Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Transfers + infrastructure

Cross-border processing under DPDP: what is known, what remains conditional

A useful transfer map separates current architecture facts from future-cohort rules, Government orders, SDF-specific specifications and other applicable law.

The transfer decision map

Architecture facts, party access and current official restrictions meet in a dated decision and monitoring record.

The transfer decision mapArchitecture facts, party access and current official restrictions meet in a dated decision and monitoring record.01Datasetpurpose · category · owner02Pathregion · replica · support03Partiesprovider · sub-service · State04Rule watchAct · order · SDF · other law05Decisionallow · constrain · remediate
  1. 01
    Datasetpurpose · category · owner
  2. 02
    Pathregion · replica · support
  3. 03
    Partiesprovider · sub-service · State
  4. 04
    Rule watchAct · order · SDF · other law
  5. 05
    Decisionallow · constrain · remediate
Editorial operating model. Replace it with your evidenced systems, owners and decisions.

02 Provision-aware reading

Three states that must not be flattened.

01Operative

What is operative now

· in force

Selected definitions, institutional machinery and rule-making provisions are in force. That does not make every substantive operating duty discussed in this article currently operative.

Check the phased ledger
02Scheduled · 18 months

What is notified for later

· notified future commencement

Most day-to-day Data Fiduciary duties discussed here sit in the notified eighteen-month cohort. The displayed date is derived from the status ledger and must be rechecked against later instruments.

Check the phased ledger

The Act gives the Central Government power to restrict transfer of personal data for processing outside India by notification, while preserving laws that provide a higher degree of protection or restriction. Rule 15, in the notified future cohort, permits transfer subject to requirements the Government may specify regarding availability to a foreign State or persons or agencies under its control. Rule 13 contains a separate conditional restriction for Government-specified data applicable to SDFs.

The practical response is not to announce that transfers are unrestricted or universally localised. Build a current map of services, regions, replicas, support access, sub-processors and government-access paths; maintain an official-order watch; and preserve a fact-specific legal decision.

Separate law status from architecture fact

A transfer review has two records. The architecture record says where data is stored, replicated, backed up, viewed, supported and routed today. The legal-status record says which Act provisions, Rules, notifications, Government orders and other laws are operative or notified for later. Combining them in one undated sentence makes both hard to update.

Name the source and review date for every restriction. Avoid statements such as “DPDP requires all data to stay in India” or “DPDP allows every transfer”. The final framework is more conditional, and other sectoral or contractual constraints may matter.

Map storage, access and movement separately

Record primary storage region, replicas, disaster recovery, backups, logs, analytics, support access and administrative control. Data can remain in one region while a support team elsewhere can access it, or move through a global network without persistent storage. The map should explain these differences without pretending technical routing alone settles the legal question.

Include SaaS configuration, cloud resources, sub-processors, data warehouses, content delivery, security tools and employee exports. Verify current consoles and provider documentation. Record unknowns and edition limitations.

Understand the Rule 15 condition carefully

Rule 15 states that personal data processed under the Act may be transferred outside India subject to requirements the Central Government may specify by general or special order in relation to making that data available to a foreign State, or a person or entity under the control of or an agency of such a State. The operational watch must look for the actual order and its scope.

Do not invent a country list, adequacy decision or contract mechanism that the official record does not provide. Track provider government-request processes as due-diligence evidence, while keeping the legal conclusion with qualified reviewers.

Keep the SDF restriction on a separate branch

Rule 13(4) describes measures for an SDF to ensure that personal data specified by the Government, based on committee recommendations, and traffic data pertaining to its flow are not transferred outside India. This depends on SDF designation and Government specification. It is not a general localisation rule for every Data Fiduciary or every SDF dataset.

Maintain three evidence points: the designation instrument, the data specification and the architecture controls. If any is absent or uncertain, record the status rather than converting preparation into a claim.

Design provider and contract evidence for change

The service register should link region, sub-processor, support-access, replication, deletion and exit information to the current agreement and configuration. Assign an owner for provider change notices and material architecture changes. A marketing page saying “data residency” may cover storage but not logs, support or backups.

Test export and migration before depending on a region change. Record encryption and key responsibilities, access controls and incident evidence. Technical safeguards are relevant, but do not present them as a substitute for a transfer rule or Government requirement.

Run a transfer-change scenario

Choose a critical service and simulate a new sub-processor, support region or official restriction. Can the team identify affected datasets and contracts, change configuration, stop new flows, export safely, revoke access and explain residual backups? Capture time, dependencies and unresolved issues.

Review the map after provider, product, region, acquisition or legal-status changes. The useful output is a dated decision with evidence and monitoring, not a permanent green status. Recheck official sources immediately before reliance.

Put the next review into somebody's working queue.

A role label is a starting point. Assign named internal owners, evidence locations and review dates in an approved system; this site stores none of them.

01

Founder

  • Avoid public localisation or unrestricted-transfer claims without evidence.
  • Fund migration and contingency options for critical services.
02

Legal / Privacy

  • Maintain the official order and designation watch.
  • Separate DPDP, sectoral, contractual and foreign-law analysis.
03

IT / Security

  • Map regions, replicas, support access, logs and keys.
  • Test configuration change, export and access revocation.
04

Product / Engineering

  • Record data paths and cross-region dependencies.
  • Design graceful stopping and migration of new flows.
05

Operations

  • Own provider notices and service-register updates.
  • Reconcile exports and support access with the transfer map.

Map first, then apply the current rule

Cross-border readiness needs an accurate architecture map and an accurate official-status record. Neither can be replaced by a slogan. Keep Rule 15, any Government order, SDF-specific conditions and other applicable law on distinct branches.

The operative conclusion is fact-specific and time-sensitive. Recheck the official instruments and seek qualified advice before acting.

Sources and change log

Gazette instruments govern the text and commencement. Government explainers are contextual; this field note remains editorial analysis.

  1. Act No. 22 of 2023Digital Personal Data Protection Act, 2023

    Section 16: processing outside India and higher-protection laws

  2. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 15: transfer subject to Government-specified requirements concerning foreign State availability

  3. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 13(4): conditional restriction for Government-specified SDF personal and traffic data

  4. G.S.R. 843(E)DPDP Act commencement notification

    Paragraph (c): section 16 and Rules 13/15 in the eighteen-month cohort

  5. G.S.R. 892(E)Corrigendum to the Digital Personal Data Protection Rules, 2025

    Published corrections read with the final Rules

Change log

Initial private-preview article created against the final Rules, commencement notification and published corrigendum.

Human-review gate: pinpoints, status and fact-specific interpretations must be rechecked before public reliance.

12 Continue with evidence

Turn the reading into a bounded operating record.

Use a template, inspect the mapped controls or answer the readiness assessment with only what your team can retrieve.

Software stackaws guidemicrosoft azure guide