Article · Cross-Border, Fintech & Emerging Technology

Cross-border data transfers: building a contracting position that survives review

Data-transfer compliance is increasingly a contracting problem before it is a technology problem. The paperwork is what a regulator reads first.

9 min read

A business that processes personal data across jurisdictions accumulates obligations from several directions at once: the law of the place of collection, the law of the place of processing, sectoral regulation, and the contractual commitments it has given to its own customers.

Map the flows before drafting the clauses

The single most common defect in data-protection paperwork is that it describes a data flow the business does not actually have. Processing agreements are executed against an assumed architecture, while the engineering team routes data through a fourth-party sub-processor nobody has named.

The contracting stack

  • A processing agreement that reflects the real flow, including sub-processors.
  • Transfer terms appropriate to each corridor, with a documented basis.
  • Security schedules stated as obligations, not aspirations.
  • Breach-notification timelines that the business can actually meet.

Where sectoral regulation overrides

In regulated sectors - payments, lending, insurance, health - sector-specific localisation and access requirements frequently sit above general data-protection law and are not satisfied by standard transfer terms. These need to be identified at the point of architecture, because retrofitting localisation is an engineering project rather than a drafting exercise.

Where the statute itself stands

The Digital Personal Data Protection Rules, 2025 were notified in November 2025, and the Data Protection Board of India is now constituted. But the obligations most relevant to a cross-border contracting exercise - the conditions governing transfer outside India, the consent and notice mechanics, and the breach-notification timelines - are not yet in force; they are presently scheduled to commence in May 2027. The contracting stack described above should be built as preparation for a notified but not yet operative regime, and revisited once the remaining provisions are brought into force.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Boards should consult qualified legal counsel for company-specific guidance.