---
title: "DPDP Act Section 16: Cross-Border Data Transfers Explained"
description: "DPDP Act Section 16 allows data transfers abroad unless the Government restricts notified countries. Sectoral exceptions (RBI) and transfer clauses explained."
url: "https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/"
image: "https://advaslam.com/og/writing/dpdp-cross-border-data-transfer-section-16.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/)

# Cross-Border Data Transfers Under the DPDP Act: What Section 16 and Rule 15 Actually Allow

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

Cross-border transfer of personal data under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508) is **permitted by default** — [Section 16(1)](https://indiacode.gov.in/handle/123456789/496508) allows transfer outside India unless the Central Government by notification restricts transfers to a notified country or territory, and [Rule 15 of the DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (G.S.R. 846(E), 13 November 2025) carries that permissive design forward. This article explains the default rule, the two restriction powers that qualify it, the sectoral exceptions that sit outside the DPDP Act, and the contract and disclosure work a Kerala business should do now — before any restriction is notified.

## What is the default position — ban, adequacy, or permission?

India chose permission with a blacklist, not a ban or an adequacy whitelist. The legislative history matters because most teams assume one of the two other models:

-   **Ban / localisation by default** — data must stay in India unless an exception allows export (the model some earlier drafts contemplated). The DPDP Act as enacted rejected this.
-   **Adequacy whitelist** — data may flow only to countries the Government has declared adequate (the GDPR Chapter V approach). The DPDP Act rejected this as well.
-   **Permission with blacklist — what the Act actually does.** Section 16(1) provides that the Central Government may, by notification, restrict transfer to any country or territory outside India. Until such a notification for a destination exists, transfer to that destination is not prohibited by Section 16. Rule 15 of the DPDP Rules, 2025 sits alongside this restriction power: the Rules themselves list neither a whitelist nor a blacklist; instead, the Government may, by general or special order, specify requirements in respect of making personal data available to a foreign State, or to any person or entity under the control of, or any agency of, such a State.

> **Practical distinction:** Law — Section 16’s permissive default — is not the same as advice that every transfer is advisable without safeguards. The Act permits; prudent contracting, security and disclosure are still required by Sections 8, 5 and 6.

No general Section 16 restriction to specific countries had been notified as of August 2026. That makes the present task for businesses preparatory: build transfers on a lawful basis, disclose them, and keep the contractual and technical ability to comply quickly if a restriction for a destination you use is later notified.

## What are the two restriction powers, and how do they differ?

| Feature | Section 16 (general) | Rule 13(4) read with Rule 15 (SDF-specific) |
| --- | --- | --- |
| **Whose data** | Any personal data transferred outside India by any Data Fiduciary | Personal data and traffic data of a notified Significant Data Fiduciary, as specified by the Government on a committee recommendation |
| **Trigger** | Notification by the Central Government restricting transfers to a notified country or territory outside India | Direction to a specific notified SDF or SDF class to keep specified data within India |
| **Default** | Transfer allowed unless restricted | Transfer allowed unless this SDF-specific direction says otherwise for the specified data |
| **Scope** | Destination-based — all fiduciaries transferring to that country are affected | Fiduciary-based and data-category-based — only that SDF and only the specified personal data and traffic data |
| **Example** | A future order restricting transfer of personal data to Country X for all fiduciaries | A direction requiring notified healthtech or fintech SDFs to keep health or financial data and associated traffic data within India |
| **Status as of Aug 2026** | No general restriction notified | No SDF class notified, so no SDF localisation direction could have been made |

A Kerala SaaS that replicates a customer database from Mumbai to a US region for analytics is therefore governed in the first instance by Section 16: the transfer is allowed today, but the business should have a contractual path to repatriate or re-route the flow if Country X were later restricted.

