Does DPDP apply to foreign companies operating in India?
The DPDP Act has extraterritorial reach. Here is what it means for foreign businesses operating in India or targeting Indian users.
What is the territorial scope of the DPDP Act?
The Act applies to: (1) processing of personal data collected within India; and (2) processing of personal data collected outside India if it is in connection with offering goods or services to data principals in India. This dual scope means: an Indian company processing data in India is covered; an Indian company outsourcing data processing to a foreign processor is covered; and a foreign company processing Indian users' data is covered. The 'within India' test covers collection point; the 'in connection with' test covers purpose.
What counts as 'offering goods or services' to Indian data principals?
Indicators that a foreign business is offering services to Indians and therefore subject to DPDP: accepting Indian rupees; having an INR pricing page; advertising in India or targeting Indian users with digital ads; displaying Indian contact numbers or addresses; using a .in domain; providing Hindi or other Indian language options; explicitly marketing to Indian businesses. A foreign company that passively receives Indian customers but has made no effort to target India would have a stronger argument that it is not 'offering' services to Indian principals — but this is a fine distinction.
Must foreign companies appoint an Indian data protection representative?
The DPDP Act does not explicitly require foreign companies to appoint an Indian representative (unlike GDPR Article 27, which requires EU representatives for non-EU companies targeting EU residents). However, the Data Protection Board must be able to reach foreign companies for enforcement purposes. Practically, a foreign company with Indian operations, an Indian subsidiary, or Indian employees already has a point of contact in India. Purely extraterritorial companies with no Indian presence may find enforcement difficult to execute against them, but they still have legal obligations.
What must a foreign company do to comply with DPDP?
A foreign company subject to DPDP must: issue a DPDP-compliant privacy notice to Indian users covering their rights; obtain consent where required; honour data principal rights (access, correction, erasure) from Indian users; implement adequate security safeguards; notify the Data Protection Board of breaches affecting Indian users; and comply with cross-border transfer regulations (when notified). Practically, this means reviewing your global privacy programme for DPDP gaps and extending DPDP compliance to Indian user populations.
Are there exemptions for foreign companies under DPDP?
No specific exemptions for foreign companies exist in the Act. The government may prescribe exemptions for certain processing activities (national security, research, journalism) that apply equally to domestic and foreign entities. Foreign companies with minimal Indian user bases may argue that enforcement priorities will focus on higher-risk Indian-market businesses first — but this is a practical observation, not a legal exemption. The compliance obligation exists from the enforcement date regardless of company origin.
How does DPDP interact with a foreign company's existing GDPR compliance?
Many GDPR-compliant processes are sufficient for DPDP too — but not all. GDPR differences from DPDP: GDPR has six lawful bases (including legitimate interests); DPDP has a narrower legitimate use basis. GDPR has data portability rights; DPDP does not (yet). GDPR has specific provisions for AI and automated decision-making; DPDP does not yet. GDPR has Standard Contractual Clauses for cross-border transfers; DPDP has an approved country list (not yet published). Review your GDPR programme against DPDP gaps — the gaps are manageable but real.
Frequently asked questions
Does a foreign company with an Indian subsidiary need to comply separately for the subsidiary?
The Indian subsidiary is a separate legal entity and is independently subject to DPDP. The subsidiary's data processing (employee data, customer data for Indian operations) is subject to DPDP compliance by the subsidiary as the Data Fiduciary. The foreign parent company may also separately be subject to DPDP for data it receives from the Indian subsidiary. Both entities must be compliant — and the intra-group data transfers between them need to be governed by a DPA or equivalent transfer mechanism.
Can a foreign company appoint a local DPDP compliance partner in India?
Yes. Engaging an Indian DPDP compliance partner — a law firm or compliance consultancy — provides expertise in the Indian regulatory framework, a point of contact for Board communications, and local support for data principal rights management. This is not the same as the statutory DPO requirement (which applies only to SDFs), but it is a practical measure for foreign companies with significant Indian user bases. A local partner can monitor DPDP regulatory developments and maintain compliance as the Rules evolve.
If an Indian user accesses a foreign website and shares their data, does DPDP apply?
If the foreign website is genuinely not targeting India — no Indian language, no INR pricing, no Indian-specific marketing — the 'offering goods or services in India' test may not be met. But if the Indian user's data is collected within India (the user is in India when they access the site), the 'collected within India' test applies. This is a complex and fact-specific question. Conservative approach: assume DPDP applies to any personal data of an Indian-resident individual, regardless of where the website is hosted.
Extend your compliance programme to cover DPDP
Niti Bharat's DPDP Gap Analysis for foreign companies maps your existing privacy programme against DPDP requirements — identifying the specific gaps to close for Indian user compliance.
Start DPDP Gap Analysis