AMLEGALS — Strategic Lawyering
Data Transfers

How to Transfer Personal Data Outside India

Structuring compliant cross border data transfers under DPDPA

Updated 12 January 2025

Executive Summary

Cross border data transfers are essential for global business operations but subject to legal constraints under DPDPA. Section 16 establishes the framework for permissible transfers, which will evolve as the government issues notifications. This guide addresses how to structure compliant transfers within the current and emerging regulatory framework.

Key Takeaways

  • 1
    Transfers are permitted only to countries or territories notified by the Central Government
  • 2
    Transfers to non-notified destinations face restrictions that may prohibit transfer
  • 3
    Contractual safeguards provide additional protection for permitted transfers
  • 4
    Sectoral regulations may impose additional requirements beyond DPDPA
  • 5
    Documentation of transfer compliance supports regulatory demonstration

1The Section 16 Framework

DPDPA permits transfers of personal data to countries or territories that the Central Government notifies as appropriate destinations. Transfers to other destinations are restricted. This framework differs from adequacy or binding corporate rules models used in other jurisdictions, creating a more binary permitted or restricted structure.

2Identifying Cross Border Transfers

Before addressing compliance, determine which data movements constitute cross border transfers requiring attention.

1

Direct Transfers

Data transmitted from India to foreign recipients, whether affiliates, partners, or service providers.

2

Cloud Storage

Data stored on cloud infrastructure located outside India, even if accessed primarily from India.

3

Remote Access

Access to data stored in India by personnel located abroad may constitute transfer depending on access modalities.

4

Third Party Processing

Where Indian organisations use foreign processors, data sent to those processors constitutes transfer.

3Checking Permitted Destinations

Verify whether intended transfer destinations are on the notified list.

1

Monitor Notifications

Track Central Government notifications regarding permitted countries. These are published in the official gazette.

2

Verify Current Status

Before relying on a destination being permitted, confirm current notification status. Permitted lists may change.

3

Document Verification

Maintain records of verification performed for each transfer, supporting compliance demonstration.

Important Warnings

  • •Notification status may change. Periodic reverification is prudent.
  • •A country being generally safe does not make it a permitted destination absent notification.

4Transfers to Permitted Destinations

For transfers to notified countries, compliance requires appropriate safeguards even though the transfer itself is permitted.

1

Contractual Safeguards

Implement contracts with foreign recipients that provide appropriate data protection commitments. As standard clauses develop, adopt them; until then, use robust bilateral terms.

2

Due Diligence

Assess recipient security practices and compliance capabilities before transferring data.

3

Purpose Limitation

Restrict recipient use to purposes consistent with the basis for original collection. Transfer does not create new processing permissions.

4

Ongoing Oversight

Maintain oversight of how transferred data is handled. Periodic audits or certifications provide assurance.

5Addressing Non-Permitted Destinations

Where a needed destination is not notified, options are limited but some approaches may be available.

1

Necessity Assessment

Confirm that transfer to the non-notified destination is actually necessary. Can the purpose be achieved with local processing or transfer to a permitted destination?

2

Data Minimisation

If transfer cannot be avoided, minimise what is transferred. Can some data be anonymised or pseudonymised before transfer?

3

Regulatory Consultation

For essential business processes requiring non-permitted transfers, consider seeking regulatory guidance on available options.

4

Alternative Structuring

Explore whether processing can be restructured to avoid the prohibited transfer, such as processing in India with only results shared abroad.

6Group Company Transfers

Transfers within multinational groups are subject to the same rules as transfers to unrelated parties, but may be structured for efficiency.

1

Group Data Transfer Agreement

Implement a group-wide agreement governing transfers among affiliates. This provides consistent protections and reduces transaction-specific negotiation.

2

Data Hub Approach

Consider designating a group entity in a permitted jurisdiction as a data hub to reduce transfer complexity.

3

Consistent Standards

Apply consistent data protection standards across the group, exceeding local requirements where necessary to enable transfers.

7Documentation and Compliance Records

Maintain comprehensive records supporting transfer compliance.

1

Transfer Inventory

Document all cross border transfers including data types, destinations, recipients, and purposes.

2

Legal Basis Records

For each transfer, record the legal basis supporting it and verification of permitted destination status.

3

Contractual Documentation

Maintain executed transfer agreements and evidence of due diligence performed.

4

Audit Trail

Preserve records demonstrating ongoing compliance monitoring and any issues identified and addressed.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Transfer Data Outside India: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Transfer Data Outside India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Transfer Data Outside India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Transfer Data Outside India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Transfer Data Outside India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Transfer Data Outside India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Transfer Data Outside India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Transfer Data Outside India · DPDPA Exposure Assessment