Privacy Without Borders? India's DPDP Act, the GDPR and the Future of Cross-Border Data Transfers

Businesses today increasingly depend on global cloud infrastructure, AI-driven platforms and cross-border service providers, making the seamless transfer of personal data across jurisdictions indispensable to global commerce. An Indian fintech stores customer information on a European cloud server.

Prefer on Google
Privacy Without Borders? India's DPDP Act, the GDPR and the Future of Cross-Border Data Transfers
About the authors+
Related firms+
Reading context+

Jurisdictions

Topics

Businesses today increasingly depend on global cloud infrastructure, AI-driven platforms and cross-border service providers, making the seamless transfer of personal data across jurisdictions indispensable to global commerce. An Indian fintech stores customer information on a European cloud server. A multinational employer runs its HR platform out of a US data centre but employs staff in Mumbai and Berlin. In each case, the same dataset may fall within both India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the EU’s General Data Protection Regulation (“GDPR”). Compliance becomes a question not of choosing one regime over the other, but of satisfying two frameworks that regulate the same transfer differently.

The GDPR requires an identified transfer mechanism under Chapter V before data leaves the EU. The DPDP Act adopts a negative-list approach instead: it permits transfer unless the Government has restricted it by notification under Section 16. The compliance burden does not disappear organisations must satisfy two independent regimes through fundamentally different mechanisms. This article asks not which regime is better, but whether India’s divergence from the GDPR model creates practical legal uncertainty, and what it means for regulatory certainty, digital sovereignty and the harmonisation of international privacy standards.

What Section 16 permits, and what it does not

Section 16 of the DPDP Act (Section 16, Digital Personal Data Protection Act, 2023) permits transfer of personal data by a Data Fiduciary outside India, and gives the Central Government a delegated power, exercised through notification, to restrict transfer to specified countries or territories, or permit it subject to conditions. Section 16(2) preserves any Indian law imposing a higher standard of protection, so RBI, SEBI and IRDAI rules continue to bind regulated entities regardless of what Section 16 allows.

As on July 2026, no restrictive notification has been issued, and Rule 15 of the DPDP Rules 2025 remains operative. A Section 16 analysis today comes down to two checks: is the destination unrestricted, and does a stricter sectoral rule apply. The statute creates no blacklist everything not notified remains permitted, and it drops the earlier distinction between personal and sensitive personal data under the erstwhile IT Rules, so all categories receive the same treatment unless a future notification says otherwise. Section 16 read with Chapter III binds the Data Fiduciary itself obligations on access, correction and erasure continue irrespective of where processing occurs, so the duty runs against the fiduciary, not the data.

It is worth recalling that the DPDP Act itself descends from the Supreme Court’s nine-judge decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, which recognised informational privacy as intrinsic to Article 21 and laid down a triple test of legality, legitimate state aim and proportionality for any state action restricting it. Any future Section 16 notification, itself state action bearing on data principals’ privacy, would in principle need to meet that same standard, a backdrop Section 16’s present, criteria-free design does not yet visibly address.

The GDPR position: an affirmative basis, not a presumption

GDPR takes the opposite starting position. Chapter V, Articles 44 to 50 (GDPR, Chapter V, Articles 44-50), treats any transfer outside the EU or EEA as requiring an affirmative basis. Article 45 permits transfer where the Commission has issued an adequacy decision; Article 46 permits transfer where the controller has appropriate safeguards, typically standard contractual clauses or binding corporate rules under Article 47; and Article 49 allows narrow derogations such as explicit consent, not built for routine, high-volume transfers.

Where SCCs or BCRs are used, the Court of Justice’s judgment in Schrems II (Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems) added a further obligation: the exporter must assess whether the destination country’s law undermines the protection those clauses guarantee, and adopt supplementary measures if it does, per the methodology in the EDPB’s Recommendations 01/2020. This attaches specifically to Article 46 transfers, not every Chapter V mechanism. The distinction worth holding onto: GDPR requires an affirmative, fact-specific basis, and for SCCs an ongoing documented assessment, while the DPDP Act currently requires neither, so long as the destination is unrestricted.

Where the friction actually shows up in practice

Take the fintech example again. Satisfying the DPDP Act does nothing for its GDPR position -it still needs a Chapter V mechanism and a Schrems II assessment of India as the destination. Satisfying GDPR does just as little for its DPDP position, since Indian law asks only whether the destination is restricted and sectoral rules are met. An Indian SaaS provider serving European customers may need SCC documentation and a Schrems II file for its European business, while separately reviewing RBI or SEBI requirements domestically -there is no single memorandum answering both questions; the analysis is built twice.

This also shapes contractual drafting in data processing agreements and vendor due diligence, where parties allocate responsibility through detailed obligations and indemnities. An Indian entity that is also GDPR-exposed cannot rely on its domestic compliance file when a European counterparty asks for transfer documentation, since no equivalent due-diligence exercise on destination-country law is required under the DPDP Act - that paperwork has to be built specifically for the European side of the business, even where the underlying data flow is identical to what happens domestically.

Does the divergence bear on a future EU adequacy assessment?

It is worth being careful here rather than predictive. No EU adequacy assessment of India’s framework currently exists, and it would be premature to forecast an outcome. What can be said is that the current architecture may face challenges in any future assessment, since the Commission’s practice under Article 45 examines legal certainty, enforceable data subject rights and independent oversight of restrictions. A framework where cross-border limits arise entirely through executive notification, without published criteria, sits at some distance from that expectation, as does the absence of a codified safeguard instrument comparable to SCCs or BCRs. These remain open questions, tested only if India or the EU pursues adequacy dialogue.

Digital sovereignty and India’s place in global data governance

Beneath the compliance mechanics lies a larger question of digital sovereignty. Section 16’s permissive design reflects a deliberate policy choice: India retains executive control over if and when cross-border flows are restricted, rather than ceding that judgment to a rules-based, ex-ante framework like the GDPR’s. This is consistent with India’s cautious posture in international digital trade discussions, where it has generally resisted binding, GDPR-style commitments, preferring domestic regulatory flexibility over a harmonised international standard.

That flexibility cuts both ways. It makes India an attractive base for global capability centres and AI infrastructure providers who value a low-friction regime. But it also sets India apart from a convergence trend that the United Kingdom, South Korea and Japan have followed, aligning more closely with GDPR-style adequacy mechanisms to ease data flows with the EU. Whether India’s model becomes a template other economies adopt, or a friction point complicating EU-linked digital trade, will depend on how the Board and future Section 16 notifications evolve -and bears on India’s standing in global data governance, since undisclosed discretion sends a different signal than published criteria do.

The commercial dimension for India’s digital economy

None of this is academic for sectors that depend on cross-border data daily, India’s IT and outsourcing industry, its cloud and AI infrastructure sector, and multinational shared-service centres based in India. India’s model offers real commercial advantage for businesses concentrated outside Europe, where the absence of a mandatory transfer mechanism means lower compliance overhead and faster time-to-market.

Those advantages narrow, however, for organisations that routinely process EU-origin personal data, since GDPR compliance continues to demand an independent transfer assessment regardless of how permissive the domestic regime is. For such organisations, the practical reality is one of parallel compliance systems rather than a single, unified strategy -one in-house teams and outside counsel will need to plan for as both frameworks mature and enforcement, on either side, begins in earnest.

Conclusion

The framework is still developing. Notifications under Section 16 have not been issued, the Data Protection Board is at an early stage of its functioning, and sector regulators continue to issue their own directions that interact with, and sometimes override, the general permission in Section 16. Judicial interpretation has not yet begun, and much of this analysis will be refined as the Board starts adjudicating cases and as the Government considers its first restrictive notification.

For businesses operating across both regimes, regulatory certainty may prove just as valuable as flexibility. A permissive regime that leaves future restrictions undefined creates its own planning risk, even where it imposes no immediate burden. Whether India achieves that certainty will depend on the transparency and consistency of Section 16’s implementation on whether future notifications arrive with published reasoning, tested against the constitutional standard Puttaswamy sets, or as unexplained executive action. It will also depend on whether India treats convergence with international standards, or continued divergence, as the touchstone of its digital sovereignty, with consequences for its integration into global digital trade and its standing in the wider conversation on cross-border data governance. Until that direction is clearer, businesses across both jurisdictions would do well to treat the current flexibility as transitional rather than permanent.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. The views expressed are those of the author. For corrections or updates, write to [email protected]