THE RULES

Rule 15 - Processing of personal data of Data Principals outside India

Official text

Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

Cross-references

Rule 15

Commentary

Rule 15 adopts a generally permissive approach to cross-border transfers. Personal data processed under the DPDPA may be transferred outside India, but the Data Fiduciary must comply with any requirements that the Central Government specifies concerning the subsequent availability of that data to a foreign State, a foreign State-controlled entity, or an agency of a foreign State.

The Rule therefore does not impose a general localisation requirement, does not establish a whitelist of approved countries, and does not reproduce the European Union’s adequacy, Standard Contractual Clauses or transfer-impact-assessment framework. Its principal concern is narrower but significant: even where ordinary overseas processing is permitted, the Central Government may regulate the circumstances in which the transferred personal data becomes available to foreign governmental authorities or entities under their control.

The final DPDP Rules were notified on 13 November 2025 and Rule 15 is scheduled to commence on 13 May 2027.

Rule 15 must be read with Section 16 of the DPDPA and Section 38.

Section 16 permits the Central Government to restrict the transfer of personal data by a Data Fiduciary to a notified country or territory outside India. It also preserves any other Indian law that provides a higher degree of protection for, or restriction on, the transfer of personal data outside India. The Act itself therefore adopts a restricted-destination model rather than requiring advance approval for every overseas transfer. The official text of the DPDPA was published on 11 August 2023.

Rule 15 adds another regulatory layer. It recognises that personal data may ordinarily be transferred outside India, but requires compliance with any general or special order governing the availability of that data to:

  • a foreign State;

  • a person or entity controlled by a foreign State; or

  • an agency of a foreign State.

The complete cross-border framework consequently has several layers:

  1. an overseas transfer is generally permissible under Rule 15;

  2. the Central Government may restrict transfers to particular countries or territories under Section 16;

  3. the Government may impose requirements concerning foreign governmental access under Rule 15;

  4. a Significant Data Fiduciary may be required under Rule 13 to keep specified personal data and associated traffic data within India;

  5. another Indian law may impose stricter sectoral or data-specific restrictions; and

  6. the Data Fiduciary remains subject to all ordinary DPDPA obligations despite the overseas transfer.

Permission to transfer is therefore not permission to transfer without governance.

2. A transfer does not change the Data Fiduciary’s responsibility

A Data Fiduciary remains responsible for processing undertaken on its behalf by a Data Processor, including where the Processor operates outside India.

An organisation cannot avoid its DPDPA obligations by moving personal data to:

  • an overseas cloud region;

  • a global payroll provider;

  • an international customer-support centre;

  • a foreign software platform;

  • an overseas analytics service;

  • a global human-resources system;

  • a foreign parent or group company;

  • an international fraud-monitoring centre;

  • or an AI service hosted abroad.

The Data Fiduciary must continue to ensure that the processing is lawful, purpose-bound, secure and consistent with the rights of Data Principals.

This means that before an overseas transfer, the Data Fiduciary should understand:

  • why the transfer is necessary;

  • what personal data will leave India;

  • which entity will receive it;

  • whether that recipient is a Processor or an independent Data Fiduciary;

  • where the data will be stored and accessed;

  • whether subprocessors are involved;

  • whether the information will move onward to other countries;

  • what security safeguards apply;

  • how a personal data breach will be reported;

  • how correction, erasure and consent withdrawal will be implemented;

  • what retention period applies;

  • and whether a foreign public authority may obtain access.

These are not separate formalities detached from Rule 15. They are necessary to determine whether the Data Fiduciary can continue observing the DPDPA once the information leaves its direct infrastructure.

2.1 Illustration: Overseas payroll provider

An Indian employer sends employee names, salary information, bank details, tax information and attendance records to a payroll provider operating through an overseas cloud environment.

Rule 15 may permit the transfer, provided no destination restriction or other stricter law applies. But the employer remains responsible for ensuring that:

  • the payroll provider processes the information only for authorised payroll purposes;

  • access is appropriately restricted;

  • required security safeguards are maintained;

  • the provider promptly reports breaches;

  • employee corrections are propagated;

  • unnecessary information is erased;

  • subprocessors are controlled;

  • and any applicable governmental-access order is followed.

The fact that payroll software is globally used does not itself establish DPDP compliance.

3. What amounts to a cross-border transfer

The Rule does not confine transfer to the physical relocation of a database. In practical terms, personal data may be transferred outside India whenever it is transmitted, replicated, disclosed or otherwise made available to a recipient or system outside India.

