Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

DPDP section 16 and its EU counterpart

Transfer of personal data outside India under section 16 of the DPDP Act: transfers are permitted by default and the Central Government may restrict named territories by notification, with sectoral rules such as the Reserve Bank of India payment data directions applying on top.

Register facts

Full name
Digital Personal Data Protection Act, 2023, section 16 on transfer of personal data outside India
Short name
DPDP section 16
Publisher
Ministry of Electronics and Information Technology
Adopted
2023-08-11
In force
2023-08-11
Status
Phased application
Read date
2026-08-26

What the EU requires beyond this

The two regimes run in opposite directions. DPDP section 16 allows outbound transfer unless a country is placed on a negative list, while GDPR Chapter V prohibits transfer unless a positive ground exists: an adequacy decision under Article 45, appropriate safeguards under Article 46 such as the Standard Contractual Clauses or binding corporate rules under Article 47, or a narrow derogation under Article 49. India holds no adequacy decision, and Article 48 means an Indian authority's order is not by itself a lawful basis for an EU controller to disclose.

What the gap means in practice

An Indian entity that is compliant on the DPDP side still has no basis for receiving EU data. The inbound leg needs the Commission's clauses, a transfer impact assessment naming the government access powers under section 69 of the IT Act and the Telecommunications Act, and documented supplementary measures. In practice EU counterparties ask for that assessment during procurement, so it is a sales document as much as a compliance one.

Official text

EU counterpart

Continue

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift