Word of the Day
Loading... Fetching today's legal term...

Cross-Border Transfer of Personal Data under the Digital Personal Data Protection Act, 2023: A Corporate Compliance Perspective

Cross-Border Transfer of Personal Data DPDPA 2023

Introduction

The rapid growth of digital commerce has transformed the way organizations collect, process, store, and share personal data. Businesses today rarely operate within the geographical boundaries of a single country. Cloud computing, enterprise software, global payroll systems, customer relationship management platforms, artificial intelligence solutions, and outsourced business processes frequently involve the movement of personal data across national borders.

Recognizing the need to regulate such data flows while promoting digital innovation, Parliament enacted the Digital Personal Data Protection Act, 2023 ("DPDP Act"). The Act establishes a comprehensive legal framework governing the processing of digital personal data and imposes statutory obligations on every Data Fiduciary that determines the purpose and means of processing personal data.

One of the significant features of the DPDP Act is its approach to cross-border transfers of personal data. Unlike several foreign data protection regimes that generally prohibit international transfers unless stringent adequacy requirements are satisfied, the DPDP Act adopts a balanced framework. Subject to restrictions that may be notified by the Central Government under Section 16, organizations are permitted to transfer personal data outside India. However, such transfers do not dilute or reduce the statutory responsibilities imposed upon the Data Fiduciary under the Act.

Accordingly, businesses transferring personal data outside India must ensure compliance not only with Section 16 but also with the broader obligations contained in Sections 4 to 15 of the DPDP Act and the accompanying Digital Personal Data Protection Rules.

Understanding Cross-Border Transfer of Personal Data

In practical terms, a cross-border transfer occurs whenever digital personal data collected in India is accessed, processed, stored, transmitted, or otherwise made available in another country. Such transfers may occur directly or indirectly through technology infrastructure or third-party service providers.

For example, a company may transfer personal data outside India when it:

  • stores customer or employee information on overseas cloud servers;
  • uses Software-as-a-Service (SaaS) applications hosted outside India;
  • shares employee records with a foreign holding or subsidiary company;
  • engages overseas payroll or human resource management providers;
  • outsources customer support operations to another country;
  • uses international email marketing or analytics platforms; or
  • permits remote access to personal data by employees or vendors located outside India.

Many organizations undertake these activities as part of their routine business operations without recognizing that they constitute cross-border processing of personal data and attract statutory compliance obligations under the DPDP Act.

Statutory Framework Governing Cross-Border Transfers

Cross-border transfer of personal data under the DPDP Act is not governed by Section 16 alone. Instead, it forms part of a larger statutory framework regulating the entire lifecycle of personal data—from its collection to its eventual erasure.

Accordingly, before transferring personal data outside India, every organization should examine its compliance with the following provisions of the DPDP Act:

  • Section 4 – Lawful processing of personal data.
  • Section 5 – Notice to the Data Principal.
  • Section 6 – Valid consent.
  • Section 7 – Processing for certain legitimate uses.
  • Section 8 – General obligations of the Data Fiduciary.
  • Section 10 – Additional obligations applicable to Significant Data Fiduciaries.
  • Sections 11 and 12 – Rights of the Data Principal, including correction, erasure, and grievance redressal.
  • Section 16 – Transfer of personal data outside India.
  • Section 33 – Penalties and adjudication.

Consequently, compliance with Section 16 alone is insufficient. A lawful international transfer presupposes that the organization has complied with every other applicable statutory obligation under the DPDP Act.

Section 16 – Cross-Border Transfer of Personal Data

Section 16 of the DPDP Act provides the legal basis for transferring personal data outside India. Under this provision, a Data Fiduciary may transfer personal data to any country or territory unless the Central Government, having regard to national security, strategic interests, or other relevant considerations, notifies restrictions on transfers to specified jurisdictions.

The Act therefore adopts a "negative list" approach. Instead of requiring prior governmental approval for every international transfer, organizations are generally free to determine where personal data may be processed, subject to any future Government notifications restricting particular destinations.

