CHAPTER IV - SPECIAL PROVISIONS

Section 16 - Processing of personal data outside India

Official text

(1)The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.

(2)Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.

Cross-references

Section 16

Commentary

1.1 Detailed clause-by-clause commentary read with Rule 15 of the DPDP Rules, 2025

Statutory provision

2. Processing of personal data outside India.

(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.

(2) Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.

2.1 Corresponding Rule 15

2.2 Processing of personal data outside India.

Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

3. Opening structure of Section 16

Section 16 establishes the DPDPA’s framework for the transfer of personal data outside India.

It has two principal elements.

First, Section 16(1) empowers the Central Government to restrict transfers to notified countries or territories outside India.

Second, Section 16(2) preserves the operation of other Indian laws that provide a higher degree of protection or impose stricter transfer restrictions.

Rule 15 adds a separate restriction concerning compliance with requirements specified by the Central Government where personal data is made available to:

  • a foreign State;

  • a person or entity under the control of a foreign State; or

  • an agency of a foreign State.

The combined structure may be represented as follows:

  1. PROPOSED TRANSFER OF PERSONAL DATA OUTSIDE INDIA
  2. HAS THE CENTRAL GOVERNMENT RESTRICTED TRANSFERS TO THE RELEVANT COUNTRY OR TERRITORY

UNDER SECTION 16(1)?

IF NO SECTION 16(1) RESTRICTION APPLIES, DOES ANOTHER INDIAN LAW IMPOSE A HIGHER

PROTECTION OR STRICTER TRANSFER RULE?

IF THE DATA MAY BE MADE AVAILABLE TO A FOREIGN STATE, STATE-CONTROLLED ENTITY OR

FOREIGN-STATE AGENCY, DO RULE 15 REQUIREMENTS APPLY?

TRANSFER MAY PROCEED ONLY IN ACCORDANCE WITH ALL APPLICABLE REQUIREMENTS `

Section 16 does not establish a single, unconditional statement that every foreign transfer is either permitted or prohibited. It creates a framework in which the applicable position depends upon:

  1. notifications under Section 16(1);

  2. stricter Indian laws preserved by Section 16(2);

  3. orders issued under Rule 15;

  4. other applicable provisions of the DPDPA.

4. The DPDPA does not impose a general prohibition on all overseas transfers

Section 16(1) does not state:

“Personal data shall not be transferred outside India.”

Instead, it authorises the Central Government to restrict transfers to countries or territories identified by notification.

Rule 15 correspondingly states that personal data processed under the Act may be transferred outside India, subject to the restriction concerning Government-specified requirements relating to foreign States, State-controlled persons or entities, and foreign-State agencies.

The framework therefore does not create a general requirement that every Data Fiduciary keep all personal data within India.

It also does not establish that every foreign transfer is automatically compliant. The Data Fiduciary must still examine:

  • whether the destination is subject to a Section 16 notification;

  • whether another Indian law imposes stricter protection;

  • whether Rule 15 requirements apply;

  • whether the original processing has a valid purpose and ground;

  • whether the foreign recipient acts as a Data Processor or another Data Fiduciary;

  • whether generally applicable security and accountability obligations are satisfied.

The basic position can be expressed as:

Key point

Foreign transfer is not prohibited merely because the destination is outside India, but the transfer remains subject to Section 16 notifications, Rule 15 orders, stricter Indian laws and all other applicable DPDPA obligations.

5. “The Central Government may”

Section 16(1) confers the transfer-restriction power on the Central Government.

The word “may” indicates that the Government has discretion to issue a notification restricting transfers to a country or territory outside India.

The existence of the power does not mean that every foreign country or territory is automatically restricted.

A restriction becomes operative where the Central Government exercises the statutory power through a notification.

The Data Fiduciary should therefore rely on:

  • the formal notification;

  • the country or territory named in it;

  • the personal data, Data Fiduciary or processing covered, where specified;

  • any conditions or effective date contained in the notification.

A Data Fiduciary should not treat:

  • public commentary;

  • diplomatic relations;

  • general security concerns;

  • media reports;

  • draft policy;

  • unofficial government statements;

as equivalent to a notification under Section 16(1).

6. “By notification”

The term “notification” is defined by the DPDPA as a notification published in the Official Gazette.

A restriction under Section 16(1) therefore requires an official Gazette notification.

This requirement provides legal certainty. The Data Fiduciary should be able to determine from the notification:

  • whether a restriction exists;

  • when it becomes effective;

  • which country or territory is involved;

  • the scope of the restriction;

  • whether any conditions or qualifications apply.

7. Notification and internal policy are different

A Data Fiduciary may adopt an internal policy that restricts transfer to certain countries for:

  • security;

  • operational;

  • contractual;

  • sectoral;

  • commercial reasons.

That internal policy is not a Section 16 notification.

Similarly, a cloud provider’s list of prohibited hosting locations does not determine the statutory Section 16 position.

The legal restriction arises from the Central Government’s notification, while private or sectoral requirements may create additional restrictions for different reasons.

8. Monitoring notifications

Because the statutory framework depends upon notification, a Data Fiduciary transferring personal data outside India should maintain a process for checking:

  • new notifications;

  • amendments;

  • revocations;

  • effective dates;

  • changes in scope.

The Act does not prescribe the frequency or technical form of that monitoring. The Data Fiduciary must nevertheless know whether its transfer destination has become restricted.

9. “Restrict the transfer”

The statutory power is to restrict the transfer of personal data.

The word “restrict” is broader than an absolute prohibition. A restriction may potentially take the form of:

  • complete prohibition;

  • conditional transfer;

  • limitation applying to particular kinds of personal data;

  • limitation applying to certain Data Fiduciaries;

  • limitation applying to a class of processing;

  • a requirement that specified conditions be satisfied.

