Cross-Border Data Transfer Under DPDP
The DPDP position is more permissive than many expected, and less settled than a compliance plan would like.
The general position
Rule 15 permits transfer outside India, subject to the Data Fiduciary meeting such requirements as the Central Government may specify by general or special order, in respect of making that personal data available to a foreign State, or to a person or entity under the control of or an agency of such a State.
This is a permissive default with a reserved power, rather than a prohibition with exceptions. It is a lighter-touch position than several other regimes take.
The Significant Data Fiduciary overlay
Rule 13(4) is separate and stricter. A Significant Data Fiduciary must ensure that personal data specified by the Central Government, on the recommendations of a committee it constitutes including officials from the Ministry of Electronics and Information Technology, is not transferred outside India — along with the traffic data pertaining to its flow.
Traffic data is easy to overlook. Restricting the payload while metadata about the flow leaves the country would not satisfy it.
Sector rules may bind harder
DPDP is not the only instrument here. RBI's payment data storage requirements, and other sector directions, impose their own localisation obligations that are stricter than Rule 15. For a regulated entity those usually determine the architecture, with DPDP layered on top.
The right question is not whether you may transfer data today. It is whether you could stop within a reasonable period if an order required it.
Infosek Team
What to do
- Record, per data set, whether it leaves India and where it goes. This is a field in the record of processing.
- Include your Data Processors and their sub-processors, since transfer often happens through the supply chain.
- Track traffic and metadata flows, not only payloads.
- Check sector obligations first, since they are frequently stricter and already binding.
- Prefer architectures where the region a data set sits in is a configuration decision rather than a rebuild.
Common questions
Can personal data be transferred outside India under DPDP?
Yes. Rule 15 permits personal data processed by a Data Fiduciary to be transferred outside India, subject to the Data Fiduciary meeting any requirements the Central Government specifies by general or special order in respect of making that data available to a foreign State, or to a person or entity under the control of or an agency of such a State.
Does DPDP require data localisation?
Not generally. Rule 13(4) applies to Significant Data Fiduciaries and requires them to ensure that personal data specified by the Central Government, on the recommendations of a committee it constitutes, together with the traffic data pertaining to its flow, is not transferred outside India.
Using overseas cloud infrastructure?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment