The Section 16 Framework
Section 16(1) of the DPDPA provides that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to any country or territory outside India. The operative mechanism is a negative list: all transfers are permitted unless specifically restricted. This is fundamentally different from the GDPR's adequacy framework, where all transfers are restricted unless specifically permitted.
How Restricted Jurisdictions Are Notified
The Central Government exercises its Section 16(1) power through official notification published in the Gazette of India. The notification will specify: the country or territory to which transfer is restricted, the effective date of the restriction, any transitional period for existing transfers, and any conditions under which limited transfers may continue (if the notification provides for exceptions).
What Changes When a Jurisdiction Is Restricted
When a jurisdiction is added to the restricted list, every Data Fiduciary that transfers personal data to that jurisdiction must: (a) immediately cease new transfers to that jurisdiction, (b) implement technical controls to prevent data from routing through that jurisdiction, (c) migrate existing data stored in that jurisdiction to a permitted jurisdiction within the transitional period, and (d) update all Data Processor Agreements to reflect the restriction.
Cloud Infrastructure Challenges
The restricted jurisdiction framework creates specific challenges for cloud-native operations. Major cloud providers (AWS, Azure, GCP) offer region selection, but many services have dependencies on global infrastructure that may route data through jurisdictions the user did not select. DNS resolution, CDN caching, DDoS mitigation, and edge computing all involve data routing decisions that may not respect geographic boundaries. Companies must work with cloud providers to obtain contractual guarantees that Indian personal data will not transit through restricted jurisdictions under any circumstances — including failover scenarios.
Monitoring Obligations
The restricted jurisdiction list is not static. Jurisdictions can be added or removed by subsequent notification. Companies must establish a monitoring mechanism to track Central Government notifications and assess the impact on their data routing architecture. This is not a one-time compliance exercise — it is an ongoing obligation that requires a process, an owner, and a response protocol.
Practical Steps for Global Operations
1. Map every system that processes Indian personal data and the jurisdictions where data is stored, processed, or transits. 2. Implement geo-fencing controls in cloud infrastructure. 3. Obtain contractual commitments from cloud providers on data routing. 4. Establish a notification monitoring process for Section 16(1) notifications. 5. Create a rapid response protocol for newly restricted jurisdictions. 6. Review CDN, DNS, and edge computing configurations. 7. Document all transfer paths as evidence of compliance. 8. Include restricted jurisdiction obligations in all new Data Processor Agreements.

