5 minutes

Does the DPDP Act apply to foreign companies?

An explanation of the extraterritorial scope of the Digital Personal Data Protection Act, 2023. This guide outlines when foreign companies face compliance obligations, how Section 3(b) triggers jurisdiction, and the rules governing cross-border data processing.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Yes. The Digital Personal Data Protection Act, 2023 applies to foreign companies processing personal data outside India. Section 3(b) establishes this extraterritorial scope. The statute activates if the processing connects to any activity related to offering goods or services to Data Principals within the territory of India. Your physical corporate location does not determine applicability. The target market dictates the legal obligation. Foreign entities lacking physical infrastructure in the country are fully subject to these rules.

The Act removes physical presence as a regulatory barrier. If a digital product, software platform, or online retail site targets users inside India, the provider falls under the regulatory framework. Section 3 sets boundaries based on data origin and commercial activity. Section 3(a) covers the processing of digital personal data within India. It applies whether the personal data is collected in digital form directly or collected in non-digital form and digitized subsequently. A local subsidiary is entirely unnecessary to trigger jurisdiction.

Section 3(b) extends this jurisdiction globally. A foreign corporation qualifies as a Data Fiduciary if it collects personal data to provide a service to individuals located in India. The law targets active commercial engagement. Incidental web traffic from India does not automatically subject a foreign entity to the DPDP Act. A business has an obligation to actively offer goods or services to Data Principals in India to trigger compliance requirements. B2B data processing presents specific structural realities under this framework. When an Indian enterprise outsources data processing to a foreign vendor, the vendor acts as a Data Processor. The primary legal responsibility remains with the original Data Fiduciary in India. The foreign vendor processes the data strictly under a commercial contract.

The statute provides specific exemptions. Section 3(c) states the Act does not apply to personal data processed by an individual for any personal or domestic purpose. Jurisdiction also excludes personal data made publicly available by the Data Principal. If a Data Principal voluntarily publishes their information on a public forum, the DPDP obligations do not attach to that data. The exemption also applies if another person makes the data publicly available under a legal obligation in India. Foreign scrapers collecting public data face different legal constraints than those collecting data directly from users.

Section 4 establishes the fundamental rules for handling personal information. A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose. The Act defines a lawful purpose as any purpose which is not expressly forbidden by law. Consent operates as the primary basis for processing. The framework permits processing without consent only where Section 7 legitimate uses apply. A foreign company collecting user data for a mobile application requires explicit agreement before extracting the information.

Cross-border data transfers are generally permitted. Section 16 outlines the rules for moving personal data outside the country. The Central Government can notify specific countries or territories where data transfers are restricted. India utilizes a negative list approach for international data flows. Companies can transfer data to foreign servers unless the destination country appears on a government restriction list. Section 16(2) provides a specific exception to this general permission. The DPDP Act does not override other Indian laws that provide a higher degree of protection or place stricter limits on data transfers by a Data Fiduciary. Sectoral regulators like the Reserve Bank of India maintain distinct local storage rules for payment data.

Non-Indian companies face immediate operational realities regarding compliance. Indian enterprise clients execute vendor audits before signing new software contracts. Procurement teams verify regulatory readiness before approving foreign vendors. With the DPDP compliance deadline set for 13 May 2027, enterprise buyers are updating their vendor risk assessments. Organizations demand documented compliance processes to clear these procurement gates. Sales pipelines depend on verifiable legal compliance.

A standard global privacy setup fails a DPDP audit. The DPDP Rules, 2025 mandate itemised notices provided in multiple languages. Foreign companies have to build specific consent workflows on their websites. These screens map directly to the Indian framework. A single global privacy policy document fails to meet the specific notice criteria. Digital platforms require localized consent architecture. The notice has to explain the exact data collected and the specific purpose for each field.

The Data Protection Board of India enforces strict timelines for security incidents. Upon detecting a data breach, Data Fiduciaries have a legal obligation to submit an intimation without delay. The Rules, 2025 require a detailed breach report within 72 hours. Foreign companies need a localized incident response plan mapped to these specific hours. The Act sets out penalties reaching up to 250 crore rupees per violation. A single breach affects balance sheets and market reputation.

Foreign entities carry specific duties regarding minors and inquiries. Service providers have to establish clear mechanics for verifying parental consent when offering services to children. The Act requires accessible grievance redressal systems. Sales teams need clear answers when Indian clients ask about these data processing obligations. Companies have a shrinking window to build these required systems before the government enforces the deadline.

1. Map your data flows directly. Identify exactly what digital personal data you collect from Data Principals in India. Track where that data resides on your global servers.

2. Update your consent mechanics today. Build itemised notices that comply with the DPDP Rules, 2025. Create separate workflows for users in India.

3. Review all vendor agreements. Confirm your global sub-processors explicitly acknowledge Indian legal obligations.

4. Establish a local grievance channel. Designate a point of contact to handle requests from Data Principals in India.

Evaluate current exposure and readiness by running internal workflows through https://www.complydp.com/audit-preview to determine the path to compliance.

Sources

Frequently asked questions

Does the DPDP Act apply to foreign companies?

Yes. Under Section 3(b) of the Digital Personal Data Protection Act, 2023, foreign companies fall under the law if they process personal data outside India in connection with offering goods or services to Data Principals within India.

Can I transfer personal data to my servers abroad?

Yes, cross-border transfers are permitted by default. Section 16 allows transfers unless the Central Government restricts specific countries through a notified negative list. Sectoral laws with higher protection still apply.

Will my existing privacy policy satisfy Indian enterprise clients?

A standard global policy fails DPDP requirements. The DPDP Rules, 2025 require itemised consent notices and specific grievance redressal mechanisms. Enterprise buyers require proof of specific localized compliance to pass procurement gates.

What happens if a foreign company ignores the DPDP Act?

Non-compliance carries penalties reaching up to 250 crore rupees per violation. The Data Protection Board has the power to restrict access to the platform. Indian enterprise clients block non-compliant services during vendor audits.

When is the deadline to comply with the DPDP Act?

Companies face a compliance deadline of 13 May 2027. Service providers have to implement updated consent workflows and breach reporting systems before this date.