Alastor InfoSec
← Back to Blog
Compliance

July 21, 2026 · Alastor InfoSec Team

DPDPA Data Localisation and Cross-Border Transfer Rules 2026: What Indian Businesses Must Know

India's Digital Personal Data Protection Act (DPDPA) is now in active implementation, with the Data Protection Board operational and enforcement deadlines bearing down fast. Most Indian businesses have focused their compliance energy on the headline obligations — consent management, breach notification, and data principal rights. But one area that is still dangerously under-prepared is cross-border data transfer and data localisation. This post covers exactly what those rules require, which businesses are affected, and what you need to do before the November 2026 enforcement window closes.

What the DPDPA Says About Cross-Border Transfers

Under Section 16 of the Digital Personal Data Protection Act, 2023, a Data Fiduciary may transfer personal data outside India only to countries or territories that have been notified by the Central Government as permissible destinations. This is a positive-list model — you need explicit government approval for a destination jurisdiction, not just the absence of a prohibition.

The list of permissible transfer destinations has not yet been fully finalised as of July 2026. The DPDP Rules notified in November 2025 set out the framework, but the Ministry of Electronics and Information Technology (MeitY) continues to consult on the specifics. This creates a real compliance gap: organisations that have been transferring data to third-party SaaS providers, cloud infrastructure in the US, Europe, or Southeast Asia cannot simply assume that will remain permissible once enforcement begins.

The practical implication is significant. If your organisation uses AWS (US-East), Azure (Europe), or any SaaS tool that stores data outside India, you need to assess whether those transfers will be covered under the permitted destinations list before November 2026.

Significant Data Fiduciaries Face Stricter Rules

The DPDPA creates a two-tier structure. Standard Data Fiduciaries must meet the general transfer requirements above. But organisations designated as Significant Data Fiduciaries (SDFs) face additional obligations, potentially including requirements to store a copy of certain categories of personal data on servers located within India — a true localisation requirement, not just a transfer restriction.

The government has not yet published the final SDF designation list, but the criteria in the rules point toward organisations processing data of large volumes of data principals, processing sensitive personal data, or operating in sectors of national importance. Fintech companies, large e-commerce platforms, healthcare providers, and EdTech firms processing data at scale should assume they may receive SDF designation and plan accordingly.

How DPDPA Data Rules Interact with CERT-In Requirements

CERT-In's 2022 Directions, which remain fully binding in 2026, already impose data localisation obligations of their own: all ICT system logs must be maintained for 180 days within India, and organisations using VPN services, cloud infrastructure, or managed security providers must ensure those logs remain on Indian soil. CERT-In also mandates NTP synchronisation with NIC or NPL servers traceable to Indian time sources.

The intersection creates a layered compliance obligation. Organisations that have sent logs to SIEM platforms hosted abroad — whether to Splunk Cloud (US), Microsoft Sentinel (Europe), or any other offshore instance — need to reassess their architecture. CERT-In's 6-hour incident reporting mandate means those logs also need to be accessible immediately when a breach occurs, making offshore storage operationally risky as well as potentially non-compliant.

What Contracts With Third Parties Must Now Include

The DPDP Rules require Data Fiduciaries to enter into contracts with their Data Processors that impose the same data protection obligations that apply to the Fiduciary itself. For cross-border data flows, this means your agreements with cloud providers, SaaS vendors, and offshore development teams must now include provisions that:

  • Restrict further transfer of personal data without prior consent from the Data Fiduciary
  • Require the processor to implement security safeguards equivalent to those mandated under the DPDP Rules
  • Allow audits, inspections, and provide records sufficient to demonstrate compliance
  • Mandate prompt notification of any breach or security incident to the Data Fiduciary

This is a significant contract remediation exercise for most organisations. A company with dozens of SaaS tools and cloud vendors will likely need to renegotiate data processing agreements or obtain DPA addenda that cover DPDPA obligations explicitly.

The Enforcement Reality: Penalties Up to INR 2.5 Billion

The Data Protection Board of India (DPBI) becomes fully operational for enforcement from November 2026. The penalty structure in the DPDP Act is graduated:

Failure to take reasonable security safeguards: up to INR 2.5 billion (approximately USD 26 million). Failure to notify breaches: up to INR 200 million. Non-compliance with the rights of data principals: up to INR 100 million. Breach of obligations regarding children's data: up to INR 2 billion.

For cross-border transfer violations specifically, the board has discretion to assess the severity, duration, and type of data involved. Nation-state and regulatory investigations have shown that enforcement authorities worldwide treat unlawful cross-border data transfers as high-severity violations, particularly where sensitive personal data is involved.

The Three Steps Every Indian Business Must Take Now

The first step is data mapping — knowing exactly what personal data you hold, where it is stored (which country, which infrastructure), and which vendors and processors touch it. Without this, you cannot assess transfer exposure. Most organisations that have not started this exercise will find it takes eight to twelve weeks to complete comprehensively.

The second step is vendor assessment. For every third-party service that touches personal data, you need to determine: is the data processed within India or outside India? Is the destination jurisdiction on MeitY's permissible list? Do your contracts meet the contractual requirements for processors under the DPDP Rules?

The third step is implementing a data residency architecture where required. For organisations that cannot or do not wish to wait for MeitY's permissible destinations list, the safest path is to ensure personal data of Indian data principals is processed and stored within India. This may mean switching cloud regions, deploying Indian data centres, or negotiating region-locked contracts with SaaS vendors.

How Alastor Shield Helps

Alastor Shield was built for exactly this compliance environment. Our platform maps your personal data flows against DPDPA obligations, automatically flags processing activities that may involve non-permissible cross-border transfers, and generates the evidence you need to demonstrate compliance to auditors or the Data Protection Board. We track the evolving MeitY permissible destinations list and notify you when your transfer arrangements require remediation.

Beyond data mapping, Alastor Shield generates the contractual templates, DPA addenda, and vendor risk questionnaires you need to bring your processor relationships into DPDPA compliance. Combined with Enforster AI's dark web and data leak monitoring, we give you continuous visibility into whether your data is already exposed — because the DPBI will ask.

For a DPDPA compliance readiness assessment or to start your data flow mapping exercise, contact us at support@alastorinfosec.com or visit Alastor Shield.

With enforcement beginning November 2026 and 83% of Indian organisations still not compliant, cross-border transfer compliance is one of the last major gaps that can still be closed before penalties begin — but only if the data mapping and vendor remediation work starts now.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.