Relevant arrangements can include:

  • uploading data to an overseas server;

  • storing backups in a foreign cloud region;

  • replicating an Indian database abroad;

  • sending files by email to an overseas recipient;

  • permitting a foreign support team to access an Indian-hosted system;

  • routing customer information through a global helpdesk;

  • submitting personal data to an overseas AI service;

  • transferring logs to a foreign security-monitoring centre;

  • making data available through a global group database;

  • or enabling an overseas administrator to view or download records.

The location of the primary server is therefore not the only consideration.

3.1 Illustration: Indian storage with overseas support

A company stores its customer database in an Indian data centre. Its technology provider’s support team in another country can log in remotely and view customer records whenever a support ticket is raised.

The company should treat this arrangement as involving cross-border availability of personal data. Saying that the server remains physically in India does not fully describe the processing.

3.2 Illustration: Overseas backup

An organisation processes all active personal data in India but automatically sends daily backups to a foreign disaster-recovery site.

The backup is itself personal data. The overseas replication is relevant to Rule 15, Section 16, security requirements and any applicable sectoral localisation requirement.

3.3 Illustration: AI drafting service

An employee submits a customer complaint containing names, account information and transaction history to an AI platform. The platform processes the prompt abroad.

This is an overseas processing event even if the employee receives the output immediately and does not deliberately save the prompt. The Data Fiduciary must assess the provider, its use of inputs, retention, subprocessors, security and foreign governmental-access exposure before permitting such use.

4. No general data-localisation requirement

Rule 15 begins from the proposition that personal data processed under the Act may be transferred outside India. The Rule therefore does not impose a universal requirement that:

  • all personal data be collected in India;

  • the primary copy be stored in India;

  • a mirror copy be maintained in India;

  • processing occur only through Indian personnel;

  • or every cloud service use an Indian region.

This is an important distinction from regimes that mandate general or sector-wide localisation.

However, the absence of general localisation does not mean that no localisation obligation can apply. Restrictions may arise from:

  • a country or territory notified under Section 16;

  • a Rule 15 governmental-access order;

  • Rule 13 concerning specified data processed by a Significant Data Fiduciary;

  • banking, payment, insurance, telecommunications or other sectoral regulation;

  • a court or regulatory direction;

  • or another Indian law providing a higher degree of protection or restriction.

The transfer analysis must therefore be performed for the particular Data Fiduciary, data category, sector, destination, system and recipient.

4.1 Illustration: Two datasets, different treatment

A financial institution uses the same international cloud provider for:

  • employee learning records; and

  • regulated payment-system data.

The fact that ordinary employee learning records may be transferable under the DPDPA does not establish that the payment-system data may use the same overseas architecture. A stricter sectoral localisation rule may govern the latter.

Rule 15 does not displace that stricter requirement.

5. Negative-list approach under Section 16

The DPDPA does not establish an approved-country list requiring the recipient country to be formally declared adequate before transfer.

Instead, Section 16 permits the Central Government to restrict transfers to notified countries or territories. The practical starting point is therefore that transfers may occur unless:

  • the destination is restricted;

  • the data is subject to Rule 13 localisation;

  • a Rule 15 order imposes relevant requirements;

  • or another law imposes a higher restriction.

A Data Fiduciary should maintain a process for monitoring government notifications and orders. Destination legality can change after a vendor is appointed.

5.1 Illustration: Existing cloud contract

A company enters into a five-year contract under which customer data is processed in several overseas regions. A later Central Government notification restricts transfer to one of those destinations.

The company cannot continue transferring data merely because the contract predates the restriction. It may need to:

  • stop new transfers;

  • migrate the processing;

  • restrict access;

  • change subprocessors;

  • address existing foreign copies;

  • or terminate the affected service.

Cross-border contracts should therefore include mechanisms for regulatory change, migration and data return.

6. Rule 15’s central concern: foreign governmental access

The distinctive feature of Rule 15 is its treatment of personal data made available to a foreign government or an entity connected with that government.

Overseas data may become available to a foreign State through:

  • a court order;

  • law-enforcement demand;

  • national-security direction;

  • regulatory request;

  • administrative subpoena;

  • compulsory production notice;

  • interception requirement;

  • direct access power;

  • or a request made to a State-controlled service provider.

Rule 15 empowers the Central Government to specify requirements that the Indian Data Fiduciary must satisfy in relation to that availability.

The Rule therefore addresses a risk that ordinary vendor due diligence may overlook. A foreign service provider may maintain strong security and still be legally compelled under its domestic law to disclose information to a governmental authority.

6.1 Illustration: Foreign law-enforcement demand

An overseas cloud provider receives a legally binding demand from a foreign enforcement agency seeking account records belonging to customers of an Indian Data Fiduciary.

The issue is not merely whether the cloud provider’s contract permits disclosure. The Indian Data Fiduciary must also comply with any applicable requirement specified by the Central Government under Rule 15.

Such a requirement could potentially address matters such as:

  • notification to the Indian Data Fiduciary;

  • review of legal validity;

  • limitation of disclosure;

  • challenge where legally permissible;

  • record keeping;

  • encryption or key control;

  • reporting to an Indian authority;

  • or restrictions on particular forms of access.

The precise obligation will depend on the relevant general or special order. Rule 15 itself creates the power and compliance duty but does not prescribe all of those controls in advance.

7. Foreign State, State-controlled entities and State agencies

Rule 15 is not limited to a conventional ministry, police force or intelligence agency. It also extends to:

  • a person or entity under the control of a foreign State; and

  • an agency of that State.

This has practical importance in countries where cloud infrastructure, telecommunications services, identity systems, data centres or technology providers may be owned or controlled by the government.

A Data Fiduciary should therefore understand not only where the recipient is incorporated but also:

  • who owns or controls it;

  • whether it performs governmental functions;

  • whether it is legally subject to direct governmental instructions;

  • and whether its subprocessors are State-controlled.

7.1 Illustration: State-controlled cloud provider

An Indian business uses a foreign cloud provider that is majority owned and controlled by the foreign government.

Even if the provider operates commercially, personal data made available to it may fall within the specific concerns addressed by Rule 15. The Data Fiduciary must determine whether a general or special order applies and what requirements must be satisfied.

7.2 Illustration: Private company responding to a State agency

A privately owned overseas provider receives a demand from a foreign intelligence or enforcement agency.

The provider itself may not be State-controlled, but the personal data is being made available to an agency of a foreign State. The Rule can therefore remain relevant.

8. General and special orders

The Central Government may specify requirements through either a general order or aspecial order.

A general order may apply broadly, for example, to:

  • all Data Fiduciaries;

  • a class of Data Fiduciaries;

  • a category of personal data;

  • a destination;

  • a category of foreign governmental request;

  • or a type of recipient.

A special order may apply to:

  • a particular Data Fiduciary;

  • a stated processing arrangement;

  • a specific foreign authority;

  • a particular incident;

  • or identified personal data.

The distinction allows the Government to respond both through general regulatory policy and through targeted intervention.

A Data Fiduciary should not assume that all relevant requirements will appear only in the DPDP Rules or in a public country-restriction list. Compliance may depend on a later order addressed to a class or, in appropriate circumstances, to the particular organisation.

8.1 Effect of an order

Once an applicable order specifies requirements, compliance is mandatory. The Data Fiduciary should translate the legal conditions into:

  • contract terms;

  • access restrictions;

  • technical architecture;

  • vendor instructions;

  • staff procedures;

  • incident-escalation rules;

  • and records of governmental requests.

An internal policy stating that foreign-access demands are handled by the vendor will not be sufficient if the order places responsibility on the Data Fiduciary.

9. Rule 15 does not itself prescribe the GDPR transfer model

The DPDPA framework should not be described using GDPR concepts as though they were requirements of Indian law.

Rule 15 does not expressly require:

  • an adequacy decision;

  • Standard Contractual Clauses;

  • Binding Corporate Rules;

  • a transfer-impact assessment in the GDPR sense;

  • reliance on derogations;

  • or approval from the Data Protection Board before transfer.

An Indian Data Fiduciary may voluntarily use contractual clauses, transfer assessments or group rules as governance tools. Those mechanisms can help it satisfy its DPDPA obligations. They do not become mandatory merely because they are familiar from the GDPR.

9.1 Illustration: European Processor

An Indian Data Fiduciary appoints a Processor in the European Union. The parties sign GDPR Standard Contractual Clauses even though the relevant transfer originates from India.

The clauses may provide protections concerning security, onward transfer, governmental requests and rights assistance. But execution of the SCCs does not, by itself, prove compliance with Rule 15.

