Abstract
The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 to implement Section 16 of the DPDP Act, 2023, via Rule 15 permit cross-border personal data transfers by default and vest the Central Government with broad authority to restrict them by general or special order. This paper compares Rule 15 with the EU GDPR's adequacy decisions and, more commonly, its 2021 Standard Contractual Clauses (SCCs) under Article 46, as refined by the CJEU in Schrems. The analysis finds that while Rule 15's negative-list approach offers Indian businesses significant flexibility, it reduces legal predictability, exporter accountability, and remedy clarity for data principals, whereas the SCC framework addresses these via enforceable contractual warranties, third-party beneficiary rights, and mandatory transfer impact assessments. Drawing on the legislative history, Rule 15, Rules 13(4)-(5), Section 17(2)(a), and the post-Schrems II evolution of SCCs, this paper recommends retaining the negative-list default while introducing an optional, government-recognized contractual instrument. This would allow data exporters to demonstrate accountability when transferring data to non-blacklisted but legally uncertain jurisdictions, without fully adopting the EU's adequacy model.
Keywords: Cross-border data transfer, Digital Personal Data Protection Rules, 2025, Standard Contractual Clauses, General Data Protection Regulation, Schrems II