Skip to main content

Sources last verified on 17 August 2026. Methodology

Does DPDP apply to foreign companies?

Applicability

By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed

The short answer

It can. The Act applies to processing of digital personal data outside India if it is in connection with any activity related to offering goods or services to Data Principals within India, so a foreign company serving Indian users is reached. In the other direction, the Act largely steps back from Indian outsourcing: where personal data of people not in India is processed by a person based in India under a contract with a person outside India, most of the operational chapters are disapplied by the statutory exemption.

The territorial questions run in both directions, and each direction has a surprise in it.

Inbound: foreign companies serving India are reached

Official requirement · verbatim

"also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India"

Note how wide the connector is: in connection with any activity related to offering. A foreign app with Indian users, a foreign store shipping to India, a foreign SaaS selling to Indian customers: geography alone does not put processing outside the framework.

Outbound: the outsourcing carve out

Section 17(1)(d) disapplies most of the operational chapters, specifically Chapter II except the responsibility and safeguards duties in section 8(1) and 8(5), all of Chapter III on rights, and section 16, where:

Official requirement · verbatim

"personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India"

That is the Indian outsourcing and BPO scenario: foreign end user data, processed by a person based in India under a foreign client contract. The safeguards duty and the fiduciary responsibility still apply, but the notice, consent, rights and transfer machinery largely does not for that data. The precise fit of an arrangement to this exemption deserves legal review; it is a carve out, not a blanket.

What to do

Foreign companies with Indian users: run the applicability check and treat the result's caveats seriously. Indian processors serving foreign clients: work out your role per data flow with the role checker and take the section 17(1)(d) fit to counsel.

Section 3, official text

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 3(b), p. 3. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 17(1)(d), p. 11. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 17(1) disapplies the provisions of Chapter II except sub sections (1) and (5) of section 8, Chapter III and section 16 in the listed cases, including this one.

foreign companiesapplicabilityoutsourcing