The Data Fiduciary must still consider:

  • Indian destination restrictions;

  • applicable Central Government orders;

  • Rule 13 localisation;

  • sectoral Indian law;

  • Processor security;

  • purpose limitation;

  • retention;

  • breach reporting;

  • and Data Principal rights.

Conversely, Rule 15 compliance does not automatically satisfy the GDPR where the GDPR independently applies.

10. Contractual safeguards

Rule 15 does not expressly prescribe a standard cross-border contract. Nevertheless, a Data Fiduciary cannot effectively manage overseas processing without enforceable contractual provisions.

Where the foreign recipient is a Data Processor, the contract should ordinarily address:

  • processing only on documented instructions;

  • permitted purposes;

  • personal-data categories;

  • authorised locations;

  • security safeguards;

  • confidentiality;

  • access control;

  • subprocessors;

  • onward transfers;

  • breach notification;

  • rights assistance;

  • correction and erasure;

  • retention;

  • audit and assurance;

  • governmental-access requests;

  • conflict of laws;

  • regulatory change;

  • migration;

  • return and deletion;

  • and evidence of compliance.

10.1 Government-access clauses

A contractual provision may require the Processor, to the extent legally permitted, to:

  • notify the Data Fiduciary of a governmental request;

  • verify that the request is legally valid;

  • direct the requesting authority to the Data Fiduciary where appropriate;

  • challenge an overbroad or unlawful demand;

  • disclose only the minimum information legally required;

  • maintain a record of the request and response;

  • preserve confidentiality;

  • and provide aggregate transparency information.

Such clauses are useful but have limits. A contract cannot override a binding foreign law. The Data Fiduciary must assess whether technical and organisational measures are also needed.

10.2 Illustration: Contractual promise defeated by foreign law

A cloud contract states that the provider will never disclose customer data without the customer’s permission. The law of the provider’s country authorises secret compulsory disclosure and prohibits notification.

The contractual promise may not provide effective protection in that situation. The Data Fiduciary should consider the legal environment, encryption design, key control, data minimisation and whether another processing location is more appropriate.

11. Technical safeguards for overseas transfers

The ability to transfer personal data outside India does not reduce the Rule 6 security obligation.

Depending on risk, safeguards may include:

  • encryption in transit and at rest;

  • customer-controlled or India-controlled encryption keys;

  • tokenisation before transfer;

  • masking;

  • pseudonymisation;

  • separation of identifying information;

  • strict role-based access;

  • multifactor authentication;

  • logging of foreign access;

  • restrictions on downloads;

  • data-loss prevention;

  • geographic access controls;

  • segmentation;

  • local processing of high-risk fields;

  • and secure deletion.

The appropriate safeguards depend on what the foreign recipient must do with the data.

11.1 Illustration: Analytics without identity

An Indian retailer wants an overseas vendor to analyse purchasing patterns. The vendor does not need customer names, mobile numbers or full account identifiers.

The Data Fiduciary can reduce risk by transferring pseudonymous transaction data and retaining the identifying key separately in India. The information may still remain personal data if re-identification is reasonably possible, but the safeguards reduce the consequences of unauthorised access.

11.2 Illustration: Foreign support access

A foreign technical-support team occasionally needs diagnostic access to an application.

Instead of granting standing access to the entire customer database, the Data Fiduciary may use:

  • time-limited access;

  • approval for each session;

  • masked records;

  • session recording;

  • restricted commands;

  • no-download controls;

  • and supervised support.

Rule 15 permits cross-border processing, but the general reasonableness and necessity requirements still govern its design.

12. Onward transfers and subprocessors

An overseas recipient may pass personal data to further recipients in other countries.

Example

For example, a software provider may use:

  • one cloud provider for hosting;

  • another provider for customer support;

  • a separate security-monitoring service;

  • a payment provider;

  • and an AI vendor.

The Data Fiduciary should therefore map the entire transfer chain, not merely the first contractual recipient.

A destination that is permissible for the primary Processor may not be permissible for a subprocessor if:

  • the subprocessor is in a restricted country;

  • a Rule 15 order applies to its governmental-access environment;

  • a Rule 13 localisation restriction prohibits any overseas transfer;

  • or sectoral law prevents the arrangement.

12.1 Illustration: Undisclosed subprocessor

An Indian company contracts with a cloud provider in one country. The provider later appoints a support subprocessor in another country and begins routing customer tickets containing personal data to that team.

