Cross-Border Transfer Tracker

Map and Manage Cross-Border Data Transfers

The DPDP Act restricts transferring personal data outside India (Section 16). dcomply's Cross-Border Transfer Tracker helps you log every international data flow, document the legal transfer mechanism, and maintain a complete register ready for regulatory review.

India Source. Low Risk
USA Standard Contracts. Medium
EU Adequacy Decision. Low
Singapore SCCs. Medium
UK DPDP-GDPR Bridge. Low
Others Review Required. High
The Problem

Most Organizations Are Blind to Their Cross-Border Flows

Under DPDP Act Section 16, every international data transfer must be documented and legally justified, yet most organizations have no register at all

Section 16 Compliance is Unmapped

Organizations routinely transfer data to cloud providers (AWS, GCP), SaaS tools, and global HQs without documenting the legal basis. Under Section 16, this is a direct violation.

No Visibility Into Data Flows

IT teams use 50+ SaaS tools, each processing personal data in different countries. Without a register, no one knows where data goes after it leaves India.

Adequacy Lists Are Changing

The list of countries with adequacy decisions changes as the government publishes notifications. Outdated transfer mechanisms expose organizations to enforcement risk.

Capabilities

Complete Cross-Border Transfer Governance

Transfer Register

Log every cross-border data transfer: recipient name, country, data categories transferred, transfer frequency, and start/end dates. Full audit trail.

Transfer Mechanism Documentation

Record the legal transfer mechanism for each flow: Government Notification (Section 16), Standard Contractual Clauses, Adequacy Decision, Consent, or Intra-group Agreement.

Adequacy Country Tracker

Track which countries have received adequacy decisions from the Indian government. Currently recognized: USA (standard contracts), EU (bilateral negotiations), UK (DPDP-GDPR bridging). Automatically flag transfers to non-adequate countries.

Risk Assessment

Each transfer is automatically assessed for risk level (Critical/High/Medium/Low) based on country risk, data sensitivity, transfer volume, and safeguards in place.

Safeguard Documentation

Record the specific safeguards for each transfer: encryption in transit and at rest, contractual protections, data minimization, and recipient security certifications.

Section 16 Register Export

Export a complete Cross-Border Transfer Register as PDF for internal governance, DPA agreements, and regulatory submissions.

How It Works

Map Every Transfer in 4 Steps

From logging data flows to generating a Section 16-ready register, dcomply keeps you covered across every jurisdiction.

Add transfer details

Enter recipient organization, country, data categories transferred, and transfer purpose. Select from common SaaS providers (AWS, Google, Microsoft, Salesforce) for quick setup.

Document legal mechanism

Choose the transfer basis: Government Notification, Standard Contractual Clauses, Adequacy Decision, or Data Principal Consent. Upload supporting documentation.

Run risk assessment

The system evaluates the transfer against country risk ratings, data sensitivity (health, financial, biometric), transfer frequency, and safeguard completeness.

Monitor and maintain

Get alerts when adequacy decisions change, contracts expire, or high-risk transfers are identified. Maintain a living register with full version history.

FAQ

Frequently Asked Questions

Section 16 restricts the transfer of personal data outside India to countries/territories notified by the Central Government. The government maintains a list of approved destinations and may impose additional conditions on specific data types. Organizations must ensure every cross-border transfer has a documented legal basis and any government-specified conditions are met.

The Central Government will notify approved countries under Section 16. Currently, transfers to countries with adequate data protection standards (EU, UK, Singapore, USA under bilateral agreements) are expected to be permitted. dcomply tracks the government's notifications and flags transfers to non-notified countries automatically.

Yes. dcomply includes pre-built profiles for major cloud providers (AWS, Google Cloud, Microsoft Azure, Salesforce) with their data center locations and applicable transfer mechanisms. You can also add any custom vendor or SaaS tool that processes personal data outside India.

Build Your Cross-Border Transfer Register

Map every international data flow in minutes

View All Features