INVESTOR INTELLIGENCE

Cross-Border Data Transfers Under the DPDP Rules 2025: India's Negative-List Model and Its Global Implications

2 January 2026 |

7 min read

The cross-border movement of personal data sits at the intersection of commercial necessity and national sovereignty. For multinational enterprises, the ability to transfer personal data freely across jurisdictions underpins everything from cloud computing to human resources management to financial services delivery. For governments, the conditions under which a state permits its residents' data to leave national borders have become an instrument of digital trade policy, geopolitical leverage, and consumer protection simultaneously. India's Digital Personal Data Protection Rules, 2025 (DPDP Rules), notified on 13 November 2025 under the Digital Personal Data Protection Act, 2023 (DPDP Act), have introduced a cross-border data transfer framework that diverges materially from the dominant global models. This blog examines that framework, situates it within the global landscape of transfer mechanisms, and evaluates its practical and legal implications for businesses operating across the India corridor.

The Legislative Architecture: Section 16 and Rule 15

The DPDP Act establishes the foundational principle governing cross-border transfers in Section 16. That provision authorises the Central Government to restrict the transfer of personal data to any country or territory by notification. Critically, it does not impose a default prohibition on outbound transfers; the prohibition is triggered only where the Central Government acts affirmatively. Rule 15 of the DPDP Rules operationalises this by providing that a Data Fiduciary may transfer personal data outside India subject to such requirements as the Central Government may specify in respect of making data available to any foreign state, or to any person or entity under the control of or any agency of such a state.

The architecture is therefore one of permissive default with carve-out authority. Transfers are permitted to any jurisdiction unless and until the Central Government notifies a restriction. This stands in contrast to the "whitelist" or "adequacy" model adopted by the European Union under the General Data Protection Regulation (GDPR), under which transfers to third countries require either an adequacy decision, standard contractual clauses, binding corporate rules, or another approved mechanism. The absence of a default restriction under India's model reflects both a development-oriented policy philosophy and an acknowledgment of India's position as both a major data exporter (through its technology services industry) and a major data importer (through its cloud infrastructure buildout).

Comparing Global Frameworks: Adequacy, Whitelist, and Negative-List Models

Three principal models govern cross-border data transfer globally, and India's choice among them carries significant commercial and strategic consequences.

The EU's adequacy model, formalised under Article 45 of the GDPR, requires the European Commission to issue a formal finding that a third country provides an essentially equivalent level of data protection before unrestricted transfers are permitted.¹ As of June 2026, the EU has issued adequacy decisions in respect of a small number of jurisdictions, including Japan, Canada (commercial organisations), New Zealand, Argentina, South Korea, the United Kingdom, and Switzerland. The process is administratively demanding and politically sensitive; India has not received an adequacy decision, meaning that EU-to-India data transfers continue to require one of the alternative transfer tools.

Singapore's Personal Data Protection Act (PDPA) takes a more business-friendly approach. Under the PDPA, transfers are permitted where the recipient provides a comparable standard of protection, with prescribed contracts, binding corporate rules, and certification schemes all serving as acceptable transfer mechanisms. Singapore has additionally concluded a series of data flow agreements with partner economies under its Digital Economy Agreements.

The United States has historically operated without a comprehensive federal data privacy law governing cross-border transfers, relying instead on sectoral regulation. The EU-US Data Privacy Framework, approved by the European Commission in July 2023, provides a mechanism for US-based organisations to receive EU data, following the invalidation of its predecessor, Privacy Shield, by the Court of Justice of the European Union in Schrems II.²

India's negative-list model stands as a distinct fourth approach. It rejects the administrative complexity of the adequacy model, eschews the proportionality framework of Singapore's PDPA, and avoids the sectoral patchwork of the United States. The practical consequence is immediate: outbound transfers from India require no pre-approval, no contractual mechanism, and no regulatory filing, at least until the Central Government populates the restricted list. Whether – and how – that list will be populated remains the central question for compliance planners.

The Significant Data Fiduciary Category and Its Transfer Implications

Rule 15 does not operate in isolation. The DPDP Rules introduce the category of "Significant Data Fiduciary" (SDF), a designation that the Central Government may apply to Data Fiduciaries whose processing activities are assessed to carry elevated risk, given the volume of personal data processed, the sensitivity of that data, the potential risk to national sovereignty and integrity, or the risk to electoral democracy and security of the state.³ Entities designated as SDFs bear enhanced obligations, including the appointment of a Data Protection Officer resident in India, the appointment of an independent data auditor, and the conduct of periodic Data Protection Impact Assessments.

The question of whether SDFs face additional transfer restrictions beyond those applicable to ordinary Data Fiduciaries is not yet definitively resolved. The DPDP Rules contemplate the possibility of differentiated regimes, and the Central Government retains broad authority under Section 16 to impose territory-specific restrictions on designated entities. Businesses that process the data of a significant number of Indian residents – particularly in financial services, healthcare, telecommunications, and digital platforms – ought to monitor SDF designation criteria closely, as designation could materially alter the permissible transfer architecture.

This blog contends that the SDF framework represents the primary mechanism through which the Central Government will exercise data localisation pressure short of outright prohibition. The pattern is visible in related regulation: the Reserve Bank of India's mandate that payment systems data be stored in India, and the Insurance Regulatory and Development Authority of India's data localisation requirements for insurance sector data, both reflect a sectoral preference for domestic data residency that the SDF framework may extend into the general data protection regime.

