Localization & Transfer of Personal Data under the Digital Personal Data Protection Act, 2023

 Businesses today operate in an increasingly interconnected digital ecosystem, where the storage, processing and movement of personal data routinely transcend national borders. As a result, personal data may be processed in multiple jurisdictions either through cloud infrastructure, outsourced service providers or global customer operations. While such arrangements offer significant commercial and operational benefits to an entity, they also raise important questions regarding accountability and the protection of personal data once it leaves a country's borders.



The Digital Personal Data Protection Act, 2023 (‘DPDP Act/Act’) and its corresponding rules (set to become fully operational by May 2027) establish the principal framework governing the processing of digital personal data in India.  Amongst other things, the DPDP framework aims to regulate the transfer and processing of personal data outside India. Consequently, organizations that store, process, or transfer personal data across jurisdictions must carefully assess their data flows, vendor frameworks and infrastructure arrangements to ensure compliance with the evolving regulatory landscape.

Applicability of the DPDP Act and Key Concepts thereunder

The DPDP Act defines ‘personal data’ as ‘any data about an individual who is identifiable by or in relation to such data.’  The Act applies to the processing of digital personal data within India and, in certain circumstances, to processing undertaken outside India where such processing relates to the offering of goods or services to individuals in India. 

Pertinently, primary obligations under the Act are largely imposed on entities that determine the purpose and means of processing personal data (referred to as Data Fiduciaries). In contrast, entities that process personal data on behalf of and in accordance with its instructions of a Data Fiduciary are classified as Data Processors. The latter typically processes personal data pursuant to contractual arrangements and in accordance with the instructions of the relevant Data Fiduciary. Further, the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary (‘SDFs’) based on an assessment of relevant factors, including the volume and sensitivity of personal data processed, the risk posed to the rights of individuals who’s data is being processed (referred to as ‘Data Principals’ under the Act), the potential impact on the sovereignty, integrity, security of India and in the interest of public order.

Cross Border Transfer of Personal Data Under the DPDP Act

The DPDP framework adopts a permissive approach towards cross-border transfers of personal data and accordingly, permits the transfer of personal data outside India, except to such countries or territories that may be specifically restricted by notification of the Central Government. Accordingly, the Act adopts a "negative-list" approach, whereby transfers are permitted unless expressly prohibited. While the list of restricted jurisdictions is yet to be notified, organizations should remain cognizant of the possibility that the Government may impose restrictions on transfers to specific countries based on security, or other strategic considerations. Importantly, it must be noted that the DPDP Act does not override sector-specific laws and regulations which might prescribe a higher degree of protection or impose additional restrictions on the transfer or storage of data. For instance, as per the directions of the Reserve Bank of India, all payment related data must be stored in systems located in India with limited processing permitted overseas. Similarly, the Insurance Regulatory and Development Authority of India (‘IRDAI’) regulations require insurer to maintain record of policies (issued) and claims (made) in data centers located in India.

Further, until the DPDP framework becomes fully operational, transfers of sensitive personal data continues to be governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (‘SPDI Rules’). Under this framework, sensitive personal data may only be transferred where the recipient maintains the same level of data protection provided under the SPDI Rules and if the transfer is either necessary for the performance of a lawful contract or undertaken with the consent of the concerned individual.

Additional Localization Obligations for Significant Data Fiduciaries

While the DPDP Act generally permits cross-border transfers, certain additional obligations may apply to entities designated as SDFs. Specifically, the DPDP rules require SDFs to implement measures ensuring that certain categories of personal data (as may be specified by the Central Government) are processed subject to the condition that such personal data (and associated traffic data) are not transferred outside the territory of India. Accordingly, organizations which may qualify as SDFs should closely monitor future notifications issued under the DPDP framework in this regard.

Exceptions to Cross-Border Transfer Restrictions

Under the DPDP Act, certain categories of processing are exempted from the restrictions relating to cross-border transfer of personal data. Most notably, the DPDP framework excludes processing undertaken in India pursuant to a contract with a person located outside India, where such processing relates to personal data of individuals situated outside India. This exemption is particularly significant for technology companies and outsourcing service providers who routinely process personal data on behalf of overseas clients. In addition, the Act provides exemptions for specific processing activities such as the enforcement of legal rights, claims, judicial and regulatory functions, investigation of offences, certain corporate restructuring transactions, and specified debt recovery activities.

Next Steps and Recommended Action

Considering that the DPDP Act and its corresponding rules are set to become operational in the near future, it is pertinent that entities identify and document the categories of personal data processed by them, the jurisdictions in which such data is stored and/or accessed, and the third parties with whom such data is shared. This will enable organizations to assess whether any cross-border transfers are taking place and the legal basis for such transfers. Further, organizations operating in regulated sectors must evaluate whether any sectoral regulations impose additional localization or transfer restrictions beyond those prescribed under the DPDP framework. Additionally, contracts with service providers, and Data Processors should clearly allocate and drive down responsibilities relating to data protection, requisite security measures, breach reporting, and cross-border transfers of personal data.

Comments

Popular posts from this blog

Why Governing Law Is Critical For Commercial Agreements

Compliance Requirements for Corporates Under the POSH Act: Key Policies and Regulations

India's Push for Self-Reliance in Defence: What It Means for Businesses and Partners