Cross-Border Data under the DPDP Act: India's Negative-List Bet and the GCC Economy

Section 16 of the Digital Personal Data Protection Act, 2023 departs from the adequacy-based "positive list" model that has become the international default since the General Data Protection Regulation, opting instead...

Abstract

Section 16 of the Digital Personal Data Protection Act, 2023 departs from the adequacy-based "positive list" model that has become the international default since the General Data Protection Regulation, opting instead for a negative list under which cross-border transfer is permitted everywhere except where the Central Government affirmatively restricts it. This article argues that the negative list, though justified in the language of ease of doing business, produces a distinctive form of regulatory uncertainty poorly suited to the investment horizon of India's Global Capability Centre economy.

The absence of a restricted-country notification should not be mistaken for deregulation. Section 16 of the DPDP Act, read with Rule 15 of the 2025 Rules, moves risk from the moment of transfer to a future executive decision. That uncertainty affects capital planning, regulatory overlap and constitutional accountability in ways that existing commentary has not fully examined.

Cross-Border Data Transfer under the Digital Personal Data Protection Act, 2023:

Negative-List Regulation and India's GCC Economy

Introduction

Cross-border data transfer is not a peripheral technical question for Indian data protection law, it is the provision on which the commercial viability of India's services economy substantially turns. Global Capability Centres, the offshore units through which multinational enterprises perform technology, finance, analytics and research functions from Indian soil, numbered over 1,700 by FY24 and generated approximately USD 64.6 billion in revenue while employing more than 1.9 million professionals, a figure projected to rise toward USD 100 billion by the decade's end.

Every one of these centres exists because personal data belonging to customers, patients, and employees abroad can be processed in India and because data on Indian data principals can, in some contexts, move outward to parent entities. The Digital Personal Data Protection Act, 2023 ("DPDP Act") governs the second half of that flow through Section 16, whose drafting history reveals a deliberate abandonment of the localisation-first orientation of earlier bills in favour of what practitioners now describe as a "negative list" or "blacklist" model.

This article examines that model doctrinally, situates it against the constitutional foundation laid by the Supreme Court in Justice K. S. Puttaswamy v. Union of India, compares it with the European Union's adequacy architecture and argues that its principal weakness is not permissiveness as such but the peculiar structure of uncertainty it creates for an economy built on long-duration, capital-intensive offshoring commitments.

From Positive List to Positive Silence: The Architecture of Section 16

Section 16(1) of the DPDP Act provides that the Central Government may, after an assessment of such factors as it considers necessary, notify that the transfer of personal data by a Data Fiduciary to any country or territory outside India shall not be made. The structure is negative in the precise sense that the statute does not require a Data Fiduciary to establish, before transferring data, that the destination enjoys any particular status. Transfer is the default, restriction is the exception.

Section 16(2) preserves the application of any other Indian law imposing a higher standard of protection or a stricter restriction, so sectoral regimes are not displaced by the general permissiveness of Section 16(1). This is a marked reversal from the trajectory of India's earlier data protection proposals. The Personal Data Protection Bill, 2019 and the Joint Parliamentary Committee's 2021 report had both contemplated mandatory localisation for sensitive and critical personal data, a position that drew sustained opposition from American and European technology and financial services interests during consultation.

The final Act abandoned this approach, a shift most commentators attribute to the government's evolving assessment of the economic cost of localisation against its speculative sovereignty benefit. It is worth pausing on what this reversal accomplishes. A localisation-first regime forces the state to identify, ex ante, the jurisdictions and data categories it trusts. A negative list regime forces the state to identify, ex post and on an ongoing basis, the jurisdictions it distrusts, while placing the burden of monitoring that determination on every data fiduciary transacting internationally.

This reversal is frequently celebrated as liberalisation; less often noticed is that it also reallocates monitoring cost from the state, which no longer certifies anything before transfers occur, to industry, which must track an open-ended and currently empty list that could be populated at any time.