The precise nature of the restriction will depend on the notification.

Section 16(1) does not itself specify:

  • mandatory contractual clauses;

  • an adequacy determination;

  • certification;

  • approval by the Board;

  • standard transfer assessments;

  • encryption requirements;

  • data-centre location;

  • prior consent for every transfer.

Such conditions may appear in another law, a notification, an order or the generally applicable security framework. They should not be attributed to Section 16 unless legally prescribed.

10. Prohibition versus conditional restriction

If a notification states that transfer to a particular country is prohibited, the Data Fiduciary cannot cure that prohibition merely by:

  • contractual consent;

  • encrypting the data;

  • obtaining customer agreement;

  • engaging a processor;

  • routing the transfer through another entity.

If a notification imposes conditions rather than a total prohibition, the Data Fiduciary must determine whether those conditions are satisfied.

The notification’s language is therefore decisive.

11. Meaning of “transfer”

Neither Section 16 nor Rule 15 provides a complete definition of “transfer.”

The ordinary focus is movement or making available of personal data outside India for processing.

Potential transfer situations may include:

  • uploading personal data to a foreign server;

  • storing personal data in an overseas data centre;

  • sending personal data to a foreign service provider;

  • providing access to an overseas affiliate;

  • using a foreign-hosted application;

  • foreign replication or backup;

  • transmitting information through an overseas processing system;

  • making personal data remotely accessible from outside India.

The precise application to particular technical situations may depend on:

  • the architecture;

  • recipient access;

  • storage;

  • processing location;

  • applicable notification;

  • applicable orders;

  • other Indian laws.

12. Physical movement is not the only relevant circumstance

A Data Fiduciary should not assume that transfer occurs only when a physical storage device crosses India’s border.

Digital personal data may be transferred electronically.

Example

For example, a Data Fiduciary in India may transfer personal data where it:

  • uploads records to a foreign cloud environment;

  • transmits customer information through an overseas application programming interface;

  • gives a foreign affiliate access to an Indian database;

  • sends information to an overseas support team.

13. Remote access

Section 16 does not expressly state whether every instance of remote foreign access constitutes transfer.

A prudent analysis should examine whether personal data is effectively made available outside India.

If personnel outside India can:

  • view;

  • retrieve;

  • download;

  • analyse;

  • modify;

  • otherwise process the information, the arrangement should not be treated as unquestionably outside Section 16 merely because the primary server is located in India.

The definitive position may depend on future notification language, orders and regulatory interpretation.

14. Transit

Section 16 refers to transfer “for processing” outside India.

The incidental routing of encrypted data through foreign network infrastructure, without access or processing there, may present a different issue from deliberate transfer to a foreign processor.

The Act does not expressly settle every technical-routing scenario.

The Data Fiduciary should distinguish:

  • mere transmission path;

  • temporary technical handling;

  • storage;

  • access;

  • substantive processing;

  • recipient availability.

15. “Of personal data”

Section 16 applies to personal data as defined by the Act, meaning data about an individual who is identifiable by or in relation to the data.

The provision is not limited to:

  • highly sensitive personal data;

  • financial information;

  • health information;

  • children’s personal data;

  • biometric information.

Any personal data may fall within Section 16 where it is transferred outside India for processing.

The sensitivity and nature of the information may affect:

  • security controls;

  • another applicable law;

  • a Government notification;

  • a Rule 15 order;

  • sectoral requirements.

But Section 16’s use of “personal data” is not restricted to a special category.

16. Anonymous information

Information that has been genuinely and irreversibly anonymised so that no individual is identifiable is no longer personal data within the statutory definition.

Section 16 would not apply to information that is genuinely outside the definition of personal data.

Pseudonymisation is different.

Replacing a name with:

  • a customer number;

  • device identifier;

  • coded reference;

  • token;

does not remove the information from Section 16 if the individual remains identifiable by or in relation to that information.

17. Encrypted personal data

Encryption protects confidentiality, but encrypted personal data may remain personal data.

The fact that information is encrypted does not necessarily mean that no transfer has occurred.

Encryption may be relevant to Section 8 security compliance and to conditions contained in another law or notification. It does not automatically remove the data from Section 16.

18. “By a Data Fiduciary”

The statutory restriction is directed to transfer by a Data Fiduciary.

A Data Fiduciary determines the purpose and means of processing personal data.

The Data Fiduciary remains accountable where transfer is undertaken:

  • directly by it;

  • on its instructions;

  • through a Data Processor;

  • through a subprocessor within the authorised processing chain.

The Data Fiduciary cannot avoid Section 16 merely because a processor technically performs the transfer.

19. Processor transfer

An Indian Data Fiduciary engages an Indian cloud service. The cloud service replicates personal data to an overseas data centre.

The Data Fiduciary must examine the foreign transfer even though it did not manually transmit the data.

Section 8(1) keeps the Data Fiduciary responsible for processing undertaken on its behalf.

Its processor arrangements should therefore identify:

  • processing locations;

  • foreign storage;

  • backup locations;

  • subprocessor locations;

  • remote access;

  • support access;

  • onward transfers.

20. Subprocessors

A Data Fiduciary may contract with Processor A in India, which engages Subprocessor B outside India.

The fact that the Data Fiduciary has no direct contract with B does not make the foreign processing irrelevant.

The Data Fiduciary should ensure that its processor arrangement gives it sufficient knowledge and control to comply with:

  • Section 16;

  • Rule 15;

  • Section 8 obligations;

  • applicable stricter laws.

21. Transfer by another Data Fiduciary

Where personal data is disclosed to another Data Fiduciary that independently transfers it abroad, each Data Fiduciary must assess its own processing and transfer responsibility.

The original Data Fiduciary remains responsible for the lawfulness of its disclosure. The recipient Data Fiduciary becomes responsible for its own subsequent transfer.

