The signing of the Comprehensive Economic Partnership Agreement (CEPA) in 2022 between India and UAE brought into focus the tariff negotiations, goods, and market access. However, another important yet less discussed commitment included in this agreement is the commitment towards free data flow across the borders with no forced data localization in the Digital Trade chapter. Four years since then, with the bilateral trade volume having reached $100 billion, this commitment has been tested by an obvious but often overlooked point India and the UAE built their data protection regimes on their own and these two regimes have not had an opportunity to fully align yet.

There are no barriers for now, however, this point is exactly what makes the issue worthy of a closer look. The absence of barriers at the moment is perceived by many businesses as a solid legal guarantee whereas it might be more accurate to regard it as just an early stage of the development of a legal framework which is yet to emerge on both sides.

What CEPA actually promises

The Digital Trade chapter of CEPA commits the two parties to facilitating cross-border data flows and avoiding any data localization mandates that would require data storage and processing to take place locally. In case of sectors like fintech, IT-enabled services, e commerce, where Indian companies serve UAE consumers and UAE companies depend on Indian technologies and capabilities, this commitment becomes a valuable one. It provides the foundation for the expectation that the data can be exchanged between these parties in the same way as goods and capitals are under the general agreement.

It should be noted that this agreement has one structural characteristic which is, the digital trade commitments are detached from the dispute resolution mechanism of CEPA. This approach is used quite often in modern trade agreements as digital trade chapters are aimed at fostering cooperation rather than being strictly justiciable obligations, which gives both governments enough room to maneuver as their digital regulatory frameworks are developing.

India's approach: a list still being built

According to the Digital Personal Data Protection Act, 2023 (“DPDP Act”), India's law on data transfer, section 16 of the DPDP Act provides the basis for a so-called negative list model, according to which the data transfer is allowed in all cases except when it is sent to the country specified by the central government as restricted. As of mid-2026, there is no such list published.

It is quite a liberal approach as compared to GDPR of the European Union, where transfers can only be made to countries listed as approved for the data transfer. Additionally, this approach reflects the policy decision taken by the Indian government to develop the digital economy in India and to facilitate the growth of global business in India. However, it should be noted that the framework has not been implemented yet. The government can notify the restricted countries or restricted data categories while implementing the rules. The other draft rules will enable the government to mandate that the certain important data fiduciaries holding significant amounts of sensitive data must store specific data categories, including health and biometric data, in India. However, the list of categories is under development.

This means that the Indian framework is something that must be monitored during further development.

The UAE's approach: adequacy across three frameworks

On the other hand, the UAE has a similar but complementary structural approach to protecting the personal data. In particular, the UAE’s data protection regime, represented primarily by the Personal Data Protection Law (“PDPL”), as well as by the unique data protection frameworks of the DIFC and ADGM financial free zones, implies an adequacy-based approach, which resembles the approach of the European Union. In general, the transfers should be made either to the jurisdictions providing adequate level of protection, or to jurisdictions having the appropriate contractual guarantees.

As there are three parallel data protection frameworks in the UAE (federal, DIFC and ADGM), each with its own data transfer provisions, companies doing business in these three frameworks must pay attention to the jurisdiction in which the transfer will be made. For the highly data intensive bilateral relationship such as the one between India and the UAE, this distinction is becoming an increasingly important aspect of cross-border structuring.

Where the frameworks are still converging

In comparison, the two systems have different default approaches. India's model starts with free flow unless the country is restricted by the law. The UAE's model generally requires recognized adequacy or contractual safeguards. The CEPA Digital Trade chapter will bring the two systems closer to the common position on the free flow of data. Both India and UAE are still developing the regulatory frameworks necessary for realizing this goal.

It is a live issue for businesses trading in this corridor. Any Indian IT or BPO’s dealing with customer data from UAE, any UAE fin-tech dealing with Indian cloud and analytical services, cross-border banking or insurance operations conducted through DIFC or ADGM entities, they all operate under a system that develops on both sides. In case India's restricted country notifications or sensitive data rules overlap with UAE linked transfers, or in case UAE adequacy determinations mature in view of India's framework, the business would be better off prepared for these changes.

Conclusion

Instead of waiting until the legislative clarity comes, a process that might take some time on both sides, businesses conducting India-UAE data transfers should apply contractual guarantees similar to European Union Standard Contractual Clauses (“EU SCC’s”) as best practice, rather than a stopgap solution. And legal departments should treat India's upcoming restricted country notifications and UAE adequacy determination as ongoing developments worth watching, rather than as already established background facts.

Broader picture is, perhaps, even more interesting than the specific example discussed. Trade agreements nowadays tend to make bold digital promises, while the corresponding domestic regulatory architecture is, inevitably, playing catch-up. The digital promise included in CEPA reflects a healthy and welcome ambition of both parties. It remains to be seen whether this ambition will develop into a legal platform for the cross-border commerce, but it certainly will happen in the years to come, and in the meanwhile it provides an interesting field of observation for legal experts.