Operationalising the Negative List: Rule 15 and the Staggered Commencement

The DPDP Rules, 2025, notified on 13 November 2025, operationalise Section 16 through Rule 15, titled "Processing of Personal Data outside India." Rule 15 confirms that a Data Fiduciary may transfer personal data outside India subject to any requirements the Central Government may, by general or special order, specify in respect of making such data available to a foreign State or to any person or entity acting on its behalf. This adds something beyond Section 16(1): the government's power is not limited to a binary "restricted or not" determination but extends to conditions on onward disclosure to foreign governments.

Rule 13(4), applicable to Significant Data Fiduciaries designated under Section 10, goes further, permitting the Central Government, on the recommendation of an inter-ministerial committee, to direct that specified categories of personal data and associated traffic data must not leave Indian territory at all. This reintroduces, through delegated rulemaking, a sectoral localisation power that the primary statute had ostensibly rejected as a general principle, a point the Software Freedom Law Centre has flagged as a significant departure from the Act's professed philosophy of permissive transfer. The commencement architecture compounds the uncertainty.

The notification of 13 November 2025 brought foundational and Data Protection Board provisions into force immediately, deferred the consent manager framework by one year and deferred the bulk of operative provisions, including cross-border transfer, notice requirements, and data principal rights, by eighteen months. As of mid-2026, no country has been notified as restricted under Section 16(1), which practitioners read as meaning transfers are, for now, unconstrained by any transfer-specific formality. But "unconstrained for the time being" is a materially different legal position from "permanently permitted," and that distinction is precisely where the negative list model's practical cost concentrates.

The Constitutional Backdrop: Puttaswamy and the Missing Proportionality Test

The DPDP Act is commonly described as operationalising the right to informational privacy recognised by the nine-judge bench in Puttaswamy, which held that privacy is protected as an intrinsic part of the right to life and personal liberty under Article 21 and that any state invasion of privacy must satisfy a threefold test of legality, legitimate aim, and proportionality. The difficulty with Section 16 is that this proportionality discipline applies awkwardly, if at all, to a provision whose default is permissive and whose restrictive power is triggered only by future executive notification.

When the government eventually designates a restricted country, that act is at least conceptually reviewable against the legality-legitimate aim-proportionality framework, since it curtails a transfer that would otherwise be lawful. But the anterior question, whether the default permissive position itself adequately protects data principals whose data is transferred to jurisdictions with weak or hostile data protection regimes, is not obviously subject to the same scrutiny, because no discrete state act triggers it.

The negative list, in other words, structurally minimises the occasions on which the Puttaswamy proportionality test can be invoked, since the test attaches to acts of restriction rather than the ongoing, unreviewed fact of permission. Existing secondary literature has tended to treat this as a matter of legislative design choice rather than a live constitutional question, and it merits closer scholarly attention than it has so far received.

Comparative Perspective: The Blacklist Against the Adequacy Whitelist

The European Union's approach under Article 45 of the GDPR reverses India's structure. Transfers without additional safeguards are permitted only where the European Commission finds that a destination provides protection essentially equivalent to EU law. That assessment considers the rule of law, regulatory independence and international human-rights commitments, and must be reviewed periodically.

As of 2026 the Commission has extended adequacy status to a limited set of jurisdictions, including Japan, the Republic of Korea, the United Kingdom, Canada for commercial organisations, and, since July 2023, participating United States entities under the EU-US Data Privacy Framework, with Brazil added in January 2026. Absent adequacy, transfers require Article 46 safeguards such as Standard Contractual Clauses or Binding Corporate Rules, mechanisms entirely absent from the DPDP Act.

The comparative point most commentators make is that India's negative list is more businessfriendly because it does not require exporters to conduct transfer impact assessments or execute standard clauses for every jurisdiction. That is true as far as it goes, but it obscures an asymmetry in institutional accountability. The EU model concentrates the adequacy determination in a reasoned, published, periodically reviewed administrative act amenable to challenge, as the Schrems litigation before the Court of Justice of the European Union demonstrated with respect to the Commission's earlier Privacy Shield decision.

India's model, by contrast, locates the equivalent judgment nowhere in particular until the Central Government chooses to notify a restriction "after an assessment of such factors as it may consider necessary," a standard neither Section 16 nor Rule 15 further defines. This absence of an articulated standard is not merely a drafting gap; it means Indian data principals have no visibility into the criteria by which their data's destination is being tacitly approved, and Indian businesses have no advance signal of what might tip a jurisdiction onto the restricted list.

