Does DPDP Apply to Foreign Companies Serving Indian Users?
Yes. Section 3(b) reaches processing that happens entirely outside India, and it does not require you to have an Indian entity, an Indian server, or a rupee transaction.
The short answer
Yes. Section 3(b) applies the Act to processing of digital personal data outside the territory of India, if that processing is in connection with any activity related to offering goods or services to Data Principals within India.
The trigger is the offering, not the infrastructure. There is no requirement for an Indian subsidiary, Indian hosting, an Indian bank account or an Indian employee.
What counts as offering goods or services
The Act does not define this exhaustively, so the sensible reading is behavioural rather than technical. Indicators that you are offering into India include pricing in rupees, Indian payment methods, India-specific marketing, an India entry on your regions or availability list, support hours covering Indian time zones, or an India-specific version of your product.
Merely being reachable from India is a weaker signal. A website accessible worldwide with no India-directed activity is a different proposition from one actively selling into the market. The question is whether the activity is directed at Data Principals in India.
What you actually have to do
The same obligations as a domestic Data Fiduciary. There is no reduced regime for foreign companies:
- Rule 3 — notice that is understandable independently of any other information you provide.
- Rule 6 — the minimum security safeguards, including access control, logging, and one year retention of logs.
- Rule 7 — breach intimation to affected Data Principals without delay, and to the Data Protection Board without delay and then in detail within seventy-two hours.
- Rule 8 — erasure once the specified purpose is no longer served.
- Rule 14 — a working process for Data Principals to exercise their rights.
The operational problem nobody plans for
Rule 7 requires an intimation to the Board within seventy-two hours of becoming aware, and both intimations start on awareness rather than on completing an investigation. For a company operating several time zones away, with no Indian presence, that is a process question before it is a legal one: who is authorised to declare awareness, and who files with an Indian regulator at short notice?
Rule 7(1) also requires you to publish business contact information for a person able to respond to a Data Principal's queries. Someone reachable has to exist before an incident, not be nominated during one.
The gap for overseas companies is rarely the drafting. It is that nobody has decided, in advance, who acts when an Indian obligation is triggered outside Indian working hours.
Infosek Team
If you are already GDPR compliant
You have a head start on the substrate: a data inventory, a lawful basis discipline, breach procedures and rights handling. What does not transfer:
- The breach timeline is a different shape. DPDP has two Board intimations with two clocks, plus immediate notice to affected individuals.
- Rule 6 specifies minimum controls including a one year log retention. GDPR's Article 32 is principle-based and does not.
- Significant Data Fiduciary status is a government notification under section 10, not a self-assessment, and Rule 13 brings a twelve-monthly DPIA and audit reported to the Board.
- Rule 13(4) can require specified personal data, and the traffic data on its flow, to stay inside India.
Common questions
Does the DPDP Act apply outside India?
Yes. Section 3(b) applies the Act to processing of digital personal data outside the territory of India where that processing is in connection with any activity related to offering goods or services to Data Principals within India.
Does a foreign company need an entity in India to be covered by DPDP?
No. Section 3(b) is drafted around the activity of offering goods or services to Data Principals in India, not around corporate presence. A company with no Indian entity, no Indian infrastructure and no Indian employees can still be within scope.
Selling into India from overseas?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment