← All legal insights

Corporate & Commercial Law02 September 2026 · 7 min read

Cross-Border Personal Data Transfers Under India's DPDP Framework: What Businesses Should Prepare for Before May 2027

Section 16 of the DPDP Act is scheduled to take effect in May 2027. A practical guide to mapping overseas data flows, reviewing processor contracts and preparing governance before the framework applies.

Cross-Border Personal Data Transfers Under India's DPDP Framework: What Businesses Should Prepare for Before May 2027

For many Indian businesses, personal data leaves India long before anyone describes it as an international transfer. A cloud-hosted CRM, a global payroll platform, an overseas support desk, a parent-company dashboard or an automated back-up can all place customer, employee or vendor information outside the country. The question is no longer whether this happens. It is whether the organisation can explain the flow, control it and respond if the rules change.

India's Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a dedicated framework for personal-data transfers outside India. The provision that matters most—Section 16—is scheduled to take effect on 13 May 2027. That gives businesses time to prepare, but not a reason to postpone the work. A sensible cross-border data plan starts with a clear record of what moves, why it moves and who can access it.

The date that matters: 13 May 2027

The Government notified the Digital Personal Data Protection Rules, 2025 in November 2025, with different provisions commencing in stages. Section 16 of the DPDP Act is among the provisions scheduled to commence eighteen months from that notification—13 May 2027. This is an important distinction. In September 2026, businesses should be building readiness for the incoming framework rather than assuming that every DPDP cross-border obligation already applies.

That does not mean existing obligations disappear. Sector-specific rules, contractual commitments, confidentiality duties and overseas customer requirements may already shape how data is hosted, accessed or disclosed. Regulated entities, businesses serving international clients and organisations handling sensitive operational information should review those requirements alongside their future DPDP position.

What is a cross-border data transfer in everyday operations?

A transfer is often more practical than dramatic. It may arise when an Indian company uses a foreign cloud region, lets a global group company view employee records, appoints an overseas processor, retains a software vendor with non-Indian support access, or keeps disaster-recovery copies in another jurisdiction. Data need not be sold or permanently moved for a cross-border question to arise; remote access and onward processing can matter just as much.

A useful first exercise is therefore a data-flow map. It should identify the categories of personal data involved, the systems in which they sit, the countries or regions connected with them, the vendor or group entity receiving access, the reason for the transfer and the team responsible for that relationship. This record is far more useful than a spreadsheet that merely says “cloud provider: yes”.

India's approach is not an EU-style adequacy list

The DPDP Act takes a restriction-based approach. Section 16 permits transfer of personal data outside India, subject to restrictions that the Central Government may specify for particular countries or territories. It is not currently framed as a system in which a business must wait for an “approved country” list before it can transfer information abroad.

Nor has India, at the time of writing, prescribed a standard contractual-clause template equivalent to the European Union's SCCs for every DPDP transfer. Contracts will still be central to risk management, especially where a processor, software supplier or overseas affiliate handles information. But businesses should avoid importing a foreign compliance model wholesale and calling it an Indian legal requirement without checking the actual position.

A practical readiness plan for boards and operating teams

1. Map the transfer before trying to regulate it

Begin with systems that are easy to overlook: collaboration tools, help-desk software, email archives, analytics products, recruitment platforms, payroll processors, cyber-security monitoring and back-up environments. Ask whether data is stored overseas, accessed overseas, replicated overseas or disclosed to a sub-processor. The answers will show which arrangements need priority review.

2. Make the supplier contract do real work

A supplier agreement should do more than repeat a privacy policy. It should clearly describe the permitted purpose of processing, confidentiality safeguards, security controls, incident escalation, deletion or return of data, limits on sub-processors and practical assistance with rights requests. These clauses need to work with the commercial terms, liability structure and operational reality of the relationship. Legal Loyalty's corporate and commercial law team can help businesses align these points in vendor, technology and group-company arrangements.

3. Keep a close eye on onward access

A company may know where its main provider hosts data but know far less about customer-support teams, analytics partners or subcontractors that can access it. Build approval and record-keeping steps for new sub-processors. Access controls, role-based permissions, encryption and dependable logs are not merely IT preferences; they make it possible to answer basic governance questions when an incident or customer query arises.

4. Check notices, consent and internal accountability

Cross-border arrangements should sit within the wider DPDP programme. Businesses should be able to explain the purpose for which personal data is processed, keep their notices understandable, respond to rights-related requests and give accountable teams a clear role in approving high-impact vendor decisions. For the technology, privacy and cyber-risk dimensions, the firm's cyber law and data protection practice is a relevant point of contact.

Do not overlook sectoral and contractual restrictions

The DPDP Act is a general data-protection statute; it does not erase every other rule that may apply to an organisation. Financial, telecom, health, employment or government-facing data may carry additional regulatory, localisation, security or contractual expectations. International customers may also ask for commitments that go beyond Indian law. The disciplined approach is to identify the highest applicable standard for the particular data set and document why the chosen arrangement meets it.

Where the solution requires updated terms, data-processing schedules, confidentiality provisions or board-approved commercial paperwork, the firm's commercial documentation and registration support can help ensure that the legal record matches the actual data flow.

Where disputes can begin

Cross-border data issues can quickly become contractual disputes: a service provider may refuse to disclose where data is held, a customer may allege a breach of security promises, or a group company may use information beyond the agreed purpose. A well-drafted agreement cannot prevent every problem, but it can make responsibility, notification and remedial steps clearer. If a technology or vendor relationship has already become contentious, early advice from lawyers experienced in arbitration and dispute resolution can help preserve the commercial relationship while protecting the business position.

Frequently asked questions

Are cross-border personal-data transfers banned under the DPDP Act?

No. Section 16 follows a restriction-based model: transfers may be made outside India, subject to restrictions the Central Government may specify for particular countries or territories. The provision is scheduled to come into force on 13 May 2027.

Do Indian businesses need EU-style standard contractual clauses now?

India has not prescribed a universal DPDP standard-clause form at the time of writing. Strong processor and vendor terms remain commercially prudent, especially for security, confidentiality, sub-processing, breach reporting and return or deletion of data.

What should a business do before May 2027?

Map overseas data flows, identify high-risk vendors and group access, review agreements, test incident escalation and make sure legal, IT, procurement and business owners know who approves new transfer arrangements.

The sensible next step

The most effective preparation is neither panic nor a template copied from another jurisdiction. It is a sober review of the organisation's real data flows and its written commitments. Businesses that start this work before Section 16 takes effect will be better placed to adapt to government restrictions when they are issued, answer customer due diligence and keep operational decisions moving.

This article is general information as at September 2026 and is not legal advice. The application of data-protection, sectoral and contractual obligations depends on the facts of each arrangement.

General information only

This article is intended for general information and does not constitute legal advice. The appropriate response depends on the facts and applicable law.