
India DPDP Act: Cross-Border Transfer Rules Not Live, Section 16 Pending
Summary
- India's DPDP cross-border transfer rules (Rule 15 and Section 16) are not yet in force, despite industry actions suggesting otherwise.
- The Digital Personal Data Protection Rules, 2025, were notified in November 2025, but only procedural aspects became effective in Stage 1.
- Substantive obligations, including cross-border transfer conditions, are part of Stage 3, expected around May 2027.
- When active, Rule 15 will implement a 'negative list' model, permitting transfers by default unless a jurisdiction is specifically restricted by the government.
- Prematurely redrafting contracts based on these rules being live could result in unnecessary costs or incorrect compliance measures.
Misconceptions Around DPDP Cross-Border Transfer Rules
Despite significant activity within the legal and compliance sectors, the critical cross-border data transfer provisions of India's Digital Personal Data Protection Act (DPDP Act) are not yet legally binding.
Despite significant activity within the legal and compliance sectors, the critical cross-border data transfer provisions of India's Digital Personal Data Protection Act (DPDP Act) are not yet legally binding. Since the Digital Personal Data Protection Rules, 2025, were formally notified in November 2025, a notable trend has emerged where various industry stakeholders, including legal professionals issuing client memos, individuals publishing LinkedIn explainers, and even compliance-tool vendors, have proceeded as if Rule 15, which specifically governs the cross-border transfer of personal data, is fully operational. This has led to widespread efforts to rewrite contract templates and amend data processing addenda, with clients being advised to incorporate “DPDP-compliant” cross-border transfer mechanisms into new vendor agreements, cloud contracts, and outsourcing arrangements.
However, this proactive approach is premature. The fundamental issue is that Section 16 of the DPDP Act, along with Rule 15 which is designed to operationalize it, has not yet come into force. The commencement of the DPDP Act has been structured in a staggered manner across three distinct stages, and the provisions related to cross-border data transfer are part of a later phase. This distinction is not merely a technicality; it carries substantial implications for how commercial lawyers and compliance officers should be approaching DPDP compliance contract drafting today, particularly concerning the DPDP cross-border transfer rules not live status.
Staggered Implementation and Effective Dates
The phased implementation of the DPDP Act means that its various components become effective at different times. The initial phase, Stage 1, commenced in November 2025. This first stage primarily focused on establishing the Data Protection Board and bringing into effect a limited number of procedural and definitional provisions of the Act. These foundational elements were necessary to set up the administrative framework for future enforcement but did not activate the substantive obligations that impact day-to-day data processing activities.
Crucially, the more extensive and impactful substantive obligations of the DPDP Act are slated for Stage 3. This includes provisions related to consent architecture, breach notification protocols, protections for children's data, and, most significantly, the conditions governing cross-border data transfers. The expected timeline for the commencement of Stage 3, which will bring the India DPDP Rule 15 commencement and DPDP Act Section 16 effective date into force, is around May 2027. Therefore, any actions taken to comply with these specific rules before this anticipated date are based on an incorrect understanding of the DPDP cross-border data transfer timeline.
Future Framework for Cross-Border Data Transfers
When Rule 15 eventually comes into effect, it will introduce a distinct framework for cross-border data transfers, adopting what is known as a “negative list” model. Under this model, personal data transfers are permitted by default to any jurisdiction globally. This approach signifies a deliberately more permissive design compared to other prominent data protection regimes, such as the General Data Protection Regulation (GDPR), which relies on an adequacy-and-safeguards regime requiring specific assessments or mechanisms for transfers.
The negative list model means that transfers will only be restricted if the Central government explicitly notifies a particular jurisdiction as being off-limits. This provides a clear, default-open stance on international data flows, with targeted restrictions rather than broad prohibitions. Understanding this future India data protection negative list model is vital for long-term strategic planning, but it does not negate the current reality that these rules are not yet active, and premature compliance measures could lead to unnecessary costs or misdirected efforts.
Practical Implications
Lawyers and compliance officers should advise clients that the Digital Personal Data Protection Act's cross-border transfer rules (Rule 15 and Section 16) are not yet in force, despite industry speculation. Prematurely redrafting contracts based on these rules being live could lead to unnecessary costs or incorrect compliance measures; instead, they should monitor the actual commencement date (expected May 2027).
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in India
Wansom is AI and can make mistakes.
