A company can be incorporated in the US, operate from the UK, and host its infrastructure in Europe yet still fall under India’s DPDP Act. Section 3(b) applies to qualifying processing outside India connected with offering goods or services to Data Principals in India.
For foreign businesses, compliance therefore depends on their India-facing activities, data flows, and processing practices, not simply server location. With the DPDP Rules, 2025 introducing a phased framework through 2027, companies serving Indian users should use this window to map personal data, review cross-border transfers and processors, and prepare their privacy, security, rights, and retention processes.
Does the DPDP Act Apply Outside India?
Yes. DPDP Act expressly covers processing of digital personal data outside India when that processing is connected with an activity related to offering goods or services to Data Principals within India.
This is the provision that gives the DPDP Act for foreign companies its extraterritorial reach. It means a company cannot determine applicability solely by asking:
- Where is the company incorporated?
- Where are its employees located?
- Where is its cloud infrastructure hosted?
- Where is its primary database located?
Instead, it must first establish whether its overseas processing is connected with offering goods or services to Data Principals in India.
That distinction matters because a company can have no Indian data center while still processing personal data belonging to Indian customers or users as part of its India-facing business.
When Does the DPDP Act Apply to a Foreign Company?
For a foreign company, the practical assessment begins with the India-facing activity and then follows the personal data generated or used to deliver it.
US SaaS companies
A US SaaS provider may collect administrator details, employee information, account credentials, support records, billing information, or other personal data while delivering its service to Indian customers.
If that processing is connected with offering the service to Data Principals in India, hosting the application and database in the US does not by itself remove the processing from Section 3(b).
UK e-commerce companies
A UK retailer serving Indian customers may process names, contact details, delivery addresses, order information, and customer-service records through systems located outside India.
The relevant consideration is the connection between those processing activities and the company's offering of goods or services to Data Principals in India.
Global platforms
A global platform may use the same application, identity layer, analytics stack, customer-support environment, and cloud infrastructure across multiple markets.
Indian personal data may therefore move through several jurisdictions without the company maintaining an India-specific technology environment.
The important distinction is that server location is not the scope test. Section 3(b) focuses on the connection between overseas processing and the offering of goods or services to Data Principals in India.
At the same time, the mere fact that an individual happens to be in India should not be treated as an automatic trigger for every foreign company's processing. The statutory language requires the relevant connection with an activity related to offering goods or services to Data Principals in India.
DPDP Act Compliance Timeline: What Changes in 2026 and 2027?
The DPDP Rules, 2025 were notified on November 13, 2025, and establish a phased commencement structure rather than bringing every provision into force at once.
The key milestones for organizations planning DPDP compliance for foreign companies are:
- November 2025: The final Rules are notified and specified provisions take effect.
- November 2026: Rule 4 is scheduled to come into force.
- May 2027: Rules 3, 5–16, 22 and 23 are scheduled to come into force under the 18-month commencement provision. These include important operational requirements covering areas such as notices, security safeguards, breach management, Data Principal rights, and cross-border processing.
The 2027 milestone should not be treated as the starting point for compliance work.
A foreign company's readiness may depend on changes across:
- privacy and consent interfaces;
- data inventories and records;
- cloud and application architecture;
- processor and subprocessor contracts;
- rights-request workflows;
- retention and deletion mechanisms; and
- incident-response processes.
Starting with data mapping gives legal, privacy, security, engineering, and procurement teams a common view of what actually needs to change.
Section 16: Can Indian Personal Data Be Processed Outside India?
Section 16 of the DPDP Act addresses the processing of personal data outside India. It allows the Central Government to restrict the transfer of personal data by a Data Fiduciary for processing to a specified country or territory outside India.
Section 16(2) also preserves the applicability of other Indian laws that provide a higher degree of protection or impose greater restrictions on overseas transfers.
This is important because Section 16 should not be interpreted as a blanket data-localization mandate.
For a foreign company, there are two separate questions:
- Is overseas processing permitted under the applicable Indian framework?
- What other DPDP and sector-specific obligations apply to the processing itself?
A US company may therefore be able to process Indian personal data through infrastructure outside India while still needing to comply with requirements concerning notice, consent, security, rights, retention, processors, and other applicable obligations.
Does the DPDP Act Require Data Localization?
The DPDP Act does not establish a blanket requirement that all Indian personal data must be stored on servers physically located in India.
Instead, Section 16(1) creates a mechanism through which the Central Government may restrict transfers to specified countries or territories. Section 16(2) also preserves stricter requirements under other Indian laws.