The Data Fiduciary should receive prior notice or approval rights sufficient to assess the new transfer. A contract that permits unlimited unnotified subprocessors may undermine the Data Fiduciary’s ability to comply with Rule 15 and Section 16.

13. Transfers within a corporate group

Personal data does not cease to be transferred merely because the overseas recipient belongs to the same corporate group.

Separate group companies are separate legal persons. Their roles should be examined factually.

An overseas parent or affiliate may act as:

  • a Data Processor for the Indian entity;

  • an independent Data Fiduciary for its own purpose;

  • a joint decision-maker;

  • or a recipient performing another role.

13.1 Illustration: Global HR database

An Indian subsidiary uploads employee information to a group-wide human-resources platform administered by its foreign parent.

The analysis should identify:

  • which entity determines the HR purposes;

  • which entity controls the platform;

  • whether the parent uses employee data for its own workforce analytics;

  • where the data is stored;

  • which group entities can access it;

  • how employee rights are fulfilled;

  • and whether foreign authorities can obtain access.

Calling the arrangement an “internal group transfer” does not remove it from Rule 15.

13.2 Independent use by a group company

If the foreign parent receives employee data to administer payroll on behalf of the Indian employer, it may act as a Processor for that purpose.

If it later combines the information across group companies to develop its own global workforce model, it may be determining a separate purpose. That activity requires its own legal analysis and cannot automatically rely on the original transfer purpose.

14. Transfers to an independent foreign Data Fiduciary

Not every foreign recipient is a Processor.

Where personal data is transferred to an overseas entity that determines its own purpose and means, contractual Processor clauses may not accurately describe the relationship.

Example

Examples may include:

  • an overseas bank receiving payment instructions;

  • an international travel provider delivering a requested service;

  • a foreign regulatory authority receiving data under law;

  • an independent insurer;

  • or a foreign professional adviser acting independently under applicable professional duties.

The transferring Data Fiduciary should identify:

  • the purpose of disclosure;

  • the lawful basis;

  • notice given to the Data Principal;

  • necessity;

  • categories of data;

  • recipient’s independent role;

  • retention;

  • onward disclosure;

  • and applicable cross-border restrictions.

A contract may still be necessary, but it should reflect the actual allocation of responsibility rather than incorrectly labelling every recipient a Data Processor.

15. Foreign-government requests received directly by the Data Fiduciary

Rule 15 can also matter where a foreign State or agency approaches the Indian Data Fiduciary directly.

The Data Fiduciary should not disclose personal data merely because the request bears the name of a foreign public authority.

It should assess:

  • authenticity of the request;

  • legal authority;

  • jurisdiction;

  • whether Indian law permits disclosure;

  • whether a treaty or recognised government channel applies;

  • whether a Central Government order imposes requirements;

  • whether the request is overbroad;

  • whether the Data Principal may be informed;

  • and whether only limited information should be supplied.

15.1 Illustration: Informal foreign police request

A foreign police officer emails an Indian platform seeking records about a user and states that the matter is urgent.

The platform should not treat the email alone as sufficient legal authority. It should verify the request and determine whether disclosure must proceed through an applicable legal-assistance process, Indian authority, court mechanism or another recognised route.

Urgency may affect escalation, but it does not replace legal authority.

16. Conflicting foreign laws

A foreign Processor may face a local disclosure requirement that conflicts with contractual restrictions or an Indian governmental order.

The possibility of conflict should be assessed before transfer, particularly for consequential data or jurisdictions with broad governmental-access powers.

The contract should require prompt escalation where legally permitted. The Data Fiduciary should have a process for:

  • legal assessment;

  • limitation of disclosure;

  • challenging requests;

  • migration;

  • suspension of transfer;

  • termination;

  • notification to Indian authorities where required;

  • and correction of future architecture.

A clause stating “the Processor shall comply with all applicable laws” does not resolve which action should be taken where two legal requirements conflict.

Rule 15 does not state that every cross-border transfer requires a separate standalone consent.

The legal basis for processing must be determined under Sections 4, 6 and 7. Where consent is the basis, the specified purpose and necessary personal data must be properly disclosed. If the overseas transfer is a material feature of the processing, the notice should not mislead the Data Principal about where and by whom the information will be processed.

The Data Fiduciary should not obtain vague consent for “sharing with partners worldwide” and treat it as unlimited authority for every future destination, recipient and purpose.

