DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

The DPDP Act 2023 applies to the processing of digital personal data in India, and importantly it also reaches processing outside India where that processing is in connection with offering goods or services to Data Principals in India. This gives it extraterritorial reach over many foreign entities serving Indian users. Cross-border data transfers out of India are permitted except to countries the government may restrict by notification. This guide explains when DPDP enforcement can reach cross-border data and foreign entities, and how to assess your exposure.

DPDP Cross-Border Enforcement — When It Reaches Foreign Entities

DPDP has real extraterritorial reach and rules on data leaving India. Here is when enforcement reaches cross-border data and foreign entities, and how exposed you are.

Assess your cross-border DPDP exposure

Managing cross-border DPDP exposure

Does the DPDP Act apply to companies outside India?

Yes, in defined circumstances. The DPDP Act 2023 applies to the processing of digital personal data within India, and it also extends to processing carried out outside India where that processing is in connection with offering goods or services to Data Principals in India. This extraterritorial reach means a foreign SaaS platform, e-commerce business, or app that serves Indian users falls within the Act even if it has no physical presence in India — a point many overseas companies underestimate.

For Indian companies, the relevant angle is usually the reverse: their own use of foreign cloud providers, group entities, and processors. In every case, the data fiduciary remains accountable for personal data even when it is processed abroad or by a third party. Niti Bharat helps both Indian mid-market companies and foreign entities serving Indian users understand exactly where DPDP reaches their cross-border data and what that requires of them.

How do cross-border transfer rules and enforcement actually work?

The DPDP Act takes a relatively open approach to cross-border transfers compared with some regimes: transfers of personal data outside India are generally permitted, except to countries that the Central Government may restrict by notification. This means the practical compliance task is not obtaining approval for every transfer, but monitoring for any notified restrictions and ensuring your transfers do not run to a restricted country. It also means keeping a clear map of which data flows leave India and why.

Enforcement reach follows the Act's application: where the Act applies — including to a foreign entity serving Indian users — the Data Protection Board's authority follows, and the fiduciary must be able to receive and respond to Board communications. Cross-border arrangements do not dilute a fiduciary's accountability; they extend it down the processing chain. Niti Bharat's fixed-price DPDP compliance services (₹75K–₹3.2L) include cross-border data mapping and processor DPA work so that data leaving India remains compliant and defensible ahead of May 2027 enforcement.

Get the cross-border DPDP exposure kit (free)

A PDF covering DPDP's extraterritorial reach, a cross-border data-flow mapping template, and a processor DPA checklist for foreign vendors.

Frequently Asked Questions

Does DPDP apply to a foreign company with no office in India?+
It can. The DPDP Act reaches processing outside India where it is connected to offering goods or services to Data Principals in India. A foreign company serving Indian users can fall within the Act even without a physical presence in India.
Can I transfer Indian users' personal data outside India?+
Generally yes. The DPDP Act permits cross-border transfers except to countries the Central Government restricts by notification. The compliance task is to monitor for any such restricted-country notifications and map which data flows leave India.
Am I still responsible for data once it goes to a foreign processor?+
Yes. As the data fiduciary you remain accountable for the personal data even when a foreign processor or sub-processor handles it. You need data processing agreements that flow your DPDP obligations down the chain to those processors.
How would the Data Protection Board enforce against a foreign entity?+
Where the Act applies to a foreign entity serving Indian users, the Board's authority follows. Such entities should plan how they will receive and respond to Board communications and meet the Act's requirements, rather than assuming distance provides immunity.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Data Principal Rights Response TimerDPDP Enforcement 2027DPDP Enforcement Milestones & Deadline TrackerPrivacy Impact Assessment ToolSee all Reference & Checklists tools →📝 Answer DPDP Questionnaire📝 Does DPDP Apply to Hrms Platforms