Cross-Border Data Transfers Under DPDPA: The Negative-List Model Explained

Where the GDPR builds a wall with gates (adequacy decisions, SCCs, BCRs), the DPDPA takes the opposite architecture: transfers are permitted by default, except to countries the Central Government specifically restricts by notification. This is Section 16's negative-list model.
What Section 16 actually says
Personal data may be transferred outside India for processing, except to countries or territories the government notifies as restricted. No transfer-impact assessments, no standard contractual clauses, no adequacy paperwork — a deliberately trade-friendly design.
The four catches
1. The list can change overnight. A country your infrastructure depends on could be notified. Know, at all times, which countries your data touches — including your processors' sub-processors.
2. Higher sectoral bars survive (s.16(2)). Any Indian law imposing a stricter standard continues to apply. The RBI's payment-data localisation mandate, IRDAI and other sectoral regimes are unaffected by the DPDPA's permissiveness. Fintechs: your RBI obligations did not relax.
3. SDF localisation. For Significant Data Fiduciaries, the government can require that specified personal data not leave India at all. If SDF designation is plausible for you, architect for the possibility now — data-residency-by-design is far cheaper than retrofitting.
4. Accountability travels. Transferring data abroad transfers none of your liability. Your DPA with every offshore processor must flow DPDPA obligations down, and you remain answerable to the Board for what happens in that region.
A practical transfer register
Maintain a register recording: data category → destination country → recipient entity → purpose → contract in place → sectoral overlay (if any). Review it whenever a vendor changes regions and whenever the government updates the restricted list.
Residency as a selling point
For India-focused businesses, the simplest posture is keeping primary processing in-country. Data Adhikaar runs on AWS Mumbai (ap-south-1) with DR in Hyderabad — Indian data residency by default — while Sambandh tracks vendor and processor geography as part of your live RoPA. Map your exposure with the readiness assessment.
Data Adhikaar Editorial Team
DPDPA Compliance Specialists, Qodequay Technologies
Get DPDPA-ready before the enforcement window closes.
Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.
Or call +91 98226 28174