At a glance
Sending Indian customers’ data overseas is broadly allowed today. The DPDP Act uses a negative-list model (Section 16): transfers are permitted unless the government restricts a specific country, and none has been restricted so far. Rule 15 adds one live condition — the government can set requirements before you make personal data available to a foreign State or its agencies. On top of that, sectoral rules (like RBI’s payment-data localisation) can still force some data to stay in India. Your DPDP duties travel with the data wherever it goes.
Educational resource only. This explains the cross-border transfer rules for personal data under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice — cross-border rules here are still partly unsettled, so re-check the current position before relying on it.
The situation
You want to route Indian customer data to a server, vendor, or team abroad, and you’ve heard conflicting things — that India now mandates localisation, that transfers need government approval, that only “adequate” countries are allowed. Most of that describes either a different law or an earlier draft that didn’t survive. The enacted position is more permissive than the rumours, but it has specific edges worth knowing before you move anything.
What’s allowed today: the negative-list default
DPDP allows overseas transfers by default and restricts by exception — the opposite of a whitelist. Section 16 of the DPDP Act empowers the central government to notify countries or territories to which personal data may not be transferred, or may be transferred only on conditions. This is a “negative list”: everything is open unless a destination is specifically named as closed. As of now, no country or territory has been notified as restricted, so the default permissive baseline applies across the board. This matters because an earlier version of India’s data-protection thinking floated a “positive list” (transfer only to approved countries) and a heavier localisation regime — neither is what the Act enacted. Planning around an approved-countries list, or assuming a blanket bar on foreign transfers, is planning against a rule that isn’t in force.
What Rule 15 actually restricts
The one concrete cross-border condition in the Rules is narrow and specific: making personal data available to a foreign government or its agencies. Rule 15 of the DPDP Rules provides that personal data may be transferred outside India subject to any requirements the central government specifies, by general or special order, for making that data available to a foreign State, or to a person or entity under the control of or acting as an agency of such a State. Read carefully, this targets a particular scenario — foreign-government access to Indian personal data — rather than ordinary commercial transfers to a private vendor abroad. So a routine transfer to your foreign cloud provider or SaaS tool isn’t what Rule 15 is aimed at; it’s the state-access channel the rule reserves the power to condition. The government hasn’t yet published the specific requirements, so the practical takeaway is to distinguish “sending data to a private processor abroad” (permitted under the default) from “making data available to a foreign State” (a reserved, conditionable category), and to watch for the orders that will flesh the latter out.
The sectoral rules that still force some data to stay
DPDP’s permissiveness doesn’t override a stricter sectoral localisation rule — those sit on top and win where they apply. Section 16 expressly preserves any Indian law that imposes a higher degree of restriction on transferring personal data outside India. The clearest live example is the Reserve Bank of India’s payment-data localisation directive, which requires payment-system data to be stored only in India — that obligation is untouched by DPDP’s general permissiveness and continues to bind regulated payment entities. Other regulated sectors (finance more broadly, insurance) carry their own record-keeping and localisation expectations. So the honest rule is: check your sector before you rely on the DPDP default. A fintech moving payment data abroad can be fully within Section 16’s general allowance and still in breach of its RBI obligations — the two are separate regimes, and the sectoral one is not softened by DPDP.
Step by step: transferring data overseas compliantly
Confirm no restriction applies, then keep your DPDP duties bolted to the data.
- Map the transfer — what data, to which destination, to which vendor or entity, for what purpose. You can’t clear a flow you haven’t described.
- Check the destination isn’t government-restricted under Section 16. Currently none is — but this is the single item that can change with one notification, so it’s a standing check, not a one-time one.
- Check your sector’s localisation rules — if you’re in payments, finance, or insurance, confirm the data class isn’t one your regulator requires to stay in India.
- Distinguish private-processor transfers from foreign-State access — the former runs on the default; the latter is the Rule 15 reserved category to treat cautiously.
- Keep every DPDP safeguard attached to the data wherever it lands — notice, consent or lawful basis, security, retention limits, and breach reporting all still apply; the transfer doesn’t discharge them.
- Bind the foreign recipient by contract as your processor, so your obligations are enforceable down the chain.
- Re-check on a cadence, because the restricted-country list and SDF localisation rules are both still open.
What’s still being decided
This is one of the most movable parts of the framework — build for the default, but design so a future restriction wouldn’t break you. Two things are genuinely unsettled: whether and which countries get added to the restricted list under Section 16, and whether Significant Data Fiduciaries will be told to keep specified data classes within India. Both would arrive by notification and could change what’s allowed with little runway. The resilient posture is to keep a clear map of where your Indian users’ data goes, avoid architecting yourself into a single foreign region you couldn’t move away from, and treat “watch this space” as an actual standing task — a periodic re-check tied to the DPDP-watch discipline — rather than a one-off. The default is permissive today; the smart build assumes it might not always be.
FAQ
Can I send Indian customer data to servers outside India?
Generally yes, under the current negative-list default — no destination country has been restricted under Section 16. Your DPDP obligations continue to apply to the data wherever it’s processed, and sectoral rules may still require some data to stay in India.
Does DPDP require me to get approval before transferring data abroad?
No general pre-approval is required for ordinary commercial transfers to a private processor. Rule 15 reserves government power over making data available to foreign States or their agencies specifically — a narrower situation than a routine vendor transfer.
Is there a list of approved countries I can transfer to?
No. DPDP uses a negative list (restricted destinations), not a positive/approved list. Today that restricted list is empty, so transfers are broadly permitted rather than limited to pre-cleared countries.
Does RBI’s data localisation still apply under DPDP?
Yes. Section 16 preserves stricter sectoral rules, so RBI’s payment-data localisation directive continues to bind regulated entities regardless of DPDP’s general permissiveness. Check your sector’s rules separately.
Could the rules on overseas transfers change?
Yes — this is one of the least settled parts of the framework. The government can notify restricted countries, and SDF-specific localisation is still open. Both would come by notification, so re-check the current position periodically rather than assuming today’s default is permanent.