{"id":20746,"date":"2026-09-13T16:40:42","date_gmt":"2026-09-13T11:10:42","guid":{"rendered":"https:\/\/lawjurist.com\/?p=20746"},"modified":"2026-09-13T16:47:10","modified_gmt":"2026-09-13T11:17:10","slug":"indias-new-cross-border-data-regime-why-commercial-contracts-must-be-drafted-for-2027","status":"publish","type":"post","link":"https:\/\/lawjurist.com\/index.php\/2026\/09\/13\/indias-new-cross-border-data-regime-why-commercial-contracts-must-be-drafted-for-2027\/","title":{"rendered":"India&#8217;s New Cross-Border Data Regime: Why Commercial Contracts Must Be Drafted for 2027"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"20746\" class=\"elementor elementor-20746\">\n\t\t\t\t<div class=\"elementor-element elementor-element-311594b1 e-flex e-con-boxed e-con e-parent\" data-id=\"311594b1\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4c213633 elementor-widget elementor-widget-text-editor\" data-id=\"4c213633\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<p>Author: Komalpreet Kaur, an Advocate in independent practice, enrolled with the Punjab &amp; Haryana Bar Council, based in Jalandhar, Punjab<\/p>\n\n\n\n<p><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-29f4d96 e-flex e-con-boxed e-con e-parent\" data-id=\"29f4d96\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-609eff4 elementor-widget elementor-widget-text-editor\" data-id=\"609eff4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Introduction<\/strong><\/p>\n<p>Every commercial contract that touches customer data, employee records or vendor information is approaching a regulatory transition that will fundamentally alter how Indian businesses think about cross-border data flows. The Digital Personal Data Protection Act, 2023 (&#8220;DPDP Act&#8221;) introduces a framework under which personal data may be processed outside India, while permitting the Central Government to restrict transfers to specified countries or territories. The Digital Personal Data Protection Rules, 2025 (&#8220;DPDP Rules&#8221;), notified on 13 November 2025, provide the implementation framework for this regime.<\/p>\n<p>The transition is particularly important for commercial contracts because the substantive provisions governing data fiduciaries, including Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, are scheduled to come into force eighteen months after notification. The commencement notification therefore places the relevant provisions in the post-May 2027 compliance landscape rather than making them immediately operative.<\/p>\n<p>Until the relevant provisions of the DPDP framework commence, organisations must continue to examine the legal requirements applicable to their existing data flows, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (&#8220;SPDI Rules&#8221;), wherever those Rules remain applicable.<\/p>\n<p>This creates an unusual drafting position. Lawyers preparing commercial agreements today are not merely addressing the law that applies on the date of execution. They are also drafting contracts that may remain in force when the DPDP framework becomes operational. The practical question is therefore not simply whether a transfer is lawful today, but whether the contractual architecture can accommodate the regulatory position that will apply tomorrow.<\/p>\n<p>This article examines that transition from the perspective of commercial contract drafting. It considers the current framework, the incoming DPDP architecture, the risks hidden behind a seemingly permissive cross-border regime, and the contractual provisions that can help businesses prepare for the transition without repeatedly renegotiating their agreements.<\/p>\n<p><strong>The Current Legal Reality: The SPDI Rules, 2011<\/strong><\/p>\n<p>Practitioners drafting contracts today should distinguish carefully between the current regime and the future DPDP framework.<\/p>\n<p>The SPDI Rules operate on a narrower conception of sensitive information. They apply to specified categories of &#8220;sensitive personal data or information&#8221;, including passwords, financial information, health information and other prescribed categories. Consequently, their transfer framework does not operate in precisely the same way as the broader personal-data framework contemplated by the DPDP Act.<\/p>\n<p>The present regime also places importance on consent, contractual necessity and equivalent protection by the recipient. Where sensitive personal data is transferred, the recipient is expected to provide the same level of data protection as required under the SPDI Rules.<\/p>\n<p>For contract drafters, this means that existing data-processing and vendor agreements cannot simply be treated as though the DPDP Act is already fully operational. A clause drafted on the assumption that Section 16 currently governs every cross-border transfer risks confusing the law presently in force with the law scheduled to take effect.<\/p>\n<p>The transition therefore requires a two-stage approach: compliance with the law currently applicable, combined with contractual preparation for the DPDP framework.<\/p>\n<p><strong>The Incoming Regime: Section 16 and Rule 15<\/strong><\/p>\n<p>The architecture of the DPDP Act is materially different from the traditional adequacy-based approach associated with the European Union&#8217;s General Data Protection Regulation (&#8220;GDPR&#8221;).