Infosek
INFOSEK

Does DPDP Apply to Foreign Companies Serving Indian Users?

Yes. Section 3(b) reaches processing that happens entirely outside India, and it does not require you to have an Indian entity, an Indian server, or a rupee transaction.

Does DPDP Apply to Foreign Companies Serving Indian Users?

The short answer

Yes. Section 3(b) applies the Act to processing of digital personal data outside the territory of India, if that processing is in connection with any activity related to offering goods or services to Data Principals within India.

The trigger is the offering, not the infrastructure. There is no requirement for an Indian subsidiary, Indian hosting, an Indian bank account or an Indian employee.

What counts as offering goods or services

The Act does not define this exhaustively, so the sensible reading is behavioural rather than technical. Indicators that you are offering into India include pricing in rupees, Indian payment methods, India-specific marketing, an India entry on your regions or availability list, support hours covering Indian time zones, or an India-specific version of your product.

Merely being reachable from India is a weaker signal. A website accessible worldwide with no India-directed activity is a different proposition from one actively selling into the market. The question is whether the activity is directed at Data Principals in India.

What you actually have to do

The same obligations as a domestic Data Fiduciary. There is no reduced regime for foreign companies:

The operational problem nobody plans for

Rule 7 requires an intimation to the Board within seventy-two hours of becoming aware, and both intimations start on awareness rather than on completing an investigation. For a company operating several time zones away, with no Indian presence, that is a process question before it is a legal one: who is authorised to declare awareness, and who files with an Indian regulator at short notice?

Rule 7(1) also requires you to publish business contact information for a person able to respond to a Data Principal's queries. Someone reachable has to exist before an incident, not be nominated during one.

The gap for overseas companies is rarely the drafting. It is that nobody has decided, in advance, who acts when an Indian obligation is triggered outside Indian working hours.

Infosek Team

If you are already GDPR compliant

You have a head start on the substrate: a data inventory, a lawful basis discipline, breach procedures and rights handling. What does not transfer:

Common questions

Does the DPDP Act apply outside India?

Yes. Section 3(b) applies the Act to processing of digital personal data outside the territory of India where that processing is in connection with any activity related to offering goods or services to Data Principals within India.

Does a foreign company need an entity in India to be covered by DPDP?

No. Section 3(b) is drafted around the activity of offering goods or services to Data Principals in India, not around corporate presence. A company with no Indian entity, no Indian infrastructure and no Indian employees can still be within scope.

Selling into India from overseas?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment