DPDP Wiki Talk to us

/The Rules · 2025

Rule 15: Transfer of personal data outside the territory of India

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 15 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 16 Processing of personal data outside India
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 15. Transfer of personal data outside the territory of India

Verbatim from the Gazette of India

Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryCentral Government

Rule 15 explains how a Data Fiduciary (an entity that determines the purpose and means of processing data) can transfer personal data outside India. Generally, the rule allows personal data to be transferred internationally under the Act.\n\nHowever, there is a specific restriction when the data is made available to a foreign government. If the data will be accessible to a foreign State, its agencies, or any person or entity controlled by that State, the Data Fiduciary must follow special requirements.\n\nThe Central Government will define these exact requirements later through a general or special order. The rule establishes that these specific government-related transfers will be regulated by those future orders.

Key points

  • A Data Fiduciary may transfer personal data outside the territory of India.
  • Transfers are restricted if the data is made available to a foreign State, its agencies, or entities under its control.
  • The Central Government will specify the requirements for these restricted transfers through a general or special order.

Common misreadings

  • People might think all international data transfers are blocked, but the rule generally allows them subject to specific government orders regarding foreign States.
  • People might assume the requirements are already listed in this rule, but the Central Government will specify them later by order.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.