However, this flexibility should not be interpreted as an exemption from compliance. The permission to transfer personal data internationally does not relieve a Data Fiduciary of its statutory responsibilities under the DPDP Act. Regardless of where the data is processed, the Data Fiduciary remains legally accountable for ensuring compliance with the Act and protecting the rights of the Data Principal.

Business Risks of Non-Compliance

Failure to implement an appropriate cross-border data transfer framework may expose organizations to:

  • regulatory investigations;
  • severe financial penalties;
  • contractual disputes;
  • operational disruption;
  • cybersecurity risks;
  • reputational damage; and
  • loss of customer confidence.

For multinational organizations, non-compliance may also adversely affect contractual relationships with international customers and business partners.

Practical Compliance Checklist

Every business should consider taking the following actions:

  • Map all cross-border data flows and transfers.
  • Identify overseas cloud and technology providers.
  • Review and update contracts with international vendors.
  • Verify the physical location of primary and backup servers.
  • Update Privacy Notices and internal data governance policies.
  • Establish robust incident response and breach notification mechanisms.
  • Monitor Central Government notifications restricting transfers to specific jurisdictions.
  • Periodically review vendor compliance and technical security practices.
  • Maintain documented records demonstrating full compliance under the DPDP Act.

Comparative Position: UK GDPR and CCPA/CPRA

The Digital Personal Data Protection Act, 2023 provides the legal framework governing the processing of digital personal data in India. However, many Indian companies operate across multiple jurisdictions through cloud services, global payroll systems, software platforms, customer support centres, and multinational corporate groups. As a result, a single cross-border transfer of personal data may also trigger foreign privacy laws such as the United Kingdom General Data Protection Regulation (UK GDPR) and the California Consumer Privacy Act, 2018 (CCPA), as amended by the California Privacy Rights Act, 2020 (CPRA).

Understanding these legal frameworks enables organizations to design a uniform privacy compliance program that satisfies both domestic and international regulatory requirements.

United Kingdom – UK GDPR

The UK GDPR, read with the Data Protection Act 2018, regulates the processing of personal data in the United Kingdom. It also applies to organizations established outside the UK where they offer goods or services to individuals in the UK or monitor their behaviour.

Unlike Section 16 of the DPDP Act, which generally permits cross-border transfers unless restricted by the Central Government, the UK GDPR permits international transfers only where the transfer complies with the statutory requirements laid down under Chapter V of the Regulation. The objective is to ensure that personal data continues to receive substantially the same level of protection after it leaves the United Kingdom.

Lawful Mechanisms for International Transfers

The UK GDPR recognizes three principal mechanisms for transferring personal data outside the United Kingdom:

  • Adequacy Regulations: The UK Government may determine that a country or territory provides an adequate level of protection for personal data. Where such an adequacy regulation exists, personal data may be transferred without requiring additional contractual safeguards.
  • Appropriate Safeguards: Where no adequacy regulation exists, organizations must adopt recognized legal safeguards before transferring personal data, including:
    • International Data Transfer Agreements (IDTA);
    • UK Addendum to the EU Standard Contractual Clauses;
    • Binding Corporate Rules (BCRs);
    • Approved Codes of Conduct; and
    • Approved Certification Mechanisms.
  • Exceptions: In limited circumstances, personal data may be transferred without adequacy regulations or contractual safeguards, such as explicit consent of the individual, establishment or defence of legal claims, or vital public interest reasons.

Corporate Compliance under the UK GDPR

For businesses, compliance involves establishing a structured privacy governance framework that includes:

  • identifying all international data transfers;
  • maintaining comprehensive records of processing activities;
  • carrying out Transfer Risk Assessments (TRAs) where required;
  • executing Data Processing Agreements (DPAs) with overseas processors;
  • implementing appropriate technical and organizational security measures; and
  • maintaining incident response and breach management procedures.

California – CCPA / CPRA

Unlike the United Kingdom, the United States does not have a single comprehensive federal law governing personal data. Privacy regulation is largely based on sector-specific laws and state legislation.

The California Consumer Privacy Act, 2018 (CCPA), as amended by the California Privacy Rights Act, 2020 (CPRA), is one of the most significant state privacy laws in the US. It applies to businesses that collect the personal information of California residents and satisfy statutory applicability thresholds.

The CCPA does not impose a separate legal framework specifically governing cross-border transfers of personal information. Instead, it regulates how businesses collect, use, retain, disclose, and share personal information while granting consumers expansive control over their data.

Key Corporate Obligations under CCPA/CPRA

Businesses subject to the CCPA/CPRA are generally required to:

  • provide clear and accessible privacy notices;
  • disclose the categories of personal information collected and the underlying business purposes;
  • inform consumers about third-party categories with whom personal information is shared;
  • provide rights to access, correct, delete, and opt out of the sale or sharing of personal information;
  • execute written agreements with service providers, contractors, and third parties; and
  • implement reasonable security safeguards to protect personal information.

Key Considerations for Corporates in India

Indian companies frequently rely on international cloud platforms, SaaS applications, payroll processors, and overseas business process outsourcing providers. Consequently, personal data collected in India may be processed across multiple jurisdictions in the ordinary course of business.

For example, an Indian technology firm might collect customer information in India, store it on cloud infrastructure located in Europe, engage a payroll provider in the UK, and operate a customer support centre in the US. In such cases, compliance with the DPDP Act alone may not be sufficient. Depending on the nature of the business and the residence of the data subjects, additional obligations under the UK GDPR or CCPA/CPRA may simultaneously apply.

Conclusion

Cross-border transfer of personal data is now a routine aspect of modern business operations. While the DPDP Act, 2023 adopts a flexible framework by permitting transfers unless specifically restricted by the Central Government, organizations remain fully accountable for ensuring data protection throughout its operational lifecycle.

The UK GDPR follows a structured framework permitting transfers only through recognized legal mechanisms, whereas the CCPA/CPRA focuses on transparency, consumer rights, and overall accountability. Despite these structural differences, all three frameworks require organizations to implement robust data governance, maintain appropriate contractual safeguards, and operate with verifiable accountability.

Looking Ahead

With statutory compliance under the Digital Personal Data Protection Act, 2023 coming into effect soon, organizations must act proactively. As the enforcement timeline approaches, delaying compliance exposes businesses to substantial legal penalties, regulatory intervention, and reputational fallout. Early preparation ensures a seamless transition into the new regulatory landscape.

Consequences of non-compliance

Failure to comply with the statutory mandate under the DPDP Act, 2023 exposes organizations to:

  • severe financial penalties reaching up to ₹250 crore per violation;
  • potential suspension of processing activities;
  • targeted blocking orders for digital platforms;
  • significant loss of customer trust and brand reputation; and
  • breach of contractual obligations with global partners.

Integrating privacy compliance into enterprise risk management frameworks and internal audit processes is no longer optional—it is a business imperative.

How Can JTS Lex Advocates & Associates Assist?

JTS Lex Advocates & Associates works closely with organizations to streamline their compliance under the Digital Personal Data Protection Act, 2023. Our team assists businesses in evaluating current data protection frameworks, performing compliance gap analyses, drafting privacy policies, structuring cross-border data transfer mechanisms, reviewing vendor agreements, and providing tailored legal strategies to build a sustainable data governance framework.

Read Also

Next Article in Legal Insights

RBI Advisory on Customer Data Protection and Management (DPDPA 2023 Alignment) →

Explore CSITE advisory mandates for Banks, NBFCs, and Financial Institutions on automated data management, access control, and incident response. Read Article

Ankit Srivastava - Associate Partner JTS Lex

About the Author:

Ankit Srivastava is a versatile legal professional specializing in consumer law and dispute resolution. He brings extensive experience in navigating complex matters involving real estate, banking, and insurance before various Consumer Commissions.

A skilled professional, Ankit is proficient in managing cases from pre-litigation strategy to the final enforcement of orders. His practice extends to the District Courts and the Hon’ble High Court of Judicature at Allahabad (Lucknow Bench), where he handles civil matters, writs, and appellate proceedings. Known for a meticulous, research-driven approach, Ankit focuses on delivering practical and result-oriented relief for his clients.

Disclaimer: The insights shared in this article represent the personal viewpoint/opinion and professional outlook of the author and do not necessarily reflect the official position of the firm, JTS Lex.

Chat with us on WhatsApp
Home