What are the rules for storing and transferring personal data outside India?

My company uses a foreign cloud provider to store customer data and I want to know what the law requires for cross-border data transfer. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

What are the rules for storing and transferring personal data outside India? is governed in India primarily by Digital Personal Data Protection Act 2023, Section 16, Information Technology Act 2000, Section 43A, RBI Storage of Payment System Data Directions 2018 and CERT-In Directions 2022, Direction 4. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Section 16 of the Digital Personal Data Protection Act 2023 permits transfer of personal data outside India except to countries specifically restricted by the Central Government through notification.

Unlike the earlier draft law, the current framework does not mandate blanket data localisation, but sector-specific regulators can impose their own storage requirements.

Payment system data must be stored only in India under the RBI's Storage of Payment System Data Directions 2018, requiring full transaction data to be maintained within Indian systems even if a foreign processor is involved.

A body corporate handling sensitive personal data through a foreign cloud provider remains liable for negligent security practices under Section 43A of the Information Technology Act 2000 regardless of where the servers are located.

Direction 4 of the CERT-In Directions 2022 requires service providers to maintain logs of their ICT systems for one hundred and eighty days within India to assist in incident investigation.

What to do next: 1) Check whether the destination country is on any restricted list notified under the DPDP Act; 2) Verify sector-specific localisation requirements applicable to your business, such as RBI's for payment data; 3) Ensure the cloud contract includes data protection and audit clauses consistent with Indian law; 4) Maintain mandated logs within India as required under the CERT-In Directions.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Digital Personal Data Protection Act 2023, Section 16 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.