3. What amounts to a cross-border transfer
The Rule does not confine transfer to the physical relocation of a database. In practical terms, personal data may be transferred outside India whenever it is transmitted, replicated, disclosed or otherwise made available to a recipient or system outside India.
Relevant arrangements can include:
-
uploading data to an overseas server;
-
storing backups in a foreign cloud region;
-
replicating an Indian database abroad;
-
sending files by email to an overseas recipient;
-
permitting a foreign support team to access an Indian-hosted system;
-
routing customer information through a global helpdesk;
-
submitting personal data to an overseas AI service;
-
transferring logs to a foreign security-monitoring centre;
-
making data available through a global group database;
-
or enabling an overseas administrator to view or download records.
The location of the primary server is therefore not the only consideration.
3.1 Illustration: Indian storage with overseas support
A company stores its customer database in an Indian data centre. Its technology provider’s support team in another country can log in remotely and view customer records whenever a support ticket is raised.
The company should treat this arrangement as involving cross-border availability of personal data. Saying that the server remains physically in India does not fully describe the processing.
3.2 Illustration: Overseas backup
An organisation processes all active personal data in India but automatically sends daily backups to a foreign disaster-recovery site.
The backup is itself personal data. The overseas replication is relevant to Rule 15, Section 16, security requirements and any applicable sectoral localisation requirement.
3.3 Illustration: AI drafting service
An employee submits a customer complaint containing names, account information and transaction history to an AI platform. The platform processes the prompt abroad.
This is an overseas processing event even if the employee receives the output immediately and does not deliberately save the prompt. The Data Fiduciary must assess the provider, its use of inputs, retention, subprocessors, security and foreign governmental-access exposure before permitting such use.