‹ All sectors

Sector reference

DPDP for Exporters, Trading Houses and SEZ Units

What is processed
Buyer contact people abroad, shipping and customs documents naming individuals, bank and remittance details, employee records, and whatever gets uploaded into a foreign buyer's own portal or social audit platform.

Why it is allowed, and when

Sending personal data out of India is permitted by default. The Act gives the Central Government a power to restrict transfer to a country or territory that it notifies, which means a restriction has to be announced before it bites. It is not a system in which you must first establish that a destination is safe.

Where the permission stops

Two things sit on top of that default. Any Indian law that already imposes a stricter transfer rule keeps its full force, and the Government may specify requirements about making personal data available to a foreign State, or to a person or entity under the control of such a State.

Questions people actually ask

Do we need an adequacy decision before sending data to a foreign buyer?

No. That requirement belongs to the European framework, not to the Indian Act. Section 16 gives the Central Government a power to restrict transfer to a country or territory it notifies, which means the default is that transfer is open and a restriction has to be announced first.

So the honest answer to a consultant asking for an Indian adequacy finding is that the Act does not create one.

Are there any real limits on sending personal data abroad?

Two, and they matter. Section 16(2) preserves any other Indian law that already imposes a higher degree of protection or a stricter transfer restriction, so sectoral rules such as the Reserve Bank's payment data requirements keep their full force.

Separately, the Rules allow the Government to specify requirements about making personal data available to a foreign State, or to a person or entity under the control of such a State. And a Significant Data Fiduciary can be told to keep specified data and its traffic data inside India.

We are a unit in a special economic zone. Does that change anything?

No. The Act has no exemption for special economic zones, export oriented units or free trade warehousing zones. Being outside the customs territory answers a customs question and nothing else.

Your unit processes digital personal data in India, so the Act applies in the ordinary way, and your largest exposure is the same as everyone else's: your workforce records and the machines they live on.

Our foreign buyer sends its own data protection contract. Does signing it cover us?

It adds obligations. It removes none. The Act binds the fiduciary irrespective of any agreement to the contrary, so an overseas contract cannot displace an Indian duty.

It is worth reading closely for a different reason: buyers often ask for deletion timelines that would collide with the Indian records you are required to keep. Reconcile that before you sign, not after.

What people get wrong

We need an adequacy decision before we can send data to our European buyer.

That is the European structure, not the Indian one. Section 16 runs the other way round: transfer is open unless the Government notifies a country as restricted. Being asked to produce an adequacy finding under the Indian Act is being asked for a document the Act does not create.

A unit in a special economic zone is outside the customs territory, so it is outside this too.

The Act contains no zone exemption. Customs territory settles customs questions. A unit inside a zone is processing digital personal data in India and is inside the Act like anyone else.

Our foreign buyer's contract governs us, so DPDP does not apply.

The Act applies to processing in India whatever a contract says, and it makes the point expressly by binding the fiduciary irrespective of any agreement to the contrary. A foreign contract stacks obligations on top. It never removes the Indian ones underneath.

Cross border transfer is the biggest DPDP risk an exporter faces.

For most exporters it is close to the smallest, because the default is open. The real exposure is workforce data, and the security of the laptops, shared drives and messaging groups the export documents actually live on.

Related questions

This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.