Nor should it rely on consent to override a statutory restriction. A Data Principal cannot consent around:

  • a Section 16 country restriction;

  • a Rule 13 localisation requirement;

  • an applicable Rule 15 order;

  • or stricter sectoral law.

17.1 Illustration: Optional overseas analytics

A platform seeks to transfer user activity to an overseas provider for optional product analytics unrelated to the core service.

If consent is the proposed basis, the notice and consent should clearly identify the purpose and relevant data. Bundling this optional transfer into acceptance of the core service may undermine the validity of consent.

17.2 Illustration: Necessary overseas reservation

A customer asks an Indian travel company to book accommodation abroad. The company must send limited identification and booking information to the overseas hotel to fulfil the request.

The transfer may be necessary for the requested service. The company should still provide an appropriate notice, limit the information shared and assess whether any destination or governmental-access restriction applies.

18. Data Principal rights after transfer

A foreign location does not reduce Data Principal rights under the DPDPA.

The Data Fiduciary must be able to implement, where applicable:

  • access;

  • correction;

  • completion;

  • updating;

  • erasure;

  • consent withdrawal;

  • grievance redressal;

  • and nomination across its overseas Processor environment.

18.1 Illustration: Correction at an overseas Processor

A customer corrects an inaccurate address in the Indian company’s application. The old address remains active in the overseas fulfilment provider’s system and continues causing deliveries to the wrong location.

The Data Fiduciary must ensure that correction reaches the Processor. Updating only the Indian customer profile is not sufficient if inaccurate personal data continues to be processed abroad.

18.2 Illustration: Erasure after account closure

A Data Principal closes an account and withdraws consent. The Indian Data Fiduciary erases the active Indian profile, but the overseas analytics provider keeps the full event history for product development.

The Data Fiduciary must determine whether the provider was authorised to use the data for that independent purpose. If it acted only as a Processor, the Data Fiduciary must cause erasure subject to lawful retention.

Cross-border transfer arrangements should therefore include practical mechanisms for locating, correcting and erasing information.

19. Retention outside India

Rule 15 may permit a transfer, but the foreign recipient cannot retain the data indefinitely simply because it operates under its own standard policy.

The Indian Data Fiduciary should define:

  • the service purpose;

  • the applicable retention period;

  • statutory retention;

  • return or deletion at termination;

  • backup expiration;

  • log retention;

  • legal holds;

  • and evidence of erasure.

19.1 Illustration: Vendor’s universal seven-year policy

An overseas software provider retains all customer data for seven years under a global corporate policy. The Indian Data Fiduciary’s purpose ends after one year, and no law requires the remaining data to be kept.

The vendor’s internal policy does not itself provide the Indian Data Fiduciary with a lawful basis for continued retention. The service and contract should be configured to follow the applicable purpose and legal period.

20. Personal data breaches involving overseas recipients

A breach at an overseas Processor can trigger the Data Fiduciary’s obligations under Section 8(6) and Rule 7.

The Processor must provide information quickly enough for the Data Fiduciary to:

  • identify affected Data Principals;

  • understand the nature and extent of the breach;

  • intimate affected individuals;

  • notify the Board;

  • submit the detailed report;

  • mitigate consequences;

  • and prevent recurrence.

20.1 Illustration: Global cloud breach

A foreign cloud provider detects unauthorised access to an environment containing records of Indian users. The provider follows its own internal reporting standard and waits several days before informing customers.

That delay may make it impossible for the Indian Data Fiduciary to meet Rule 7. The contract should therefore impose an escalation period tied to the Data Fiduciary’s Indian obligations rather than relying only on the provider’s general policy.

The foreign location of the breach does not remove the Board’s relevance where the affected processing falls under the DPDPA.

21. Relation to Rule 13 localisation

Rule 15 and Rule 13 must be kept distinct.

Rule 15 generally permits overseas transfer, subject to:

  • Section 16 restrictions;

  • governmental-access requirements;

  • and other applicable law.

Rule 13 permits the Central Government to specify personal data processed by a Significant Data Fiduciary that, together with traffic data pertaining to its flow, must not be transferred outside India.

If data is specified under Rule 13, the general permission in Rule 15 cannot be used to transfer it abroad.

21.1 Illustration: SDF using a global cloud

An SDF uses a global cloud architecture. The Central Government later specifies a category of personal data that must remain in India.

