EDPS Denies Data Transfer to India

25th June, 2025

In early 2024, the European Data Protection Supervisor (EDPS) denied authorisation for a request placed by European Investment Bank (EIB) to transfer contact data to India. As per the EDPS’ 2024 annual report, denial of this authorisation stemmed from serious concerns that India did not demonstrate enough evidence and proof that it “could protect individuals’ personal data in the same way as in the EU,” This report underscored that India’s Digital Personal Data Protection Act, 2023 (DPDPA) remains insufficient in practice to meet the EU’s legal threshold for international data transfers.  
 
Though enacted in August 2023, the DPDPA is yet to be operationalised, with crucial rules and procedures still undergoing the process of public consultation. Critics argue that the DPDPA grants excessive power to the government, lacks independent oversight, and weakens user rights, raising serious concerns about surveillance and accountability. It contains broad exemptions for government authorities, leading to considerable ambiguity about whether individuals have meaningful protections or redress against unwarranted state surveillance. These gaps in oversight and enforcement significantly weaken the credibility of India’s data protection framework in the eyes of European regulators. We, at The London Story, have written about government overreach and weak enforcement of India’s Data Protection regime here.  
 
The move on the part of the EDPS is grounded in Article 46 of the General Data Protection Regulation (GDPR) which mandates that any third country receiving personal data from EU must offer protections and remedies equivalent to those in the EU. The landmark Schrems II decision of 2020 further clarified that authorities like the EDPS must carefully assess whether the legal systems of recipient countries allow for adequate oversight and accountability, especially in relation to surveillance and access to data by public authorities. 
 
The implications of this decision are far-reaching.  At the policy level, it reflects how EU remains unconvinced, noting that mere legislative text without enforcement mechanisms and independent oversight does not satisfy the GDPR’s demands. The absence of a Data Protection Board in India and lack of clarity around remedies for affected individuals were key concerns highlighted in the EDPS’s rationale. For businesses in India and the EU, this adds legal uncertainty and compliance hurdles to cross-border operations, particularly in financial services, cloud computing, and business process outsourcing. 
 
In the absence of an EU adequacy decision for India, the only viable paths forward for Indian companies and their European partners are to use standard contractual clauses or obtain explicit, case-by-case consent under GDPR-compliant derogations. Until India addresses the core deficiencies in its data protection regime, particularly in enforcement, state surveillance limits, and access to remedies, it is unlikely to secure seamless data transfer status from the EU.