Cross-Border Data Transfers Under DPDPA 2023
Introduction
The Digital Personal Data Protection Act, 2023 (DPDPA) marks India's definitive entry into the global data protection landscape. For multinational corporations, technology companies, and any business processing personal data of Indian residents, the Act's provisions on cross-border data transfers demand immediate attention.
This article examines the DPDPA's framework for international data flows and practical compliance strategies.
The Cross-Border Transfer Framework
Section 16 - Default Permission: Unlike many data protection regimes that restrict transfers, DPDPA permits cross-border transfers of personal data to any country unless specifically prohibited by the Central Government.
Blacklist Approach: The government will notify countries to which transfers are restricted, rather than approving countries for transfers. This represents a departure from the adequacy-based approach of the EU GDPR.
Pending Notification: As of now, no country has been blacklisted. However, the government retains broad discretion to restrict transfers to specific jurisdictions based on national security, public order, or inadequate protection considerations.
What This Means for Businesses
Current Position: Until restrictions are notified, personal data can flow freely from India to other countries. This facilitates global business operations, cloud computing, and centralized data processing.
Uncertainty Risk: The blacklist approach creates regulatory uncertainty. Countries could be added with limited notice, requiring rapid operational changes.
Sectoral Overlay: Sector-specific regulators (RBI for financial data, health authorities for medical records) may impose additional restrictions beyond DPDPA.
Compliance Strategies
Map Your Data Flows: Document all instances where personal data leaves India:
- Cloud service providers and data centers
- Group company transfers for centralized processing
- Third-party vendors with offshore operations
- Business process outsourcing arrangements
Review Cloud Arrangements: Verify data storage locations with cloud providers. Negotiate contractual commitments on data residency where appropriate.
Update DPAs with Vendors: Data Processing Agreements should address:
- Transfer mechanisms and locations
- Commitments to comply with transfer restrictions if imposed
- Notification obligations for changes in processing locations
- Return or deletion of data upon restriction notification
Build Flexibility into Operations: Design systems that can adapt to transfer restrictions:
- Identify data processing that could be repatriated to India
- Assess alternative service providers with India-based infrastructure
- Document business justification for essential transfers
Interaction with Other Regimes
EU GDPR: Companies subject to both DPDPA and GDPR must comply with both. GDPR's Standard Contractual Clauses remain relevant for EU-to-India transfers, even though DPDPA does not require them for India-outbound transfers.
US Framework: There is no mutual recognition arrangement between India and the US. Monitor developments in both jurisdictions.
Sectoral Regulations: RBI's data localization requirements for payment data continue to apply independently of DPDPA. Health data localization proposals remain under discussion.
Data Localization Considerations
While DPDPA takes a relatively permissive approach to transfers, other Indian regulations mandate local storage:
Payment Data: RBI requires domestic storage of payment system data. The requirement has been strictly interpreted and enforced.
Insurance Data: IRDAI regulations require certain insurance records to be maintained in India.
Telecom Data: DoT regulations may require traffic and user data localization.
Critical Information Infrastructure: CII entities face additional data residency requirements.
Preparing for Potential Restrictions
Scenario Planning: Develop playbooks for potential transfer restrictions to key jurisdictions (particularly those with geopolitical sensitivities).
Contractual Protections: Include provisions in customer and vendor agreements addressing potential regulatory changes affecting data transfers.
Insurance Review: Assess whether existing cyber and business interruption policies cover losses from data transfer restrictions.
Stakeholder Communication: Prepare internal and external communications for potential restrictions affecting business operations.
Conclusion
DPDPA's cross-border transfer framework offers current flexibility while retaining government authority to impose restrictions. Organizations should leverage this permissive period to assess data flows, build operational flexibility, and prepare for potential future constraints.
Our Data Privacy team advises organizations on DPDPA compliance, cross-border data transfer strategies, and data localization requirements.
%20(2)-BGWsnxji.png)