<\/p>\n<p>Section 16(1) of the DPDP Act does not establish a general prohibition on transferring personal data outside India. Instead, it empowers the Central Government to restrict the transfer of personal data by a Data Fiduciary for processing to a country or territory outside India. Section 16(2) further preserves the operation of Indian laws that impose a higher degree of protection or greater restrictions on transfers.<\/p>\n<p>Rule 15 of the final DPDP Rules follows this architecture. It provides that personal data processed by a Data Fiduciary under the Act may be transferred outside India, subject to requirements that the Central Government may specify concerning the making available of such personal data to a foreign State, or to persons or entities under the control of, or acting as agencies of, such a State.<\/p>\n<p>This is important for commercial drafting. The DPDP framework does not simply reproduce the GDPR&#8217;s standard contractual mechanism for international transfers. Nor does Section 16 itself prescribe a universal requirement for Standard Contractual Clauses (&#8220;SCCs&#8221;) or Binding Corporate Rules (&#8220;BCRs&#8221;).<\/p>\n<p>However, the absence of a blanket SCC requirement should not be mistaken for the absence of contractual risk.<\/p>\n<p>First, the Government may impose restrictions on transfers through notification. Secondly, Section 16 expressly preserves stricter sectoral or other Indian legal requirements. Thirdly, the Data Fiduciary remains responsible for compliance with its obligations even where processing is carried out through an overseas Data Processor.<\/p>\n<p>The result is a regime that may permit international data flows by default while simultaneously requiring organisations to maintain sufficient contractual flexibility to respond when the regulatory position changes.<\/p>\n<p><strong>The Compliance Trap Behind a &#8220;Permissive&#8221; Regime<\/strong><\/p>\n<p>For contract drafters, the apparent simplicity of the DPDP cross-border framework creates several risks.<\/p>\n<p><strong>First,<\/strong> permission to transfer is not permission to process.** A lawful cross-border transfer does not independently establish that the underlying processing is lawful. The Data Fiduciary must still comply with the substantive obligations of the DPDP Act, including requirements relating to lawful processing, notice, consent where applicable, security safeguards and Data Principal rights. The Rules require notices to be clear and understandable and to provide specified information about the personal data being processed and the purposes of processing.<\/p>\n<p>A contract that focuses exclusively on the physical movement of data therefore addresses only one part of the compliance problem. The commercial agreement should also identify the purposes for which the overseas processor may process the data, prevent unrelated secondary use and require cooperation with the Indian Data Fiduciary&#8217;s statutory obligations.<\/p>\n<p><strong>Second:<\/strong> The regulatory position may change. Section 16 creates a mechanism through which the Central Government can restrict transfers to specified countries or territories. A jurisdiction that is acceptable when a contract is signed may therefore become subject to restrictions later. A contract drafted around a static list of permitted destinations can quickly become obsolete. This is why cross-border agreements should contain mechanisms for changing hosting locations, redirecting data flows and approving replacement sub-processors.<\/p>\n<p><strong>Third:\u00a0<\/strong> Sectoral law may impose stricter requirements. Section 16(2) expressly preserves other Indian laws that provide a higher degree of protection or impose greater restrictions on transfers. Accordingly, a contract may comply with the general DPDP framework and still fail to satisfy a sector-specific localisation requirement. This is particularly important in highly regulated sectors such as banking, payments and insurance, where separate regulatory requirements may govern the storage or transfer of particular categories of information.<\/p>\n<p><strong>Fourth,<\/strong> &#8220;no blanket mandate&#8221; does not mean &#8220;no safeguard.&#8221; The fact that the DPDP Act does not universally prescribe GDPR-style SCCs or BCRs does not make contractual safeguards unnecessary. Businesses may still use detailed data-processing provisions, audit rights, security commitments, sub-processing controls, deletion obligations and liability provisions to allocate commercial risk. The key is to draft these provisions because they solve identifiable operational and legal problems, rather than mechanically importing every GDPR requirement into an Indian agreement.<\/p>\n<p><strong>What the Contract Should Say<\/strong><\/p>\n<p>The most important work during the transition will occur at the contract level. Whether the overseas recipient is a processor, sub-processor or intra-group entity, a well-drafted agreement should address at least the following.<\/p>\n<p><strong>1. Data-processing terms.<\/strong><\/p>\n<p>The agreement should identify the categories of personal data involved, the permitted processing activities and the purposes for which the data may be used. Generic language allowing a processor to process information &#8220;as reasonably required&#8221; can create unnecessary uncertainty. Purpose limitation should be reflected directly in the contractual language.