## How do sectoral rules interact with Section 16?

DPDP is not the only transfer rule in the room. Three sectoral frameworks continue to operate in parallel and can be stricter than the DPDP default:

-   **Payments.** The [RBI circular dated 6 April 2018 on Storage of Payment System Data](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244) requires that all data relating to payment systems — including end-to-end transaction details and information collected or processed as part of a payment instruction — be stored in systems located only in India. This is a binding sectoral localisation independent of DPDP. A fintech that assumes DPDP’s permissive default overrides the RBI storage requirement is mistaken.
-   **Insurance, securities and telecom.** IRDAI, SEBI and DoT impose data-handling and retention conditions for regulated data that include system-location and access requirements. Those conditions persist alongside DPDP.
-   **Government access.** Section 17(1)(a) DPDP Act exempts processing necessary for enforcing any legal right or claim; Section 17(2)(a) exempts processing by a notified instrumentality of the State in the interests of sovereignty and integrity of India, security of the State, public order or preventing incitement to any cognizable offence; and Section 17(2)(b) covers research, archiving or statistical processing subject to prescribed standards. Those exemptions can affect availability and access, but they do not create a general exemption from the sectoral storage mandates.

The correct mental model is cumulative: the most restrictive applicable rule governs the specific data, and DPDP’s permissive default fills the space where no sectoral rule imposes a stricter condition.

## What must the Section 5 notice and Section 6 consent say about transfers?

Neither Section 5 nor Section 6 creates a standalone transfer-consent, but both shape what a compliant transfer looks like:

-   **Section 5 notice.** The notice given before or at the time of seeking consent must be itemised and in clear, plain language, available in English and the Eighth Schedule languages the Data Principal chooses (including Malayalam for Kerala users). It must describe the personal data and the specified purpose. Where the purpose involves processing outside India — for example, analytics, support or model training in a foreign region — the purpose description should make that transparent. A notice that says data is processed to provide analytics without disclosing that analytics occurs outside India is not inaccurate under Section 16, but it is weaker disclosure than a notice that transparently describes the processing location where material to the user’s understanding.
-   **Section 6 consent.** Consent must be free, specific, informed, unconditional and unambiguous by clear affirmative action. If the purpose for which consent is sought includes cross-border processing, the specificity requirement means the consent cannot be a bundled, vague authorisation for unspecified future transfers — it must be tied to the described purpose. Withdrawal must be as easy as giving consent (Section 6(4)), which means a transfer that continues after withdrawal of consent for that purpose is no longer on a valid basis.

## What contract terms cover cross-border transfers in practice?

The transfer itself is operational; the contract is what makes it governable. For every processor or sub-processor outside India that handles personal data on your behalf, align the agreement with these DPDP anchors:

1.  **Purpose and scope tie to the notice and consent.** The agreement should recite the specified purpose from the Section 5 notice and prohibit processing beyond it. This is the Article 28 GDPR equivalent that Indian vendor contracts increasingly need — not because the DPDP Act copies GDPR, but because purpose limitation under Section 8(1) and Section 4 requires it.
2.  **Sub-processing controls.** No onward transfer or sub-engagement without prior authorisation, with the same obligations flowed down. This is essential where a US analytics provider sub-processes through its own foreign sub-processors.
3.  **Security floor under Rule 6.** Encryption or masking, access controls, logging for at least one year, monitoring and backups — the Rule 6 minimum — must be contractually required of every processor, including foreign ones. DPDP’s highest penalty band — up to two hundred and fifty crore rupees — sits on failure of reasonable security safeguards (Section 8(5)).
4.  **Breach timelines that let you meet Rule 7.** The processor must notify you of any personal data breach without delay and in any event within a time that lets you meet your own without-delay intimations to affected individuals and to the Board and your detailed 72-hour report. A processor clause that allows notification in 72 hours fails this test — you need notification in hours, not days. For the dual-clock problem where CERT-In’s six-hour duty also applies, see the [CERT-In 6-hour vs DPDP 72-hour guide](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/).
5.  **Erasure and return.** Section 8(7) erasure once consent is withdrawn or the purpose is no longer served (unless retention is required by law), plus Rule 8 timelines and the Third Schedule three-year clock for large e-commerce, gaming and social media fiduciaries. The contract must require certified deletion and return on termination and on your instruction, and must address backups and logs.
6.  **Restriction-readiness.** An undertaking to comply promptly with any future restriction under Section 16 or direction under Rule 13(4) — including repatriation or re-routing of data — and to cooperate with audits. Build the clause now so a later notification does not require renegotiation under time pressure.
7.  **Rights assistance.** Technical and organisational assistance to fulfil Data Principal rights under Sections 11 to 14 and grievance redressal under Section 13 within the Rule 14 ninety-day window.

