India DPDP Act
DPDP Cross-Border + Breach (Sec 16-17)

India DPDP Act DPDP-CrossBorder-Transfer-Breach-Notification-Sec16-Sec17-DPBI-72Hour-IT-Act-Coord: DPDP Act Sections 16-17 + Cross-Border Personal Data Transfer + Negative List Approach + Personal Data Breach Notification to DPBI 72 Hours + Cooperation with Adjudication + Coord with CERT-In + IT Act 43A Repeal

Sections 16-17 of DPDP Act 2023 address cross-border transfer + breach notification. Section 16 Processing of Personal Data Outside India: Central Government may by notification restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be notified - effectively a negative list approach where transfers are permitted by default to all countries except those that the Government specifies as blacklisted/restricted. This is a SOFTER approach than GDPR Chapter V (which requires adequacy decisions or appropriate safeguards) + reflects India India-Stack-driven approach to global digital commerce. Sub-section (2): Where any other law for the time being in force in India provides for a higher degree of protection or restriction on the transfer of personal data by a Data Fiduciary outside India + the provisions of such law shall prevail (e.g. RBI Storage of Payment Systems Data 2018 which mandates onshore storage for payment data + RBI Master Direction NBFC-AA data localisation + CERT-In 180-day log retention in India + sectoral data localisation under TRAI/SEBI/IRDAI). Section 17 Exemptions: certain processing exempted from particular DPDP provisions per Section 17(1) including (a) preventing detection investigation prosecution of cognisable offences; (b) court proceedings; (c) defining or relating to merger demerger amalgamation; (d) prevention detection investigation of any other offence under law; (e) any function of State + governmental enterprises. Personal Data Breach Notification: Per Section 8(5) and DPDP Rules 2025 - within 72 hours of becoming aware of the breach (or such longer period as may be prescribed) the Data Fiduciary shall give intimation of such breach to the Data Protection Board of India (DPBI) and to each affected Data Principal in such form and manner as may be prescribed including (a) description of the breach + categories and approximate number of Data Principals affected + categories and approximate number of personal data records concerned + likely consequences + measures taken or proposed + name and contact details of DPO or other contact. Coordinates with CERT-In Directions 2022 (6-hour reporting separate from DPDP 72-hour) + RBI Cyber Framework + IT Act 43A (now repealed) + IT Rules 2011 SPDI (now repealed) + GDPR Arts 33 + 34 + 44-50 + UK GDPR + Singapore PDPA Notice of Notifiable Data Breach + APEC CBPR + India Stack DPI integration. DPDP Sec 16-17 Cross-Border + Breach applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 138 controls across 61 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 6 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 6 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement
  • GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions

Bahrain PDPL · 4 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

APPI · 3 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-D5-1 Incident planning and strategy

FISMA · 3 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

ISO/IEC 27010:2015 · 3 controls

  • 27010-16.1 Continuity of Sharing
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT

GLBA · 2 controls

  • GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
  • GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions

HITECH Act · 2 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors

IEEE 1686 · 2 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team
  • DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26 Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-3 Data Localization and Cross-Border
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • AL-DPA-14 Direct Marketing
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue

FDA 21 CFR Part 11 · 1 control

  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

MITRE D3FEND · 1 control

  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • RUSPD-4 Special Categories, Biometric Data
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 138 it maps to, and the evidence behind each claim, over MCP and REST.