INDIA Law and Practice Contributed by: Raj Ramachandran, Kartik Jain, Mannat Nirola and Anmol Mahajan, JSA Advocates & Solicitors
8.2 Geographical Scope Extraterritorial Application
Principal’s consent or for specified legitimate uses, including compliance with law, employment-related purposes, public health emergencies, certain govern - mental functions, etc. Data Fiduciaries are required to implement reasonable security safeguards, establish grievance redressal mechanisms, ensure that personal data is processed only for the purpose for which con - sent has been obtained, facilitate the exercise of Data Principal rights and notify personal data breaches to the Data Protection Board of India (DPBI) and affected Data Principals in the prescribed manner. The DPDP Act also recognises the concept of Sig - nificant Data Fiduciaries (SDFs), which are sub - ject to enhanced compliance obligations, including audits and impact assessments. Data Principals are granted rights relating to access, correction, erasure, withdrawal of consent, grievance redressal and nomi - nation. Non-compliance may attract significant mon - etary penalties. The DPDP Rules operationalise the statutory frame - work by prescribing requirements relating to consent notices, security safeguards, breach notifications, processing of children’s data and the functioning of the DPBI. Information Technology Framework Until the DPDP Framework is fully operationalised, the IT Act and SPDI Rules continue to apply in certain respects. Section 43A of the IT Act imposes liability for failure to implement reasonable security practices, while Section 72A prescribes penalties for unlawful disclosure of personal information. The SPDI Rules regulate the collection, use, retention, transfer and disclosure of sensitive personal data. The framework requires consent-based processing, pur - pose limitation, implementation of reasonable security practices and appointment of a grievance officer. In addition, sector-specific regulators in areas such as financial services, insurance, securities and telecom - munications continue to prescribe separate require - ments relating to cybersecurity, operational resilience and data governance.
The DPDP Act applies not only to entities within India but also to entities incorporated outside India that pro - cess the personal data of individuals located in India in connection with the offering of goods or services to them. Consequently, any organisation offering goods or services in India or processing data of individuals in India falls within the scope of the framework, regard - less of where the organisation is located. However, Section 17 of the DPDP Act contains various carve-outs, with one carve-out being of particular rel - evance to India’s significant technology and business process outsourcing sector. Section 17 (1)(d) exempts from the core obligations the processing of personal data of individuals located outside India, where such processing is carried out within India by an Indian enti - ty pursuant to a contract with a person outside India. Cross-Border Transfer Under the DPDP Framework One of the more structurally distinctive features of the DPDP Framework is its approach to cross-border data transfers. Section 16 of the DPDP Act and Rule 15 of the DPDP Rules together adopt a negative list model, under which personal data may be transferred by a Data Fiduciary to any country or territory in the world, unless the Central Government has expressly restricted transfers to that jurisdiction. However, as of the date of writing, no countries have been placed on the restricted list. Section 16 and the cross-border transfer obligations under Rule 15 become fully operational only from 14 May 2027, meaning that organisations have until then to map their global data flows, restructure internation - al transfer arrangements and renegotiate contracts with overseas recipients. Further, where sector-specific laws or regulations impose stricter transfer restrictions or localisation requirements, those requirements continue to apply alongside the DPDP Framework. Consequently, locali - sation mandates imposed by sectoral regulators con - tinue to operate independently of the general transfer regime.
454 CHAMBERS.COM
Powered by FlippingBook