Abstract
The transnational movement of personal data now underlies commerce, governance, and communication, yet the legal architecture governing that movement remains sharply fragmented across jurisdictions. This article undertakes a comparative doctrinal study of the frameworks governing cross-border data transfers in the European Union, the United States, and India, examining the General Data Protection Regulation, the sectoral and executive-driven American model, and India's newly operational Digital Personal Data Protection Act, 2023 together with the Digital Personal Data Protection Rules, 2025. It traces the doctrinal foundations laid by the Court of Justice of the European Union in the Schrems litigation, the extraterritorial assertions embedded in the CLOUD Act, and the blacklist-style restriction contemplated under Section 16 of the Indian statute. The article argues that while the three regimes differ in regulatory philosophy — rights-maximisation, market-pragmatism, and calibrated sovereignty — they are converging functionally toward layered systems of adequacy findings, contractual safeguards, and government-to-government access controls. It concludes with suggestions for interoperability between these regimes, with particular attention to the compliance burden facing Indian data fiduciaries as the DPDP Rules move through their phased implementation between November 2025 and May 2027.
I. Introduction
A. Background
Personal data has become what oil once was to the industrial economy — a resource whose extraction, refinement, and cross-border movement drives value creation. Cloud computing, outsourced processing, and platform-based services routinely transmit personal data across national boundaries within milliseconds, often without the data subject's awareness of where the data ultimately resides. This reality has forced legal systems to confront a foundational tension: data protection law is territorially enacted, but data flows are not. The European Union responded first and most comprehensively, embedding cross-border transfer restrictions within the General Data Protection Regulation ("GDPR"), which conditions the export of personal data outside the European Economic Area on a threshold showing of adequate protection.[1]
The United States, by contrast, has no single federal statute governing cross-border data transfer; it relies instead on a patchwork of sectoral laws, state legislation such as the California Consumer Privacy Act, and executive instruments negotiated with trading partners, most recently the EU-U.S. Data Privacy Framework.[2] India entered this field only recently. The Digital Personal Data Protection Act, 2023 received presidential assent in August 2023, but its substantive machinery, including the Digital Personal Data Protection Rules, 2025, was notified only on 13 November 2025 and is being rolled out in three phases culminating on 14 May 2027.
B. Research Questions
This article addresses three interlinked questions: first, how do the EU, the US, and India each structure the legal conditions under which personal data may lawfully leave, or enter, their jurisdiction; second, to what extent do these frameworks converge on common regulatory instruments despite differing constitutional starting points; and third, what practical and doctrinal challenges confront India's evolving cross-border transfer regime as it moves from Section 16 of the parent Act toward operational rules.
C. Objective and Methodology
The objective of this study is to produce a comparative doctrinal account that situates India's emerging regime within the wider global conversation on data sovereignty, rather than treating it in isolation. The methodology adopted is doctrinal and comparative: it draws on primary legal texts (the GDPR, the DPDP Act and Rules, and relevant American statutes), leading judicial decisions of the Court of Justice of the European Union and the Supreme Court of India, and secondary regulatory commentary published through 2026. The comparative method follows a functional approach, examining not merely textual similarity but whether each regime performs an equivalent regulatory function — namely, preventing the erosion of data-subject protection through transfer to a jurisdiction with weaker safeguards.
II. Legal Provisions and Comparative Analysis
A. The European Union: Regulatory Maximalism under the GDPR
Chapter V of the GDPR erects a three-tier system for international transfers. The first and preferred route is an adequacy decision, whereby the European Commission determines that a third country's domestic law provides protection "essentially equivalent" to that guaranteed within the Union.[3] In the absence of adequacy, controllers may rely on "appropriate safeguards," chiefly Standard Contractual Clauses ("SCCs") issued by the Commission or Binding Corporate Rules for intra-group transfers.[4] Only exceptionally may a controller invoke the derogations in Article 49, such as explicit consent, which the European Data Protection Board treats as a route of last resort.
The doctrinal centre of gravity in this field is the Schrems jurisprudence. In Schrems I, the Court of Justice invalidated the US–EU Safe Harbour arrangement, holding that a Commission adequacy finding cannot immunise a transfer mechanism from judicial review where the destination country's surveillance law permits generalised access to transferred data.[5] Five years later, in Schrems II, the Court struck down the successor Privacy Shield framework on similar grounds, while preserving SCCs subject to a case-by-case "transfer impact assessment" obligation on exporters.[6] This obligation has since become the operative compliance burden for any company transferring data out of the EU, effectively requiring a private law assessment of a foreign state's surveillance regime before each transfer.
B. The United States: Sectoral Pragmatism and Extraterritorial Access
The American approach inverts the European starting point. Rather than restricting outbound transfer, US law has historically prioritised inbound access by domestic law enforcement, most visibly through the Clarifying Lawful Overseas Use of Data Act ("CLOUD Act"), which authorises US law enforcement to compel American service providers to produce data stored on servers located anywhere in the world.[7] The Act was enacted in direct response to United States v. Microsoft Corp., in which the government sought emails stored on a server in Ireland and the underlying jurisdictional question was rendered moot by the new legislation before the Supreme Court could resolve it on the merits.[8]
On the inbound side, the absence of an omnibus federal privacy statute has pushed regulatory innovation to the states, most prominently through the California Consumer Privacy Act and its successor amendments, which impose transparency and opt-out obligations on entities selling or sharing personal data without erecting a formal cross-border transfer licensing regime comparable to the GDPR.[9] International data flows into and out of the US are instead governed through negotiated instruments, of which the current EU-U.S. Data Privacy Framework — adopted after Executive Order 14086 created a redress mechanism for EU data subjects before a new Data Protection Review Court — is the most consequential example. The Framework represents an attempt to satisfy the "essential equivalence" standard articulated in Schrems II through executive rather than legislative reform.
