DPDP cross-border rules aren’t live yet: how to prepare wisely
A column published by Bar and Bench on 18 September 2026 makes a point many compliance teams need to hear: India’s cross-border transfer rule under the Digital Personal Data Protection (DPDP) framework is not yet in force, yet contracts across the market are being rewritten as though it were. With the first anniversary of the DPDP Rules approaching in November, now is the right moment to separate what is required today from what is sensible preparation.
Where the DPDP timeline actually stands
India’s Digital Personal Data Protection Rules, 2025 were notified in November 2025 and commence in phases. As summarised by Hunton’s privacy team, the definitions and the provisions constituting the Data Protection Board took effect immediately; registration and obligations of consent managers follow after one year; and the substantive obligations, including notice, individuals’ rights and breach notification, apply after 18 months.
The Bar and Bench column describes this as three stages: November 2025 for the Board and procedural provisions, November 2026 for consent manager registration and enforcement machinery, and May 2027 for substantive obligations, including the conditions on cross-border transfers.
- November 2025
- DPDP Rules notified; Data Protection Board provisions in force.
- November 2026
- Consent manager registration and obligations begin.
- May 2027
- Core obligations for data fiduciaries, including notices, rights, breach notification and transfer conditions.
Why the cross-border point matters
The column argues that India’s model is very different from the GDPR. Under Rule 15, as described in the piece, transfers outside India are permitted by default unless the Central Government restricts transfers to particular countries. There are no standard contractual clauses, no transfer impact assessments and no adequacy whitelist.
That has two practical consequences for multinational groups, particularly UK and EU businesses with Indian operations or suppliers:
- Copying GDPR transfer machinery into Indian contracts is not required and may create obligations that do not match the eventual Indian regime.
- The real risk is a future restriction. If the Government notifies a restricted country, data flows into that jurisdiction would need to change. Contracts should make that change easy, not assume it will never happen.
The author recommends “regulatory change” clauses that require good-faith renegotiation once Rule 15 and any restriction notification take effect, alongside clear distinctions between present obligations and forward-looking preparation.
“Good DPDP preparation is about knowing your data flows, not pasting GDPR clauses into Indian contracts.”
— Praeferre analysisWhat to do now
The months before May 2027 are best spent on work that pays off whatever the final detail looks like.
- Map your data flows. Identify which Indian personal data leaves India, where it goes and which suppliers touch it. This is the foundation for every later decision.
- Audit your vendor chain. Know which processors and sub-processors handle Indian data, and secure audit and cooperation rights in contracts now.
- Add flexible transfer clauses. Use regulatory change provisions rather than hard-coding mechanisms that may never apply.
- Prepare for consent managers. From November 2026, registered consent managers will begin operating. Consider how your consent capture and withdrawal will interoperate with them.
- Build breach and rights workflows. Notification, access, correction and erasure processes take time to design, test and staff. Do not leave them to 2027.
- Be honest internally. Label work as “required now” or “preparation” so budgets and priorities reflect real deadlines.
With teams in London and Hyderabad, Praeferre supports organisations operating across the UK, EU and India. Our GRC automation platform maps DPDP requirements to controls you may already have for GDPR and ISO 27001, and our Third-Party Risk Management service helps you understand where Indian data travels. Read our DPDP framework overview.
Map your DPDP obligations against the controls you already run for GDPR and ISO 27001.
Explore DPDPCommon questions
Not yet. Section 16 of the DPDP Act and Rule 15 of the DPDP Rules are expected to take effect with the substantive obligations in May 2027, 18 months after the Rules were notified.
The DPDP model, as currently described, permits transfers by default unless the Government restricts a country. It does not require standard contractual clauses, though contracts should allow for future restrictions.
The provisions on registration and obligations of consent managers are due to take effect one year after the Rules were notified in November 2025.
Sources
- The DPDP cross-border transfer rules aren’t live yet; so why are contracts being redrafted as if they are? — Bar and Bench, 18 September 2026
- India Enacts Data Protection Rules, Introducing New Privacy Regime — Hunton Andrews Kurth, 26 November 2025