22. “For processing”

The transfer must be for processing outside India.

“Processing” is broadly defined under the Act and includes operations performed on digital personal data.

Potential foreign processing includes:

  • collection;

  • recording;

  • organisation;

  • structuring;

  • storage;

  • adaptation;

  • retrieval;

  • use;

  • alignment;

  • combination;

  • indexing;

  • sharing;

  • disclosure by transmission;

  • dissemination;

  • restriction;

  • erasure;

  • destruction.

Accordingly, Section 16 is not limited to permanent foreign storage.

A transfer may fall within the provision where personal data is sent outside India for:

  • customer support;

  • analytics;

  • fraud detection;

  • cloud hosting;

  • payroll;

  • AI processing;

  • document review;

  • software support;

  • disaster recovery;

  • communication delivery.

23. Temporary processing

The provision does not exempt a transfer merely because the foreign processing is temporary.

If personal data is sent abroad for short-term analysis and then returned or erased, the information was still transferred for processing.

Duration may affect risk and contractual controls. It does not necessarily remove the transfer from the section.

24. Storage as processing

Foreign storage is itself processing under the statutory framework.

A Data Fiduciary cannot argue that Section 16 does not apply because an overseas backup provider merely stores the information and does not actively analyse it.

25. “To such country or territory outside India”

The Central Government may notify a country or territory outside India.

This wording allows geographic specificity.

A notification may identify:

  • an entire foreign country;

  • a territory;

  • potentially more than one country or territory in the same notification.

The Act does not use the expressions:

  • adequate country;

  • approved country;

  • white-listed country;

  • safe country.

The statutory formulation is one of restricted destinations.

26. Country and territory

The separate use of “territory” allows the Government to address an area that may require distinct treatment even where it does not constitute a separate sovereign State for all purposes.

The exact geographic scope must be determined from the notification.

27. Processing across multiple locations

A cloud or technology service may process personal data across several countries.

The Data Fiduciary must identify all materially relevant processing destinations rather than checking only:

  • the provider’s headquarters;

  • the contract-signing entity;

  • the primary data centre.

A foreign provider may use:

  • regional replicas;

  • overseas support teams;

  • global monitoring systems;

  • foreign subprocessors;

  • disaster-recovery locations.

If one location is subject to a restriction, the Data Fiduciary must determine whether the architecture causes transfer to that destination.

28. Routing through an unrestricted country

A Data Fiduciary cannot assume that routing data first through an unrestricted country cures an onward transfer to a restricted country.

The relevant question is whether the personal data is ultimately transferred for processing to the notified country or territory.

29. “As may be so notified”

The restriction applies according to the notification’s terms.

The Data Fiduciary should examine:

  • destination;

  • personal data covered;

  • Data Fiduciaries covered;

  • class covered;

  • activity covered;

  • exceptions;

  • conditions;

  • date of effect;

  • transitional treatment.

Section 16 itself does not answer whether a future notification will apply:

  • prospectively only;

  • to personal data already stored abroad;

  • to new transfers only;

  • to continued overseas access;

  • to a specific class.

Those matters should be determined from the notification and general principles governing its operation.

30. Existing foreign data

If a destination becomes restricted after data has already been transferred, the notification may need to address:

  • continued storage;

  • continued access;

  • return;

  • erasure;

  • transition period.

The Data Fiduciary should not assume that an earlier lawful transfer authorises indefinite continued processing after a new restriction takes effect.

At the same time, Section 16 does not itself prescribe mandatory repatriation of all pre-existing data. The notification’s wording will be important.

31. Rule 15: “Any personal data processed by a Data Fiduciary under the Act may be transferred”

Rule 15 begins with a permissive formulation.

It confirms that personal data processed under the Act may be transferred outside India, subject to the Rule’s restriction and the Act.

The words “under the Act” are important. Foreign transfer does not cure an otherwise unlawful processing operation.

Before transfer, the Data Fiduciary must still have:

  • a lawful purpose;

  • a valid processing ground under Section 4;

  • an applicable notice and consent or Section 7 basis;

  • a valid processor arrangement where relevant;

  • appropriate technical and organisational measures;

  • reasonable security safeguards;

  • compliance with child-data provisions;

  • compliance with retention requirements.

Rule 15 is not an independent lawful ground for processing.

It regulates territorial movement of personal data that is otherwise processed under the Act.

32. Section 16 and Rule 15 address different restrictions

Section 16(1) and Rule 15 should not be treated as identical.

33. Section 16(1)

Addresses Government restriction of transfers to a notified:

  • country; or

  • territory.

34. Rule 15

Addresses requirements specified by general or special order regarding making personal data available to:

  • a foreign State;

  • a person or entity under the control of a foreign State;

  • an agency of a foreign State.

The first is destination-based.

The second is recipient and foreign-State-access based.

Both may apply to the same transfer.

Example

A Data Fiduciary proposes to use a service provider in Country X.

It must ask:

  1. Is Country X or the relevant territory restricted under Section 16(1)?

  2. Is the provider under the control of a foreign State?

  3. Could the data be made available to a foreign-State agency?

  4. Has the Central Government specified requirements under Rule 15?

  5. Does another Indian law impose stricter restrictions?

Passing one inquiry does not eliminate the others.

35. “Subject to the restriction”

Rule 15 permits transfer subject to a specific restriction.

The Data Fiduciary must comply with requirements the Central Government may specify in relation to making the personal data available to the specified foreign public or State-connected recipients.

The Rule does not itself list those requirements.

They may be specified through:

  • a general order; or

  • a special order.

Until an applicable order is identified, the exact requirements cannot be stated conclusively.

A commentary should not invent Rule 15 requirements such as:

  • mandatory encryption standards;

  • Government permission for every transfer;

  • localisation of all copies;

  • mandatory contractual clauses;

  • prior notice to every Data Principal;

  • a prohibition on foreign government access.

Any such requirement must arise from the applicable order or another law.

36. “The Data Fiduciary shall meet such requirements”

The duty remains with the Data Fiduciary.

The Data Fiduciary must determine:

  • whether an applicable order exists;

  • whether it is general or special;

  • whether it covers the Data Fiduciary, data, recipient or transfer;

  • what requirements must be met;

  • what evidence demonstrates compliance.

The Data Fiduciary cannot transfer this statutory responsibility entirely to its foreign cloud or service provider.

A provider may support compliance through:

  • contractual terms;

  • data-location information;

  • access controls;

  • legal-request procedures;

  • audit evidence;

  • processing records.

The ultimate Rule 15 obligation is framed as one of the Data Fiduciary.

37. “General or special order”

Rule 15 permits the Central Government to issue:

  • a general order; or

  • a special order.

38. General order

A general order may apply to a category or class, such as:

  • specified Data Fiduciaries;

  • specified personal data;

  • specified destinations;

  • specified recipients;

  • specified circumstances.

The exact scope depends on the order.

39. Special order

A special order may be directed to:

  • a particular Data Fiduciary;

  • a particular transfer;

  • a particular recipient;

  • a particular category of personal data;

  • a defined circumstance.

The Rule does not prescribe the form, publication process or contents of every order in the text supplied.

40. Difference from Section 16 notification

Section 16(1) expressly requires a notification.

Rule 15 refers to a general or special order.

These are distinct legal instruments.

A Data Fiduciary should not assume that:

  • only Gazette country notifications matter; or

  • a Rule 15 special order must necessarily take the same form as a Section 16 notification.

The Data Fiduciary must identify and comply with each applicable instrument according to its legal nature and terms.

41. “In respect of making such personal data available”

Rule 15 is concerned with making personal data available to specified foreign public or State-connected recipients.

“Making available” may be broader than a deliberate final disclosure.

It may potentially include circumstances where the foreign recipient can obtain or access the data through:

  • direct transmission;

  • remote access;

  • system integration;

  • legally compelled disclosure;

  • provider access;

  • administrative access.

The Rule does not define every technical form of availability.

The Data Fiduciary should therefore examine actual accessibility, not merely formal storage location.

42. Mere theoretical possibility

The Rule should not be read as automatically triggered by every remote possibility that a foreign State could seek data under its law.

Its application depends on:

  • an applicable Government order;

  • the nature of the recipient;

  • whether the data is made available;

  • the requirements specified.

The Data Fiduciary should not assume that every overseas vendor is automatically under foreign-State control merely because it is incorporated abroad.

43. “Any foreign State”

The term concerns a State other than India.

Rule 15 does not itself prohibit making personal data available to every foreign State.

It requires the Data Fiduciary to meet requirements specified by the Central Government in respect of such availability.

The applicable order may distinguish among:

  • foreign States;

  • types of requests;

  • categories of data;

  • types of Data Fiduciaries;

  • legal processes.

The Rule’s function is to enable conditions to be imposed, not to establish in its own text that every foreign-State disclosure is categorically unlawful.

44. “Any person or entity under the control of a foreign State”

Rule 15 also reaches persons or entities under foreign-State control.

The Rule does not define “control.”

The determination may depend on:

  • ownership;

  • legal authority;

  • governance;

  • operational control;

  • applicable order;

  • factual relationship with the foreign State.

Foreign incorporation alone does not necessarily establish foreign-State control.

Similarly, a privately incorporated entity may be under State control depending on the applicable legal and factual arrangement.

The Data Fiduciary should avoid unsupported assumptions in either direction.

45. State-owned providers

Where a cloud, communications or technology provider is owned or controlled by a foreign State, Rule 15 may become relevant if an applicable order specifies requirements concerning making personal data available to that provider.

The fact that the service is commercially offered does not necessarily remove its State-controlled status.

46. Private providers

A purely private foreign provider is not automatically an entity under State control merely because it is subject to the laws of its home country.

However, disclosure by that provider to a foreign-State agency may separately engage the Rule where an applicable order covers such availability.

47. “Any agency of such a State”

A foreign-State agency may include a governmental or public agency of that State, depending on the applicable legal context.

Potentially relevant circumstances include making personal data available to:

  • a foreign law-enforcement agency;

  • foreign intelligence agency;

  • foreign regulatory agency;

  • another governmental authority.

Rule 15 does not itself determine whether a particular foreign request must be accepted or refused.

The Data Fiduciary must examine:

  • the applicable Central Government order;

  • the foreign request;

  • Indian law;

  • contractual arrangements;

  • any applicable legal process.

The Rule should not be interpreted as independently authorising a Data Fiduciary to disclose personal data to a foreign agency. Nor should it be interpreted as an absolute prohibition in the absence of the applicable specified requirement.

A foreign service provider may receive a demand from a foreign State or agency seeking personal data originally transferred from India.

Rule 15 addresses the Data Fiduciary’s obligation to meet Central Government-specified requirements concerning such availability.

The Data Fiduciary should ensure that its foreign processing arrangement enables it to understand and, where legally possible, control:

  • foreign government requests;

  • provider disclosure procedures;

  • notification to the Data Fiduciary;

  • challenge mechanisms;

  • scope of disclosure;

  • compliance with Indian requirements.

These are possible subjects of contractual and operational control. Rule 15 itself does not prescribe a universal contractual clause.

49. Section 16(2): Savings for stricter Indian laws

Section 16(2) provides that nothing in Section 16 restricts the applicability of another Indian law providing:

  • a higher degree of protection; or

  • a stricter restriction on overseas transfer.

This is a savings provision.