The SDF must identify all locations and flows involving that data, including:

  • backups;

  • support access;

  • analytics;

  • logs;

  • telemetry;

  • subprocessors;

  • and AI services.

Keeping only the principal database in India may not be sufficient if specified personal data or related traffic data continues moving abroad.

22. Relation to stricter sectoral law

Section 16 expressly preserves Indian laws that impose a higher degree of protection or restriction on overseas transfers.

This means the DPDPA is not necessarily the final rule for every sector.

A Data Fiduciary may separately be subject to requirements issued by:

  • the Reserve Bank of India;

  • the Securities and Exchange Board of India;

  • the Insurance Regulatory and Development Authority of India;

  • telecommunications authorities;

  • health regulators;

  • government procurement authorities;

  • or another competent body.

Rule 15 cannot be invoked to override a stricter obligation.

22.1 Illustration: Permissible under Rule 15, restricted by sectoral rule

A regulated entity concludes that the destination is not restricted under Section 16 and no Rule 15 order prevents transfer.

If an applicable sectoral rule still requires the relevant data to remain in India or imposes conditions on outsourcing, the transfer must comply with that stricter rule.

The cross-border assessment must therefore be sector-specific, not limited to reading Rule 15 in isolation.

23. Transfers involving children or persons represented by guardians

The transfer of children’s personal data remains subject to Sections 9 and Rules 10 to 12.

Where parental consent is required, verifying the parent does not itself authorise every overseas disclosure. The child-data purpose, notice, necessity, well-being and restrictions on monitoring or targeted advertising remain relevant.

Similarly, where a lawful guardian gives consent for a person with disability under Rule 11, the guardian’s authority must cover the relevant processing. A guardianship appointment is not unlimited permission to send the person’s data to foreign recipients for unrelated uses.

23.1 Illustration: Overseas educational platform

A school uses an overseas learning platform for educational activities. Even where a Fourth Schedule exemption applies to limited educational monitoring, the school must still assess:

  • which student data is transferred;

  • whether the provider acts only on instructions;

  • whether it trains independent models;

  • retention;

  • security;

  • governmental-access exposure;

  • and applicability of Section 16 and Rule 15.

The educational exemption does not create a cross-border safe harbour.

24. Organisational implementation

An effective Rule 15 programme should form part of the Data Fiduciary’s ordinary data governance rather than exist as a one-time legal memorandum.

The Data Fiduciary should maintain a current view of:

  • overseas recipients;

  • types of personal data transferred;

  • purposes;

  • destinations;

  • hosting and backup locations;

  • access locations;

  • subprocessors;

  • transfer methods;

  • governmental-access exposure;

  • applicable orders;

  • Section 16 restrictions;

  • sectoral restrictions;

  • security measures;

  • retention;

  • and rights support.

24.1 Change management

The organisation should reassess a transfer where:

  • the provider changes hosting location;

  • a new subprocessor is appointed;

  • foreign support access is introduced;

  • a new category of personal data is transferred;

  • the purpose changes;

  • the provider begins using customer data for model training;

  • a government notification restricts a destination;

  • a Rule 15 order is issued;

  • Rule 13 localisation applies;

  • or a breach reveals a new risk.

24.2 Illustration: SaaS configuration change

A software provider initially processes data only in India. It later enables a global support feature that automatically sends diagnostic logs containing user information to another country.

The original assessment is no longer complete. The Data Fiduciary must evaluate the new flow before or when the configuration changes.

25. Approach to foreign-government requests

A Data Fiduciary should establish a specific governance process for foreign-government access.

A mature procedure should ensure that:

  1. requests received by the Data Fiduciary or Processor are escalated promptly;

  2. authenticity and legal authority are examined;

  3. applicable Rule 15 orders are identified;

  4. disclosure is limited to what is legally required;

  5. challenge or redirection is considered where lawful;

  6. confidentiality restrictions are understood;

  7. disclosure is securely transmitted;

  8. the request, assessment and response are recorded;

  9. the Data Principal is informed where legally permitted and required; and

  10. recurring or systemic risks are reviewed.

The procedure should not leave these decisions solely to an overseas vendor’s customer-support team.

26. Government-access transparency

A Data Fiduciary conducting consequential overseas processing should seek enough information to understand the recipient’s experience and procedures concerning governmental access.

