DPDP Wiki Talk to us

/Guides · Compliance leads

Cross-border data transfers and processing by the State

How the DPDP Act and Rules treat sending personal data outside India, and the separate rules that apply when the State processes personal data.

Interpretation · not legal adviceUpdated 9 September 20267 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

Two questions get asked together and answered differently here. One is whether personal data may leave India. The other is what the Act asks of the State when it processes personal data, and where it lets the State out of the Act altogether.

What section 16 says, and does not say#

Section 16(1) gives the Central Government a single power: it "may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified". That is a power to name countries that are off limits, not an approval requirement and not a list of approved destinations.

Section 16(2) protects stricter regimes already in place. Nothing in the section "shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India". Any law in force that restricts transfer more tightly keeps operating on its own terms. That sits alongside section 38(1), under which the Act is "in addition to and not in derogation of any other law".

Section 16 comes into force eighteen months from publication of G.S.R. 843(E), which is 13 May 2027. None of the notifications published on 13 November 2025 restricts transfer to any country or territory.

The transfer rule, as printed#

Rule 15 is one sentence:

"Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State."

Transfer is the default and one condition is attached, aimed at a narrow class of recipient: a foreign State, or a person, entity or agency under its control. The requirements are to come by general or special order. Rule 15 starts on 13 May 2027 under rule 1(4).

One localisation obligation sits outside all of this. A Significant Data Fiduciary must ensure that personal data specified by the Central Government, on a committee's recommendations, is not transferred outside India, along with the traffic data about its flow (rule 13(4)).

When the State provides a subsidy, benefit, service, certificate, licence or permit#

Section 7(b) is a legitimate use, so the State and its instrumentalities may rely on it without fresh consent. It covers providing or issuing "such subsidy, benefit, service, certificate, licence or permit as may be prescribed", through one of two gateways: the individual previously consented to processing by the State or an instrumentality for any such subsidy, benefit, service, certificate, licence or permit, or the data is already in digital form (or digitised later) in a database, register, book or other document that the State maintains and the Central Government has notified.

The clause carries its own condition: processing is "subject to standards followed for processing being in accordance with the policy issued by the Central Government or any law for the time being in force for governance of personal data" (section 7(b)).

Rule 5(1) supplies those standards by pointing at the Second Schedule. Rule 5(2) then defines three ways such a benefit can be delivered: "under law" (exercise of a power or function under any law in force), "under policy" (a policy or instruction issued by the Central or a State Government), and "using public funds" (expenditure from, or receipts accruing to, the Consolidated Fund or public account of India or a State, or the funds of a local authority).

The Second Schedule standards#

The Second Schedule requires appropriate technical and organisational measures to ensure effective observance of eight things. Processing must be lawful, limited to the uses in section 7(b) or the purposes in section 17(2)(b), limited to the personal data necessary for them, and carried out while making reasonable efforts to ensure completeness, accuracy and consistency. Data is retained only while required for those uses or for compliance with law, and reasonable security safeguards must protect it, including where a Data Processor handles it.

For section 7(b) processing the Schedule adds a notice-like duty: the Data Principal gets an intimation, contact information for someone who can answer questions, and the link and other means for exercising her rights. The eighth standard is accountability of whoever determines the purpose and means.

Processing for the functions of the State#

Section 7(c) is broader and carries no schedule. It covers processing "for the performance by the State or any of its instrumentalities of any function under any law for the time being in force in India or in the interest of sovereignty and integrity of India or security of the State". Both clauses start on 13 May 2027 (G.S.R. 843(E)).

Where the Act stops applying to the State#

Section 17(2)(a) is the widest carve-out in the statute. The Act does not apply to processing "by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these", nor to the Central Government's processing of data that such an instrumentality furnishes to it. It depends on a notification naming the instrumentality.

Section 17(2)(b) exempts processing necessary for research, archiving or statistical purposes, provided the data is not used to take a decision specific to a Data Principal and the standards in the Second Schedule are followed (rule 16). Section 17(4) is narrower: for State processing, the erasure duty in section 8(7) and the erasure right in section 12(3) do not apply, and section 12(2) drops away where the purpose does not include a decision affecting the individual.

The power to call for information#

Section 36 is short: "The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for."

Rule 23 narrows how that power reaches a Data Fiduciary or intermediary. Information may be called for only for the purposes listed in the Seventh Schedule, through the authorised person that Schedule names, within the period specified in the demand. Where disclosure is likely to prejudicially affect the sovereignty and integrity of India or the security of the State, the Data Fiduciary or intermediary can be told not to disclose it to the affected Data Principal or anyone else without the authorised person's prior written permission (rule 23(2)).

Purpose in the Seventh ScheduleAuthorised person
Use by the State of personal data in the interest of sovereignty and integrity of India or security of the StateAn officer designated by the Central Government or the head of the notified instrumentality
Use by the State for performing a function under law, or disclosing information to meet an obligation under lawPerson authorised under applicable law
Assessing whether to notify a Data Fiduciary or class as a Significant Data FiduciaryAn officer of the Ministry of Electronics and Information Technology designated by its Secretary

Rule 8(3) leans on the same Schedule, requiring a Data Fiduciary to retain personal data, associated traffic data and logs for at least one year for those purposes.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.