Triad ICS
Menu

Insights/Regulatory Newsroom

Cross-Border Data Transfers Under DPDP: What Indian B2B SaaS Must Know

Published

Reading time2 minutes

FromTriad ICS Research

The DPDP Act permits transfers by default, with important exceptions. Sector rules may still keep your data at home.

Indian B2B SaaS companies routinely move personal data across borders: hosting in a foreign cloud region, support tools in the US, analytics in Europe. The DPDP Act 2023 takes a relatively open approach to these transfers, but “open” does not mean “unregulated”.

The general rule: transfers allowed unless restricted

Section 16 of the Act allows the Central Government to restrict transfers of personal data to countries or territories it notifies. Until a country is notified, transfers are permitted. This is often described as a negative-list approach, and it is lighter than the adequacy model used in Europe.

Conditions in the Rules

The DPDP Rules 2025 add that transfers outside India are subject to requirements the Central Government may specify, by general or special order, including about making data available to foreign states or their agencies. Watch for these orders; they can change your obligations without a new law.

Significant Data Fiduciaries face more

If you are notified as a Significant Data Fiduciary, the Rules allow the Government, based on a committee’s recommendations, to require that specified personal data, and traffic data about its flow, is not transferred outside India.

Sector rules still apply

Section 16(2) preserves any other Indian law that provides a higher degree of protection or restriction. For SaaS vendors this matters because your customers’ regulators may be stricter than the DPDP Act:

  • Payment system data under RBI’s 2018 storage directive must be stored only in India.
  • Banks, NBFCs, insurers and securities market entities have their own outsourcing and data expectations from RBI, IRDAI and SEBI.
  • Government and public sector customers often require hosting in India as a contract condition.

What to do now

  • Map your data flows: every sub-processor, the country it processes in, and which personal data it touches.
  • Keep an India-hosted option for core customer data, even if some tooling sits abroad.
  • Update data processing agreements to cover security safeguards, breach notification to you, and deletion on termination.
  • Maintain a transfer register so you can respond quickly if a country is notified.
  • Tell customers clearly where their data lives. Regulated buyers will ask, and a precise answer shortens procurement.

The bottom line

For most Indian B2B SaaS companies, cross-border transfers remain possible under DPDP. The risk is in not knowing where your data goes, and in forgetting that your customers’ sector rules become your rules the moment you sign their contract.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action