In short: Under India’s DPDP cross-border data transfer India framework, your startup can send personal data abroad to almost any country — unless the Central Government expressly restricts that destination. No country has been blocked yet, but Significant Data Fiduciaries face tighter localisation rules for specific categories of data.
Key points
- The DPDP Rules, 2025 were officially notified on 14 November 2025 (Gazette reference G.S.R. 846(E)) and set out detailed compliance obligations for every organisation that processes the personal data of individuals in India.
- Cross-border transfers follow a “negative list” model: transfers are permitted everywhere unless the Central Government specifically restricts a country — and no country has been restricted so far.
- Rule 15 is the operative provision for cross-border transfers: a Data Fiduciary may transfer personal data outside India except where the Central Government restricts such transfer — no standard contractual clauses, adequacy assessments, or transfer impact evaluations are required by default.
- Significant Data Fiduciaries (SDFs) face an additional obligation under Rule 13(4): certain categories of personal data specified by a government-constituted committee must not leave India at all — though no such categories have been notified yet.
- Existing sectoral rules — for example, payments data localisation — continue to apply alongside the DPDP framework.
- Most substantive obligations come into force 18 months after notification, i.e., 14 May 2027, giving businesses a compliance runway.
What law governs DPDP cross-border data transfer in India?
Two layers of law apply. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) sets the overall framework, and the DPDP Rules, 2025 fill in the operational detail.
Section 16 of the DPDP Act is the parent provision. It allows personal data to be transferred to any country or territory outside India, subject only to restrictions the Central Government may impose.
Rule 15 of the DPDP Rules, 2025 operationalises Section 16. Its text is short and deliberate: “A Data Fiduciary may transfer personal data outside India except where the Central Government restricts such transfer.”
That’s it. No adequacy decisions. No standard contractual clauses. No transfer impact assessments — unless the government imposes them later by notification.
How does India’s model differ from GDPR?
Most founders who’ve dealt with European privacy law expect an “adequacy” or “whitelist” approach — you can only transfer data to countries the regulator has approved as providing sufficient protection.
India has flipped this logic. The table below summarises the key difference.
| Feature | GDPR (EU) approach | DPDP Rules 2025 (India) approach |
|---|---|---|
| Default rule | Transfers blocked unless destination is approved | Transfers permitted unless destination is restricted |
| List type | Whitelist / adequacy list | Negative / blacklist |
| Additional safeguards required by default? | Yes — SCCs, BCRs, or adequacy decision needed | No — unless the government notifies specific conditions |
| Current restricted countries | Multiple (non-adequate countries require safeguards) | None notified as of 27 June 2026 |
For most Indian startups, the practical effect is significant: you can currently route data to AWS servers in the US, use a UK-based analytics provider, or store backups in Singapore without needing to sign any special data transfer agreement under the DPDP framework.
What are Significant Data Fiduciaries and why do they face stricter rules?
Not every organisation is treated the same. The Central Government can designate certain organisations as “Significant Data Fiduciaries” (SDFs) based on factors such as the volume of data processed, sensitivity of data, and potential risk to national security or public order.
Once designated as an SDF, Rule 13(4) kicks in. This rule requires an SDF to ensure that personal data of the categories specified by the Central Government — following recommendations of a committee that must include MeitY officials and may include officials from other ministries — is not transferred outside India at all.
This is genuine data localisation: a hard prohibition on certain data leaving the country, not merely a condition on how it travels.
What categories of data are localised for SDFs?
As of the date of this article, the Central Government has not notified any specific data categories under Rule 13(4). The committee required to make recommendations has not yet published its conclusions.
That means even if you are (or expect to be) designated an SDF, you cannot finalise your data architecture around Rule 13(4) localisation requirements yet — you’ll need to watch for government notifications. Check our Law for You guides for plain-language updates as the rules develop.
What about sectoral data localisation rules?
The DPDP framework does not override existing sectoral obligations. If your startup processes payments data, the Reserve Bank of India’s rules on payments data localisation continue to apply independently.
Always check whether your sector — fintech, health tech, telecom — has its own regulator-specific localisation requirements alongside the DPDP regime.
When do these rules actually become binding?
MeitY has structured implementation across three phases. The table below maps out the timeline based on the gazette notifications of 14 November 2025.
| Date | What comes into force |
|---|---|
| 13–14 November 2025 (immediate) | Rules 1, 2, and 17–21: definitions, Data Protection Board constitution and appointments, Board procedures, digital functioning, and terms of service |
| 13–14 November 2026 (one year after notification) | Rule 4: Consent Manager registration and obligations |
| 13–14 May 2027 (eighteen months after notification) | Substantive provisions of the DPDP Act and remaining DPDP Rules, including cross-border transfer and localisation obligations |
This phased approach gives most startups time to build compliance systems before enforcement begins. However, “compliance runway” does not mean “ignore it” — data architectures take time to change, and building localisation or transfer-logging capabilities into your product from day one is far cheaper than retrofitting.
What does this mean practically for your startup?
If you are a general Data Fiduciary (not an SDF)
You can continue to use global cloud infrastructure, international SaaS vendors, and overseas data processors without specific DPDP-mandated contractual mechanisms — at least until the government notifies a restricted country or imposes new conditions.
Document your cross-border data flows anyway. The government can add countries to the restricted list at any time, and knowing where your data goes will help you respond quickly.
If you may be classified as an SDF
Plan conservatively. Even though Rule 13(4) localisation categories have not been notified, large consumer platforms, health data processors, and any organisation processing significant volumes of sensitive data should build technical capability to isolate and store particular data categories domestically on short notice.
Watch for notifications from MeitY and the as-yet-unnamed committee on which categories will be localised.
Frequently asked questions
Do I need standard contractual clauses (SCCs) for DPDP cross-border data transfers from India?
No — not under the current DPDP Rules. Rule 15 permits transfers to any country that the Central Government has not expressly restricted, and no additional mechanisms such as SCCs or transfer impact assessments are required by default. This may change if the government notifies specific conditions for particular countries or categories of data, so monitor official notifications from MeitY.
Which countries are currently blacklisted under the DPDP Rules 2025?
As of 27 June 2026, the Central Government has not restricted any country under the DPDP framework. Transfers to all jurisdictions remain permissible under Rule 15. The government has the authority to add countries to a restricted list at any time by notification, so it is good practice to keep your cross-border data flow records up to date.
When do the cross-border transfer obligations under the DPDP Rules become enforceable?
The substantive provisions of the DPDP Act and Rules — including the cross-border transfer and localisation obligations — are scheduled to come into force approximately 18 months after the Rules were notified, which works out to around 14 May 2027. However, the government could accelerate or adjust this timeline, and SDFs should begin planning now given the complexity of data architecture changes.
This article is for general information only and is not legal advice. Laws change; verify against the primary sources cited and consult a qualified advocate for your situation.


