Cross-Border Transfer Of Healthcare Data: Reconciling India's DPDPA With GDPR
Faisal Yaseen
23 July 2026 12:30 PM IST

After the world was hit by the pandemic, the use of technology saw a paradigm shift, especially in the field of healthcare as patients quickly realized that adoption of technological communications was much more convenient than physical visits at hospitals. As the healthcare industry underwent a profound digital transformation, it accelerated a widespread reliance on remote medical expertise. Today, digital consultations, virtual diagnostics and cross-border medical opinions have become mainstream pillars of modern medicine. As this digital mode of consultation proliferated, patients began expecting medical expertise that transcends domestic boundaries. However, this borderless transmission of healthcare data introduces an intricate legal challenge, namely, the protection and governance of cross-border healthcare data transfers. To tackle this situation, various jurisdictions have adopted legal frameworks to safeguard these borderless flow of healthcare data. Accordingly, in this article, we will examine the dual pillars of modern data privacy, the European Union's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDPA), focusing specifically on how they reconcile with respect to cross border flow of healthcare data.
Before delving into the law governing the cross-border transfer of healthcare data, it is essential to outline how healthcare data is classified under DPDPA and GDPR.
When it comes to the legal frameworks governing cross border flow of healthcare data, the GDPR and the DPDPA exhibits a fundamental divergence and takes different regulatory approaches.
GDPR draws a significant distinction between personal data and sensitive data, unlike DPDPA. According to Article 4(1) of GDPR, “personal data” is defined as any information that is related to an identified or identifiable natural person, such as name, address, date of birth, education, etc. However, under Article 9 of GDPR, healthcare data is explicitly categorized under a 'special category' of personal data which requires a higher level of processing protection.
In India, DPDPA does not specifically define or mention healthcare data instead, it has been subsumed under the term 'personal data' as defined under Section 2 (t) of the DPDPA. According to Section 2(t) of DPDPA, “personal data” means “any data about an individual who is identifiable by or in relation to such data.” In other words, personal data includes any information such as name, age, address, gender, contact details, marital status, etc., which can be used directly or indirectly to identify a person.
In stark contrast to GDPR's approach, India's DPDPA does not formally segregate personal data into categories such as “sensitive” or “special category.” Therefore, one could argue that under DPDPA, a uniform standard is applied for processing the most innocuous data such as a basic email address and the most sensitive data like an oncological report.
This systemic vulnerability was vividly demonstrated when a leading private hospital in Ernakulum, Kerala, was targeted by the cybercriminal group known as “The Gentlemen”. The Hospital fell victim to a massive server level ransomware attack in mid-march, 2026, resulting in theft of 800 GB of highly sensitive healthcare data which was subsequently put up on dark web. An exfiltration of this magnitude would trigger catastrophic penalties and special category data protection under EU's GDPR. However, under India's DPDPA, the legal assessment of this massive breach treats the entire 800 GB exfiltration under a singular, uniform baseline of “personal data.” This lack of statutory granularity fails to legally distinguish between a basic corporate credential leakage and a medical data breach, ignoring the uniquely severe financial, psychological, and physical vulnerabilities associated with health related breaches.
Before explaining the complex legal mechanisms that govern the cross-border flow of healthcare data, let's consider a hypothetical scenario centred on the rapidly evolving digital health landscape across borders: -
Imagine a hospital runs its own health-tech company called “Heal India,” which offers a premium AI diagnostic feature to escalate patients' requests for medical expertise beyond borders. A patient based in Delhi, diagnosed with a skin disease, uses this app to upload his details containing name, contact number, age, address, co-morbidities, skin scans, previous medical reports, etc. to consult a specialist sitting across oceans. To facilitate a rapid diagnosis, the app instantly sends this entire data over the internet to a specialized medical AI server hosted by 'Toggle' in California. Within minutes, AI processes the scans to flag potential risks, which are immediately routed onto the dashboard of the overseas doctor. After reviewing the AI's analysis, the doctor signs off on the final diagnosis and transmits the report back to the patient in Delhi.
Considering the above situation or scenario under European GDPR, this data transfer would have had to go through multi-layered assessment as detailed under relevant articles of GDPR. Patient name, age, contact number, and address would have been treated as personal data, while co-morbidities, skin scans, and previous medical reports would immediately shift into a 'special category' requiring strict processing enforcement. On the contrary, under DPDPA, this entire transmission of healthcare data would find itself being treated on an identical baseline with personal data.
Cross-border data transfer in the simplest form may be referred to as the movement/storage of personal or sensitive information across national boundaries. In a healthcare ecosystem, this international transmission of health data of a patient for the purpose of remote diagnosis, virtual consultation, cloud storage, or global medical research refers to a cross-border transfer of healthcare data. The legality of such cross-border data flows is primarily shaped by the distinct statutory provisions of the EU's GDPR, India's DPDPA, and the recently notified Digital Personal Data Protection Rules, 2025, which have been discussed hereafter.
DIGITAL PERSONAL DATA PROTECTION ACT, 2023 –
Section 16 of DPDPA talks about processing of personal data outside India, however, it takes a negative approach and authorizes the Central Government to curate a negative list of prohibited jurisdictions for the transfer of personal data. Under this mechanism, Data Fiduciaries[1] face absolute statutory prohibitions against transferring or processing the personal data of Data Principals[2] within any explicitly blacklisted country. However, Clause 2 of Section 16 is a saving clause, and it explicitly states that the above-mentioned provision does not weaken any other existing Indian law that imposes stricter rules or higher protection on cross-border data transfer.
