Cross-Border Data Transfer Restrictions: How the Blacklist Model Actually Works
Section 16 flips the usual adequacy logic on its head. Transfers are allowed everywhere except where the government says otherwise, and that list is still largely empty.
The default position
Section 16 of the DPDP Act permits a Data Fiduciary to transfer personal data outside India, subject to any restrictions the central government may notify by way of a list of restricted countries or territories. Read plainly, this means the default rule is permissive: absent a specific notification naming a country as restricted, cross-border transfer of personal data to that country is not, by itself, a violation of Section 16.
This is a structurally different design from many other major data protection frameworks, which tend to restrict transfers by default and carve out exceptions for approved destinations, and it reflects a policy choice to keep cross-border data flows relatively open unless a specific concern about a specific jurisdiction is identified.
Contrast with GDPR's adequacy model
Under GDPR, transfers outside the EEA are restricted unless the destination has received an adequacy decision from the European Commission, or the transfer is protected by an approved mechanism such as standard contractual clauses or binding corporate rules. The burden effectively sits with the exporting organisation to establish a lawful basis for each transfer destination.
The DPDP Act's blacklist model shifts that burden onto the government to identify specific problem jurisdictions, rather than requiring each fiduciary to justify each destination country individually. This is likely to mean substantially lighter transfer-specific documentation burden for Indian fiduciaries compared to their GDPR-side counterparts, at least while the restricted list remains short or empty.
What could still constrain a transfer
Even where Section 16 itself does not block a transfer, other obligations under the Act, and sector-specific requirements outside it, can still constrain cross-border data movement in practice. General security safeguard obligations under Section 8(5) apply regardless of where the data is processed, and sector regulators such as the Reserve Bank of India maintain data localisation expectations for certain categories of payment system data that predate the DPDP Act and continue to operate alongside it rather than being displaced by it.
Organisations should therefore not read an empty or short restricted-country list as meaning cross-border transfer is unconstrained in every respect; it means one particular constraint, the Section 16 mechanism, has not yet been activated for most destinations, while other sources of constraint remain fully in force.
Where to go next
The companion guide on DPDP versus GDPR structural differences discusses this contrast in more depth, and the Timeline Explorer indicates when Section 16 and its notification mechanism become operative relative to other provisions.