Skip to content

Cross-border transfers and localisation

DPDP — not yet effective

Act section 16 and Rule 15 are scheduled for 13 May 2027.

The DPDP model is not a blanket “India-only” requirement. Section 16 permits the Central Government to restrict transfer to notified countries or territories and preserves Indian laws that provide a higher degree of protection or restriction. Rule 15 permits requirements concerning making personal data available to a foreign State, or a person/entity under its control.

As of the cut-off, this research pass did not locate a general restricted-country order, a general Rule 15 order or a Rule 13(4) SDF data-localisation specification. Absence of those DPDP instruments does not displace existing sector restrictions.

Record more than primary storage location:

  • source/destination country and legal entities;
  • controller/Fiduciary and processor roles;
  • data, purpose, Principal population and volume;
  • storage, backup, disaster recovery, logs, telemetry and support access;
  • encryption/key location and administrators;
  • subprocessors and onward transfers;
  • foreign-government access exposure;
  • DPDP order, SDF rule, sector rule and contract;
  • exit and deletion method.

Remote access from outside India is evaluated; “the database is in Mumbai” is incomplete when support staff, logs, keys or replicas are elsewhere.

ALLOW only if:
no active DPDP restricted-country rule blocks destination
AND any Rule 15 foreign-State availability requirement is met
AND any SDF specified-data/traffic-data rule is met
AND every sector rule permits the topology
AND contract/customer policy permits the topology
AND security assessment is approved

Unknown is not allow. It enters legal review without asserting prohibition.

The deployment policy can constrain region, backup region, object-store replication, KMS/HSM, observability sink, support session, outbound connector and subprocessor. Evidence combines cloud inventory, configuration policy results and periodic access tests.

  • RBI-regulated entities must apply the exact outsourcing, payment-data or activity-specific instruments applicable to them; one RBI circular cannot be generalised to all financial data.
  • SEBI entities apply their entity class, CSCRF/cloud framework and later clarifications.
  • ABDM participation brings ecosystem policy and consent artefacts but is not a universal health data localisation statute.
  • Customer contracts may require India-only handling even where public law does not.
  • Given India primary storage and Singapore log export, when assessed, then Singapore appears as a transfer/access destination.
  • Given a future country restriction, when legal configuration activates, then affected connector deployments are blocked and existing flows generate remediation—not silently deleted.
  • Given no SDF localisation notification, then no DPDP “India-only” badge appears.