Section 16 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 16 is the Act's single provision on cross-border transfer. It lets the Central Government, by notification, restrict a Data Fiduciary from transferring personal data for processing to a country or territory outside India that it names. Every other destination stays open under this Act, and any other Indian law that is stricter continues to apply. If your business sends data abroad, a legal consultation can help you map the flows against this section and other laws.
Section 16(1) is a notification-based restriction: the Central Government may restrict transfers of personal data by a Data Fiduciary for processing to such country or territory outside India as may be notified. Section 16(2) says the section does not displace any other Indian law that gives a higher degree of protection or restriction on such transfers. The Act itself contains no list of restricted countries and no general ban. Sectors that have their own stricter rules must keep following them.
What section 16 says, sub-section by sub-section
| Sub-section | What it provides | What to take from it |
|---|---|---|
| 16(1) | The Central Government "may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified" | Restriction is by notified destination; it is a power, not an automatic rule |
| 16(2) | Nothing in the section restricts the applicability of any law in force in India that provides a higher degree of protection for, or restriction on, transfer by a Data Fiduciary outside India, in relation to any personal data, any Data Fiduciary or a class of either | Other laws sit on top; the Act sets a floor, not a ceiling |
How the model works
Many readers expect a whitelist of "safe" countries. Section 16 is the opposite in design. Transfer is the default position; the Government may close specific destinations by notification. Until a destination is notified, this Act does not itself stop a Data Fiduciary from processing data abroad or engaging a Data Processor there. Check the Government's notifications and the DPDP Rules, 2025 (notified November 2025), because the Act says nothing on which countries, if any, are covered.
Three points follow from the wording.
- It binds the Data Fiduciary. The restriction is on "transfer of personal data by a Data Fiduciary". The fiduciary remains responsible for data processed on its behalf by a Data Processor under section 8(1), and section 8(5) requires safeguards for processing "by it or on its behalf by a Data Processor". Sending data to an overseas vendor does not shift that responsibility. See section 8(1).
- It is about transfer "for processing". The text does not define transfer and does not say whether remote access from abroad is covered. Do not assume either way; read the notification when one is issued.
- It works alongside the territorial reach in section 3. Section 3(b) applies the Act to processing outside India if it is connected with offering goods or services to Data Principals in India. So a foreign company serving Indian customers is within the Act, and an Indian company sending data to it is within section 16 if the destination is notified. See section 3.
Section 16(2): stricter laws continue
The second sub-section is a saving clause. If another law in force in India restricts transfers more tightly for certain data, certain fiduciaries or a class of them, that law still applies. The Act does not name any such law. Section 38(1) adds that the Act is "in addition to and not in derogation of any other law", while section 38(2) says the Act prevails over a conflicting provision. Read together: where another law is stricter on transfer, section 16(2) keeps it alive; where another law is merely different and conflicts, section 38(2) decides. See sections 38 and 39.
A practical reading for a business: the Act does not relieve you from a sector rule or a contractual restriction that already limits where data may sit. Your compliance test is the strictest of all the rules that apply to the data, not the DPDP Act alone.
Where section 16 does not apply
Section 17(1) says section 16 "shall not apply" in the situations listed there, for example where processing is necessary for enforcing a legal right or claim, or where the data of Data Principals outside India is processed under a contract with a person outside India by a person based in India. Section 17(2) removes the whole Act in its two cases, and section 17(5) lets the Government declare exemptions from any provision for notified fiduciaries within five years of commencement. See section 17 exemptions.
What the section does not say
- It does not list countries or set criteria for choosing them.
- It does not require consent for a transfer, a separate notice or a contract clause. Consent and notice follow sections 5 and 6 for the processing itself.
- It does not require data to be stored in India.
- It does not name a penalty. The Schedule has no item for section 16; item 7 covers breach of any other provision of the Act or the rules, up to fifty crore rupees, and the Board imposes it only after an inquiry finds the breach significant (section 33(1)).
- It does not say what a fiduciary must do about a notification that arrives after a transfer has begun.
- Notifications under section 16 are laid before each House of Parliament for thirty days under section 41.
Practical steps
- Map your flows. List every Data Processor, cloud region, support desk and group company that receives personal data, and the country of each.
- Record the legal basis. For each flow, note the section 4 ground (consent or legitimate use) that covers the processing.
- Keep a contract trail. Section 8(2) permits a Data Processor only under a valid contract. Record what the contract says on location of processing. See section 8 processors.
- Check sector rules. Identify any other law or regulator that limits where your data may go.
- Build a switch. Keep the ability to move or stop a flow quickly if a destination is notified.
Example
An Indian online retailer uses a support platform hosted in another country and sends customer names and order data to it. Today, under this Act, the retailer's questions are: is there a contract, are safeguards in place, is the processing covered by consent or a legitimate use, and does any stricter Indian law apply to this data? If the Government later notifies that country under section 16(1), the retailer must stop transferring to it for processing. The Act does not give a transition period; read the notification for any.
Need help with cross-border data flows?
Working out where your data goes, and which rules apply to each flow, is tedious but essential before a notification changes the picture. Our legal consultation team can help you review vendor arrangements and keep a defensible record of each transfer.
Key takeaways
- Section 16(1) lets the Central Government restrict transfers to notified countries or territories.
- There is no list in the Act, so check notifications and the Rules.
- Section 16(2) preserves any stricter Indian law on transfer.
- Responsibility for data sent to a Data Processor stays with the Data Fiduciary (section 8(1)).
- Section 17 switches section 16 off in listed cases.
- No Schedule item names section 16; residual item 7 covers breach of other provisions.
Read next
- Cross-border data transfer under the DPDP Act
- Section 3 of the DPDP Act, 2023: application inside and outside India
- Section 17 exemptions: legal claims, courts and offences
- Section 8 of the DPDP Act, 2023: responsibility for compliance and Data Processors
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
