The negative-list model
The DPDP Act permits transfer of personal data outside India by default, except to countries or territories the government restricts. This negative-list approach is more permissive than a whitelist, but it places the onus on organisations to know where their data goes and to stop flows to restricted destinations.
Why AI changes the risk
The fastest-growing cross-border channel is not a database export — it is personal data placed inside a prompt to a foreign large-language-model API. These flows are often invisible to compliance teams because they originate deep inside an application.
Praman classifies every egress flow by destination country and controller, and raises a prominent verdict when personal data heads to a foreign model API, so the risk surfaces before it becomes a violation.
- ▹Maintain a negative list of restricted jurisdictions
- ▹Classify every egress flow by country and controller
- ▹Treat personal data in foreign LLM prompts as a transfer