Does DPDP apply to foreign companies?
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 9 min read
Does the DPDP Act apply to companies outside India?
The short answer
Yes, once it commences. Section 3(b) applies the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering of goods or services to Data Principals within India, so a foreign company with Indian users is reached on the same test as an Indian one. 2 things almost every guide leaves out. First, section 3 is itself in the group commencing 18 months after publication of notification G.S.R. 843(E), computed as 13 May 2027 and interpretation until officially confirmed, so the provision that decides application is not in force today. Second, the Act creates no local presence duty at all: representative, subsidiary and branch office each appear 0 times in it, so there is nothing to register and, unless the Central Government notifies you as a Significant Data Fiduciary under section 10(1), nobody to appoint. The route against a company with no Indian assets is section 37, which lets the Central Government order blocking of public access to information in any computer resource that enables the company to carry on an activity relating to offering goods or services to Data Principals in India, but only on a reference from the Board after monetary penalty in 2 or more instances, and section 37 sits in the same 18 month group.

Almost every answer to this question says the same true thing and stops one step too early. Yes, the Act reaches a company outside India that offers goods or services to people in India. What almost nobody adds is that the provision which says so is not in force yet, that the Act asks nothing of a foreign company by way of local presence, and that the enforcement route against a company with no assets in India is a blocking order rather than a fine.
The provision that decides this is not in force
Start here, because it changes what a foreign company should be doing this quarter.
Section 3 is the application provision. It is the section that decides whether the Act reaches you at all. It is named in paragraph (c) of commencement notification G.S.R. 843(E), the group that comes into force 18 months after publication, computed as 13 May 2027 and interpretation until officially confirmed.
So the position today is not "the Act applies to you extraterritorially". It is that the Act's own application provision commences with the substantive duties it would switch on, and until then there is no obligation on a Data Fiduciary or a Data Processor under it to breach. Section 2, the definitions, is in force already under paragraph (a) of the same notification, which is why you can read a settled definition of Data Fiduciary today while the provision deciding whom it binds is still ahead.
That is not a reason to do nothing. It is a reason to be precise about which rulebook a demand comes from, because a vendor questionnaire asserting a live DPDP obligation on a foreign supplier today is asserting something the commencement notification does not support.
Inbound: the test when it arrives
Read the whole provision, chapeau included, because the opening words govern all 3 limbs, the exclusions in clause (c) included:
"Subject to the provisions of this Act, it shall— (a) apply to the processing of digital personal data within the territory of India where the personal data is collected–– (i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;"
2 separate limbs, and foreign companies usually only look at the second.
Clause (a) turns on where the processing happens, not on who is doing it. It has 2 elements, and the second is easy to miss: the processing must be within the territory of India, and the personal data must have been collected in digital form, or in non-digital form and digitised subsequently. On a plain reading of those words a foreign company processing such data in India is inside clause (a) without clause (b) doing any work, and the nationality of the processor is irrelevant to it. That last step is a reading rather than a settled position, because the Act does not say where processing is taken to happen.
Clause (b) is the extraterritorial limb, and its connector is unusually wide. Not "offering goods or services", but processing "in connection with any activity related to offering of goods or services". 3 softeners stack: in connection with, any activity, related to. On a reading of that connector, processing that never touches an Indian customer directly, such as analytics on aggregate behaviour or a fraud model trained across markets, can still be processing in connection with an activity related to the offering. That is a reading and not a settled position: section 3 is not in force, so no authority has applied it.
What the limb does not say matters too. It does not say the offering must be paid for. It does not say the company must target India, and it does not carry the "directing activities" language that other regimes use. It fixes on a relationship between the processing and an activity related to offering to people in India.
What the test is not: there is no local presence duty
This is where GDPR habits mislead, and it is checkable rather than arguable.
Counted across the full Gazette text of the Act on 27 August 2026:
| Term | Occurrences in the DPDP Act 2023 |
|---|---|
| representative | 0 |
| subsidiary | 0 |
| branch office | 0 |
| establishment | 1, and it is the marginal heading "Establishment of Board" beside section 18 |
The count is of those exact words. The inflected forms established and establish do appear 4 times between them, at sections 2(a), 2(c), 8(10) and 18(1), and none of them is about a company having an establishment in India.
So there is no registration for foreign entities, no threshold that creates an Indian nexus, and no filing that makes a foreign company visible to the regulator. Section 10(2) does create appointment duties, but they attach only to a Significant Data Fiduciary once the Central Government notifies one under section 10(1). Clause (a) requires a Data Protection Officer who must be based in India and who, in the words of section 10(2)(a)(i), shall represent the Significant Data Fiduciary under the provisions of this Act. Clause (b) requires an independent data auditor. Neither is triggered by being foreign: the trigger is a government notification, on factors listed in section 10(1) that do not include nationality or place of incorporation.
If you are carrying an EU style representative obligation across into your India work, that obligation has no counterpart in this text. Check the EU side against the official source separately; the claim here is only about the Indian instrument.
The exclusions are not about you
Section 3(c) is the only place the application provision takes anything out, and neither limb helps a foreign business:
"not apply to— (i) personal data processed by an individual for any personal or domestic purpose; and (ii) personal data that is made or caused to be made publicly available by — (A) the Data Principal to whom such personal data relates; or (B) any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available."
Clause (c)(i) is about an individual acting personally, so it does not reach a company at all. Clause (c)(ii) is about data already made public, and its (B) limb is narrower than it looks: the obligation to publish must arise under a law in force in India, so data a foreign registry publishes under foreign law is not obviously inside it. That is a reading of the words rather than a settled position, and it is one worth taking advice on if your product is built on scraped public data.
Outbound: the outsourcing carve out
The traffic runs the other way too, and here the Act steps back. Section 17(1)(d) is one of the listed cases in which section 17(1) disapplies Chapter II except sections 8(1) and 8(5), the whole of Chapter III on rights, and section 16:
"personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India"
That is the Indian outsourcing and global capability centre scenario: foreign end user data, processed in India, under a contract with a foreign client. 3 conditions have to line up, and each is a place an arrangement can fall outside the clause. The Data Principals must not be within India. The contract must be entered into with a person outside India. And that contract must be entered into by a person based in India, which is what the clause says rather than that the processing itself must be done in India.
2 things survive inside the exemption and are routinely assumed not to. Section 8(1) keeps the Data Fiduciary responsible for compliance whatever any agreement to the contrary says. Section 8(5), the reasonable security safeguards duty, stands while the breach intimation duty in section 8(6) falls. What a section 17 exemption switches off, and what survives sets that out provision by provision. Section 17 is in the same 18 month group, so this carve out is not available yet either.
How it would be enforced against a company with no Indian assets
This is the part the field gets wrong most often. A common line is that the framework provides no way to reach a foreign company. It provides one, and it is not a fine.
Section 37 lets the Central Government, or an officer it specially authorises, order the blocking of public access to information in any computer resource that enables a Data Fiduciary to carry on an activity relating to offering goods or services to Data Principals in India. Sub-section (2) binds every intermediary receiving such a direction to comply. Sub-section (3) takes computer resource, information and intermediary from the Information Technology Act, 2000.
The preconditions are cumulative, printed as (a) and (b) joined by "and", and they are demanding:
- a reference in writing from the Board;
- that reference intimates monetary penalty already imposed by the Board on that Data Fiduciary in 2 or more instances;
- the reference advises blocking in the interests of the general public;
- the Data Fiduciary has been given an opportunity of being heard;
- the Central Government is satisfied it is necessary or expedient in the interests of the general public, with reasons recorded in writing.
Read that sequence and the practical position for a foreign company becomes clear. On these words the escalation runs through money and then to market access, and it does not skip the money: monetary penalty has to have been imposed in 2 or more instances before the Board can even advise blocking. What section 37 adds is a lever that does not depend on recovering anything, which is why having no assets and no subsidiary in India is not the shield it is often assumed to be. It is also a long road: 2 penalty orders mean an inquiry, an order and a hearing before any of this begins. That practical conclusion is a reading of the sequence in section 37(1) and not something the provision says.
And it is not available today. Section 37 is in the same 18 month group as section 3, so the application provision, the outsourcing exemption and the blocking power all arrive together. Nor is there anyone to start it: the Data Protection Board had no appointed members as of 27 August 2026, and section 27, its powers, is not in force either.
What a foreign company should actually do now
The honest sequence, given that nothing above binds anyone today.
Decide which limb reaches you, and write down why. Clause (a) if you process in India, clause (b) if you process abroad in connection with an activity related to offering to people in India, and both is common. The applicability checker walks the same questions, and takes the caveats with it.
Work out your role per data flow rather than per company. A single foreign entity is often a Data Fiduciary for its own users and a Data Processor for a client's data, and the duties differ. The role checker does this flow by flow.
Do not build for a local representative. There is no such duty in this text. Building an entity or an appointment to satisfy one is work with no provision behind it.
If you are an Indian supplier to foreign clients, get the section 17(1)(d) fit reviewed rather than assumed. All 3 conditions have to hold, and the exemption is narrower than the sector treats it.
Watch for a Significant Data Fiduciary notification, not a threshold. Section 10(1) makes that status a matter of government notification, and no notification of any Data Fiduciary had been located as of 27 August 2026. Being large, or being foreign, does not put you in it by itself.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Role and Actor Checker
Work out your likely role for a processing activity, such as Data Fiduciary or Data Processor.
Open
Section 3, official text →Section 37, the blocking power →
Foreign companiesApplicabilityOutsourcingSection 3Section 37