Law note · India

Digital Personal Data Protection Act, 2023, cross-border transfer restrictions

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, cross-border transfer, s.16 stage IMMINENT in force in 256 days effective 2027-05-13 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • India's cross-border transfer restriction on personal data, including a voiceprint or other biometric identifier, has not yet commenced and is scheduled to take effect 13 May 2027. Once in force, an app may transfer the personal data of an Indian data principal to any country or territory by default, unless the Central Government has notified that destination as restricted.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Section 16(1) sets a blacklist model: transfer of personal data outside India is permitted by default to any country or territory, except where the Central Government affirmatively notifies a restriction. This flips the 2019/2021 draft Bills' government-approved whitelist model. No data-localization mandate appears anywhere in the Act.

Section 16 sits inside the sections-3-to-17 bucket; Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as this bucket's commencement date. No restricted-country list has been notified because the enabling section is not yet in force.

← Back to the example  ·  Lint your app →