one jurisdiction must simultaneously satisfy DPDPA notification requirements in India, GDPR requirements in Europe, and potentially notification requirements in every other jurisdiction where affected data principals reside. The DPDPA does not accommodate multi jurisdictional coordination delays. The obligation is to notify "without delay."

Foreign companies must pre position their India breach response protocols. The protocol must identify the Indian notification authority, the DPDPA notification requirements, the legal adviser managing the Indian response, and the evidence preservation requirements. Constructing this protocol after the breach is not an option. The Board's standard of assessment will be whether the protocol existed before the incident, not whether it was created during it.

A breach in Frankfurt triggers notification obligations in India. The protocol must exist before the incident, not emerge during it.

05

Five components of a pre notification compliance architecture

The foreign company that builds its India cross border compliance architecture before the Section 16 notification is issued will have a defensible position. The architecture has five components.

Data Flow Registry. A maintained, auditable inventory of every cross border data flow involving Indian personal data. Updated quarterly.

DPA Library. India specific Data Processing Agreements with every processor and sub processor. Not GDPR SCCs. Not global templates. DPDPA native contracts constructed on Section 8(2) terms.

Transfer Impact Assessment. For every receiving jurisdiction, a documented assessment of the legal regime, the enforcement landscape, and the adequacy of protections. This becomes the evidence file if transfers to that jurisdiction are restricted.

Breach Response Protocol: India Chapter. A standalone protocol for DPDPA breach notification that integrates with the global incident response plan but operates independently for Indian notification requirements.

Board Response Package. Pre assembled documentation that can be produced within 48 hours of any regulatory inquiry. Consent records. DPA library. Transfer impact assessments. Breach protocol test results.

Five components. Built before the notification. The only cross border compliance architecture that produces a defensible position in Board proceedings.

Key takeaways

01

The DPDPA negative list under Section 16 is the inverse of GDPR adequacy. Current permissibility is not permanent.

02

Every cross border data flow involving Indian personal data must be mapped, documented, and governed by DPDPA specific DPAs.

03

GDPR Standard Contractual Clauses do not discharge Section 8(2) obligations. DPAs must be reconstructed.

04

A breach anywhere in the world affecting Indian data triggers DPDPA notification obligations. The protocol must pre exist.

05

The five component pre notification architecture is the defensible strategy.

Frequently asked questions

Are cross border data transfers currently permitted under the DPDPA?

Yes. Until the Central Government issues a notification under Section 16 restricting transfers to specific countries. The obligation to document and govern those transfers through compliant DPAs exists now, regardless of the notification status.

Can GDPR Standard Contractual Clauses be used for India transfers?

No. GDPR SCCs do not satisfy DPDPA Section 8(2) requirements. The Act imposes India specific obligations on processors, including consent mapped processing purposes, Indian breach notification requirements, and DPDPA specific deletion obligations, that have no equivalent in European SCCs.

What happens if a country is added to the restricted list after data has been transferred there?

The Government notification under Section 16 will specify the requirements. Foreign companies must either obtain specific authorisation, repatriate the data, or cease processing. Organisations with pre existing transfer documentation and alternative arrangements will transition. Others will face operational disruption and potential enforcement action.

Ready to assess your India compliance position?

Get in Touch

DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies: questions and answers

Does DPDPA apply to companies outside India?

The Act applies to processing of digital personal data outside India where the processing is connected with any activity relating to the offering of goods or services to Data Principals within the territory of India. The statutory test is the offering of goods or services within India — not the citizenship or residence of the individual.

How does DPDPA regulate cross-border transfer of personal data?

Cross-border processing is governed by (a) Section 16, under which the Central Government may, by notification, restrict transfer of personal data to specified countries or territories; and (b) Rule 15, which requires compliance with any requirements the Central Government may specify concerning access to such data by foreign States, their agencies or entities controlled by them. Sectoral localisation obligations under RBI, IRDAI, SEBI and other regulators continue to apply independently and must be preserved.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA for foreign companies: Cross Border Data Transfers Foreign Companies · DPDPA Exposure Assessment