Back to DPDP Rules

Cross-Border Transfer Restrictions (R.15)

Section 16 permits cross-border transfers by default; the Central Government may notify restricted countries under section 16(1). Rule 15 is a separate requirement about making data available to a foreign State, and creates no committee or list.

6 min read

Cross-Border Transfer Restrictions

The DPDP Act permits transfer of personal data outside India by default. There is no approval mechanism, no permitted list of countries, and no body that assesses jurisdictions in advance. Section 16(1) empowers the Central Government, by notification, to restrict transfer of personal data by a Data Fiduciary "to such country or territory outside India as may be so notified": so transfers are permitted unless and until a country is notified as restricted. Rule 15 of the DPDP Rules 2025 adds a separate requirement: a Data Fiduciary transferring personal data outside India must meet such requirements as the Central Government may specify, by general or special order, in respect of making that data available to a foreign State, or to an entity under its control or acting as its agency. Rule 15 sets out no requirements itself and creates no evaluating body. It comes into force eighteen months after publication of the Rules. Two restrictions sit outside this mechanism. Section 16(2) preserves any other Indian law imposing stricter transfer restrictions, so sectoral rules such as the RBI's payment-data localisation directive apply on their own terms. Rule 13(4) requires a Significant Data Fiduciary to keep Government-specified personal data, and the traffic data pertaining to its flow, within India.

Practical Implications

Organisations should prepare for potential cross-border restrictions by: • Mapping all cross-border data flows by jurisdiction • Identifying critical data processing operations in foreign jurisdictions • Developing contingency plans for data localisation if specific jurisdictions are restricted • Reviewing vendor and processor contracts for cross-border compliance clauses • Monitoring Government notifications for updates to the restricted list • Considering data minimisation in cross-border transfers • Implementing technical safeguards (encryption, pseudonymisation) for cross-border data flows

Frequently Asked Questions

Was this useful?

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.