The DPDP cross-border transfer rules aren't live yet; so why are contracts being redrafted as if they are?
Cite this
Citations are auto-generated; verify before publishing. The news classification is PolicyDhara's, not the source's.
News coverage — journalism about policy, not a policy document. Useful as timely context; the underlying instrument is linked where known.
Summary
Since the Digital Personal Data Protection Rules, 2025 were notified in November 2025, a wave of client memos, LinkedIn explainers and even compliance-tool vendors have treated Rule 15 - the provision governing cross-border transfer of personal data - as though it is fully operative. Contract templates are being rewritten. Data processing addenda are being amended. Clients are being told to build “DPDP-compliant” cross-border transfer mechanisms into new vendor agreements, cloud contracts and ou
Key Facts
Key Numbers
Key Authorities
Key Stakeholders
Government Context
Impact Assessment
Key Outcomes
- DPDP Act 2023 enacted — India's first comprehensive data law
- Data Protection Board constituted
- Rules for consent management and cross-border data flow notified
Challenges
- Government exemptions criticized
- Compliance readiness of SMEs
- Board independence concerns