Guides/7 min read

Cross-border data transfer under the DPDP Act

India uses a negative-list model for transfers abroad. Here is how it works, why foreign model APIs are the new risk, and how to stay on the right side of it.

Updated 22 June 2026

The negative-list model

The DPDP Act permits transfer of personal data outside India by default, except to countries or territories the government restricts. This negative-list approach is more permissive than a whitelist, but it places the onus on organisations to know where their data goes and to stop flows to restricted destinations.

Why AI changes the risk

The fastest-growing cross-border channel is not a database export — it is personal data placed inside a prompt to a foreign large-language-model API. These flows are often invisible to compliance teams because they originate deep inside an application.

Praman classifies every egress flow by destination country and controller, and raises a prominent verdict when personal data heads to a foreign model API, so the risk surfaces before it becomes a violation.

  • ▹Maintain a negative list of restricted jurisdictions
  • ▹Classify every egress flow by country and controller
  • ▹Treat personal data in foreign LLM prompts as a transfer

FAQ

Is data transfer abroad banned under DPDP?

No. Transfers are allowed by default under a negative-list model, except to jurisdictions the government restricts, or where a sector or category requires localisation.

Is sending PII to a foreign LLM a cross-border transfer?

In substance, yes — personal data leaving India to a foreign-controlled endpoint is a transfer. Praman flags these explicitly as the headline AI risk.

Turn this obligation into a live check.

Praman evaluates it against your real systems and proves the result.

Request a demo

This guide is general information, not legal advice. Verify obligations with qualified counsel.