Summary: As businesses become increasingly global, requests from foreign regulators, courts and law-enforcement agencies for information held in India are becoming a routine part of cross-border compliance. Businesses must now play the balancing act—comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), on the one hand, and the laws of the requesting jurisdiction on the other. The DPDP framework does not automatically exempt foreign regulatory requests. Business must, therefore, regularly assess the basis for processing and disclosure, cross-border transfer requirements and, determine whether such request should be routed through an Indian legal mechanism.
The business problem: When cooperation itself creates risk
Indian businesses operating across jurisdictions often receive data requests from overseas regulators investigating bribery, sanctions, fraud, market conduct, anti-trust, financial crime or other regulatory issues. This requires them to produce communications, emails, employee records, customer information, transaction data, KYC records, vendor information and other such documents. The commercial pressure to respond can be significant. Business may face enforcement action, sanctions, adverse findings, contempt proceedings or reputational consequences in the requesting jurisdiction for delayed or incomplete response. In a civil or commercial dispute, the information may be used to compute damages.
However, sending the requested information overseas may result in compliance breach in India if it contains personal data. The DPDP Act, therefore, forces Indian businesses to confront an increasingly difficult question: how should businesses cooperate with foreign authorities without infringing India’s data-protection law especially in the face of potential financial consequences? The Schedule provides for penalties as high as INR 250 crore (approximately USD 30 million). The actual penalty will depend on the specific contravention.
The provisions of the DPDP Rules, most relevant to foreign data requests, are scheduled to come into force on May 13, 2027. Hence, businesses can build processes before foreign regulatory requests begin to clash with the full DPDP framework.
When faced with a request: Start with the information, not the regulator
The first question to be asked, when faced with a request from a foreign regulator, should be what information is being sought. A request may cover a mixture of personal and non-personal information, concerning individuals located in India and elsewhere. Some Indian personal data appearing in a global dataset should not, by itself, mean that the entire dataset is treated as subject to the DPDP Act. Businesses should first identify the relevant data and processing activity.
Similarly, genuinely anonymised information would generally fall outside the definition of personal data. Hashing, pseudonymisation or other technical transformations, however, may not necessarily amount to anonymisation where an individual can still be identified. The DPDP Act’s application cannot be determined solely basis where the database or server is physically located.
The legal basis for disclosure must be established
Upon identification of the information, the nature of the foreign request should be determined, which may originate from a foreign civil court, regulator, prosecutor, law-enforcement authority or arbitral tribunal. It may be a binding order, a formal request under a statutory or treaty mechanism like the Hague Convention on Taking of Evidence Abroad in Civil or Commercial Matters, 1970 (“Hague Convention”), or an informal request for voluntary cooperation. These distinctions are important because the DPDP Act does not treat all foreign requests in the same manner.
The DPDP Act permits processing basis consent or for specified “legitimate uses”. One potentially relevant legitimate use is Section 7(e), which permits processing where it is necessary for compliance with a judgment, decree or order issued under the law of a foreign State relating to a contractual or civil claim. Accordingly, a foreign court order requiring production of personal data in civil proceedings may potentially fall within this provision.
Section 7(e), however, may not be treated as a general gateway for foreign regulatory cooperation. Its language is directed towards judgments, decrees and orders relating to contractual or civil claims. Accordingly, a foreign regulator’s informal request or a request arising from a foreign criminal or administrative investigation is not covered. As the DPDP Act does not specifically refer to arbitral tribunals in Section 7(e), the position on foreign arbitral tribunal orders is unsettled. However, pending the commencement of the DPDP Act provisions or any rules framed by the government thereunder, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, will continue to govern the handling of sensitive personal data or information. This includes the applicable requirements concerning collection, disclosure and reasonable security practices.
Section 17 lists exemptions that may be relevant under certain circumstances, but these too require careful consideration. Section 17(1)(a) concerns processing necessary for enforcing a legal right or claim. Hence, if processing is genuinely necessary to enforce such a right or claim, it can be applied. However, it should not be considered as a broad exemption for complying with foreign regulatory requirements or avoiding potential regulatory penalties. Section 17(1)(c) concerns processing necessary for investigation, prevention, detection or prosecution of offences or contraventions under Indian law. It does not create a general exemption for processing related to foreign criminal or regulatory proceedings, including those undertaken by the United States Securities Exchange Commission (“USSEC”) or the Department of Justice (“DOJ”). Section 17(1)(d) may be particularly relevant for businesses with cross-border operations. It exempts processing of personal data of Data Principals located outside India, only if it is pursuant to a contract entered into with a person outside India and is undertaken by a person in India. Applicability will depend on the facts and contractual structure of the arrangement.
