Readiness assessment
Share this section

Chapter IV · Special Provisions

Section 16: Transfer of personal data outside India

Section 16 lets personal data flow outside India by default, but gives the Central Government power to restrict transfers to specified countries, and keeps every stricter Indian law fully in force.

Official text
Section 16Cross-border transfers
Chapter
Chapter IV · Special Provisions
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Fiduciaries
Official citation
DPDP Act, 2023, s.16
Reading time
7 min
Updated
August 2026

At a glance

Section 16 sets a permissive, government-controlled framework for cross-border transfers. Transfers of personal data outside India are allowed by default, but the Central Government may, by notification, restrict transfers to a specified country or territory [16(1)] - a negative-list model, not blanket localisation or an approved-country list. Section 16 does not override any Indian law that provides higher protection or a greater transfer restriction [16(2)], so sectoral and localisation rules still apply. The DPDP Rules, 2025 add conditions where data could be made available to a foreign State, and a targeted localisation for Significant Data Fiduciaries. Moving data abroad does not move accountability abroad: the Data Fiduciary stays fully responsible. It is scheduled to take effect on 13 May 2027.

Applies to Data FiduciariesChapter Chapter IVEffective 13 May 2027Read time 7 min

Key takeaways

  • Transfers are permitted by default: the Central Government may restrict transfers to a notified country or territory [16(1)] - a negative-list model, not blanket localisation.
  • Section 16 does not displace stricter Indian laws [16(2)]: sectoral, regulatory, contractual or localisation rules that impose more still apply.
  • Treat any overseas access as a transfer: cloud regions, disaster recovery, foreign SaaS, group-company access, remote support, logs and telemetry, and AI prompts carrying identifiable data.
  • The DPDP Rules, 2025 add conditions where data could be made available to a foreign State or State-controlled entity, and a targeted localisation for Significant Data Fiduciaries.
  • Accountability does not cross the border: you stay responsible under Section 8 even when a processor holds the data overseas.
  • It is a continuously governed capability: a single notification can restrict a destination, recipient type or data category, so build a watch process.

Who should read this

Read this if you use foreign cloud, SaaS, support, analytics, AI or group-company access for Indian personal data, because Section 16 decides what you can send abroad and what still keeps you accountable at home.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 16 is India's cross-border rule, and it is permissive by default. There is no blanket data-localisation and no approved-country whitelist. Personal data can generally flow overseas unless the Central Government notifies a specific country or territory as restricted (a negative list).

But the default is not the whole story. Section 16(2) keeps every stricter Indian law in force, so a transfer that DPDP allows can still be blocked by a sectoral regulator, a licence condition, a public-sector contract, or an existing localisation rule such as in banking. The DPDP Rules, 2025 also add conditions where data could reach a foreign State, plus a targeted localisation for Significant Data Fiduciaries.

The single most important idea: moving data abroad does not move accountability abroad. If your Indian company sends user data to a US CRM, a Singapore cloud region or an EU support desk, you remain the accountable Data Fiduciary for every DPDP obligation.

The text of the law

Section 16: Transfer of personal data outside India

16(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India as notified.

16(2) Nothing in this section restricts any law in force in India that provides a higher degree of protection or a greater restriction on the transfer of personal data outside India.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Build a cross-border data map: for each flow record the data category, purpose, recipient, destination or region, access method, and whether the recipient could be reachable by a foreign State. Include subprocessors (log, error-monitoring, AI, enrichment, incident-response tools).
  • Run a notification watch: assign privacy or legal to track Section 16 country restrictions, DPDP Rules orders, SDF designations and sectoral rules, because the position can change on a single notification.
  • Strengthen processor contracts: approved locations, no unapproved onward transfers, security, breach support, assistance with access and erasure, deletion at exit, and notice of foreign-government access demands where lawful.
  • Engineer geographic control: region-lock production, control replication and backup locations, tokenise or encrypt before transfer, restrict overseas privileged access, and gate sensitive-data prompts to external AI.
  • If you may be a Significant Data Fiduciary, design so you can keep specified data and its traffic data in India if the Government requires it.
  • Do not claim "data is always stored in India" if support, logs, backups, analytics or SaaS can access it. Not sure your architecture holds up? Take the readiness assessment or find a specialist.

Frequently asked questions

Does the DPDP Act require data localisation?
No. Section 16 is permissive: transfers are allowed by default and the Central Government may restrict specific countries by notification. It is not blanket localisation or an approved-country whitelist.
Can I use foreign cloud and SaaS under Section 16?
Generally yes, unless the destination is restricted by notification or a stricter Indian law applies. You remain accountable as the Data Fiduciary and should map flows and control your processors.
What does Section 16(2) mean for me?
A transfer that DPDP permits can still be restricted by another Indian law that gives higher protection or a greater restriction, such as a sectoral or localisation rule. You must check both.
Do Significant Data Fiduciaries face localisation?
The DPDP Rules, 2025 provide a targeted mechanism: an SDF may be required to keep specified personal data and its traffic data within India, based on a government committee's recommendation. It is conditional, not universal.
When does Section 16 take effect?
It is scheduled to come into force on 13 May 2027 under the phased commencement, alongside the DPDP Rules, 2025.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment