Rushikesh Mahajan logo

Rushikesh Mahajan

Archives
Log in
Subscribe
August 31, 2026

No country is restricted. Your data still cannot leave.

Two new readers joined this desk on 30 August. You are starting at Issue 05 — the back catalogue is at buttondown.com/the_desk/archive, and Issues 02 to 04 cover the commencement clock, the Consent-Manager bar, and the EU AI Act's reach into Indian companies.


TL;DR

Almost every cross-border conversation about the DPDP framework opens with the GDPR's question — "what is our transfer mechanism?" — and India has not written that question into its law. Section 16 inverts the default: transfer is permitted everywhere until the Government restricts a destination, and no destination has been restricted. The provision is also not yet in force. Which means the rule actually governing an Indian company's data exports today is not the DPDP at all — and a great many readiness programmes are being built against the wrong instrument.

  • The deep dive: s.16(1) is a negative list, not an adequacy regime. Nothing has been notified under it, and on the published commencement schedule s.16 and Rule 15 take effect on 13 May 2027.
  • The catch: s.16(2) expressly preserves every stricter Indian law. The RBI's 2018 payment-data mandate and its sectoral cousins are the live constraint — today and after May 2027.
  • What Rule 15 actually says: it is drafted around making personal data available to a foreign State or its agencies. It is a government-access provision, not a commercial transfer mechanism.
  • India desk: Rule 12 is where a real localisation power sits — for Significant Data Fiduciaries, over categories the Central Government notifies, extending to traffic data.
  • Global: the EU has granted seventeen adequacy decisions. India is not one of them — and the asymmetry between the two regimes is where the real work sits.

THE DEEP DIVE — India did not build a transfer mechanism, and that is the point

There is a conversation I have had four times this year in slightly different words. A founder, or a general counsel, or a CTO who has been handed privacy as a fourth job, asks some version of: we use a US cloud, our analytics vendor is in Ireland, our support tool is in Singapore — what is our DPDP transfer mechanism?

The honest answer is that there is not one, because the Act does not ask for one. And the reason that answer lands badly is that the question was imported whole from a different statute.

What Section 16 actually does. Section 16(1) of the Digital Personal Data Protection Act, 2023 reads, in full:

"The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified."

Read what that sentence contains and, more importantly, what it does not. There is no adequacy assessment. No standard contractual clauses. No binding corporate rules. No derogation architecture, no necessity test, no supplementary-measures analysis. There is a power in the Union Government to name a country and shut the door to it.

This is the negative-list model, and it is the mirror image of the European one. Under the GDPR a transfer out of the EEA is prohibited unless the exporter can point to a mechanism that permits it. Under Section 16 a transfer out of India is permitted unless the Government has pointed at the destination and forbidden it.

And no destination has been named. So far as is publicly reported, no country or territory has been notified as restricted under Section 16 at any time up to the date of this issue. I put it that way deliberately. That is a statement about what appears in the public record, not a guarantee about a gazette I have not seen — and it is a status that could change with a single notification, which is precisely the design.

There is a second fact that almost nobody carries into the conversation. Section 16 is not in force. On the commencement schedule published alongside the Digital Personal Data Protection Rules, 2025, the cross-border limb — Section 16 of the Act together with Rule 15 of the Rules — sits in the eighteen-month tranche and takes effect on 13 May 2027, alongside notice, security safeguards, breach reporting, retention and children's data. The only obligations that commence earlier, on 13 November 2026, are the Consent-Manager package.

Put those two facts together and the position today is stark: the DPDP framework currently imposes no cross-border rule at all, and the rule it will impose has an empty restricted list. A readiness programme whose transfer workstream consists of mapping vendors against a list that does not exist, under a section that has not started, is not early. It is aimed at the wrong target.

What Rule 15 is really about. It is worth reading the operative rule rather than the summaries of it. Rule 15 of the DPDP Rules, 2025 is headed "Transfer of personal data outside the territory of India" and provides:

"Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State."

The operative words are "to any foreign State, or to any person or entity under the control of or any agency of such a State." The rule is not drafted around your AWS region or your Dublin analytics processor. It is drafted around the circumstance in which Indian personal data becomes available to a foreign government — its agencies, and entities under its control. That is a sovereignty and lawful-access concern, and it is a very different anxiety from the commercial-processor anxiety the GDPR's Chapter V addresses.