For foreign companies, this distinction is critical.
DPDP data localization should not be treated as synonymous with DPDP compliance. An organization may operate an overseas cloud environment and still need to understand:
- where Indian personal data is stored;
- where it is replicated;
- which jurisdictions can access it;
- which processors receive it; and
- whether another Indian law imposes additional restrictions.
The correct compliance question is therefore not simply “Is the data in India?” but “What data is moving where, under whose control, and subject to which restrictions?”
Rule 14: What Does It Mean for Cross-Border Data Transfers?
Rule 14 of the DPDP Rules, 2025 deals with restrictions concerning the transfer of personal data outside India. The provision applies to personal data processed by a Data Fiduciary within India and to processing outside India in connection with offering goods or services to Data Principals in India.
It provides that the Central Government may specify requirements concerning making such personal data available to a foreign State, or to a person or entity under the control of or an agency of such a State.
For a foreign company, this makes the access model as important as the storage model.
Consider a global SaaS environment with:
- production databases in the US;
- backups replicated to another jurisdiction;
- cloud administrators operating remotely;
- a support platform receiving customer records;
- analytics vendors processing identifiers; and
- subprocessors handling parts of the service.
A cross-border assessment that looks only at the primary database location would miss these additional access and processing paths.
Where Is Indian Personal Data Stored and Who Can Access It?
Foreign companies should map the full environment in which Indian personal data exists or can be accessed.
This should include:
- production databases and cloud environments;
- backup and disaster-recovery systems;
- employee and administrator access;
- contractors and support personnel;
- CRM, analytics, monitoring, and support platforms;
- cloud infrastructure providers; and
- subprocessors with access to the data.
The objective is to establish where the data exists, who can access it, why they need access, and under whose control that access occurs.
Third-Party Processors and Cross-Border Data Transfers
Processor governance should extend beyond confirming that a vendor has a privacy policy or follows a recognized security standard.
For each relevant processor, a foreign company should establish:
- What data is shared.
- Why it is processed.
- Where processing and storage occur.
- Who can access it.
- Which subprocessors are involved.
- What security controls apply.
- How and when the data is deleted or returned.
This matters because cross-border exposure can arise indirectly. A support platform can receive customer information, an analytics tool can ingest identifiers, and a monitoring service can retain operational data even when none of these systems form part of the company's primary customer database.
Key DPDP Compliance Requirements for Foreign Companies
The core compliance challenge is not simply publishing an updated privacy notice. Foreign organizations need controls that follow Indian personal data through its entire lifecycle from collection and processing to access, transfer, retention, and deletion.
Notice and Consent Requirements
Sections 5 and 6 establish requirements concerning notice and consent. Section 5 requires notice about the personal data and purpose of processing, while Section 6 addresses consent, including the ability to withdraw consent.
The final Rules add requirements around how notices are presented. Rule 3 requires the notice to be understandable independently of other information and to provide an itemized description of the personal data and the specified purposes for processing.
For a foreign company, this means an existing global privacy notice should be assessed rather than automatically treated as sufficient.
The more difficult implementation question is what happens after consent changes. Withdrawal should be reflected in the systems and processing activities that depend on that consent, including relevant processor workflows.
Data Principal Rights and Grievance Redressal
The Act sets out Data Principal rights in Sections 11–13, including the right to access information about personal data, correction and erasure, and grievance redressal.
For a foreign company, fulfilling these rights requires operational coordination.
A workable process should allow the organization to:
- identify the relevant Data Principal;
- locate personal data across applicable systems;
- coordinate actions with processors;
- apply correction or erasure where required;
- maintain a record of the request and response; and
- route unresolved grievances through the prescribed mechanism.
An organization with existing GDPR rights workflows may be able to reuse part of this infrastructure, but the DPDP-specific requirements still need to be mapped separately.
Security Safeguards and Personal Data Breach Management
Section 8(5) requires a Data Fiduciary to protect personal data in its possession or control by taking reasonable security safeguards to prevent personal data breaches. The obligation also extends to processing undertaken by a Data Processor. Section 8(6) addresses notification of personal data breaches to the Board and affected Data Principals in the prescribed manner.
For a foreign company, this connects privacy compliance directly to security operations.
The organization needs to be able to determine:
- whether Indian personal data was affected;
- which systems and processors were involved;
- what categories of Data Principals may be affected;
- what containment and remediation steps are required; and
- what notifications must follow.
