GIR India: data privacy rules take shape, raising new questions for cross-border investigations

SCOPE OF DATA PROTECTION LAWS RELEVANT TO CROSS-BORDER INVESTIGATIONS

WHAT LAWS AND REGULATIONS IN YOUR JURISDICTION REGULATE THE COLLECTION AND PROCESSING OF PERSONAL DATA? ARE THERE ANY ASPECTS OF THOSE LAWS THAT HAVE SPECIFIC RELEVANCE TO CROSS-BORDER INVESTIGATIONS?

In 2023, the Indian legislature enacted the country’s first comprehensive data privacy legislation – the Digital Personal Data Protection Act 2023 (DPDPA). On 13 November 2025, the DPDPA was officially notified together with the Digital Personal Data Protection Rules 2025 (the DPDP Rules), the delegated legislation framed thereunder. The notifications adopt a phased implementation model: (1) provisions establishing the Data Protection Board of India (DPB), the regulatory authority under the DPDPA, the foundational definitions and the central government’s rule-making power came into force with immediate effect from 13 November 2025; (2) provisions relating to the registration and obligations of consent managers will commence on 13 November 2026; and (3) the remaining substantive provisions, including the notice-and-consent regime, obligations of data fiduciaries, cross-border transfer provisions, the data breach reporting framework, the additional obligations of significant data fiduciaries and the rights of data principals, will commence on 13 May 2027. In practical terms, as of the date of this publication, only the DPB establishment framework and the foundational definitions are in force. The substantive data protection obligations do not yet apply.

From 13 May 2027 (when the remaining substantive provisions are expected to take effect), the DPDPA will regulate, among other things, the processing of “digital” personal data in India. (“Processing” itself is defined in a manner similar to the EU General Data Protection Regulation (GDPR) and subsumes the “collection” of personal data.) The DPDPA defines data fiduciaries (entities that determine the purpose and means of processing of personal data – akin to “data controllers” under the GDPR); data processors (entities that process personal data, including those processing on behalf of data fiduciaries); and data principals (individuals to whom the personal data relates – akin to “data subjects” under the GPDR) and outlines their respective obligations, rights and duties.

The DPDPA also empowers the central government to regulate transfers of personal data outside India by maintaining a list of countries to which transfer is restricted. The specific countries, if any, to be placed on that list have not yet been notified, introducing a degree of uncertainty for cross-border investigations that will only be resolved through enforcement practice after that date.



Disclaimer
: This update is for general information purposes only. It does not purport to provide comprehensive legal or other advice. The publisher and the contributors accept no responsibility for losses that may arise from reliance upon information contained in these publications.