I flag this because the mismatch produces a specific and repeated drafting error. I have now read several vendor questionnaires and one draft data-processing addendum that recite "compliance with Rule 15 transfer requirements" as though Rule 15 issued a set of clauses. It has not issued anything. It reserves a power to specify requirements by general or special order, and no such order is in the public domain.

So what is actually binding an Indian company's data exports right now? Section 16(2) answers it, and it is the sub-section that gets skipped:

"Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof."

The DPDP framework sets a floor, not a ceiling, and it explicitly steps aside for anything stricter. The clearest example is the Reserve Bank of India's directive of 6 April 2018 on storage of payment system data, issued under the Payment and Settlement Systems Act, 2007, which requires payment system operators to store the full end-to-end payment data — customer data, payment-sensitive data, payment credentials, transaction data — within India. That directive is in force, it is enforced, and Section 16(2) means the DPDP's permissiveness does nothing whatever to soften it. The same logic runs across the sectoral regulators.

For most companies the practical hierarchy of cross-border constraints in 2026 therefore looks nothing like the one a GDPR-trained adviser would draw. In rough order of how likely each is to actually bite:

  1. Your sectoral regulator, if you have one. Payments, banking, insurance, telecom and securities all carry their own data rules, and they outrank the DPDP by the express terms of Section 16(2).
  2. Your counterparty's contract. If a European or British customer's DPA obliges you to hold their data in a particular way, that obligation binds you because you signed it, not because India requires it.
  3. The GDPR or UK GDPR flowing the other way, where you are the recipient of European data or are offering into those markets.
  4. Section 16 and Rule 15, from 13 May 2027, and only to the extent something is notified under them.

None of which makes the exercise pointless. Three things follow, and none of them is "wait".

First, map the flows anyway — but file the map under the right heading. A data map that records where every category of personal data physically rests, who touches it, and under whose control, is the input to every one of the four constraints above. It is not DPDP transfer-compliance work. It is the work you need in order to answer your regulator, your customer's security questionnaire, and Section 16 whenever it arrives. Build it once.

Second, stop writing transfer mechanisms into Indian contracts that do not have them to write. A clause reciting "the parties shall execute Standard Contractual Clauses as required under the DPDP Act" is describing an instrument that does not exist in Indian law. What an Indian data-processing schedule should actually carry is the Section 8(2) processor obligation, the security expectations, the breach-notification chain, deletion on termination, and — if the counterparty has European exposure — the European mechanism in its own right, correctly labelled.

Third, treat the empty restricted list as a live risk rather than a settled state. The power in Section 16(1) is exercisable by notification. It requires no consultation period written into the section and no transition. A company whose architecture assumes a particular jurisdiction is fine has taken a position on future government policy, and should know that it has. The cheapest insurance is not localisation. It is knowing, on one page, exactly which processing would have to move if a given country were named — which is, again, the map.

A closing note on why this matters beyond transfers. The pattern here repeats across the whole framework, and it is the single most useful thing to carry out of this issue. India did not translate the GDPR. It borrowed the vocabulary — data principal for data subject, data fiduciary for controller, and a consent architecture that looks familiar at a distance — and then made materially different structural choices underneath. Section 7's legitimate uses are a closed list of enumerated categories with no balancing test, and are not the GDPR's legitimate-interests ground wearing an Indian name. The transfer regime is a negative list, not an adequacy regime. Every place where the vocabulary matches and the structure does not is a place where a GDPR-trained instinct produces a confident, well-drafted, wrong answer.


INDIA DESK

The localisation power that does exist sits in Rule 12, and it is aimed at Significant Data Fiduciaries. While Section 16 holds a restriction power that has not been used, Rule 12 of the DPDP Rules, 2025 does something narrower and sharper. It provides that a Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government — on the recommendations of a committee constituted by it — is processed subject to the restriction that that personal data, and the traffic data pertaining to its flow, is not transferred outside the territory of India. Two features are worth noting. The trigger is SDF designation, so it reaches only entities the Government has notified as significant. And the inclusion of traffic data is a meaningful extension: it is not only the payload that must stay, but the metadata of its movement. Like the rest of the substantive package, Rule 12 is not yet in force. [Source: SFLC.in — DPDP Rules, 2025: Significant Data Fiduciaries and Data Transfers · Tsaaro — Obligations of Significant Data Fiduciaries]