A processor's incident should therefore feed into the company's broader DPDP breach-response process rather than remain isolated within vendor management.
Data Retention and Erasure Under DPDP
Section 8(7) addresses erasure when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, subject to applicable legal retention requirements. It also requires the Data Fiduciary to cause its Data Processor to erase personal data made available for processing. Section 12 separately establishes the Data Principal's right to correction and erasure.
For a global environment, deletion therefore needs to extend beyond the primary application.
A retention and erasure process should account for:
- production records;
- replicated datasets;
- processor-held copies;
- relevant backups; and
- systems where the data is retained for legally required purposes.
This is where a data inventory becomes operationally valuable: an organization cannot reliably delete or retain what it cannot locate.
Does GDPR Compliance Automatically Make You DPDP Compliant?
No. GDPR compliance can provide a strong starting point for DPDP compliance for foreign companies. A company may already have:
- data inventories;
- privacy notices;
- consent mechanisms;
- processor contracts;
- rights-request workflows;
- retention policies; and
- security and incident-response controls.
But those controls should be mapped against the DPDP Act rather than assumed to be equivalent.
The DPDP framework has its own terminology, statutory structure, consent requirements, Data Principal rights, grievance mechanism, security obligations, and provisions concerning processing outside India.
The practical approach is therefore a gap assessment:
- Identify controls already operating under GDPR.
- Map them against the relevant DPDP provisions.
- Identify requirements that can be reused without modification.
- Adapt processes where DPDP differs.
- Build new workflows where no equivalent control exists.
GDPR can reduce the implementation burden, but it does not remove the need for a DPDP-specific assessment.
DPDP Compliance Checklist for Foreign Companies
Before the substantive DPDP provisions take effect, a foreign company processing Indian personal data should be able to answer:
- Scope: Which products, services, and processing activities bring the organization within Section 3(b)?
- Data: What personal data relating to Data Principals in India is being processed?
- Purpose: Why is each category of data being processed?
- Data flows: Where is it collected, stored, replicated, transferred, and accessed?
- Processors: Which vendors and subprocessors receive it?
- Transfers: Which countries and jurisdictions are involved?
- Notice and consent: What information is presented to the Data Principal, and how is consent captured or withdrawn?
- Rights: Can access, correction, erasure, and grievance requests be handled across relevant systems?
- Security: Are reasonable safeguards and breach-response procedures in place?
- Retention: When should each category of personal data be deleted?
- Governance: Who owns DPDP compliance across legal, privacy, security, engineering, and vendor-management teams?
Build Readiness Before the 2027 Deadline
For US, UK, and other foreign companies, DPDP compliance starts with knowing where Indian personal data enters the business and where it goes next. Section 3(b), Section 16, and Rule 14 provide the legal framework for assessing overseas processing and transfers.
With substantive requirements scheduled for 2027, organizations should now map data flows, review processors, and align consent, security, rights, retention, and deletion controls. A focused assessment today can reveal DPDP gaps early and help integrate the required changes into existing privacy and security programs.
FAQs
1. Does a US company need an office in India to be covered by the DPDP Act?
No. Section 3(b) applies the Act to qualifying processing outside India when it is connected with an activity related to offering goods or services to Data Principals in India. A physical office in India is therefore not the statutory test.
2. Can a UK company store Indian personal data in the UK?
The DPDP Act does not impose blanket localization of all Indian personal data. Section 16 provides for possible government restrictions on transfers to specified countries or territories and preserves stricter requirements under other Indian laws.
3. Is Rule 14 the same as a data-localization requirement?
No. Rule 14 addresses requirements concerning making personal data available to a foreign State or to persons or entities under its control or agencies of such a State. It should be considered alongside the company's wider cross-border data, storage, and access model.
4. When do the main DPDP Rules apply?
The Rules use a phased commencement structure. Rules 3 and 5–16, along with Rules 22 and 23, are scheduled to take effect 18 months after notification, making May 2027 the key milestone for these substantive provisions.
5. Does keeping Indian data outside India avoid DPDP obligations?
No. Section 3(b) specifically addresses qualifying processing outside India connected with offering goods or services to Data Principals in India. Where data is stored and whether the Act applies are separate questions.
6. What should a foreign company do first?
Start with a data-flow and scope assessment. Identify which products serve Data Principals in India, what personal data they process, where that data travels, which processors can access it, and how the organization handles consent, rights, security, retention, and deletion. That assessment provides the foundation for a targeted DPDP compliance program rather than a generic privacy-policy exercise.




Leave a Comment