Its purpose is to ensure that Section 16 is not treated as reducing protections imposed by another applicable Indian law.

The structure is:

  1. DPDPA SECTION 16 Provides general overseas-transfer framework
  2. OTHER APPLICABLE INDIAN LAW May impose stronger protection or stricter transfer controls
  3. THE STRONGER OR STRICTER REQUIREMENT CONTINUES TO APPLY

A Data Fiduciary cannot rely on the absence of a Section 16 country restriction to disregard a stricter sectoral law.

50. “Nothing contained in this section shall restrict”

Section 16(2) prevents Section 16 from being interpreted as an exhaustive code that displaces every other Indian transfer restriction.

Example

For example, if another Indian law requires certain personal data to be:

  • stored in India;

  • processed only in approved locations;

  • transferred only with regulatory approval;

  • retained in an Indian copy;

  • subject to stricter conditions;

Section 16 does not dilute that requirement.

The Data Fiduciary must comply with both frameworks to the extent each applies.

51. Section 38 consistency with other laws

The DPDPA generally operates in addition to other laws and prevails only to the extent of inconsistency as provided under Section 38.

Section 16(2) is more specific. It expressly preserves another Indian law where that law provides a higher degree of protection or transfer restriction.

The Data Fiduciary should therefore not assume that the DPDPA automatically supersedes sectoral transfer or localisation requirements.

52. “Any law for the time being in force in India”

The stricter requirement must arise under a law in force in India.

This may include an applicable statutory or regulatory framework having legal force.

The phrase does not automatically include:

  • voluntary standards;

  • a private contract;

  • an internal policy;

  • non-binding industry guidance;

  • a foreign law merely because a foreign recipient is subject to it.

A contract may impose stricter transfer terms between parties, but its status is not the same as the statutory savings provision concerning Indian law.

53. Foreign law

Section 16(2) refers specifically to Indian law.

Foreign law may affect the foreign recipient or create disclosure risks, but it is not the “law for the time being in force in India” preserved by subsection (2).

Rule 15 separately addresses requirements concerning foreign States, State-controlled entities and their agencies.

54. “Higher degree of protection”

Another Indian law may apply a higher degree of protection without completely prohibiting foreign transfer.

It may require safeguards beyond the general Section 16 framework.

Whether another law provides a higher degree of protection depends on its legal requirements.

Section 16 does not define a comparison test.

The Data Fiduciary should examine:

  • data covered;

  • entity covered;

  • processing covered;

  • safeguards required;

  • approvals;

  • recipients;

  • location;

  • retention;

  • access.

A requirement is not displaced merely because Section 16 is less restrictive.

55. “Restriction on transfer”

Another Indian law may impose a stricter transfer restriction.

This may potentially include:

  • full localisation;

  • restricted categories;

  • prior approval;

  • permitted-recipient limitations;

  • data-copy requirements;

  • sector-specific conditions.

Section 16(2) preserves those restrictions.

The Data Fiduciary should not assume that:

“The destination is not prohibited under Section 16, therefore the transfer is lawful.”

The correct conclusion is:

“The destination is not restricted under the present Section 16 assessment, but all other applicable Indian transfer laws must still be examined.”

56. “In relation to any personal data”

The stricter Indian law may apply to a particular category of personal data.

It does not need to apply to every item of personal data.

A law may distinguish among:

  • payment data;

  • financial records;

  • health information;

  • telecommunications information;

  • identity information;

  • another regulated category.

The Data Fiduciary should perform category-level analysis rather than treating the entire dataset identically.

Example

For example, a single database may contain:

  • ordinary customer contact information;

  • regulated payment data;

  • security logs;

  • marketing preferences.

Different transfer rules may apply to different fields.

57. “Any Data Fiduciary or class thereof”

Another Indian law may impose stricter requirements by reference to:

  • an individual Data Fiduciary;

  • a class of Data Fiduciaries;

  • a regulated sector;

  • a category of service provider.

This means the transfer position may vary among entities even when they transfer similar personal data to the same country.

A regulated financial institution may face restrictions that do not apply to an unrelated retailer.

Section 16(2) expressly allows those stricter entity or class-specific requirements to continue.

58. Difference between transfer restriction and data localisation

The concepts should not be treated as identical.

58.1 Transfer restriction

Controls whether and under what conditions personal data may be transferred outside India.

58.2 Localisation

Requires particular data to remain, be stored, or be processed within India according to the applicable legal instrument.

Section 16(1) enables destination restrictions. It does not itself require universal localisation.

Section 16(2) preserves localisation or stricter transfer requirements under other Indian laws.

Rule 13(4) separately creates a targeted localisation mechanism for personal data specified by the Central Government in relation to Significant Data Fiduciaries.

59. Relationship with Rule 13(4) for Significant Data Fiduciaries

Rule 13(4) requires an SDF to ensure that personal data specified by the Central Government, and traffic data pertaining to its flow, are not transferred outside India.

That provision differs from Section 16 and Rule 15.

ProvisionPrincipal subject
Section 16(1)Restrictions on transfers to notified countries or territories
Rule 15Government-specified requirements concerning availability to foreign States, State-controlled entities or foreign-State agencies
Section 16(2)Preservation of stricter Indian laws
Rule 13(4)India-only restriction for Government-specified SDF personal data and related traffic data

An SDF may therefore face several overlapping inquiries.

If personal data is specified under Rule 13(4), it cannot be transferred outside India even where:

  • the destination is not restricted under Section 16(1);

  • the recipient is not a foreign-State-controlled entity;

  • no Rule 15 order independently prohibits the transfer.

Rule 13(4) applies according to its own terms.

60. Relationship with Section 3 territorial scope

Section 3 determines when the DPDPA applies. Section 16 concerns overseas transfer after the Act applies to the relevant processing.

The two provisions perform different functions.

