Skip to content

Cross-Border Data Transfers

Cross-Border Data Transfers: current Indian law, practical example, evidence checklist, risks and Finin2min summary.

Current-law position: As at 4 July 2026, institutional and enabling DPDP provisions are in force. Section 6(9) and section 27(1)(d) are scheduled for 13 November 2026; most substantive processing obligations are scheduled for 13 May 2027. Readiness work should distinguish current duties from future commencement.

Finin2min crux

The framework permits transfers subject to notified restrictions and other Indian or foreign sectoral rules.

Legal anchors

DPDP Act s.16 and government directions

The legal conclusion must be read with the current rules, notifications, portal instructions and binding judgments applicable to the event date.

How to analyse it

1. Applicability

Identify the person, activity, location, transaction date, threshold and regulator before applying the rule.

2. Statutory condition

Separate mandatory legal conditions from portal fields, industry practice and contractual preference.

3. Evidence

Link each conclusion to contemporaneous documents, approvals, filings and accounting records.

4. Action

Maintain country, vendor and sector restriction mapping.

Practical illustration

A group centralises analytics outside India.

Decision point: Reperform the analysis if a material fact, date, location or legal status changes.

Evidence pack

What can go wrong?

DPDP permissibility does not displace banking, insurance, telecom or contract localisation.

Additional risks include stale source use, incomplete authority, inconsistent portal data, weak contemporaneous evidence and failure to consider linked tax, accounting, contract or sector rules.

Finin2min action workflow

StageControlOutput
FactsFreeze transaction, party, date and locationFact sheet
LawRead Act, Rules and later instrumentsLegal map
EvidenceReconcile filings, books and documentsEvidence index
DecisionApprove, remediate, disclose or escalateSigned action note

Quick Q&A

What is the direct answer?

The framework permits transfers subject to notified restrictions and other Indian or foreign sectoral rules.

Which provision should be opened first?

DPDP Act s.16 and government directions

What should be preserved?

data inventory and processing register, privacy notice and consent artefacts, processor contracts and security schedules.

What is the immediate next step?

Maintain country, vendor and sector restriction mapping.

Official sources

Digital Personal Data Protection Act, 2023

MeitY

Open official source

Source reviewed 4 July 2026

Digital Personal Data Protection Rules, 2025

MeitY

Open official source

Source reviewed 4 July 2026

DPDP phased commencement notification, 13 November 2025

MeitY

Open official source

Source reviewed 4 July 2026

Data Protection Board establishment and appointment material

MeitY

Open official source

Source reviewed 4 July 2026

CERT-In directions under section 70B

CERT-In

Open official source

Source reviewed 4 July 2026

Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules

MeitY

Open official source

Source reviewed 4 July 2026

Law, portal and source review: 4 July 2026. Case law and transaction-specific conditions should be checked immediately before professional reliance.