Relevant information may include:

  • the jurisdictions whose laws apply;

  • categories of authorities that may request data;

  • whether the provider reviews legal validity;

  • whether it challenges overbroad requests;

  • whether it redirects authorities to the customer;

  • whether it notifies customers when permitted;

  • whether it publishes transparency reports;

  • whether it can disclose only selected data;

  • and whether encryption prevents direct access.

This assessment should be proportionate. A foreign recipient handling a small set of business contact details may not require the same examination as a provider processing:

  • detailed financial information;

  • health records;

  • identity documents;

  • children’s information;

  • biometrics;

  • large-scale behavioural records;

  • or sensitive government-related data.

Several interpretations of Rule 15 should be avoided.

27.1 “The DPDPA allows unrestricted international transfer”

Incorrect. Transfer is generally permitted, but remains subject to Section 16, Rule 15 orders, Rule 13 localisation and stricter Indian laws.

Incorrect. Consent cannot override a governmental restriction or stricter legal requirement. Consent must also be valid, specific and connected to the processing purpose.

27.3 “Indian server location means no overseas transfer”

Incorrect. Foreign remote access, backups, analytics, logs and support processing may still create cross-border availability.

27.4 “A global vendor’s standard contract is sufficient”

Incorrect. Standard terms may not address Indian governmental-access orders, rights support, breach timing, destination changes, Processor use or local retention requirements.

27.5 “Every overseas recipient is a Data Processor”

Incorrect. The role depends on who determines the purpose and means of processing.

27.6 “Rule 15 requires GDPR SCCs”

Incorrect. Rule 15 does not prescribe the GDPR transfer mechanisms, although similar contractual protections may support governance.

27.7 “Every SDF must localise all data”

Incorrect. Rule 13 localisation depends on Central Government specification of particular personal data.

27.8 “Foreign law decides the entire disclosure question”

Incorrect. The Indian Data Fiduciary must also consider the DPDPA, applicable Central Government orders, Indian sectoral rules and recognised legal channels.

28. Enforcement implications

A significant contravention of Rule 15 or Section 16 may fall within the residual penalty entry for breach of another provision of the Act or Rules, carrying a maximum monetary penalty of up to ₹50 crore.

The maximum is not automatic. The Board must conduct the statutory inquiry, give the person an opportunity of being heard and apply the Section 33 factors.

A transfer failure may be especially serious where the Data Fiduciary:

  • knowingly transfers data to a restricted destination;

  • ignores an applicable general or special order;

  • allows a foreign State-controlled entity to access personal data contrary to specified requirements;

  • misrepresents where data is processed;

  • fails to identify foreign support or backup access;

  • permits uncontrolled onward transfers;

  • transfers Rule 13-localised data abroad;

  • ignores a stricter sectoral requirement;

  • fails to control a foreign Processor;

  • or continues transfer after becoming aware of non-compliance.

The same facts may engage separate penalty categories. For example:

  • inadequate security at the foreign Processor may engage Section 8(5);

  • failure to intimate an overseas breach may engage Section 8(6);

  • failure to erase foreign copies may engage the erasure framework;

  • and unlawful processing of children’s data abroad may engage Section 9.

Conclusion

Rule 15 establishes aconditional permission model for cross-border processing.

Its starting point is that personal data may be transferred outside India. That permission is subject to four principal boundaries:

  1. the Central Government may restrict transfers to specified countries or territories under Section 16;

  2. the Data Fiduciary must meet requirements imposed by general or special order concerning access by a foreign State, its agencies or entities under its control;

  3. specified data processed by an SDF may be prohibited from leaving India under Rule 13; and

  4. another Indian law may impose a higher degree of protection or transfer restriction.

Within those boundaries, the Data Fiduciary remains fully accountable for overseas processing. It must understand the recipient’s role, destination, subprocessors, onward transfers, security, retention, governmental-access exposure and ability to support Data Principal rights.

The Rule does not require every Data Fiduciary to reproduce the GDPR transfer framework. It also does not allow international processing to be treated as a routine procurement issue. Cross-border transfer is a continuing data-governance decision requiring legal, contractual, technical and operational control.

Key point

Rule 15 permits personal data to move outside India, but it does not permit responsibility to move with it. The Data Fiduciary remains answerable for the purpose, recipient, security, retention, onward transfer, rights support and governmental-access conditions attached to the data. Overseas processing is lawful only while the complete arrangement remains consistent with the DPDPA, Central Government restrictions and any stricter Indian law.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.