61. Section 3

Asks whether the processing falls within the DPDPA’s territorial and material scope.

62. Section 16

Asks whether personal data may be transferred outside India for processing and subject to what restrictions.

Foreign processing may remain subject to the DPDPA where the conditions of Section 3 are satisfied.

The fact that data is processed abroad does not by itself remove the processing from the Act.

Likewise, Section 16 does not independently extend the Act to processing that falls outside Section 3.

A Data Principal’s consent is relevant to the lawful ground for processing.

It does not override:

  • a Section 16 notification;

  • a Rule 15 order;

  • a Rule 13(4) localisation requirement;

  • another stricter Indian law.

A Data Fiduciary cannot state:

“The Data Principal consented to overseas processing, so every statutory transfer restriction is waived.”

Consent cannot authorise processing prohibited or restricted by law.

Conversely, the absence of a Section 16 restriction does not eliminate the need for valid consent where consent is the applicable processing ground.

The two questions are separate:

QUESTION ONE

Does the Data Fiduciary have a lawful ground to process the personal data?

QUESTION TWO

Is the overseas transfer permitted under

Section 16, Rule 15 and other applicable laws?

Both must be answered.

64. Notice and overseas processing

Section 5 requires notice concerning personal data and the specified processing purpose.

Neither Section 16 nor Rule 15 expressly creates a separate mandatory transfer notice containing:

  • destination country;

  • foreign recipient;

  • foreign government-access risk;

  • data-centre location.

A Data Fiduciary should not claim that Section 16 itself expressly requires all those disclosures.

Where foreign processing forms part of the processing activity or recipient arrangement, the Data Fiduciary should ensure that its notice and consent remain sufficiently specific and informed under Sections 5 and 6.

The exact notice content should be determined from those provisions and Rule 3 rather than invented as an independent Section 16 requirement.

65. Data Processors outside India

The DPDPA does not prohibit engagement of a foreign Data Processor solely because it is foreign.

The Data Fiduciary must still comply with:

  • Section 8(1) responsibility;

  • Section 8(2) valid processor contract;

  • Section 8(4) technical and organisational measures;

  • Section 8(5) security safeguards;

  • Section 8(7) erasure;

  • Section 16;

  • Rule 15;

  • any stricter Indian law.

The contract should enable compliance with applicable obligations.

The Act does not expressly prescribe a mandatory foreign processor agreement format or standard contractual clauses.

The Data Fiduciary should nevertheless ensure that the arrangement does not prevent it from:

  • responding to rights;

  • investigating breaches;

  • causing erasure;

  • complying with transfer restrictions;

  • meeting Rule 15 requirements.

66. Onward transfer by a foreign processor

A foreign processor may wish to share personal data with:

  • another processor;

  • a subprocessor;

  • an affiliate;

  • a foreign government agency.

The Data Fiduciary must examine whether the onward transfer is consistent with:

  • the permitted processing purpose;

  • the processor contract;

  • Section 16 notifications;

  • Rule 15 orders;

  • stricter Indian laws.

An initial transfer to an unrestricted country does not automatically authorise onward transfer to a restricted country or recipient.

The Data Fiduciary should maintain sufficient visibility over the processing chain to determine the actual destinations and recipients.

67. Cloud hosting

Cloud architecture may involve more than the location selected in the service console.

Relevant elements may include:

  • primary data region;

  • replicas;

  • backups;

  • disaster recovery;

  • support access;

  • security logs;

  • telemetry;

  • subprocessors;

  • administrative systems.

A contract stating “India region” does not conclusively prove that no foreign processing occurs.

Equally, use of a foreign-headquartered cloud provider does not necessarily mean all data is transferred abroad. The actual architecture must be examined.

Section 16 applies to transfers and processing destinations, not merely provider nationality.

68. Artificial intelligence services

A Data Fiduciary may transfer personal data outside India when using a foreign AI provider.

Potential data flows may include:

  • prompts;

  • documents;

  • photographs;

  • voice;

  • embeddings;

  • model outputs;

  • conversation logs;

  • safety logs;

  • service telemetry.

The Data Fiduciary should determine:

  • which personal data leaves India;

  • where it is processed;

  • whether the provider retains it;

  • whether subprocessors are involved;

  • whether it is used for model training;

  • whether a restricted destination or Rule 15 recipient is involved;

  • whether another Indian law applies.

Section 16 does not create special lawful treatment for AI.

Foreign AI processing remains subject to the same transfer framework as other processing.

69. Employee and group-company access

Multinational organisations often provide overseas access to:

  • employee records;

  • payroll information;

  • performance information;

  • customer-support systems;

  • global HR databases;

  • internal investigation records.

Use within a corporate group does not remove the transfer from Section 16.

A foreign parent or affiliate may be:

  • another Data Fiduciary;

  • joint Data Fiduciary;

  • Data Processor;

depending on the actual processing operation.

The Data Fiduciary should identify:

  • role;

  • purpose;

  • destination;

  • access;

  • onward transfer;

  • applicable restrictions.

“Internal group sharing” is not a statutory exception.

70. Children’s personal data

Section 16 does not establish a separate overseas-transfer prohibition specifically for children’s data.

Where child personal data is transferred, the Data Fiduciary must comply with:

  • Section 9;

  • Rule 10 where parental consent is required;

  • Section 16;

  • Rule 15;

  • any applicable exemption;

  • any stricter Indian law.

Parental consent does not override a country restriction or localisation requirement.

A foreign processor receiving child personal data remains within the Data Fiduciary’s responsibility under Section 8(1).

71. Personal data breaches outside India

A personal data breach occurring at a foreign processor remains relevant under the DPDPA where the Data Fiduciary is responsible for the processing.