The Board's chairs: still nothing in the public record. Last issue set out that the Data Protection Board of India, whose constitution provisions are among the parts of the Act already in force, had no appointed Chairperson and no appointed Members as at 1 August 2026, following MeitY's nomination communications of 6 May 2026 and 6 June 2026. I have looked again for this issue and found no announcement of an appointment. I note, because a reader may encounter it, that at least one widely-mirrored open-source reference now carries a purported name for the Chairperson. It traces to no government record I can find and I am not repeating it. Practitioners should verify the Board's composition at the moment of advising rather than rely on any secondary source, including this one. [Source: LiveLaw, 1 Aug 2026 · Mondaq, 17 Apr 2026]


GLOBAL — DATA PROTECTION & AI GOVERNANCE

Seventeen adequacy decisions exist. India is not one of them. The European Commission currently recognises seventeen jurisdictions as providing an adequate level of protection for personal data: Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organisations certified under the EU–US Data Privacy Framework), Uruguay, and the European Patent Organisation. The most recent addition is Brazil, on 26 January 2026. The United Kingdom's decision, first made in June 2021, was renewed on 19 December 2025. India does not appear on the list.

Set that against the Indian position this issue describes and the asymmetry is the whole story. Europe built an institution for saying yes, and has said it seventeen times. India built a power for saying no, and has not yet used it once. The two architectures produce exactly opposite defaults — a European exporter must find a permission before data moves, an Indian exporter must find a prohibition before it stops — and an Indian company sitting between a European customer and an American processor is subject to both at the same time, pointing in opposite directions.

That is the honest shape of cross-border work for an Indian technology business in 2026, and it is worth saying plainly: the hard constraint is almost never Section 16. It is the European instrument reaching in, the sectoral regulator sitting above, and the contract already signed. [Source: European Commission — Adequacy decisions · Kennedys — International data transfers in 2026]


RUNNING CLOCK — computed 31 August 2026

The distances below are as at the date of this line and nowhere else in this issue. Everything above is stated in absolute dates so that it reads correctly whenever you open it.

Date What it is Distance from 31 Aug 2026
13 Nov 2025 DPDP Rules, 2025 notified 291 days ago
5 Nov 2025 India AI Governance Guidelines released 299 days ago
6 Apr 2018 RBI payment system data storage directive in force
13 Nov 2026 Rule 4 / s.6(9) — Consent-Manager registration commences 74 days
2 Dec 2026 EU AI Act Art 50(2) transitional relief expires 93 days
13 May 2027 s.16 + Rule 15 (cross-border), and the substantive package 255 days

PRACTITIONER'S VERDICT

What to tell a client this fortnight. If they have been quoted a price for "DPDP cross-border transfer compliance", ask what instrument it is being performed under — because Section 16 is not in force, nothing has been notified beneath it, and Rule 15 is addressed to foreign States rather than to their cloud provider. If they are regulated by the RBI, or any sectoral regulator, tell them plainly that Section 16(2) leaves that regulator's rules entirely intact and that the DPDP's permissiveness buys them nothing. And if their privacy programme was written by someone fluent in the GDPR, the highest-value hour they can spend is not on transfers at all — it is on finding every place where India borrowed the European word and changed the structure underneath it. That list is longer than most people expect, and every item on it is a confident wrong answer waiting to be given.


FOOTER

This publication is informational and educational only. It is not legal advice and creates no advocate–client relationship. Authored from India; readers in other jurisdictions should map terms to local law.

Every statutory reference and every date in this issue was checked against at least two independent sources before it went out. Where a claim could not be verified to that standard it does not appear, or it is stated as an absence of record rather than as a fact — including the restricted-country position and the Board's composition, both of which are written above as what the public record shows rather than as what is certainly true. The archive, and everything else I have been building, is at wolfgangrush.github.io.

Don't miss what's next. Subscribe to Rushikesh Mahajan:
← Newer It predicts the next word. That is the whole machine. Older → 81 days to register. Who exactly receives the application?
Powered by Buttondown, the easiest way to start and grow your newsletter.