Chapter IV · Special Provisions
Section 16: Transfer of personal data outside India
Section 16 lets personal data flow outside India by default, but gives the Central Government power to restrict transfers to specified countries, and keeps every stricter Indian law fully in force.
- Chapter
- Chapter IV · Special Provisions
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.16
- Reading time
- 7 min
- Updated
- August 2026
At a glance
Section 16 sets a permissive, government-controlled framework for cross-border transfers. Transfers of personal data outside India are allowed by default, but the Central Government may, by notification, restrict transfers to a specified country or territory [16(1)] - a negative-list model, not blanket localisation or an approved-country list. Section 16 does not override any Indian law that provides higher protection or a greater transfer restriction [16(2)], so sectoral and localisation rules still apply. The DPDP Rules, 2025 add conditions where data could be made available to a foreign State, and a targeted localisation for Significant Data Fiduciaries. Moving data abroad does not move accountability abroad: the Data Fiduciary stays fully responsible. It is scheduled to take effect on 13 May 2027.
Key takeaways
- Transfers are permitted by default: the Central Government may restrict transfers to a notified country or territory [16(1)] - a negative-list model, not blanket localisation.
- Section 16 does not displace stricter Indian laws [16(2)]: sectoral, regulatory, contractual or localisation rules that impose more still apply.
- Treat any overseas access as a transfer: cloud regions, disaster recovery, foreign SaaS, group-company access, remote support, logs and telemetry, and AI prompts carrying identifiable data.
- The DPDP Rules, 2025 add conditions where data could be made available to a foreign State or State-controlled entity, and a targeted localisation for Significant Data Fiduciaries.
- Accountability does not cross the border: you stay responsible under Section 8 even when a processor holds the data overseas.
- It is a continuously governed capability: a single notification can restrict a destination, recipient type or data category, so build a watch process.
Who should read this
Read this if you use foreign cloud, SaaS, support, analytics, AI or group-company access for Indian personal data, because Section 16 decides what you can send abroad and what still keeps you accountable at home.
In plain language
Section 16 is India's cross-border rule, and it is permissive by default. There is no blanket data-localisation and no approved-country whitelist. Personal data can generally flow overseas unless the Central Government notifies a specific country or territory as restricted (a negative list).
But the default is not the whole story. Section 16(2) keeps every stricter Indian law in force, so a transfer that DPDP allows can still be blocked by a sectoral regulator, a licence condition, a public-sector contract, or an existing localisation rule such as in banking. The DPDP Rules, 2025 also add conditions where data could reach a foreign State, plus a targeted localisation for Significant Data Fiduciaries.
The single most important idea: moving data abroad does not move accountability abroad. If your Indian company sends user data to a US CRM, a Singapore cloud region or an EU support desk, you remain the accountable Data Fiduciary for every DPDP obligation.
The text of the law
Section 16: Transfer of personal data outside India
16(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India as notified.
16(2) Nothing in this section restricts any law in force in India that provides a higher degree of protection or a greater restriction on the transfer of personal data outside India.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Build a cross-border data map: for each flow record the data category, purpose, recipient, destination or region, access method, and whether the recipient could be reachable by a foreign State. Include subprocessors (log, error-monitoring, AI, enrichment, incident-response tools).
- Run a notification watch: assign privacy or legal to track Section 16 country restrictions, DPDP Rules orders, SDF designations and sectoral rules, because the position can change on a single notification.
- Strengthen processor contracts: approved locations, no unapproved onward transfers, security, breach support, assistance with access and erasure, deletion at exit, and notice of foreign-government access demands where lawful.
- Engineer geographic control: region-lock production, control replication and backup locations, tokenise or encrypt before transfer, restrict overseas privileged access, and gate sensitive-data prompts to external AI.
- If you may be a Significant Data Fiduciary, design so you can keep specified data and its traffic data in India if the Government requires it.
- Do not claim "data is always stored in India" if support, logs, backups, analytics or SaaS can access it. Not sure your architecture holds up? Take the readiness assessment or find a specialist.
Frequently asked questions
Does the DPDP Act require data localisation?
Can I use foreign cloud and SaaS under Section 16?
What does Section 16(2) mean for me?
Do Significant Data Fiduciaries face localisation?
When does Section 16 take effect?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.