<\/p>\n<p><strong>2. Security standards.<\/strong><\/p>\n<p>The contract should establish minimum security requirements covering encryption, access controls, logging, monitoring, incident response and business continuity. The final DPDP Rules expressly contemplate contractual provisions between a Data Fiduciary and Data Processor concerning reasonable security safeguards. Drafting to an appropriate future-facing security standard reduces the need for immediate renegotiation when the DPDP framework becomes operational.<\/p>\n<p><strong>3. Data Principal rights.<\/strong><\/p>\n<p>The overseas processor should be required to assist the Indian Data Fiduciary in responding to requests relating to Data Principal rights. The processor may not be directly responsible for answering the individual in every situation, but it controls the infrastructure in which the relevant information is held. The contract should therefore establish clear procedures for locating, correcting, exporting or deleting information when required.<\/p>\n<p><strong>4. Breach notification<\/strong>.<\/p>\n<p>Contractual breach notification should be significantly faster than the outer regulatory reporting period applicable to the Data Fiduciary. The final DPDP Rules require notification to the Board without delay, followed by detailed information within seventy-two hours of becoming aware of the breach, unless the Board allows a longer period. An overseas processor that waits for its domestic law deadline may therefore create a compliance gap for the Indian Data Fiduciary. The contract should require immediate notification and rapid cooperation.<\/p>\n<p><strong>5. Sub-processing restrictions.<\/strong><\/p>\n<p>The agreement should regulate the appointment of sub-processors and identify the jurisdictions in which they may operate. A processor should not be able to move Indian personal data to a new country simply because its commercial cloud architecture changes. Advance notification, approval or objection mechanisms can give the Indian contracting party visibility over the data chain.<\/p>\n<p><strong>6. Localisation fallback and rerouting.<\/strong><\/p>\n<p>Contracts should anticipate the possibility that a particular country or hosting location becomes restricted. A practical clause can require the processor to migrate data to an alternative permitted jurisdiction within a defined period, with appropriate assistance and without unreasonable additional cost. This converts a future regulatory change from an immediate contractual crisis into an operational contingency.<\/p>\n<p><strong>7. Termination and data retrieval.<\/strong><\/p>\n<p>Termination provisions should address more than confidentiality. The Indian Data Fiduciary should have a defined right to retrieve its data and require deletion of remaining copies, subject to legally required retention. The contract should also specify how deletion is verified and what happens to backups.<\/p>\n<p><strong>8. Audit and compliance rights. <\/strong><\/p>\n<p>Appropriate audit and information rights can help the Data Fiduciary demonstrate oversight of its processors. This is particularly relevant to Significant Data Fiduciaries, which face additional obligations under the Rules, including periodic Data Protection Impact Assessments and audits. The final Rules also contemplate restrictions on transferring specified personal data and associated traffic data outside India where the Central Government identifies such data for that purpose.<\/p>\n<p><strong>9. Liability allocation.<\/strong><\/p>\n<p>Statutory responsibility cannot simply be transferred to an overseas processor by contract. However, contractual indemnities, liability provisions and insurance requirements can determine who ultimately bears the financial consequences of a processor&#8217;s failure. The contract should therefore clearly allocate responsibility for security incidents, regulatory penalties where legally recoverable, third-party claims, investigation costs and remediation expenses.<\/p>\n<p><strong>Immediate Action During the Transition<\/strong><\/p>\n<p>Organisations do not need to wait until the DPDP provisions commence.<\/p>\n<p>The first step should be data-flow mapping. Businesses should identify where personal data originates, where it is stored, where it is accessed and which cloud providers, SaaS platforms and sub-processors participate in the processing chain.<\/p>\n<p>The second step is vendor-contract auditing. Existing international Data Processing Agreements should be reviewed to determine whether they identify processing locations, regulate sub-processing, provide adequate security commitments and contain workable deletion and exit provisions.<\/p>\n<p>The third step is upgrading privacy and notice workflows. Contractual compliance cannot be separated from the information given to Data Principals. Organisations should ensure that their operational systems can provide the information required by the DPDP framework when the relevant provisions commence.<\/p>\n<p>The fourth step is to create a jurisdiction-and-sector matrix. Cross-border compliance should be assessed not only against the DPDP framework but also against any applicable sectoral requirements. This prevents businesses from treating the general data-protection framework as the entire regulatory landscape.