The DPDP Act 2023 applies to the processing of digital personal data in India, and importantly it also reaches processing outside India where that processing is in connection with offering goods or services to Data Principals in India. This gives it extraterritorial reach over many foreign entities serving Indian users. Cross-border data transfers out of India are permitted except to countries the government may restrict by notification. This guide explains when DPDP enforcement can reach cross-border data and foreign entities, and how to assess your exposure.
DPDP has real extraterritorial reach and rules on data leaving India. Here is when enforcement reaches cross-border data and foreign entities, and how exposed you are.
Yes, in defined circumstances. The DPDP Act 2023 applies to the processing of digital personal data within India, and it also extends to processing carried out outside India where that processing is in connection with offering goods or services to Data Principals in India. This extraterritorial reach means a foreign SaaS platform, e-commerce business, or app that serves Indian users falls within the Act even if it has no physical presence in India — a point many overseas companies underestimate.
For Indian companies, the relevant angle is usually the reverse: their own use of foreign cloud providers, group entities, and processors. In every case, the data fiduciary remains accountable for personal data even when it is processed abroad or by a third party. Niti Bharat helps both Indian mid-market companies and foreign entities serving Indian users understand exactly where DPDP reaches their cross-border data and what that requires of them.
The DPDP Act takes a relatively open approach to cross-border transfers compared with some regimes: transfers of personal data outside India are generally permitted, except to countries that the Central Government may restrict by notification. This means the practical compliance task is not obtaining approval for every transfer, but monitoring for any notified restrictions and ensuring your transfers do not run to a restricted country. It also means keeping a clear map of which data flows leave India and why.
Enforcement reach follows the Act's application: where the Act applies — including to a foreign entity serving Indian users — the Data Protection Board's authority follows, and the fiduciary must be able to receive and respond to Board communications. Cross-border arrangements do not dilute a fiduciary's accountability; they extend it down the processing chain. Niti Bharat's fixed-price DPDP compliance services (₹75K–₹3.2L) include cross-border data mapping and processor DPA work so that data leaving India remains compliant and defensible ahead of May 2027 enforcement.
A PDF covering DPDP's extraterritorial reach, a cross-border data-flow mapping template, and a processor DPA checklist for foreign vendors.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.