Practical guidance for planning, not legal advice. Confirm your own obligations with counsel and against the Gazette text.
“We need to move everything onto Indian servers because of DPDP.” We hear versions of this constantly, and it has launched a fair number of expensive migration projects. For most companies it is wrong.
The Digital Personal Data Protection Act, 2023 does not impose a general data localisation mandate. It does the opposite by default.
What the law actually says
Section 16(1): “A Data Fiduciary may transfer personal data of a Data Principal to a place outside India, subject to such terms and conditions as may be prescribed and in accordance with the provision of this Act.”
Section 16(2): “The Central Government may, after an assessment of such factors as it may consider necessary, notify such countries or territories outside India to which a Data Fiduciary may not transfer personal data of a Data Principal.”
Rule 15 of the DPDP Rules, 2025 carries it through: “Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify…”
Read those together and the model is clear. Transfer is permitted to anywhere, except to destinations the government specifically restricts.
A negative list, not an adequacy list
If your mental model comes from GDPR, this is the inversion worth internalising. GDPR works from a positive list: transfers need an adequacy decision or a safeguard mechanism, and the default is no. DPDP works from a negative list: everywhere is fine until India names a country it is not.
And as things stand, no restricted-country notification has been issued. The blocklist is, for the moment, empty.
This does not mean cross-border transfer is unregulated. Every other obligation still travels with the data — consent, purpose limitation, security safeguards, breach notification, the individual's right to erasure. Moving data abroad does not move the responsibility off you.
Three cases where residency genuinely does bind
The myth persists because for some companies it is true. Check whether you are one of them before concluding you are not.
- Your sector regulator says so. This is the big one. RBI, SEBI and IRDAI can and do impose stricter localisation inside their domains — RBI's payment-system data requirements being the best-known example. If you are in payments, lending, broking or insurance, your binding constraint is your regulator, not DPDP, and it may well predate DPDP entirely.
- You are a Significant Data Fiduciary. SDFs are designated by the volume and sensitivity of data they handle, and reporting on the Rules indicates they can be made subject to localisation for categories of data the Central Government notifies.
- Your customer's contract says so. Enterprise buyers and government tenders frequently require in-country processing regardless of what the statute permits. That is a commercial requirement, and it is just as binding as a legal one.
What to do instead of panic-migrating
The government can publish a restricted list at any time, and sectoral rules change. The sensible posture is not to pre-emptively move everything onshore — it is to know where your data sits and to be able to move it without a rebuild.
- Write down, per system, which country the data is processed and backed up in. Most teams cannot produce this today.
- Ask each vendor whether region is configurable, and what changing it would cost in time and downtime.
- Get the sub-processor list, and the notification terms for when it changes. A vendor in an allowed country with a sub-processor in a restricted one is still your exposure.
- If you are regulated, start from the regulator's rule and treat DPDP as the floor rather than the ceiling.
We are headquartered in Jaipur, and we will tell you plainly where your data would sit and what we can constrain — ask us as part of the eight vendor questions, and see what we ship today on our security and compliance page.
Where this comes from
Section 16 is quoted from the published text of the DPDP Act, 2023 and Rule 15 from the published text of the DPDP Rules, 2025. Checked 8 August 2026.
The absence of a restricted-country notification is a point-in-time fact and the thing most likely to change after publication. Verify the current position before you make an architecture decision on the back of it — against the Gazette and your counsel, not against a vendor's blog.
