Key takeaways
- Section 16 permits transfer of personal data outside India to any territory or sector, unless the Central Government restricts it by notification.
- This "blacklist" model is the opposite of GDPR's "whitelist" adequacy approach — under the DPDP Act, the default is that transfers are allowed.
- Restrictions will be territory-based or sector-based, so organizations should watch MeitY notifications and build transfer flexibility into architecture.
The default: transfers are allowed
Section 16 of the DPDP Act provides that a Data Fiduciary may transfer personal data outside India, subject to such restrictions as the Central Government may prescribe. In practice, this means the default position is permissive — you can transfer data across borders unless the Government has restricted a specific territory or sector.
Blacklist versus whitelist
| Aspect | DPDP Act (India) | GDPR (EU) |
|---|---|---|
| Default position | Transfers allowed | Transfers restricted |
| Model | Blacklist — Government restricts specific territories/sectors | Whitelist — adequacy decisions plus safeguards (SCCs, BCRs) |
| Approval needed | No per-transfer approval | Yes, unless adequacy or safeguards apply |
| Enforcement tool | Notification of restricted territories | Adequacy decisions, SCCs, BCRs, derogations |
What this means in practice
For a company processing Indian personal data, cross-border transfer compliance is less about pre-approval and more about monitoring: does the Government restrict the destination territory or sector? Notifications from MeitY and the DPB are the primary signal.
Because restrictions can be sector-specific, an organization's transfer map matters — which data, to which territory, for which processing purpose. If a territory is later restricted, the data map tells you what to relocate or change.
Practical steps
- Build a transfer inventory: record where personal data flows, for which purposes and under which contracts.
- Watch for restrictions: track Government notifications on restricted territories and sectors.
- Design for portability: choose cloud and vendor architectures that can move data quickly if a territory is restricted.
- Align with GDPR: for global organizations, one transfer matrix covering both blacklist (India) and whitelist (EU) regimes reduces surprises.
Map your cross-border data flows
KryptoMindz helps global teams build transfer inventories and architectures that stay compliant under both DPDP and GDPR.
Discuss Your Transfer Strategy