At a glance
The DPDP Act takes a “negative list” approach to sending personal data abroad: transfers are allowed by default unless the government has restricted a country, and none currently is. So a visa consultant emailing a client’s passport to a foreign embassy isn’t blocked by the Act itself. What it still requires, transfer or not, is the same notice, consent and security discipline that applies to any other use of that data — the cross-border step adds no new consent requirement, but removes none of the existing ones.
Educational resource only. This explains how the cross-border transfer rule under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to visa and immigration consultants sending client documents abroad; it is not formal legal advice. This is a genuinely evolving area — re-check current guidance before relying on it.
The situation
Visa and immigration consultants send some of the most sensitive identity documents in a person’s file — passports, financial statements, sometimes medical records for visa categories that require them — to destinations outside India as a routine part of the job: embassies, consulates, visa-processing centres, and partner firms abroad. It’s worth knowing precisely what the DPDP Act does and doesn’t say about that movement, because the headline fear (“can I even send this abroad?”) is usually not the actual compliance gap.
Does DPDP restrict sending data to specific countries?
Not currently, for any country. The DPDP Act’s cross-border transfer provision (Section 16, operationalised through Rule 15) works on a negative list model — the opposite of the EU’s adequacy-based approach. Transfers outside India are permitted by default; the government can restrict transfers to a specific country or territory by notification, but as of today, no such restriction has actually been issued. Practically: sending a client’s passport to a foreign embassy or visa centre is not blocked by the Act itself, in any destination country.
What this means in practice for visa consultants
The default-permissive rule covers the “can we send it” question — it doesn’t answer “should we send it this way.” A consultant is free, as far as the DPDP Act’s cross-border rule goes, to transmit passport copies, financial documents and supporting materials to embassies, consulates and overseas partner firms as the visa process requires. What that freedom doesn’t touch is everything else the Act asks of the same data before it ever crosses a border — which is where the actual day-to-day compliance work sits.
What DPDP still requires, transfer or not
The transfer itself isn’t the gap most consultancies have — the intake and handling around it usually is.
- Notice and consent at collection — the client should know, before handing over a passport, that it will be shared with a specific embassy or processing centre as part of the application, not just “some third parties.”
- Minimisation — only the documents the specific visa category actually needs, not a maximal document set collected once and reused across applications.
- Security in transit — encrypted or access-controlled channels for sending sensitive documents to embassies and partners, rather than plain email attachments, especially for high-value applications (family visas, investment/HNI categories).
- Retention discipline — passport copies and supporting documents held only as long as the specific application needs them, not indefinitely across a client’s history with the consultancy.
How visa-processing centres actually handle client data
Most Indian visa applications don’t go straight from consultant to embassy — they route through an outsourced visa-processing centre (VFS Global and similar operators run this model for the large majority of Schengen, UK and several other visa categories), which adds its own data-handling layer worth understanding rather than treating as a black box. These centres operate strictly as processors, collecting and submitting documents on behalf of the client government — they don’t make visa-approval decisions themselves, and shouldn’t be confused with the embassy or consulate they serve. Based on how these centres typically describe their own practices: application-specific data (the passport copy, supporting documents, biometric data where collected) is generally deleted from the centre’s own systems once it’s been transmitted to the client government, but a smaller set — name, contact details, passport number — is often retained separately to handle appointment scheduling and status queries. Where a client pays for value-added services (courier return, SMS updates, premium lounge access), that transaction data is typically held for a defined period tied to the service itself, not the visa application’s lifecycle. Two flows are worth being explicit with clients about: the centre shares data with the client government or diplomatic mission (the actual decision-maker on the visa), and separately with courier partners for physical document return — both are third-party disclosures a consultant’s own notice should account for, even though the consultant isn’t the one making them.
