Introduction
An Indian fintech routes its customer support data to a processing centre in a country nobody has thought twice about. Nothing in Indian law stops it right now. Under the DPDP Act, the default position on cross-border data transfer is permission, not restriction, and that single design choice is going to shape how a lot of Indian companies think about data residency for the next year, often incorrectly.
Section 16 of the Act is the whole of India's cross-border transfer regime, and it says less than most privacy professionals expect a transfer provision to say. There is no adequacy test. There is no requirement for standard contractual clauses. There is, as things stand in mid-2026, no restricted country list at all. What there is instead is a government that has reserved the right to name one, whenever it chooses to.
This piece works through what Section 16 actually permits today, why the absence of a restricted list is doing more work in boardroom conversations than it should, where sector-specific rules already limit what the Act itself leaves open, and what a genuinely prepared organization does about a restriction regime that could arrive with no notice period at all.
How Section 16 Actually Works
Section 16(1) states that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to a country or territory outside India. Read that carefully and the structure becomes obvious: transfer is allowed to every destination in the world except the ones the government, specifically names. Lawyers call this a negative list, or a blacklist model, and it is close to the opposite of how the GDPR handles the same question. The European regulation blocks a transfer by default and only permits it once the destination has an adequacy decision or the exporter puts contractual safeguards in place. India starts from permission and only takes it away by exception.
Rule 15 of the DPDP Rules, 2025 gives some shape to how that exception might get used, authorizing the Central Government to issue general or special orders specifying restrictions on data transfers, particularly concerning foreign states or foreign state-controlled entities. None of that is a checklist a company can audit against today, because none of it has been applied to an actual country yet. It reads more like a menu of justifications the government has kept available for whenever it decides to use them.
It would be a mistake to assume this permissive design was inevitable. The 2019 draft bill leaned toward hard data localization, while the 2022 draft proposed a "whitelist" model permitting transfers only to explicitly approved destinations. Parliament dropped that approach in favour of the much simpler notification power (a "blacklist" model) that made it into the final Act, trading precision for flexibility the government can exercise on its own schedule.
Why No List Exists Yet, and Why That Is Different from No Risk
As of mid-2026, that flexibility has not been used. No restricted country list has been issued. Prevailing market observations reflect this status. Several law firms tracking the Act closely have said as much within the last two months and treating that silence as settled policy is where a lot of the current confidence in Indian boardrooms is coming from.
That confidence deserves a second look. The cross-border provisions of the Act sit in the same bucket as most of its substantive compliance obligations, which only take legal effect eigtheen months after the Rules were notified, on May 13, 2027. A restricted list issued before that date would still be a valid exercise of the government's notification power under Section 16. Because Section 16 does not explicitly mandate a statutory transition window, any sudden executive notification presents a major operational risk for unmapped data flows, as companies could be forced to adapt on short notice. An organization that has built a data flow around a jurisdiction the government later restricts does not get advance warning to unwind it.
Where Sector-Specific Rules Already Fill the Gap
None of this happens in a vacuum, either. Two other legal frameworks already sit alongside Section 16 and constrain what companies can do, regardless of how permissive the Act itself is.
The Reserve Bank's DPDP ActDPDP Act by five years and was never written with it in mind, but it still binds every payment company operating in India today. Where RBI's rule is stricter than what Section 16 permits, RBI's rule wins. A fintech that reads Section 16 as its ceiling on cross-border payment data is reading the wrong provision.
Section 17(2)(a) adds a different kind of complication. It exempts certain government agencies from most of the Act's compliance obligations, including Section 16, when they are processing personal data for national security or for maintaining friendly relations with foreign states. That carve-out was not built with private-sector data flows in mind, but it signals how the government is likely to think about cross-border transfer once it does start restricting countries: as a national security and foreign policy lever first, and a pure privacy tool second.
There is a broader pattern worth naming here too. India's approach to data sovereignty has always been more fragmented than commentators give it credit for, a patchwork of sector-specific localization rules built up over almost a decade, layered under a single overarching privacy statute that arrived much later and chose not to override any of them. Section 16 was never meant to be the last word on where Indian data can go. It was meant to be the general rule that sits underneath whatever a sector regulator has already decided, which is precisely why reading it in isolation gives an incomplete, and occasionally wrong, answer.
The Open Question Nobody Has Answered Yet
There is a genuine open unresolved legal interaction sitting underneath all of this that nobody in government or industry has resolved yet. India already has mutual legal assistance treaties and other bilateral arrangements that govern how personal data moves for law enforcement and investigative purposes. How a future Section 16 restriction would interact with an existing treaty commitment, whether the restriction power can override it or has to work around it, is untested in practice because no restriction has been issued yet.
The Readiness Gap: What Most Organizations Are Missing
Most privacy and legal teams at Indian companies are aware, in the abstract, that Section 16 exists. Far fewer have mapped what would happen to their own data flows the day a restriction is issued, and the shortfall shows up in a few predictable places.
Data flow maps that stop at the first hop
Most organizations can point to where their primary cloud provider stores data. Considerably fewer can trace where that data goes next, if a sub-processor, an analytics vendor, or a support tool routes it somewhere else entirely. A restriction on a country three hops downstream is just as much a compliance problem as one on the primary vendor, and most companies would not know they had exposure there until it was already a violation.
Vendor contracts written for a permanent status quo
Very few data processing agreements signed in the last year include a clause addressing what happens if the destination country a vendor operates from gets added to a future restricted list. That is a one-paragraph addition most companies have simply not thought to ask for yet.
Sectoral rules treated as a footnote, not a parallel regime
Teams building their cross-border compliance program around Section 16 alone risk missing RBI, sectoral telecom, or insurance localization requirements that already apply regardless of what the DPDP Act permits.
Nobody owns the watch
Monitoring for a restricted-country notification is not currently anyone's explicit job at most organizations, which means the notification, when it comes, is more likely to be noticed by a vendor's legal team than by the company actually exposed to it.
Way Forward
A few things worth doing now, while the list is still empty rather than after it is not:
- Map data flows past the first vendor, not just to it, so that a restriction on a country several hops downstream would be visible.
- Build a standard clause into new and renewed vendor contracts addressing what happens operationally if the vendor's processing location is later restricted.
- Separate the sectoral localization obligations, RBI, telecom, insurance, from the general DPDP cross-border analysis, since the stricter rule applies regardless of what Section 16 allows.
- Assign a specific person or team to track Ministry of Electronics and Information Technology notifications under Section 16, the same way breach and consent-related notifications are already being tracked.
- Build a contingency plan, even a rough one, for unwinding a data flow to a specific country within days rather than months, since the Act gives no transition period once a notification is published.
- Brief business teams that are choosing new vendors or cloud regions on the fact that today's permissive default is a policy choice, not a permanent guarantee.
Conclusion
The absence of a restricted country list is not the same thing as an absence of risk. It is closer to an unused power sitting in the government's hands, one that can be exercised with a single notification and no warning period attached. Section 16 gives Indian businesses more room than the GDPR ever did. What it does not give them is the certainty that the room stays the same shape indefinitely.
The organizations in the best position when a restriction eventually lands will not be the ones that read Section 16 once and moved on. They will be the ones that treated the current silence as exactly what it is, a government that has not yet decided to use a power it has always had and built their data flows with that in mind from the start.
We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.
We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).
For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.
For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025
We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025
We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus