Rule 15 · Rule 13(4)

Rule 15: Cross-Border Data Transfers

Rule 15 permits personal data processed under the Act to be transferred outside India, subject to requirements the Central Government may specify for making such data available to a foreign State or related entities. It is not a ban on transfers and not a blanket data-localisation mandate.

What Rule 15 says

Rule 15 provides that any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India, subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

Read carefully: the default framing is permissibility of transfer, qualified by government orders that may set requirements for availability to foreign States and related persons or entities. That is a different design from a statute that prohibits outbound transfer unless an adequacy finding or standard contractual clause is used. Do not describe Rule 15 as a blanket ban or as a rule that all Indian personal data must remain in India.

Separately, Rule 13(4) addresses Significant Data Fiduciaries. An SDF shall undertake measures so that personal data specified by the Central Government (on recommendations of a committee constituted for that purpose) is processed subject to the restriction that such personal data and traffic data pertaining to its flow are not transferred outside India. That SDF-specific mechanism depends on government specification of the relevant personal data; it is not a general localisation rule for every Fiduciary.

What it means in practice

Inventory where personal data is stored, processed and accessed — including cloud regions, group companies, processors and support tools. Track Central Government orders under Rule 15 as they are issued, and assess whether your transfers make data available in the sense the Rule contemplates. Contract and architecture choices should remain flexible enough to meet future specified requirements.

If you are notified as a Significant Data Fiduciary, monitor Rule 13(4) specifications of personal data that must not be transferred outside India, including related traffic data. Until such data is specified, do not invent categories or assume GDPR-style transfer tools are required by DPDP.

Cross-border processing still sits under the rest of the Act: purpose, notice, consent or legitimate use, security, retention and rights. Transfer permission under Rule 15 does not waive those obligations.

Common mistakes

  • Claiming DPDP bans cross-border transfers or requires all personal data to stay in India.
  • Applying Rule 13(4) SDF transfer restrictions to organisations that are not Significant Data Fiduciaries, or inventing restricted data categories before government specification.
  • Importing GDPR transfer mechanisms as if they were DPDP Rule 15 requirements.
  • Ignoring government orders once issued under Rule 15’s “general or special order” mechanism.

Official source

ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.

Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.