DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

India's DPDP Act 2023 applies extraterritorially. A foreign company with no physical presence in India is still covered if it processes the digital personal data of individuals in India in connection with offering goods or services to them. So a global SaaS, e-commerce, or app company serving Indian users generally must comply — appointing a Grievance Officer, providing notice, obtaining valid consent, and meeting security and breach-notification obligations — even without an Indian office. This tool checks whether the DPDP Act applies to your foreign company and, if so, what you must do.

Does DPDP Apply to a Foreign Company?

No office in India but you have Indian users? The DPDP Act 2023 applies extraterritorially. Check whether it reaches your company and exactly what you would need to do.

Check whether the DPDP Act applies to you

DPDP applicability for a foreign company — what triggers it

How does the DPDP Act reach foreign companies with no office in India?

The DPDP Act 2023 is expressly extraterritorial. It applies to the processing of digital personal data within India, and also to processing outside India where that processing is in connection with offering goods or services to individuals located in India. In plain terms, a global SaaS platform, mobile app, e-commerce store or online service that has Indian users — and processes their personal data to serve them — is generally within the Act's scope even if it has no Indian subsidiary, office or staff. Physical presence is not the trigger; the connection to individuals in India is.

This mirrors the extraterritorial logic many global companies already know from GDPR, but the obligations are DPDP-specific. A covered foreign company cannot simply point to its GDPR or CCPA programme and assume it is compliant. It needs a DPDP-aligned privacy notice for Indian users, a valid consent basis, a published Grievance Officer as the local contact point, security safeguards and a breach-notification process under the DPDP Rules 2025, and a working mechanism to honour Data Principal rights.

What should a covered foreign company do first?

The most efficient starting point is an applicability and gap assessment: confirm the Act applies, identify which of your data flows involve individuals in India, and map your current practices against the DPDP obligations. For many global companies the biggest practical gaps are the absence of a published Grievance Officer (a role with no exact GDPR equivalent), a consent mechanism that meets the DPDP standard of specific, informed and unambiguous consent, and a breach-notification process aligned to the Indian rules rather than only the foreign ones they already follow.

Niti Bharat works with global companies serving Indian users — SaaS platforms, app developers and MNCs — to make them DPDP-compliant without duplicating everything they already do for other regimes. The approach is fixed-price (₹75,000–₹3.2 lakh depending on scope) and focused on the specifically Indian obligations that a foreign privacy programme typically misses, so the company is defensible before the expected May 2027 enforcement date.

Get the foreign-company DPDP applicability guide (free)

A practical PDF covering when the DPDP Act reaches a company with no Indian office, the core obligations for covered foreign firms, and a first-90-days compliance checklist.

Frequently Asked Questions

Does the DPDP Act apply to a company with no office in India?+
It can. The DPDP Act applies extraterritorially to the processing of digital personal data of individuals in India done in connection with offering goods or services to them. A physical office in India is not required for the Act to apply — serving Indian users and processing their data is the trigger.
We are GDPR-compliant. Does that cover DPDP?+
Not automatically. GDPR compliance provides a strong foundation (data mapping, security, rights processes), but DPDP has India-specific requirements — notably a published Grievance Officer, a DPDP-standard consent notice, and breach notification under the DPDP Rules 2025 — that a GDPR programme does not cover by default.
Do we need to set up an Indian entity to comply with DPDP?+
No. The DPDP Act does not require a foreign company to incorporate in India in order to comply. It requires meeting the obligations — notice, consent, Grievance Officer, security, breach notification and rights handling — which can be done without an Indian entity, though many companies designate a Grievance Officer contactable by Indian users.
What if only a few Indian users sign up on their own?+
Even incidental Indian users can bring a company within scope if it is, in effect, offering goods or services to them. The safer assumption for any global product with genuine Indian usage is that the Act applies, and to build the core compliance elements accordingly.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Act 2023 for Education & EdTech: Complete Com…DPDP Act 2023 for Fintech CompaniesDPDP Act 2023 for Manufacturing Companies: What Yo…Logging & Retention Checker for DPDP (Engineering)See all By Sector tools →📝 Does DPDP Apply to Startups Small Business📝 DPDP for Edtech Platforms