Back to DPDP Rules
Cross-Border Transfer Restrictions (R.15)
Rule 15 cross-border framework - Committee mechanism, evaluation factors, scope covering processors and Consent Managers, and practical implications.
6 min read
Committee Mechanism
Rule 15 references a Committee mechanism for evaluating cross-border transfer restrictions. The Central Government may, based on the Committee's recommendations, restrict transfer of personal data to specific countries or territories. This reflects the 'negative list' approach authorised by Section 16 of the Act.
The Committee approach provides a structured, advisory-based process for determining transfer restrictions, rather than unilateral executive action. This allows for consideration of multiple factors and stakeholder input before restrictions are imposed.
Rule 15 Committee Composition
The mandated composition of the Rule 15 Committee is:
• Chairperson: Secretary, Ministry of Electronics and Information Technology (MeitY)
• Member: Secretary, Department of Legal Affairs
• Member: Secretary, Ministry of External Affairs (crucial for geopolitical considerations)
• Experts: Two experts of repute possessing special knowledge in data governance, the digital economy, or law
This composition ensures that recommendations balance technical, legal, and foreign-policy considerations before any country is added to the restricted list.
Evaluation Factors
The Committee considers several factors when recommending transfer restrictions:
• The legal framework for data protection in the recipient country or territory
• International agreements and treaties between India and the recipient jurisdiction
• The nature and sensitivity of personal data being transferred
• The adequacy of safeguards available in the recipient jurisdiction
• Any history of data protection incidents or breaches in the recipient jurisdiction
• Geopolitical and national security considerations and bilateral relations
• Reciprocity - whether the foreign State allows data flow to India
These factors are broadly similar to GDPR adequacy assessment criteria, though the DPDPA adopts a 'negative list' approach (restricting specific countries) rather than a 'positive list' approach (approving specific countries).
Scope of Restrictions
Importantly, Rule 15 restrictions apply not only to Data Fiduciaries but also to:
• Consent Managers - who manage consent records that may involve cross-border elements
• Data Processors - who may process data in restricted jurisdictions
This broad scope means the entire data processing chain must comply with transfer restrictions, not just the primary Data Fiduciary. Organisations must cascade restrictions to all downstream entities.
Practical Implications
Organisations should prepare for potential cross-border restrictions by:
• Mapping all cross-border data flows by jurisdiction
• Identifying critical data processing operations in foreign jurisdictions
• Developing contingency plans for data localisation if specific jurisdictions are restricted
• Reviewing vendor and processor contracts for cross-border compliance clauses
• Monitoring Government notifications for updates to the restricted list
• Considering data minimisation in cross-border transfers
• Implementing technical safeguards (encryption, pseudonymisation) for cross-border data flows
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