If disclosure is permissible, can the data be transferred outside India?
Establishing a basis for processing or disclosure does not, by itself, imply that the information may be transferred outside India. Section 16 of the DPDP Act regulates the transfer of personal data outside India for processing. Accordingly, an Indian entity proposing to send personal data directly to a foreign regulator, must answer two distinct questions: is disclosure legally permissible and whether transfer outside India is permissible.
This distinction is crucial in the context of Rule 15, which permits the Central Government to specify, by general or special order, requirements relating to making personal data available to a foreign State, an entity or person controlled by such State, or an agency of such State. Rule 15 is scheduled to come into force on May 13, 2027.
Businesses must, therefore, undertake such analysis at both stages. They must not assume that a lawful basis for disclosure under Section 7 or an applicable exemption under Section 17 can address the requirements governing cross-border transfer. Conversely, the ability to transfer data outside India does not establish a lawful basis for the underlying disclosure.
Is direct disclosure to foreign authorities necessary?
If the foreign request pertains to information held in India, the business should consider whether it can or should be provided through an Indian legal mechanism rather than transferred directly to the requesting authority.
For criminal investigations, Section 113 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (“BNSS”), provides a mechanism for a foreign court or authority to issue a letter of request seeking assistance in obtaining evidence or information in India. Depending on the jurisdiction and nature of the proceedings, mutual legal assistance treaties (“MLATs”), often used by foreign bodies such as the DOJ, regulator-to-regulator arrangements, such as the one between the USSEC and the Securities and Exchange Board of India, and other applicable international cooperation mechanisms like the Hague Convention, may also be available. Civil proceedings may engage separate mechanisms under the Code of Civil Procedure, 1908.
These mechanisms do not necessarily replace the DPDP analysis. Rather, they change how information is collected and transmitted and, consequently the applicable data-protection and cross-border transfer considerations. The availability and appropriateness of a particular mechanism will depend on the nature of the proceeding, the requesting authority and the jurisdiction concerned.
Additional restrictions to be considered
The DPDP Act should not be considered in isolation. Section 16(2) expressly preserves laws that provide a higher degree of protection or restriction on transfer of personal data. Consequently, businesses operating in regulated sectors should separately assess whether sector-specific requirements apply to the information sought.
This may be particularly relevant when requests involve financial, securities, insurance, telecommunications, payments or other regulated data. Permissible disclosure under the DPDP Act does not displace a more restrictive obligation under another applicable law or regulatory framework.
The same consideration applies to the involvement of employees, service providers and overseas advisers. An organisation may have a basis to process employee data for internal purposes, including under Section 7(i), but that does not automatically provide a basis for onward disclosure to a foreign authority. Similarly, whether an overseas adviser is a Data Processor must be assessed basis the actual nature of its processing activities and not merely the contractual terminology used by the parties.
If the request involves a large global dataset, businesses must determine whether all the information is necessary for the foreign proceeding. Information that is not responsive, or personal data whose identification is unnecessary for the purpose of the request, should be excluded or anonymised. The DPDP Act does not establish a standalone GDPR-style data-minimisation principle in identical terms. However, limiting processing and disclosure to what is necessary for the relevant purpose remains an important component of a defensible approach.
Conclusion
Globally integrated businesses are increasingly exposed to foreign regulatory requests, and responding to them is not generally prohibited under the DPDP Act. However, it requires businesses to consider several questions that may have been previously addressed via a single disclosure decision. These are: identifying the data and establishing whether the DPDP Act is applicable; determining the legal basis for processing and disclosure; assessing whether transferring such data outside India is restricted; considering whether an Indian legal or regulatory mechanism should be used; and identifying sector-specific or other applicable restrictions.
This framework is crucial because the consequences of an incorrect decision may arise in two jurisdictions simultaneously. While satisfying the demands of a foreign regulator, a business will have to be compliant with Indian law. Before the relevant DPDP provisions commence on May 13, 2027, businesses must use this window to establish a defined internal process for handling such requests, including escalation protocols, data-mapping procedures and criteria for determining the appropriate basis and mechanism for disclosure.
Recent Comments