The Data Fiduciary cannot refuse to comply with breach obligations merely because:

  • the server is overseas;

  • the processor is foreign;

  • the breach occurred under foreign law;

  • the foreign provider is investigating.

Sections 8(5) and 8(6), together with Rules 6 and 7, operate independently of Section 16.

Section 16 regulates foreign transfer. It does not exempt foreign processing from security and breach obligations.

72. Rights of Data Principals where data is abroad

Foreign storage or processing does not remove applicable Data Principal rights.

Where Sections 11 to 14 apply, the Data Fiduciary must be capable of:

  • obtaining relevant information from the foreign processor;

  • correcting data;

  • updating data;

  • causing erasure;

  • responding to grievances;

  • recognising a valid nominee.

A foreign processor’s inability or refusal to assist does not automatically excuse the Data Fiduciary.

This follows from the Data Fiduciary’s responsibility for processing undertaken on its behalf.

Section 16 should therefore not be treated solely as a destination-screening exercise. The foreign arrangement must permit the Data Fiduciary to comply with the rest of the Act.

73. Erasure and foreign copies

Section 8(7) requires the Data Fiduciary to cause its Data Processor to erase personal data where the statutory conditions apply.

A foreign processor should therefore be capable of erasing:

  • active records;

  • working copies;

  • processor-held profiles;

  • subprocessor copies, subject to applicable legal retention and technical treatment of backups.

The fact that foreign law permits the processor to retain personal data does not automatically create an Indian lawful ground for the Data Fiduciary.

The Data Fiduciary must assess:

  • applicable Indian law;

  • applicable contract;

  • foreign legal requirements;

  • whether the proposed processor architecture is compatible with DPDPA compliance.

74. No express adequacy test

Section 16 does not establish a formal adequacy framework under which the Central Government declares that a foreign jurisdiction provides an equivalent level of data protection.

Its operative mechanism is restriction of transfers to notified countries or territories.

A commentary should therefore not state that the DPDPA requires:

  • adequacy decisions;

  • adequacy assessments by every Data Fiduciary;

  • a finding that foreign law is equivalent to Indian law;

  • approval of every recipient country.

A Data Fiduciary may voluntarily examine foreign legal and security risks as part of its governance and security obligations. That should not be presented as an express adequacy requirement under Section 16.

75. No express standard contractual clauses

Section 16 and Rule 15 do not prescribe standard contractual clauses for foreign transfers.

A Data Fiduciary may use contractual protections to manage:

  • processor instructions;

  • security;

  • rights assistance;

  • breach reporting;

  • erasure;

  • government requests;

  • onward transfers.

Those contractual provisions support compliance with Sections 8 and 16.

They are not a separately prescribed statutory transfer mechanism equivalent to a formal standard-clause regime unless the Government later specifies such requirements through an applicable instrument.

Section 16 does not expressly require the Data Fiduciary to obtain a second or separate consent merely because processing occurs outside India.

The applicable consent must still satisfy Section 6 where consent is the processing ground.

If the overseas processing changes:

  • purpose;

  • data;

  • recipient;

  • nature of processing;

the Data Fiduciary must determine whether the existing notice and consent cover that processing.

The correct position is not:

“Every foreign transfer requires separate consent.”

Nor is it:

“Consent is irrelevant to foreign processing.”

Consent governs the processing ground where applicable. Section 16 governs transfer restrictions.

77. No universal data-location disclosure right under Section 16

Section 16 does not expressly create a Data Principal right to obtain:

  • a complete list of countries;

  • every data-centre address;

  • every support location;

  • every foreign legal demand.

Section 11 may require identities of Data Fiduciaries and Data Processors with whom personal data has been shared, subject to its scope and limitations.

The Data Fiduciary should apply Section 11 according to its wording. It should not describe Section 16 as independently creating a country-disclosure right.

78. Government restriction and existing contracts

A Data Fiduciary cannot rely on a private contract to override a statutory restriction.

If a Section 16 notification or Rule 15 order becomes applicable, the Data Fiduciary may need to:

  • amend the contract;

  • change the processing location;

  • restrict access;

  • replace the processor;

  • cease the transfer;

  • take another action required by the instrument.

A contractual commitment to store data abroad does not supersede Indian law.

The Data Fiduciary should structure foreign processor agreements to accommodate changes in applicable transfer restrictions.

Section 16 itself does not prescribe a mandatory change-in-law clause, but the absence of contractual flexibility does not excuse statutory non-compliance.

79. Transfers from outside India to another foreign country

A Data Fiduciary may initially transfer personal data from India to Country A, after which the processor transfers it to Country B.

The onward transfer must be analysed because personal data originally processed under the Act is being transferred for further processing.

If Country B is restricted, routing through Country A should not be treated as avoiding Section 16.

Similarly, Rule 15 may apply where B is:

  • a foreign State;

  • a State-controlled recipient;

  • a foreign-State agency;

and an applicable order specifies requirements.

The Data Fiduciary should therefore map onward transfers rather than examine only the first foreign destination.

80. Return transfer to India

Section 16 concerns transfer outside India.

A transfer of data back into India is not, by itself, the outward transfer addressed by Section 16(1).

However, the full processing chain may still include:

  • continued foreign copies;

  • overseas logs;

  • backups;

  • foreign access;

  • onward disclosure.

Returning one copy to India does not necessarily terminate the foreign processing.

The Data Fiduciary should determine whether the overseas recipient continues to retain or process the information.

81. Recordkeeping and evidence

Section 16 does not prescribe a particular international-transfer register.

A Data Fiduciary should nevertheless maintain sufficient information to demonstrate compliance with its applicable obligations, including:

  • destination countries or territories;

  • recipients;

  • recipient roles;

  • processing purposes;

  • personal data categories;

  • processors and subprocessors;

  • applicable Section 16 notifications;

  • applicable Rule 15 orders;

  • stricter Indian laws;

  • data locations;

  • foreign access arrangements;

  • security and erasure controls.

