top of page

Sending personal data outside India: Section 16 and Rule 15

3 days ago
5 min read

This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.

Using a cloud region outside India, an overseas email platform or a group company’s shared HR system sends personal data abroad. The Digital Personal Data Protection Act, 2023 does not ban this. It lets the Central Government restrict it. A Data Fiduciary is the person or business that decides why and how personal data is processed. Three layers apply to every transfer it makes: Section 16 of the Act, Rule 15 of the DPDP Rules, 2025, and any other Indian law that is stricter. A fourth applies to Significant Data Fiduciaries.

Layer 1: Section 16(1), restriction by notification

Section 16(1) says the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to any country or territory outside India that it notifies.

The model is a restriction list. Transfers are not limited to approved countries; instead, the government can name countries or territories to which transfers are restricted. For you, that means:

  • No list of “safe” countries exists in the Act or the Rules for you to rely on.

  • The position can change by notification. A destination that is unrestricted when you sign a contract can be notified later.

Before relying on any destination, check the Gazette for notifications under Section 16(1), and re-check on a schedule you set.

Layer 2: Rule 15, data made available to a foreign State

Rule 15 confirms that personal data processed under the Act may be transferred outside India, subject to one restriction. The Data Fiduciary must meet any requirements the Central Government specifies, by general or special order, about making that data available to a foreign State. The same applies to any person or entity under the control of such a State, and to any of its agencies.

Rule 15 does not itself list those requirements; they come from orders. So each transfer raises two questions. Could the data be made available to a foreign State or a body it controls? Has an order been issued that applies? Record whether each recipient is a foreign State, or controlled by or an agency of one, so you can answer the second question when orders appear.

Layer 3: stricter Indian law still applies

Section 16(2) preserves any other law in force in India that gives a higher degree of protection for, or restriction on, transfers of personal data outside India. Section 16 does not limit such a law. If a sector law, or a regulation or direction with the force of law, requires data to stay in India or sets conditions on transfers, that requirement continues alongside the Act.

Significant Data Fiduciaries: a localisation duty

Rule 13(4) adds a duty for Significant Data Fiduciaries. The Central Government may specify personal data, on the recommendations of a committee it constitutes. A Significant Data Fiduciary must take measures to ensure that such data, and the traffic data about its flow, is not transferred outside India. This applies only to notified Significant Data Fiduciaries and only to data the government specifies.

Processing abroad and the Act

Section 3(b) applies the Act to processing outside India when it is connected with offering goods or services to Data Principals in India. Moving that processing offshore does not end your obligations. For other offshore processing, such as staff data hosted abroad, the text is not explicit, so take advice.

Your responsibility for vendors also travels with the data. Section 8(1) keeps you responsible for processing done on your behalf by a Data Processor, and Section 8(5) requires reasonable security safeguards for that processing. Where Section 8(2) applies, you need a valid contract with the processor; see what goes in a Data Processing Agreement.

The reverse case: foreign clients’ data processed in India

Section 17(1)(d) covers a person based in India who processes the personal data of Data Principals not within India, under a contract with a person outside India. For that processing, Chapter II (other than Sections 8(1) and 8(5)), Chapter III and Section 16 do not apply. Security safeguards and overall responsibility still do.

Checking each transfer

  1. Log each transfer activity, not just each vendor: the data, destination, recipient, purpose and contract.

  2. Check Section 16(1). Has the destination country or territory been notified? Record the date you checked.

  3. Check Rule 15. Could the data be made available to a foreign State or a body it controls, and does any general or special order apply?

  4. Check other law. Does any sector law that binds you set a stricter rule (Section 16(2))?

  5. If you are a notified Significant Data Fiduciary, check whether the data is specified under Rule 13(4).

  6. Re-check on a cycle, and whenever a new notification or order is published. The interval is your choice; the Act does not set one.

A transfer you have never checked should count as unchecked, not as permitted.

Transfers already running

Sections 3, 8, 16 and 17, and Rules 13 and 15, apply from 13 May 2027 (clause (c) of G.S.R. 843(E); Rule 1(4)). Transfers already running on that date are covered from then, so the register should be ready before it.

Sources

Every section, rule and date above was checked against the official text on 4 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

  • Section 3(b): Processing outside India linked to offering goods or services in India

  • Section 8(1): Responsible for processing by a Data Processor

  • Section 8(2): Processor engaged for activities related to offering goods or services: only under a valid contract

  • Section 8(5): Security safeguards

  • Section 16(1): Restriction on transfers to notified countries or territories

  • Section 16(2): Stricter Indian law continues to apply

  • Section 17(1)(d): Foreign Data Principals' data processed in India under a foreign contract

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4): Rules 13 and 15 in force eighteen months from publication

  • Rule 13(4): Significant Data Fiduciaries: specified data not transferred outside India

  • Rule 15: Requirements, by general or special order, about making data available to a foreign State

Notifications

  • G.S.R. 843(E), clause (c): Sections 3, 8, 16 and 17 in force eighteen months from 13 November 2025

Log every transfer and keep re-checking it

How-to 10 is a cross-border transfer register: one row per transfer activity, a status for each, and a re-check routine against the Gazette, with no list of "safe" countries.

The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.

Drafting aid, not legal advice.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Cyber Security Services

           CynorSense Solution Pvt. Ltd. is your dedicated partner in the ever-evolving domain of cybersecurity. We are committed to delivering cutting-edge cybersecurity solutions, tailored to meet the unique needs of each client. Our comprehensive suite of services includes DPDPA, Penetration Testing, SOC & SIEM Services, Incident Response, and Cyber Security Consultation.

​

Our expertise extends across Secure Code Review, Vulnerability Assessment and Penetration Testing (VAPT) Services, Security Audits, Risk and Threat Assessment, and Vulnerability Scanning. In addition, we offer services in Malware Analysis, Phishing Simulation, Social Engineering Testing, Web Application Testing, Mobile Application Testing, Network Security Testing, Infrastructure Security Testing, Application Security Testing, and Data Security Testing. 

​

We understand the importance of compliance in today's regulatory environment. Our Compliance Testing services are designed to help your organization navigate the complex landscape of regulations such as DPDPA, ISO 27001, PCI DSS, HIPAA, SOX, GLBA, NERC CIP, FISMA, and the NIST Cybersecurity Framework. 

​

At CynorSense, we blend innovative technology with a robust understanding of the cybersecurity landscape to provide you with the tools and knowledge needed to safeguard your digital assets. Let us be your trusted guide in the realm of cybersecurity, providing the assurance you need in an increasingly interconnected world.

ISO 27001 and ISO 9001 certified company

TELEPHONE:

 +91 80 62 181 669

 ADDRESS: 

 Cynor Sense Solutions Pvt. Ltd.

 Vijay Krishna Towers,   Nanakramguda, Hyderabad,

 Telangana, India - 500032

© 2026 CynorSense Solutions Pvt. Ltd. All rights reserved.

bottom of page