Sectoral Fragmentation: Section 16(2) and the Localisation Overlay

Section 16(2)'s preservation of stricter sectoral law means the negative list's general permissiveness is, in practice, punctured by a patchwork of binding localisation mandates predating the DPDP Act. The Reserve Bank of India's 2018 directive on storage of payment system data requires such data to be stored exclusively within India, with no carve-out for crossborder analytics. SEBI has separately issued a framework governing cloud adoption by regulated entities, constraining where trading and investor data may be processed.

For financial services GCCs, a substantial share of India's capability centre base given the concentration of global banks and asset managers in the sector, Section 16's liberalisation is close to irrelevant: the operative constraint remains the sectoral regulator's localisation mandate, which the DPDP Act cannot override. The negative list's headline permissiveness thus applies unevenly, generous for technology and analytics functions, largely beside the point for BFSI-linked centres already bound by a stricter baseline.

The GCC Stakes: Why the Negative List Matters for Long-Duration Investment

The conventional account holds that the negative list benefits the GCC economy because it removes the transactional friction of adequacy assessments and standard contractual documentation for the ordinary, high-volume flow of employee, customer, and operational data between Indian centres and their global parents. This is not wrong, but it understates the character of GCC investment. A capability centre is not a single transaction; it is typically a multi-year real estate commitment, a technology stack built around a specific data architecture, and a headcount investment that Nasscom and Zinnov project will grow the sector past 2,400 centres and 4.5 million jobs by 2030.

These commitments assume the regulatory environment governing data flows will remain reasonably stable over the life of the investment, not merely at the moment of setup. The negative list model offers a misleading form of comfort here. Because no country is currently restricted, a multinational deciding today whether to route a data-intensive analytics or AI function through an Indian GCC sees no formal barrier to moving data between India and its other global hubs.

But the structure of Section 16 means this could change through a single executive notification, issued after an internally conducted assessment whose criteria are not published in advance, with no requirement of prior consultation and no guaranteed transition period beyond whatever the notification itself specifies. This is the inverse of the EU's problem. Under the GDPR, an adequacy decision, once granted, offers durable certainty subject to periodic, reasoned review; risk is front-loaded into a lengthy assessment process, but the certainty that follows is comparatively strong. Under Section 16, certainty is front-loaded, Nasscom, GCC Summit & Awards 2025, nasscom.

in/gcc2025 (projecting over 2,400 GCCs and 4.5 million jobs by 2030); Zinnov, India's Global Capability Center (GCC) Story in 2025, zinnov. com. GDPR, art. 45(3)-(5) (requiring periodic review at least every four years and a reasoned, non-retroactive procedure for amendment or repeal of an adequacy decision).

The regime imposes few front-loaded conditions, but its back-loaded risk remains unbounded and lacks the procedural runway found in the European Union's withdrawal-of-adequacy process. GCC investments are planned over five- and ten-year periods. A rule that creates no obstacle today but permits an unquantified restriction tomorrow is not necessarily more predictable than a slower, more durable whitelist model.

Conclusion

Section 16 of the DPDP Act, read with Rule 15 and the localisation overlay in Rule 13(4), reflects a coherent policy choice to prioritise transactional ease over ex ante certification, in deliberate contrast to both India's own earlier legislative drafts and the European Union's adequacy architecture. That choice is defensible as short-term industrial policy, and it is not difficult to see why a government courting Global Capability Centre investment would prefer a regime imposing no upfront transfer formalities.

For the GCC economy, the negative list matters less for the compliance costs it avoids today than for the restriction risk it postpones. No published standard explains when that risk may crystallise. The permissive default may also escape the proportionality scrutiny associated with Puttaswamy until the Government eventually acts.

A mature transfer regime for an economy of India's scale will eventually need to resolve this tension, either by publishing the criteria that will guide future restriction, or by accepting that permissiveness without predictability is not, in the end, the deregulatory achievement it is often described as being.

Primary materials

Key primary materials: Digital Personal Data Protection Act, 2023 and subordinate legislation; Ministry of Electronics and Information Technology.

Technology and Digital RightsTechnology LawData Protection