DIGITAL PERSONAL DATA PROTECTION RULES, 2025 –
The Digital Personal Data Protection (DPDP) Rules operationalize the broader statutory mandate established under the parent legislation, the DPDP Act. Specifically, through a passed enforcement timeline where Rules 15 and 16 delineate the boundaries of cross-border transmission of personal data.
Rule 15 governs the mechanism for transferring personal data outside the sovereign territory of India operating under the administrative framework for Section 16 of the DPDPA. As Section 16 adopts a negative list policy, the rule essentially implements a “free rein with a short leash policy.” Data fiduciaries have been given the freedom to transfer data across borders subject to the limitation that the central government may step in and expressly restrict or blacklist particular countries that pose a potential risk.
On the other hand, Rule 16 of DPDP Rules provides an exception from the stringent compliance of flow of cross-border data when the same is processed for research, archiving, or statistical purposes. However, such exemption is conditional upon compliance with the standards set out under the Second Schedule of the DPDP Rules, 2025.
GENERAL DATA PROTECTION REGULATION –
Chapter V of the GDPR relates to “Transfers of personal data to third countries or international organizations” spanning Articles 44 to 50. The primary objective of this chapter is to establish a strict legal framework governing cross-border data flows and to ensure the highest level of protection guaranteed to individuals within the European Economic Area (EEA) when their data travels outside their country.
Unlike DPDPA, GDPR operates on a 'whitelist' approach, which is based on the adequacy principle. Under this framework, GDPR allows the transfer of sensitive personal data only to countries that have an adequate level of data protection, which is outlined in Article 45 of GDPR. Article 45 permits the seamless transfer of data across borders, provided that the recipient country guarantees an adequate or equivalent level of protection of data to that underlined in GDPR.
However, if the recipient country lacks an adequate level of protection of data as required under Article 45 of GDPR, data transfer cannot take place seamlessly. Instead, they must fall back on alternative legal frameworks, enunciated in Article 46, which requires data exporters to implement “appropriate safeguards” alongside enforceable individual rights and effective legal remedies.
The primary legal instrument under Article 46 is Standard Contractual Clauses (SCCs), which are the most widely used for transfer mechanisms globally. Standard Contractual Clauses (SCCs) are standardized clauses, approved by the European Commission, that allow the transfers of data outside the European Economic Area (EEA). Both parties involved in the transfer need to sign an agreement containing the Standard Contractual Clauses, without modifying the operative clauses in a manner that undermines the protection guaranteed by the SCCs.
When it comes to large multinational corporations, safeguards are enshrined under Article 47, which offers significant protection under the guise of Binding Corporate Rules (BCRs). BCRs serve as an internal, legally binding privacy policy tailored for multinational corporations. If a competent European Data Protection Authority (DPA) formally approves the framework, they allow a company group to transmit personal data among its international affiliates, subject to stringent legal requirements.
While Articles 45 to Article 47 regulate proactive, commercial data flows while Article 48 acts as an emergency shield for and when a foreign government or court demands access to EU data. Article 48 protects EU data from extraterritorial overreach by stating that third-country court judgments or administrative orders cannot be independently enforced. Instead, such disclosures are only permitted if there exists an official international agreement in place between EU and foreign country, like a Mutual Legal Assistance Treaty (MLAT).
As a last resort, if a transfer lacks an adequacy decision (Article 45), safeguards (Articles 46-47), or an international treaty (Article 48), Article 49 prohibits the data flow subject to specific satisfaction such as explicit consent or contractual necessity. Together, this sequential flow guarantees that personal data never leaves the safety of the EEA without an explicit, structured layer of legal accountability.
Therefore, it is clearly evinced that the operational mechanics of cross-border healthcare data transfers under India's DPDPA and the EU's GDPR reveal fundamentally opposing regulatory philosophies. Under India's DPDPA, data transfers operate on a negative-list or “blacklist” approach, meaning that data flows are permitted by default to all international jurisdictions unless a country is explicitly restricted by the Central Government. Conversely, the EU's GDPR functions on a strict “whitelist” approach based on the adequacy principle. However, the primary limitation of the DPDPA's permissive framework within the healthcare sector is its vulnerability to structural asymmetry with foreign laws. Because India does not enforce a rigid, baseline whitelist standard or mandatory SCC architecture for cross-border transfer, Indian telemedicine platforms exporting data to third-party countries with weak privacy infrastructures could inadvertently expose Indian citizens' health profiles to unchecked foreign surveillance or secondary commercial monetization. Therefore, the intersection of global teleconsultation and data privacy demands a sophisticated legal balancing act. Moving forward, the true test of India's framework will lie in its executive capacity to dynamically intercept international privacy risks, ensuring that the pursuit of digital convenience does not inadvertently compromise the sacred trust of patient confidentiality.
Section 2(i) of DPDPA defines Data Fiduciary as any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. ↑
Section 2 (j) of DPDPA defines Data Principal as an individual to whom personal data belongs or relates. ↑
Author is an Assistant Manager (Legal) at Medanta Hospital, Gurugram. Views are personal.


