If you are choosing between a Mumbai data centre and a Singapore one, the DPDP framework probably matters less to that decision than you would expect, but not zero. Here is what the Act and Rules actually require when personal data crosses a border, and what they deliberately leave open for businesses operating across jurisdictions.
The negative list approach
Section 16 of the Act gives the Central Government the power to restrict transfer of personal data to specific countries by notification. Everywhere else, transfer is permitted by default. This is the inverse of the EU's adequacy-list model, which prohibits transfer unless a destination is pre-approved. That mandatory localisation requirement proposed in earlier draft bills was dropped before the final Act, in favour of this much more liberal negative-list approach.
Sectoral overrides still apply
Open by default under DPDP does not mean unregulated. Sectoral localisation rules sit on top of DPDP and are explicitly preserved by Section 16(2).
- The RBI's payment-data localisation requirement continues to apply at full strength.
- SEBI's data-residency rules for regulated entities remain entirely unaffected.
- No restricted-country list has been notified under Section 16 as of writing, so transfer is open to every destination by default for now.
Contractual safeguards and liability
Rule 15 operationalises Section 16, but it does not introduce Standard Contractual Clauses the way GDPR does. However, Section 8 keeps a Data Fiduciary responsible for what its Data Processor does with personal data, including a processor sitting overseas. Many organisations are layering contractual safeguards in anyway for vendor accountability. You must map where personal data physically sits, get data-processing terms with every overseas vendor that name the DPDP Act, and watch for Section 16 restricted-country notifications that could take effect on the date of publication with little lead time.