## How should a Kerala business handle transfers today, before any restriction?

A practical posture that satisfies the current permissive default while preserving agility:

1.  **Map transfer destinations.** For every personal-data flow, record where data is stored and where it is processed — including failover regions, support access from outside India, and analytics copies — not only the primary region.
2.  **Check sectoral constraints first.** If the data is payment system data or otherwise subject to a sectoral storage mandate, that mandate governs regardless of DPDP’s default.
3.  **Ensure notice and consent cover the destination purpose.** Update the Section 5 notice to transparently describe processing purposes that involve outside-India systems, and ensure Section 6 consent is specific to those purposes.
4.  **Harden processor contracts** against the seven points above, and keep a register of foreign processors and sub-processors with their locations and purposes — the record the Board would ask for first.
5.  **Monitor for notifications.** Section 16 and Rule 13(4) actions appear as Gazette notifications and press releases from MeitY. Assign ownership for monitoring them — the DPO or the contact person published under Section 8(9) is the natural owner — and keep a written playbook for repatriation or re-routing if a destination you use is restricted.

## Primary sources

-   [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 4, 5, 6, 8, 10, 16, 17 and the Schedule)
-   [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 13, 15)
-   [RBI Circular on Storage of Payment System Data (6 April 2018)](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244)
-   [PIB backgrounder and press release on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)

FAQ

## Common questions

**Does the DPDP Act ban transferring personal data outside India?**

No. Section 16(1) of the DPDP Act, 2023 states that the Central Government may, by notification, restrict transfer of personal data to a country or territory outside India — which means the default is permissive. Cross-border transfer is allowed unless the Government has issued such a notification for a destination (Rule 15 provides the general-or-special-order machinery for requirements on making data available to a foreign State). No such general restriction had been notified as of August 2026.

**Do I need consent to transfer personal data outside India under the DPDP Act?**

The DPDP Act does not add a separate consent for transfer as a distinct legal basis. If the processing — including the transfer — is covered by valid consent for the specified purpose under Section 6 or by a legitimate use under Section 7, and the general conditions of Section 16 and Rule 15 are met (no applicable restriction to that destination), no additional transfer-specific consent is required. The Section 5 notice should, however, describe that the data may be transferred and the purpose for which.

**If my Kerala startup stores data on AWS Mumbai but analytics runs in the US, is that a cross-border transfer under the DPDP Act?**

Yes. Moving personal data from systems in India to systems outside India — including to a foreign region of the same cloud provider for processing or analytics — is a transfer outside India for Section 16 purposes. It is permitted by default unless the destination is restricted by a Government notification under Section 16 or a localisation direction under Rule 13(4) for Significant Data Fiduciaries, but you must still have a lawful basis under Sections 4 to 7, provide the Section 5 notice, and ensure the transfer is covered by your disclosed purposes and by appropriate contractual protections with the processor.

**Can the Government require data to stay in India under the DPDP Act?**

Yes, in two ways. Under Section 16(1) the Government can, by notification, restrict transfer to specific countries or territories. Separately, under Rule 13(4), the Government can, on a committee recommendation, direct a notified Significant Data Fiduciary to keep such personal data and traffic data as it specifies within India. The second power is SDF-specific and targeted; the first is general. Neither had been exercised by general notification as of August 2026.

**Does RBI's requirement that payment data be stored in India still apply after the DPDP Act?**

Yes. The DPDP Act does not override sectoral localisation that already exists. The RBI circular of 6 April 2018 requiring storage of payment system data in India continues to operate independently of the DPDP framework. A business handling payment data must comply with both — the RBI storage requirement and the DPDP Act's general conditions on processing and transfer.

