India's DPDP Act 2023 applies extraterritorially. A foreign company with no physical presence in India is still covered if it processes the digital personal data of individuals in India in connection with offering goods or services to them. So a global SaaS, e-commerce, or app company serving Indian users generally must comply — appointing a Grievance Officer, providing notice, obtaining valid consent, and meeting security and breach-notification obligations — even without an Indian office. This tool checks whether the DPDP Act applies to your foreign company and, if so, what you must do.
No office in India but you have Indian users? The DPDP Act 2023 applies extraterritorially. Check whether it reaches your company and exactly what you would need to do.
The DPDP Act 2023 is expressly extraterritorial. It applies to the processing of digital personal data within India, and also to processing outside India where that processing is in connection with offering goods or services to individuals located in India. In plain terms, a global SaaS platform, mobile app, e-commerce store or online service that has Indian users — and processes their personal data to serve them — is generally within the Act's scope even if it has no Indian subsidiary, office or staff. Physical presence is not the trigger; the connection to individuals in India is.
This mirrors the extraterritorial logic many global companies already know from GDPR, but the obligations are DPDP-specific. A covered foreign company cannot simply point to its GDPR or CCPA programme and assume it is compliant. It needs a DPDP-aligned privacy notice for Indian users, a valid consent basis, a published Grievance Officer as the local contact point, security safeguards and a breach-notification process under the DPDP Rules 2025, and a working mechanism to honour Data Principal rights.
The most efficient starting point is an applicability and gap assessment: confirm the Act applies, identify which of your data flows involve individuals in India, and map your current practices against the DPDP obligations. For many global companies the biggest practical gaps are the absence of a published Grievance Officer (a role with no exact GDPR equivalent), a consent mechanism that meets the DPDP standard of specific, informed and unambiguous consent, and a breach-notification process aligned to the Indian rules rather than only the foreign ones they already follow.
Niti Bharat works with global companies serving Indian users — SaaS platforms, app developers and MNCs — to make them DPDP-compliant without duplicating everything they already do for other regimes. The approach is fixed-price (₹75,000–₹3.2 lakh depending on scope) and focused on the specifically Indian obligations that a foreign privacy programme typically misses, so the company is defensible before the expected May 2027 enforcement date.
A practical PDF covering when the DPDP Act reaches a company with no Indian office, the core obligations for covered foreign firms, and a first-90-days compliance checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.