<\/p>\n<p><strong>A Practical Illustration: The Indian Fintech and the US SaaS Provide<\/strong>r<\/p>\n<p>Consider a mid-sized Indian fintech company that engages a US-based SaaS provider to host customer analytics data.<\/p>\n<p>Under the present regime, the fintech must assess the applicable requirements governing the categories of information involved and the manner in which the overseas recipient handles that information.<\/p>\n<p>However, a future-facing agreement should go considerably further.<\/p>\n<p>The contract could contain a data-residency schedule identifying the countries and cloud regions in which the provider may process the data. It could require prior notification before a material change in processing location. It could impose immediate breach notification obligations, require cooperation with Data Principal requests and establish a defined process for migration if a particular jurisdiction becomes restricted.<\/p>\n<p>The agreement should also address sub-processors, deletion, backup retention, audit cooperation and liability.<\/p>\n<p>The important point is that none of these provisions depends upon waiting until the commencement date. They are contractual mechanisms designed to manage foreseeable regulatory and operational risks.<\/p>\n<p>A contract drafted with the transition in mind can therefore reduce the likelihood that hundreds of vendor agreements will need to be reopened simultaneously when the new framework becomes operational.<\/p>\n<p><strong>Recommendations for Commercial Contract Drafters<\/strong><\/p>\n<p>Four practical principles should guide organisations during the transition.<\/p>\n<p><strong>First<\/strong>, build a living data map before drafting the clause. The contract should reflect actual data flows, not an assumed architecture.<\/p>\n<p><strong>Second,<\/strong> draft for the transition rather than a single legal snapshot. Agreements signed today may continue beyond the commencement of the DPDP framework. Their provisions should therefore be capable of operating across the regulatory change.<\/p>\n<p><strong>Third,<\/strong> draft for volatility. Cross-border compliance should not depend on the assumption that the list of permissible destinations will remain unchanged. Rerouting, replacement-provider and termination mechanisms should be built into the agreement from the outset.<\/p>\n<p><strong>Fourth,<\/strong> treat sectoral regulation as a parallel compliance track. A DPDP-compliant contract is not necessarily a fully compliant contract if another Indian law imposes stricter localisation or transfer requirements.<\/p>\n<p><strong>\u00a0Conclusion<\/strong><\/p>\n<p>India&#8217;s emerging cross-border data-transfer framework represents a significant departure from a model based on broad restrictions or mandatory adequacy mechanisms. Section 16 establishes a restriction-based architecture, while Rule 15 permits overseas transfers subject to requirements that may be specified by the Central Government.<\/p>\n<p>Yet regulatory permissiveness does not eliminate the need for careful contractual drafting. The real challenge for commercial lawyers is not simply determining whether data can leave India. It is designing an agreement that continues to function when the legal, technological or contractual circumstances surrounding that transfer change.<\/p>\n<p>The eighteen-month transition period therefore presents an opportunity rather than merely a waiting period. Organisations can map their data flows, audit international vendors, strengthen processing agreements and introduce contractual mechanisms for changing jurisdictions, responding to breaches and retrieving data.<\/p>\n<p>The strongest commercial contracts will consequently not be drafted only for the law as it exists on the date of signature. They will be drafted for the regulatory environment in which the contract is likely to operate.<\/p>\n<p>For Indian businesses transferring personal data across borders, the lesson is straightforward: future-proof the contract before the law forces you to rewrite it.<\/p>\n<p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Author: Komalpreet Kaur, an Advocate in independent practice, enrolled with the Punjab &amp; Haryana Bar Council, based in Jalandhar, Punjab Introduction Every commercial contract that touches customer data, employee records or vendor information is approaching a regulatory transition that will fundamentally alter how Indian businesses think about cross-border data flows. The Digital Personal Data Protection [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5033,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/posts\/20746"}],"collection":[{"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/comments?post=20746"}],"version-history":[{"count":3,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/posts\/20746\/revisions"}],"predecessor-version":[{"id":20749,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/posts\/20746\/revisions\/20749"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/media\/5033"}],"wp:attachment":[{"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/media?parent=20746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/categories?post=20746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawjurist.com\/index.php\/wp-json\/wp\/v2\/tags?post=20746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}