Glossary · Cross-Border Transfer
What Is Cross-Border Transfer Under DPDPA?
Most Indian SMBs already send personal data abroad without calling it a transfer — CRM, helpdesk, payroll, LIS. Section 16 is permissive by default, but sectoral localisation and processor liability still bind you. Inventory the regions before 13 May 2027.
Last reviewed: 13 August 2026
Definition
A cross-border transfer is any movement of personal data you hold in India to a server, service or team outside India — a US email tool, a Singapore cloud region, an offshore support desk, a founder pulling a customer list into a foreign spreadsheet. Section 16 of the DPDP Act, 2023 takes a permissive approach: transfers are allowed by default, and the Central Government may restrict them only by notifying specific countries or territories. There is no adequacy list and no standard contractual clauses to sign. Section 16(2) preserves any Indian law that is stricter, so sectoral localisation rules still bind you on top. Rule 15 additionally subjects every Data Fiduciary transferring personal data outside India to requirements the Central Government may specify.
How this matters in practice
Most SMBs transfer data abroad without realising it — CRM, helpdesk, analytics and payroll all default to foreign regions. Section 8(2) requires a valid processor contract; Section 8(5) keeps you liable for security of processing done on your behalf, regardless of what that contract says. Privigo maps every vendor's hosting region against your data inventory, flags sectoral localisation conflicts, and keeps that vendor list export-ready for the Section 11 access request.
Frequently asked questions
Can I keep using AWS, Google Workspace or a US-based CRM?
Almost certainly yes. DPDPA is the opposite of GDPR here — you don't need an adequacy finding, standard contractual clauses or a transfer impact assessment. Section 16(1) only bites once the Central Government notifies a specific country or territory as restricted. Check the latest MeitY notifications before relying on this; no restricted-country list should be treated as permanent. Practically, your job is not to justify each transfer but to know where your data actually sits, so you can act quickly if a country is later notified. Rule 15 additionally subjects every Data Fiduciary transferring personal data outside India to requirements the Central Government may specify.
My sector has its own data localisation rule — which one wins?
The stricter one. Section 16(2) says nothing in the section restricts the application of any other Indian law that gives a higher degree of protection or restriction on transfer. RBI's 2018 payment systems directive requiring end-to-end payment data to be stored only in India survives DPDPA untouched, and similar sectoral mandates apply in insurance and telecom. So an NBFC or payments SMB can be fully DPDPA-compliant on transfers and still be in breach of its regulator. Check your sector rule first; DPDPA is the floor, not the ceiling. Separately, a Significant Data Fiduciary may face extra localisation once categories are specified — Rule 13 binds SDFs only, and SDF status is conferred by Central Government notification under Section 10.
What happens if my overseas vendor has a breach?
It is treated as your breach. Section 8(2) requires a valid contract before a Data Processor handles personal data on your behalf; Section 8(5) makes you responsible for reasonable security safeguards including processing undertaken by that processor, and no contract shifts that. The reporting clock runs in parallel and cumulatively: a CERT-In report within 6 hours of noticing the incident; Rule 7(1) intimation to affected Data Principals without delay; Rule 7(2)(a) initial Board intimation without delay; and Rule 7(2)(b) the detailed report to the Board within 72 hours. Penalties sit in separate slabs — up to ₹250 crore for failing reasonable security safeguards under Section 8(5), and up to ₹200 crore for failing to notify a breach under Section 8(6). Build your vendor register backwards from 13 May 2027.
Find out where your data actually sits
Book a 30-minute call. We list your vendors, their hosting regions, and any sectoral localisation conflict — the map you need for a Section 11 request and for a Saturday-night breach.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.