**What clauses should cross-border processor contracts include for DPDP compliance?**

At minimum: scope and purpose limitation tied to the Section 5 notice and Section 6 consent, a prohibition on sub-processing without authorisation, the Rule 6 security safeguards floor (encryption or masking, access controls, logging for one year, backups), breach-notification timelines that let you meet the Rule 7 72-hour Board duty, erasure and return on termination under Section 8(7) and Rule 8, audit rights, and a commitment to comply with any future Section 16 restriction or Rule 13(4) direction that may apply to the data.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

Keep reading

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies.

6 Sept 2026

[Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act](https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"Cross-Border Data Transfers Under the DPDP Act: What Section 16 and Rule 15 Actually Allow","description":"DPDP Act Section 16 allows data transfers abroad unless the Government restricts notified countries. Sectoral exceptions (RBI) and transfer clauses explained.","url":"https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/","mainEntityOfPage":"https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/","datePublished":"2026-09-01T00:00:00.000Z","dateModified":"2026-09-01T00:00:00.000Z","keywords":"DPDP Act cross border data transfer, Section 16 DPDP Act, Rule 15 DPDP Rules, can I transfer data outside India DPDP, DPDP data localisation, DPDP transfer to US AWS","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/dpdp-cross-border-data-transfer-section-16.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"Cross-Border Data Transfers Under the DPDP Act: What Section 16 and Rule 15 Actually Allow","item":"https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Does the DPDP Act ban transferring personal data outside India?","acceptedAnswer":{"@type":"Answer","text":"No. Section 16(1) of the DPDP Act, 2023 states that the Central Government may, by notification, restrict transfer of personal data to a country or territory outside India — which means the default is permissive. Cross-border transfer is allowed unless the Government has issued such a notification for a destination (Rule 15 provides the general-or-special-order machinery for requirements on making data available to a foreign State). No such general restriction had been notified as of August 2026."}},{"@type":"Question","name":"Do I need consent to transfer personal data outside India under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"The DPDP Act does not add a separate consent for transfer as a distinct legal basis. If the processing — including the transfer — is covered by valid consent for the specified purpose under Section 6 or by a legitimate use under Section 7, and the general conditions of Section 16 and Rule 15 are met (no applicable restriction to that destination), no additional transfer-specific consent is required. The Section 5 notice should, however, describe that the data may be transferred and the purpose for which."}},{"@type":"Question","name":"If my Kerala startup stores data on AWS Mumbai but analytics runs in the US, is that a cross-border transfer under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Yes. Moving personal data from systems in India to systems outside India — including to a foreign region of the same cloud provider for processing or analytics — is a transfer outside India for Section 16 purposes. It is permitted by default unless the destination is restricted by a Government notification under Section 16 or a localisation direction under Rule 13(4) for Significant Data Fiduciaries, but you must still have a lawful basis under Sections 4 to 7, provide the Section 5 notice, and ensure the transfer is covered by your disclosed purposes and by appropriate contractual protections with the processor."}},{"@type":"Question","name":"Can the Government require data to stay in India under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Yes, in two ways. Under Section 16(1) the Government can, by notification, restrict transfer to specific countries or territories. Separately, under Rule 13(4), the Government can, on a committee recommendation, direct a notified Significant Data Fiduciary to keep such personal data and traffic data as it specifies within India. The second power is SDF-specific and targeted; the first is general. Neither had been exercised by general notification as of August 2026."}},{"@type":"Question","name":"Does RBI's requirement that payment data be stored in India still apply after the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"Yes. The DPDP Act does not override sectoral localisation that already exists. The RBI circular of 6 April 2018 requiring storage of payment system data in India continues to operate independently of the DPDP framework. A business handling payment data must comply with both — the RBI storage requirement and the DPDP Act's general conditions on processing and transfer."}},{"@type":"Question","name":"What clauses should cross-border processor contracts include for DPDP compliance?","acceptedAnswer":{"@type":"Answer","text":"At minimum: scope and purpose limitation tied to the Section 5 notice and Section 6 consent, a prohibition on sub-processing without authorisation, the Rule 6 security safeguards floor (encryption or masking, access controls, logging for one year, backups), breach-notification timelines that let you meet the Rule 7 72-hour Board duty, erasure and return on termination under Section 8(7) and Rule 8, audit rights, and a commitment to comply with any future Section 16 restriction or Rule 13(4) direction that may apply to the data."}}]}]}
```