C. India: The Digital Personal Data Protection Act, 2023 and the Emerging Transfer Regime
India's constitutional foundation for this field was laid in Justice K.S. Puttaswamy (Retd.) v. Union of India, where a nine-judge bench of the Supreme Court recognised privacy as a fundamental right under Article 21, holding informational privacy to be an intrinsic facet of that guarantee and thereby obligating the state to enact a data protection regime consistent with the doctrine of proportionality.[10] That obligation culminated, after several draft iterations, in the Digital Personal Data Protection Act, 2023. Unlike the GDPR's default prohibition subject to adequacy, Section 16 of the Act adopts a negative or "blacklist" model: cross-border transfer of personal data is permitted to any country or territory outside India except those the Central Government specifically restricts by notification.[11]
The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 together with the constitution of the Data Protection Board of India, operationalise the bulk of the Act's obligations relating to notice, consent, and breach reporting, but the specific criteria for the Section 16 restricted-country list, along with the compliance requirements applicable to Significant Data Fiduciaries handling cross-border flows, remain subject to a further, separate government notification as implementation proceeds through 2026 and into the final compliance deadline of 14 May 2027.[12] This deferred architecture leaves Indian data fiduciaries in a position functionally closer to the pre-GDPR European landscape: transfer is presumptively lawful, but the boundaries of that permission are still being drawn by delegated legislation rather than the parent statute.
D. Comparative Assessment: Divergence in Design, Convergence in Function
Placed side by side, the three regimes appear to start from opposite premises. The EU begins from a rebuttable presumption against transfer, releasing data only once adequacy or a contractual safeguard is demonstrated. India begins from a rebuttable presumption in favour of transfer, restricting it only once a specific jurisdiction is blacklisted. The United States begins from no general presumption at all, relying on sectoral rules and negotiated frameworks layered atop a permissive default. Yet functionally, all three converge on the same three regulatory instruments: a government-issued country-level determination (adequacy decisions in the EU, the eventual Section 16 list in India, and framework-specific decisions in the US); standard-form contractual safeguards for private parties (SCCs in the EU, and their likely analogue once India's rules mature); and an residual, judicially or administratively supervised mechanism for individual redress. The doctrinal insight from Schrems II that a paper adequacy finding is meaningless if the destination state's surveillance law permits unchecked access is equally applicable to the CLOUD Act's extraterritorial reach and to any future Indian blacklist criteria, since none of the three regimes has fully reconciled national-security access powers with cross-border privacy guarantees.
III. Findings and Discussion
Three findings emerge from this comparison. First, the European model, despite its stringency, has proven the most litigation-resilient precisely because judicial review under the Charter of Fundamental Rights forces periodic reassessment of adequacy, whereas the American framework has twice been struck down by the CJEU for want of an equivalent independent review mechanism, and now depends on the durability of an executive order that a future administration could revise or revoke. Second, India's blacklist model offers a lighter initial compliance burden for data fiduciaries and is well suited to a jurisdiction seeking to remain an attractive outsourcing and cloud-hosting destination, but it currently offers data principals less certainty than either comparator, since the absence of a notified restricted-country list means the practical scope of Section 16 cannot yet be tested against any judicial standard. Third, all three jurisdictions face a common unresolved problem: reconciling their own law-enforcement and national-security access regimes with the export controls they impose on other states, a tension the CJEU has flagged repeatedly but which no legislature has yet resolved through a single coherent framework.
V. Conclusion
Cross-border data protection law is no longer a niche compliance topic but a central pillar of digital-economy governance. The European Union, the United States, and India each answer the underlying regulatory question under what conditions may personal data leave a jurisdiction's protective umbrella through markedly different constitutional and administrative instruments, yet each is converging toward the same functional toolkit of country-level determinations, contractual safeguards, and redress mechanisms. As India's Digital Personal Data Protection Rules, 2025 move through their phased implementation toward the May 2027 compliance deadline, the manner in which the Central Government defines the Section 16 restricted-country list will determine whether India's regime matures into a rights-protective framework comparable to the GDPR or remains a lighter-touch model closer to the pre-reform American approach. Either path will have consequences well beyond India's borders, given the country's position as one of the world's largest exporters of data-processing services.
Reference
[1]Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with regard to the Processing of Personal Data (General Data Protection Regulation), 2016 O.J. (L 119) 1, ch. V, arts. 44–50.
[2]Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 Pursuant to Regulation (EU) 2016/679 on the Adequate Level of Protection of Personal Data under the EU-U.S. Data Privacy Framework, 2023 O.J. (L 231) 118.
[3]GDPR, supra, art. 45(1); Case C-362/14, Schrems v. Data Prot. Comm'r, ECLI:EU:C:2015:650, ¶ 73 (Oct. 6, 2015).
[4]GDPR, supra, art. 46(2)(c)–(d).
[5]Schrems I, supra, ¶¶ 94–98.
[6]Case C-311/18, Data Prot. Comm'r v. Facebook Ir. Ltd. (Schrems II), ECLI:EU:C:2020:559, ¶¶ 190–202 (July 16, 2020).
[7]Clarifying Lawful Overseas Use of Data Act, Pub. L. No. 115-141, div. V, 132 Stat. 1213 (2018) (codified as amended in scattered sections of 18 U.S.C.).
[8]United States v. Microsoft Corp., 584 U.S. 236 (2018) (dismissed as moot following enactment of the CLOUD Act).
[9]California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020.
[10]Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
[11]The Digital Personal Data Protection Act, 2023, No. 22 of 2023, § 16, India Code (2023).
[12]Digital Personal Data Protection Rules, 2025 (India), notified by G.S.R. 843–846(E), Ministry of Electronics and Information Technology (Nov. 13, 2025).