Does DPDP require data localisation? Cross border transfers, and the 1 rule that does
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 6 min read
Does the DPDP framework require data localisation, and can personal data be transferred outside India?
The short answer
Transfer is permitted by default. Rule 15 says personal data processed under the Act may be transferred outside the territory of India, subject to meeting requirements the Central Government may specify by general or special order about making that data available to a foreign State, or to any person or entity under the control of or any agency of such a State. Section 16(1) is a separate power to restrict transfer to notified countries, a negative list rather than an approved list, and we have located no such notification. The common claim that the framework contains no localisation requirement is wrong on 1 point: Rule 13(4) requires a Significant Data Fiduciary to undertake measures to ensure that personal data specified by the Central Government, on a committee's recommendation, and the traffic data about its flow, is not transferred outside the territory of India. No such specification has been located, so nothing is operative yet. Section 16(2) separately preserves any Indian law giving higher protection or a stronger transfer restriction. Section 16 and Rules 13 and 15 are all in the group due 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.

Two questions arrive together and get answered as if they were one. Can personal data leave India, and does the framework require it to stay? The answers point in different directions, and the second one is where almost every summary is incomplete.
Transfer is permitted by default
Rule 15 is a single sentence, and its shape is the whole story:
"Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State."
The main clause grants permission. There is no approval to obtain, no adequacy finding to wait for and no prescribed contractual mechanism.
Then read what the condition attaches to. The requirements the Government may specify are "in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State". On our reading that points the rule at access by foreign governments and the entities they control rather than at the ordinary commercial act of sending data to a processor abroad. 2 cautions belong with that reading: a private company can itself be an entity under the control of a State, and an order framed around foreign State access could still set requirements that bite on an ordinary commercial transfer. No order under this rule has been located, so nothing here is more than a reading of the sentence.
Section 16 is a negative list, not an approved list
The Act adds a separate lever:
"The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified."
That is a power to close specific destinations. Everything not notified stays open. It is the inverse of a regime built on approved destinations, and it is the single biggest structural difference for a team arriving from the GDPR, whose Chapter V works from adequacy decisions and safeguards instead. We have located no notification under section 16(1).
The localisation requirement that does exist
Here is where the common answer goes wrong. "The DPDP framework contains no data localisation requirement" is repeated widely, and Rule 13(4) contradicts it:
"A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India."
That is a localisation obligation in terms. Three limits define how far it reaches, and all 3 matter:
| Limit | What it means |
|---|---|
| Only Significant Data Fiduciaries | It does not touch an ordinary Data Fiduciary. Whether you are an SDF is a matter of government notification under section 10, not of size alone |
| Only specified data | It bites on personal data the Central Government specifies, on the recommendation of a committee constituted by the Central Government. Rule 13(5) says that committee shall include officials from the Ministry of Electronics and Technology, which is how the sub rule is printed and a phrase the corrigendum did not correct |
| Traffic data too | The restriction covers "the traffic data pertaining to its flow", not only the personal data. That is a wider technical obligation than a storage location rule, because flow metadata is generated by the architecture rather than chosen |
We have located no specification of data under Rule 13(4), and no constitution of the Rule 13(5) committee, so nothing under it is operative. That is a statement about what we could find rather than a certified negative, and Rule 13 does not commence until the 18 month group in any case.
So the accurate answer to "does DPDP require localisation" is not no. It is: not generally, not for most organisations, and not yet, but the framework contains the machinery, it is pointed at Significant Data Fiduciaries, and it would reach flow metadata as well as the data.
The "not yet" is the part reporting has put in question. Rules 13(4) and 15 are 2 of the limbs the January 2026 proposal to cut the window to 12 months would reportedly bring into force immediately rather than at 18 months. No such instrument has been located, and a limb with no instrument behind it has no date at all, which is the difference between a plan and a headline.
Stricter Indian law survives, and that is deliberate
Section 16(2) is easy to skim past:
"Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof."
Read it against section 38. Section 38(1) makes this Act additional to other law, and section 38(2) says that where the 2 conflict, this Act prevails. Section 16(2) is best read as carving section 16 out of that rule: a stricter transfer restriction elsewhere in Indian law is expressly preserved rather than overridden. That is our reading of how the 2 provisions fit together, and it carries a limit worth stating. Section 16(2) speaks only of this section, so on its own words it does not settle what happens if another law conflicts with Rule 15.
That is the provision under which any sector specific restriction continues to operate. This site holds no official copy of the sectoral instruments that are usually cited in this context, so we do not describe what any of them require; what section 16(2) establishes is that section 16 does not restrict the applicability of a law that gives a higher degree of protection or a stronger transfer restriction.
When this starts
Section 16 falls inside "sections 11 to 17" in the 18 month group of notification G.S.R. 843(E). Rules 13 and 15 both fall inside "Rules 5 to 16" in the matching group under Rule 1(4). So the permission, the restriction power and the localisation machinery all commence together, computed as 13 May 2027 from the printed publication date, and that calendar date is interpretation until officially confirmed. None of the transfer provisions described here is in force as at 26 August 2026. Section 38 is the exception: it sits in the first group of G.S.R. 843(E) and has been in force since 13 November 2025.
What to do before then
The practical task this framework creates is unusual, and it is not a transfer approval process. It is watching for 3 instruments we have not been able to locate: an order under Rule 15 about foreign State access, a notification under section 16(1) closing a destination, and a specification under Rule 13(4) if you are or may become a Significant Data Fiduciary.
What that means for contracts is practical rather than legal. A processor agreement signed today that assumes data may sit anywhere for the life of the contract has no room for any of those 3 instruments. Leaving room for them is cheaper than renegotiating, and the vendor and processor checklist covers the clause. If you are coming from a GDPR programme, the transfer row of the gap checker sets out what not to assume. And if the entity doing the processing sits outside India in the first place, the prior question is whether the Act applies to it at all.
Related tool
Vendor and Processor Checklist
Identify DPDP relevant actions for your vendors and Data Processors.
Open
Related tool
DPDP vs GDPR Gap Checker
If you have a GDPR program, find the DPDP specific areas that need separate review.
Open
Rule 15, official text with sources →Section 16, official text with sources →What else a Significant Data Fiduciary owes →
Cross borderTransfersRule 15Data localisationMyth correction