Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 16 of the Digital Personal Data Protection Act, 2023: Transfer of personal data outside India

Section 16(1) is a notification-based restriction: the Central Government may restrict transfers of personal data by a Data Fiduciary for processing to such country or territory...

Published
Updated
Reading time
7 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 7, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 16 is the Act's single provision on cross-border transfer. It lets the Central Government, by notification, restrict a Data Fiduciary from transferring personal data for processing to a country or territory outside India that it names. Every other destination stays open under this Act, and any other Indian law that is stricter continues to apply. If your business sends data abroad, a legal consultation can help you map the flows against this section and other laws.

What section 16 says, sub-section by sub-section

Sub-sectionWhat it providesWhat to take from it
16(1)The Central Government "may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified"Restriction is by notified destination; it is a power, not an automatic rule
16(2)Nothing in the section restricts the applicability of any law in force in India that provides a higher degree of protection for, or restriction on, transfer by a Data Fiduciary outside India, in relation to any personal data, any Data Fiduciary or a class of eitherOther laws sit on top; the Act sets a floor, not a ceiling

How the model works

Many readers expect a whitelist of "safe" countries. Section 16 is the opposite in design. Transfer is the default position; the Government may close specific destinations by notification. Until a destination is notified, this Act does not itself stop a Data Fiduciary from processing data abroad or engaging a Data Processor there. Check the Government's notifications and the DPDP Rules, 2025 (notified November 2025), because the Act says nothing on which countries, if any, are covered.

Three points follow from the wording.

  1. It binds the Data Fiduciary. The restriction is on "transfer of personal data by a Data Fiduciary". The fiduciary remains responsible for data processed on its behalf by a Data Processor under section 8(1), and section 8(5) requires safeguards for processing "by it or on its behalf by a Data Processor". Sending data to an overseas vendor does not shift that responsibility. See section 8(1).
  2. It is about transfer "for processing". The text does not define transfer and does not say whether remote access from abroad is covered. Do not assume either way; read the notification when one is issued.
  3. It works alongside the territorial reach in section 3. Section 3(b) applies the Act to processing outside India if it is connected with offering goods or services to Data Principals in India. So a foreign company serving Indian customers is within the Act, and an Indian company sending data to it is within section 16 if the destination is notified. See section 3.

Section 16(2): stricter laws continue

The second sub-section is a saving clause. If another law in force in India restricts transfers more tightly for certain data, certain fiduciaries or a class of them, that law still applies. The Act does not name any such law. Section 38(1) adds that the Act is "in addition to and not in derogation of any other law", while section 38(2) says the Act prevails over a conflicting provision. Read together: where another law is stricter on transfer, section 16(2) keeps it alive; where another law is merely different and conflicts, section 38(2) decides. See sections 38 and 39.

A practical reading for a business: the Act does not relieve you from a sector rule or a contractual restriction that already limits where data may sit. Your compliance test is the strictest of all the rules that apply to the data, not the DPDP Act alone.

Where section 16 does not apply

Section 17(1) says section 16 "shall not apply" in the situations listed there, for example where processing is necessary for enforcing a legal right or claim, or where the data of Data Principals outside India is processed under a contract with a person outside India by a person based in India. Section 17(2) removes the whole Act in its two cases, and section 17(5) lets the Government declare exemptions from any provision for notified fiduciaries within five years of commencement. See section 17 exemptions.

What the section does not say

  • It does not list countries or set criteria for choosing them.
  • It does not require consent for a transfer, a separate notice or a contract clause. Consent and notice follow sections 5 and 6 for the processing itself.
  • It does not require data to be stored in India.
  • It does not name a penalty. The Schedule has no item for section 16; item 7 covers breach of any other provision of the Act or the rules, up to fifty crore rupees, and the Board imposes it only after an inquiry finds the breach significant (section 33(1)).
  • It does not say what a fiduciary must do about a notification that arrives after a transfer has begun.
  • Notifications under section 16 are laid before each House of Parliament for thirty days under section 41.

Practical steps

  • Map your flows. List every Data Processor, cloud region, support desk and group company that receives personal data, and the country of each.
  • Record the legal basis. For each flow, note the section 4 ground (consent or legitimate use) that covers the processing.
  • Keep a contract trail. Section 8(2) permits a Data Processor only under a valid contract. Record what the contract says on location of processing. See section 8 processors.
  • Check sector rules. Identify any other law or regulator that limits where your data may go.
  • Build a switch. Keep the ability to move or stop a flow quickly if a destination is notified.

Example

An Indian online retailer uses a support platform hosted in another country and sends customer names and order data to it. Today, under this Act, the retailer's questions are: is there a contract, are safeguards in place, is the processing covered by consent or a legitimate use, and does any stricter Indian law apply to this data? If the Government later notifies that country under section 16(1), the retailer must stop transferring to it for processing. The Act does not give a transition period; read the notification for any.

Need help with cross-border data flows?

Working out where your data goes, and which rules apply to each flow, is tedious but essential before a notification changes the picture. Our legal consultation team can help you review vendor arrangements and keep a defensible record of each transfer.

Key takeaways

  • Section 16(1) lets the Central Government restrict transfers to notified countries or territories.
  • There is no list in the Act, so check notifications and the Rules.
  • Section 16(2) preserves any stricter Indian law on transfer.
  • Responsibility for data sent to a Data Processor stays with the Data Fiduciary (section 8(1)).
  • Section 17 switches section 16 off in listed cases.
  • No Schedule item names section 16; residual item 7 covers breach of other provisions.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 16

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does the DPDP Act ban transfer of personal data outside India?

No. Section 16(1) only allows the Central Government to restrict transfer to countries or territories that it notifies.

Does the Act list the restricted countries?

No. The Act contains no list. Check the Government's notifications and the DPDP Rules, 2025.

When in doubt, read the provision itself rather than a summary of it — including this one.

— TaxClue Compliance Desk

Section 16: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. Section 16(1) only allows the Central Government to restrict transfer to countries or territories that it notifies.

No. The Act contains no list. Check the Government's notifications and the DPDP Rules, 2025.

Yes. Section 16(2) preserves any law in force in India that gives a higher degree of protection or restriction on transfer.

A Data Fiduciary transferring personal data for processing. The fiduciary stays responsible for its Data Processors under section 8(1).

Yes, if its processing is connected with offering goods or services to Data Principals in India (section 3(b)).

The Schedule has no item for it. Item 7 covers any other provision, up to fifty crore rupees, after a Board inquiry.