Cross-border movement happens at more than one layer, and it’s worth naming both to a client rather than only the obvious one. The visa application itself moves to the client government’s country as part of the process — that’s the transfer a client expects. Less visible: many processing centres also route data through their own internal systems, which can mean a secondary transfer to the centre’s data centres (commonly located in Europe or North America for global operators), governed by the centre’s own cross-border safeguards — Standard Contractual Clauses for transfers into the EU/European Economic Area (EEA) is the mechanism most commonly used. A consultant relying on one of these centres isn’t the one responsible for that internal transfer’s legal basis, but should be able to tell a client, in general terms, that the centre itself may move data through more than one country before it reaches the embassy.
Sub-agents and outsourcing partners
A consultancy that routes part of its own workflow through a sub-agent — a local representative for a specific visa category, a document-collection partner in another city, a translation or attestation service — has created a data flow that’s easy to overlook because it never crosses an international border, but still needs the same processor discipline as anything sent abroad. The DPDP Act’s cross-border rule governs data leaving India; it says nothing about a domestic sub-agent handling the same passport copies and financial documents inside the country. That doesn’t make the arrangement lower-risk — it just means the relevant duty is the ordinary Data Processor discipline (a written agreement, defined purpose, no repurposing, return-or-destroy on completion) rather than the transfer rule specifically.
In practice, three questions are worth answering before handing a client’s file to a sub-agent or outsourcing partner:
- Does the client’s consent notice actually name this category of recipient? “We may share your documents with our processing partners” is vaguer than what most clients would expect if asked directly whether a different, unnamed company would be handling their passport.
- Does the sub-agent have its own agreement with the consultancy, covering security expectations, what happens to the documents once that specific task is done, and confirmation the sub-agent isn’t retaining copies beyond the engagement?
- Is the sub-agent relationship stable, or does it change per case (a different local representative depending on the destination country or visa category)? A rotating set of sub-agents without a consistent baseline agreement is a harder position to defend than a small, vetted panel the consultancy actually manages.
A consultancy that has never mapped its own sub-agent network this way is often surprised, once it does, by how many hands a client’s passport copy actually passes through before the visa is granted — and each of those hands is a point where the same notice, security and retention duties apply, border-crossing or not.
Why this could still change
This is one of the more unsettled corners of the DPDP Act, and the current permissiveness isn’t guaranteed to stay static. The government retains the power to notify country-level restrictions at any time, and separate proposals around cross-border rules for Significant Data Fiduciaries have circulated without being finalised. A consultancy that builds its cross-border document flow assuming today’s default-permissive rule is permanent should keep an eye on updates rather than treat this as settled law — this hub’s freshness log tracks changes as they’re notified.
FAQ
Can a visa consultant legally send a client’s passport copy to a foreign embassy?
Yes — the DPDP Act’s cross-border rule permits transfers by default, and no country is currently restricted. The consultant still needs the client’s informed consent and reasonable security for the transfer itself.
Are there any countries Indian businesses currently can’t send personal data to under the DPDP Act?
Not as of now — the government hasn’t issued any country-specific restriction notification under Section 16. That could change with future notifications.
Does sending data abroad trigger any extra paperwork under the DPDP Act beyond normal consent?
Not currently — there’s no separate cross-border consent form or mechanism required beyond the standard notice-and-consent and security obligations that already apply to the data.
Do RBI, SEBI or other sector regulators impose stricter rules than the DPDP Act for cross-border data?
Yes, in their own domains — sector-specific data-localisation requirements (in financial services, for instance) can be stricter than the Act’s general permissive rule and apply on top of it where relevant, though this typically isn’t the case for passport and visa-consultancy work specifically.
Does a visa-processing centre like VFS Global delete client documents after submission?
Application-specific documents are typically deleted from the centre’s own systems once transmitted to the client government, though a smaller set of contact and reference details is usually retained for appointment and status-query purposes. The exact retention period is set by the centre, not the consultant — worth confirming directly if a client asks.
Does using a local sub-agent for part of the process count as a cross-border transfer?
No — a domestic sub-agent handling documents inside India isn’t a cross-border transfer, but it still needs the ordinary Data Processor safeguards: a written agreement, a defined purpose, and no retention beyond what the specific task requires.