Cross-border transfers and localisation
Act section 16 and Rule 15 are scheduled for 13 May 2027.
The DPDP model is not a blanket “India-only” requirement. Section 16 permits the Central Government to restrict transfer to notified countries or territories and preserves Indian laws that provide a higher degree of protection or restriction. Rule 15 permits requirements concerning making personal data available to a foreign State, or a person/entity under its control.
As of the cut-off, this research pass did not locate a general restricted-country order, a general Rule 15 order or a Rule 13(4) SDF data-localisation specification. Absence of those DPDP instruments does not displace existing sector restrictions.
Transfer inventory
Section titled “Transfer inventory”Record more than primary storage location:
- source/destination country and legal entities;
- controller/Fiduciary and processor roles;
- data, purpose, Principal population and volume;
- storage, backup, disaster recovery, logs, telemetry and support access;
- encryption/key location and administrators;
- subprocessors and onward transfers;
- foreign-government access exposure;
- DPDP order, SDF rule, sector rule and contract;
- exit and deletion method.
Remote access from outside India is evaluated; “the database is in Mumbai” is incomplete when support staff, logs, keys or replicas are elsewhere.
Policy resolution
Section titled “Policy resolution”ALLOW only if: no active DPDP restricted-country rule blocks destination AND any Rule 15 foreign-State availability requirement is met AND any SDF specified-data/traffic-data rule is met AND every sector rule permits the topology AND contract/customer policy permits the topology AND security assessment is approvedUnknown is not allow. It enters legal review without asserting prohibition.
Deployment controls
Section titled “Deployment controls”The deployment policy can constrain region, backup region, object-store replication, KMS/HSM, observability sink, support session, outbound connector and subprocessor. Evidence combines cloud inventory, configuration policy results and periodic access tests.
Sector examples
Section titled “Sector examples”- RBI-regulated entities must apply the exact outsourcing, payment-data or activity-specific instruments applicable to them; one RBI circular cannot be generalised to all financial data.
- SEBI entities apply their entity class, CSCRF/cloud framework and later clarifications.
- ABDM participation brings ecosystem policy and consent artefacts but is not a universal health data localisation statute.
- Customer contracts may require India-only handling even where public law does not.
Acceptance tests
Section titled “Acceptance tests”- Given India primary storage and Singapore log export, when assessed, then Singapore appears as a transfer/access destination.
- Given a future country restriction, when legal configuration activates, then affected connector deployments are blocked and existing flows generate remediation—not silently deleted.
- Given no SDF localisation notification, then no DPDP “India-only” badge appears.