Scope of India's international data transfer regime — Digital Personal Data Protection Act, obligations for data fiduciaries and processors
India's international data transfer regime is governed primarily by the Digital Personal Data Protection Act, 2023 (DPDP Act), which became law on 11 August 2023 and represents the country's first comprehensive personal data protection statute. The DPDP Act establishes requirements for entities classified as "data fiduciaries" (a body or individual who determines the purpose and means of data processing, Sec. 2(i)) and "data processors" (entities that process data on behalf of data fiduciaries, Sec. 2(k)), closely paralleling the controller/processor distinction in the GDPR.
Territorial scope: The DPDP Act applies to the processing of digital personal data within the territory of India, as well as to processing outside India if it is in connection with offering goods or services to individuals within India (Sec. 3(a)-(b) DPDP Act). This extraterritorial reach is similar to GDPR Art. 3(2) but is narrowly focused on the nexus to the provision of goods or services within India.
International transfers: The transfer of personal data outside India is covered by Sec. 16 of the DPDP Act, which provides that the Central Government may notify countries or territories to which data fiduciaries are permitted to transfer personal data (Sec. 16(1)), and may impose conditions or restrictions on such transfers. Until such notifications are issued, there is no blanket prohibition or approval process for cross-border transfers, but data fiduciaries remain responsible for compliance with general DPDP Act obligations regardless of location (Sec. 8(2), 16(1)). Sensitive or critical personal data rules remain to be defined — earlier drafts contemplated stricter regimes, but these do not appear in the 2023 text.
Supervisory Authority: The Data Protection Board of India (DPBI) is designated as the enforcement authority for the Act (Sec. 18(1)), empowered to inquire into breaches and impose penalties. As of July 2024, the Board is in the process of appointment and operationalization. No regulatory guidance or notifications regarding approved transfer destinations have been published as of this writing.
Future notification of approved transfer countries and practical compliance steps pending Central Government designation
The Digital Personal Data Protection Act, 2023 (DPDP Act) introduced a mechanism for cross-border transfer of personal data in Section 16, under which the Central Government is authorized to formally designate specific countries or territories to which personal data transfers are permitted. As of July 2024, the Central Government has not yet published any formal notifications specifying approved countries, nor has it issued additional guidance on the process for designation or required contractual safeguards (such as model clauses analogous to the EU SCCs) to support transfers to non-designated countries.
Practical impact: Until notifications are issued under Sec. 16(1), data fiduciaries (controllers) and data processors remain subject to the general requirements of the DPDP Act for cross-border transfers, without a requirement for explicit government pre-approval or restriction. There is, however, a continued obligation to ensure that all processing (including transfers outside India) complies with the principles set out in the DPDP Act (see, e.g., Sec. 8(2), which makes clear that the obligations in the Act apply regardless of where processing occurs). Unlike the GDPR or South Korea PIPA, there is no statutory requirement or official guidance on binding corporate rules, standard contractual clauses, or supplementary transfer impact assessments as of this date.
Enforcement risk: Since the Data Protection Board of India (DPBI) is not fully operational and no transfer country list has been notified, the immediate enforcement risk on international transfers is low for technical noncompliance with a non-existent list, but entities remain exposed to penalties for breaches of DPDP Act principles on accountability, purpose limitation, and data security regardless of transfer destination (Sec. 8, 33, 35). Organizations should closely monitor forthcoming notifications and be prepared to adjust transfer documentation and operational safeguards promptly when the first transfer country designations are published.
Contractual safeguards and data transfer agreements under the DPDP Act — absence of statutory SCCs or BCR requirements
The Digital Personal Data Protection Act, 2023 (DPDP Act) does not mandate the use of standard contractual clauses (SCCs), binding corporate rules (BCRs), or specific data transfer agreements as a condition for transferring personal data outside India. Section 16 sets out that the Central Government may designate permissible transfer countries, but provides no direction regarding required contractual safeguards for transfers to countries not on a whitelisted list, nor for onward transfers. The current (as of July 2024) text of the DPDP Act is silent on the content, mechanics, or enforcement of data transfer contracts analogous to the GDPR's Art. 46 SCCs or BCR mechanisms.
Historical context is instructive. Prior drafts of Indian data protection law (notably the 2018 and 2019 Personal Data Protection Bill versions) contemplated explicit contractual and corporate-rule-based mechanisms inspired by the GDPR model. These were omitted in the enacted DPDP Act of 2023. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (IT Rules, 2011) — issued under the IT Act — remain in force for legacy sectoral oversight, including a requirement that data exporters receive "the same level of data protection as is adhered to under these Rules" (Rule 7; Gazette Notification GSR 313(E), 2011). However, the IT Rules, 2011 are subordinate to and do not override the DPDP Act, and their contractual transfer clause is not recapitulated in the 2023 Act.
In the absence of government-issued SCCs or BCR provisions, data fiduciaries and processors should structure export agreements to cover transparency, onward transfer, accountability, redress, and security, aligning in substance with the Act's general obligations (Sec. 8), but these are not prescribed in statute. The Data Protection Board of India (DPBI) has not issued guidance as of July 2024 on recommended or required contract content. Pending government notification or sectoral circular, contractual safeguards are prudent risk mitigation but are not a statutory compliance mechanism under the DPDP Act.
Sensitive and critical personal data: no statutory localization or cross-border transfer restrictions under the DPDP Act 2023
The Digital Personal Data Protection Act, 2023 (DPDP Act) does not define or regulate "sensitive personal data" (SPD) or "critical personal data" (CPD) as formally distinct categories. This marks a clear departure from earlier Personal Data Protection Bill drafts (notably the 2018 and 2019 versions), which imposed stringent data localization, storage, or transfer restrictions on SPD and absolute transfer bans or localization on CPD. The enacted DPDP Act omits these categories, instead treating all personal data under a unified regime.
Section 16 of the DPDP Act governs cross-border transfers and empowers the Central Government to notify categories of personal data, countries, or territories to which transfers may be restricted or allowed, but does not reference SPD or CPD at all. There is no prohibition on transferring specific categories of personal data out of India, nor any requirement to store any class of data exclusively within Indian territory. Data fiduciaries and processors are required to comply with the Act’s general principles—consent, purpose limitation, security safeguards, and accountability—regardless of the nature of the personal data (Sec. 8). As of July 2024, no notifications under Sec. 16 specifying additional transfer restrictions or approved countries have been issued.
Historical/sectoral note: The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (IT Rules, 2011, Rule 3) list certain data classes (including health and financial information) as "sensitive personal data or information." However, the DPDP Act is silent on such categories, and as the newer and comprehensive data protection framework, it governs in case of inconsistency (Sec. 39). Accordingly, unless/until the Central Government issues notifications under Sec. 16(1), there is no additional statutory restriction or localization requirement for SPD/CPD transfer under current Indian law.
Entities operating across multiple APAC regimes (such as South Korea PIPA or China PIPL) must note that India's law no longer features sector-specific or category-based transfer bans, but must remain attentive to evolving government notifications or sectoral circulars that could reintroduce such requirements in the future.
Legacy IT Rules, 2011 cross-border transfer clause — statutory position after the DPDP Act and transitional status as of July 2024
Before the Digital Personal Data Protection Act, 2023 (DPDP Act), cross-border transfer of sensitive personal data in India was regulated by Rule 7 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT Rules, 2011"). Rule 7 states that a body corporate or any person in India may transfer sensitive personal data or information to any person outside India only if the recipient ensures "the same level of data protection that is adhered to by the body corporate as provided for under these Rules." This was enforced primarily for data identified as "sensitive personal data or information" following Rule 3 of the IT Rules, 2011.
After the DPDP Act: The DPDP Act became law on 11 August 2023 (see the Gazette publication). Section 39 of the DPDP Act gives it overriding effect: "The provisions of this Act shall have effect notwithstanding anything inconsistent therewith contained in any other law for the time being in force." As of July 2024, the Government of India has not published any notification in the Gazette formally repealing or amending the IT Rules, 2011. The DPDP Act does not reference the IT Rules, 2011, nor does it specify transitional arrangements for Rule 7. No sectoral regulator has published formal guidance addressing IT Rules, 2011 contract terms post-DPDP Act.
Accordingly, the enforceability of the IT Rules, 2011 cross-border transfer provision after the DPDP Act depends on: (a) whether data in question qualifies as "personal data" within the DPDP Act (which does not use the 'sensitive personal data' category), and (b) whether performance of legacy contracts creates ongoing sectoral or contractual obligations. Where the DPDP Act and IT Rules, 2011 are inconsistent, the DPDP Act prevails for data processing after its effective date.
As of July 2024, Rule 7 of IT Rules, 2011 remains published law, formally unrepealed, but its practical application is limited by the overriding effect of the DPDP Act for acts within its scope. No government, sectoral, or regulatory notification has clarified the relationship or issued transitional guidance for legacy data transfer agreements referencing Rule 7. The statutory position is therefore unsettled and should be monitored for future notifications.
Source: IT Rules, 2011, Rule 7 (India) Source: Digital Personal Data Protection Act, 2023 (India), Sec. 39