The record itself should be proportionate to the processing.

Without visibility over destinations and recipients, the Data Fiduciary may be unable to determine whether a notified restriction or Government order applies.

82. Practical transfer analysis within the Act and Rule

A legally anchored transfer review may ask the following questions.

83. Is personal data involved?

If the information is no longer personal data because it is genuinely anonymous, Section 16 may not apply.

If it remains identifiable, including through pseudonymous or coded identifiers, continue the assessment.

84. Is the Data Fiduciary transferring or causing the transfer?

Consider direct transfer, processor transfer, subprocessor transfer and foreign access.

85. Is the data transferred outside India for processing?

Identify storage, access, analysis, hosting, transmission and other processing operations.

86. Is the country or territory restricted?

Check formal notifications under Section 16(1).

87. Does Rule 15 apply?

Determine whether the personal data may be made available to:

  • a foreign State;

  • a State-controlled person or entity;

  • a foreign-State agency;

and whether an applicable general or special order specifies requirements.

88. Does another Indian law impose higher protection or stricter restriction?

Apply Section 16(2).

89. Do other DPDPA requirements remain satisfied?

Check:

  • processing ground;

  • notice and consent where applicable;

  • processor contract;

  • security;

  • erasure;

  • children’s data;

  • Data Principal rights;

  • SDF localisation where applicable.

This is not a statutorily prescribed checklist. It follows directly from the distinct legal controls contained in Section 16, Rule 15 and the related DPDPA obligations.

90. What Section 16 does not provide

Section 16 should not be expanded beyond its enacted content.

It does not expressly create:

  • blanket localisation of all personal data;

  • a universal prohibition on overseas processing;

  • an adequacy regime;

  • a white list of approved countries;

  • standard contractual clauses;

  • mandatory Government approval for every transfer;

  • separate consent for every foreign transfer;

  • a universal country-disclosure right;

  • a complete definition of transfer;

  • a general exception for corporate-group transfers;

  • a general exception for cloud providers;

  • exemption of foreign processors from security or erasure;

  • permission to disregard stricter sectoral laws;

  • an absolute prohibition on every foreign-government disclosure;

  • authority to transfer personal data for an otherwise unlawful purpose.

Any such requirement or permission must arise from:

  • a Section 16 notification;

  • a Rule 15 general or special order;

  • Rule 13(4);

  • another applicable Indian law;

  • another provision of the DPDPA.

91. Consolidated interpretation

Section 16 adopts a restriction-based framework for overseas processing.

The Central Government may notify countries or territories to which transfers are restricted. The restriction may be absolute or conditional depending on the notification. No country becomes restricted merely because it is foreign or is considered risky in public commentary. The statutory restriction must arise through notification.

Rule 15 confirms that personal data processed under the Act may be transferred outside India, but it adds a separate foreign-State-access control. A Data Fiduciary must comply with requirements specified by general or special order where personal data is made available to a foreign State, a State-controlled person or entity, or an agency of that State.

The two mechanisms are distinct. Section 16(1) addresses the destination country or territory. Rule 15 addresses specified requirements relating to foreign public and State-connected recipients or access.

Section 16(2) preserves stricter Indian laws. The absence of a country restriction does not make a transfer lawful where another Indian law requires stronger protection, localisation, approval or another transfer limitation.

The Data Fiduciary remains responsible where the transfer is made by a processor or subprocessor on its behalf. The assessment must therefore follow actual data flows, not merely the location of the contracting entity or primary server.

Foreign processing remains subject to the rest of the DPDPA. The Data Fiduciary must still establish a lawful purpose and ground, use valid processor arrangements, maintain security, respond to breaches, honour rights, cause erasure and comply with children’s-data obligations. Overseas transfer is not an exemption from Indian data-protection duties.

For Significant Data Fiduciaries, Rule 13(4) may impose a separate India-only restriction on personal data specified by the Central Government and the traffic data pertaining to its flow. That requirement is different from the country-restriction mechanism under Section 16.

Key point

The controlling proposition is that Section 16 permits overseas processing within a controlled statutory framework: the transfer must not contravene a notified country or territory restriction, an applicable Rule 15 order, a targeted SDF localisation requirement or any stricter Indian law, and the Data Fiduciary remains fully accountable for the personal data and processing after the data leaves India.

91.1 SCHEDULE II

Key point

Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub-section (2) of section 17

Implementation of appropriate technical and organisational measures to ensure effective observance of the following, in accordance with applicable law, for the processing of personal data, namely:, (a) Processing is carried out in a lawful manner; (b) Processing is done for the uses specified in clause (b) of section 7 of the Act or for the purposes specified in clause (b) of sub-section (2) of section 17 of the Act, as the case may be; (c) Processing is limited to such personal data as is necessary for such uses or achieving such purposes, as the case may be; (d) Processing is done while making reasonable efforts to ensure the accuracy of personal data; (e) Personal data is retained till required for such uses or achieving such purposes, as the case may be, or for compliance with any law for the time being in force; (f) Reasonable security safeguards to prevent personal data breach to protect personal data in the possession or under control of the Data Fiduciary, including in respect of any processing undertaken by it or on its behalf by a Data Processor; (g) Where processing is to be done under clause (b) of section 7 of the Act, the same is undertaken while giving the Data Principal an intimation in respect of the same and, (i) giving the business contact information of a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data; (ii) specifying the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may exercise her rights under the Act; and (iii) is carried on in a manner consistent with such other standards as may be applicable to the processing of such personal data under policy issued by the Central Government or any law for the time being in force; and (h) Accountability of the person who alone or in conjunction with other persons determines the purpose and means of processing of personal data, for effective observance of these standards.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.