Practical Compliance Considerations for Data Fiduciaries

For businesses operating across the India corridor, the practical compliance framework under the DPDP Rules presents a distinctive set of challenges. Four deserve particular attention.

First, the Notice and Consent Infrastructure. Rule 3 of the DPDP Rules prescribes detailed requirements for notice and consent. A Data Fiduciary must provide notice in clear and plain language, specifying the personal data to be processed, the purpose of processing, the manner in which the Data Principal may exercise rights, and the manner in which a complaint may be made to the Data Protection Board of India (DPB). Crucially, this notice requirement must be fulfilled not merely at the point of data collection but as a condition precedent to any processing, including transfer. An entity that transfers data to an overseas affiliate without having obtained valid consent to that specific transfer may be in breach of the Act regardless of whether the destination jurisdiction appears on a restricted list.

Second, the Consent Manager Architecture. The DPDP Rules establish a consent manager framework under Rule 4, through which Data Principals may manage their consents across multiple Data Fiduciaries via a single registered intermediary. The consent manager must be registered with the Data Protection Board of India and must maintain interoperability across platforms. For businesses that rely on complex data sharing arrangements – particularly those in the advertising technology, financial services aggregation, and health-tech sectors – the consent manager architecture imposes both a technical interoperability burden and a contractual restructuring obligation.

Third, Data Retention and Deletion. Businesses must implement retention schedules consistent with the DPDP Act's purpose-limitation and storage-limitation principles. Personal data may not be retained beyond the period necessary for the purpose for which it was collected. The obligation to delete extends to data held by processors (described as Data Processors in the Act), meaning that international cloud vendors, data analytics providers, and managed service providers used by Indian Data Fiduciaries must contractually commit to deletion obligations that align with Indian law.

Fourth, Breach Notification. Rule 7 of the DPDP Rules requires Data Fiduciaries to notify the Data Protection Board of India of a personal data breach in the prescribed form and within the prescribed timeframe. The notification obligation extends to affected Data Principals. In a cross-border context, this creates the possibility of concurrent breach notification obligations across multiple jurisdictions – a scenario already familiar to multinational enterprises dealing with GDPR, but now applicable across the India corridor as well.

The Data Protection Board of India: Adjudicatory Architecture

The DPDP Act establishes the Data Protection Board of India as the primary adjudicatory authority. The DPB is empowered to inquire into complaints, impose financial penalties of up to Rs. 250 crore for breach of the obligations of a Data Fiduciary, Rs. 200 crore for breach of obligations relating to children's data, and Rs. 50 crore for breach of the notice and consent requirements, among other heads of penalty.⁴ The DPB also has the authority to direct Data Fiduciaries to take remedial measures, cease processing, and delete data.

The DPB's adjudicatory process is designed to be digital-native: proceedings are conducted online, decisions are communicated electronically, and appeals lie to the High Court. The Board exercises concurrent jurisdiction with civil courts in certain matters, and its decisions are subject to judicial review on the standard grounds applicable to statutory authorities.

For cross-border compliance, the critical analytical question is the extent to which the DPB may exercise jurisdiction over foreign entities. The DPDP Act applies to the processing of digital personal data within India and to processing outside India where such processing is in connection with any activity related to offering goods or services to Data Principals within India. This extra-territorial reach mirrors the approach of the GDPR under Article 3 and brings foreign companies that target Indian consumers squarely within the regulatory perimeter.

India's Framework in the ASEAN Digital Economy Context

India's negative-list approach deserves evaluation not only against the GDPR but also against the broader ASEAN digital economy framework. The ASEAN Cross-Border Privacy Rules (CBPR) system, and Singapore's more advanced binding corporate rules framework, both operate on the premise that certified internal compliance frameworks can substitute for bilateral transfer agreements. India has not acceded to the CBPR system, and the DPDP framework as currently structured does not provide for a comparable certification mechanism.

This creates a structural asymmetry for businesses operating across both the ASEAN corridor and the India market. A company that has obtained ASEAN CBPR certification and Singapore PDPA-compliant binding corporate rules may nonetheless require a separate compliance analysis for its India operations. The absence of interoperability between these frameworks is a practical commercial friction that the Ministry of Electronics and Information Technology would benefit from addressing, particularly as India negotiates its Digital Economy Agreements within the India-UAE CEPA, the India-UK FTA, and the broader Indo-Pacific Economic Framework.

Conclusion

India's DPDP Rules 2025 establish a cross-border data transfer framework that is structurally permissive, administratively light, but strategically uncertain. The negative-list model avoids the compliance complexity of the EU's adequacy regime and the administrative cost of prior approval systems. It reflects India's recognition that its technology services industry – which generates approximately USD 250 billion in annual export revenue – depends on relatively frictionless data flows. At the same time, the Central Government's broad authority to restrict transfers, the SDF designation mechanism, and the sectoral data localisation norms that coexist alongside the DPDP framework mean that the compliance picture for cross-border data flows is less settled than the face of Rule 15 suggests. This blog concludes that Data Fiduciaries operating across the India corridor ought to build compliance architectures that assume the eventual population of the restricted list, map SDF designation risk carefully, and negotiate data transfer obligations with processors and sub-processors on a forward-looking basis.




Endnotes

1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [2016] OJ L 119/1, art 45.

2. Case C-311/18 Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II) EU:C:2020:559; Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework [2023] OJ L 231/118.

3. Digital Personal Data Protection Act 2023 (India), s 10(1).

4. Digital Personal Data Protection Act 2023 (India), s 33, Schedule.

Authors

Silverlake Advisory
SL

Silverlake Advisory

Silverlake Advisory