At a glance
Yes — the DPDP Act reaches foreign companies. Section 3(b) applies the Act to processing of personal data done entirely outside India whenever that processing is connected to offering goods or services to people in India. So a company with no Indian office, staff, or servers is still bound if it targets or serves Indian users, much as GDPR reaches Indian firms. What it doesn’t catch is processing with no India-facing offering behind it. If Indian users are your customers, you’re in scope wherever you sit.
Educational resource only. This explains the extra-territorial reach of India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
A company based in the US, Singapore, or the EU, with no Indian entity, often assumes an Indian law simply can’t reach it. Under the DPDP Act that assumption is wrong, and getting it wrong is expensive: the Act was written to follow Indian users’ data across borders, not to stop at the country’s edge. Whether it applies to you turns on who you serve, not where you’re incorporated.
The short version: reach follows the user
The Act’s jurisdiction attaches to the Indian data principal, not to your company’s address. The organising idea behind DPDP’s territorial scope is that an Indian person’s personal data should carry the same protection whether it’s processed by a firm in Bengaluru or one in California. So the question the Act asks isn’t “is this company Indian?” — it’s “is this processing connected to serving people in India?” A foreign business that never set foot in India but signs up Indian customers is doing exactly the kind of processing the Act is designed to cover. This mirrors the model most modern privacy laws use, GDPR included, which is why a compliance team that already handles GDPR’s extra-territorial reach will find the logic familiar.
What Section 3(b) actually says
Section 3(b) extends the Act to processing outside India that’s “in connection with any activity related to offering of goods or services” to data principals in India. In plain terms: if your processing of personal data, done wholly outside India, is tied to offering goods or services to people located in India, the Act applies to that processing regardless of where your company or servers are. Two elements do the work. There has to be processing of personal data, and it has to be in connection with offering goods or services to people in India. Meet both and you’re in scope; the absence of an Indian office, bank account, or data centre doesn’t take you out of it. The provision is deliberately broad on this point, because a narrower rule would let any foreign platform serving millions of Indians sidestep the law by hosting abroad.
When a foreign company is caught — and when it isn’t
The line is whether there’s an India-facing offering behind the processing — targeting Indian users pulls you in; incidental, non-India-directed processing generally doesn’t.
- Caught: a foreign SaaS product, e-commerce site, app, or service that markets to, sells to, or onboards users in India. The Indian users’ data is squarely in scope, and the more your offering is directed at India (pricing in rupees, India-specific features, local marketing), the clearer it is.
- Not the target of 3(b): processing with no offering of goods or services to people in India behind it. A purely internal foreign operation, or a foreign business none of whose data principals are in India, isn’t reached by this limb — though if any of your users are in India, their data is back in scope.
The grey zone is the company that isn’t actively targeting India but has some Indian users anyway. The safer reading, given how broadly the provision is drafted, is that once you’re knowingly serving Indian data principals, you should treat their data as in scope rather than betting on a narrow interpretation of “offering.”
What an in-scope foreign company has to do
Being caught by Section 3(b) means the full fiduciary playbook applies to your Indian users’ data — not a lighter foreign-company version. There’s no diluted regime for overseas fiduciaries: if the Act applies, you owe Indian data principals the same core duties an Indian company does — a compliant notice, a valid basis (consent or a defined legitimate use), purpose-limitation, retention limits, security, breach reporting to the affected people and the Data Protection Board of India, and a working way to exercise rights and raise grievances. In practice that usually means a reachable grievance contact for Indian users and processes that actually respond within the Act’s timelines. The mistake to avoid is treating Indian users as an edge case bolted onto a GDPR or US setup; the obligations overlap heavily but aren’t identical, and the gaps are where the exposure lives.
The overlap with other countries’ laws
DPDP applying to you doesn’t switch off anyone else’s law — a global service is usually complying in several directions at once. If you serve Indian users you’re in DPDP scope; if you also serve EU users you’re in GDPR scope; and satisfying one does not automatically satisfy the other. The pragmatic path most global companies take is to build to the stricter common denominator where the rules align, and handle the genuine divergences (India’s negative-list transfer model versus GDPR’s adequacy approach, the under-18 children’s threshold, the absence of a separate “sensitive data” category in DPDP) explicitly rather than assuming their existing programme already covers India. Treat DPDP as its own line item, mapped against what you already do, not as a subset of a law you’ve already implemented.
FAQ
Does DPDP apply if my company has no office or servers in India?
Yes, if your processing is connected to offering goods or services to people in India. Section 3(b) reaches processing done entirely outside India on that basis — physical presence in India isn’t what triggers it.
What actually triggers DPDP for a foreign company?
Processing personal data in connection with offering goods or services to data principals located in India. The clearer your service is directed at Indian users, the more clearly you’re in scope.
If I have only a handful of Indian users, am I exempt?
There’s no numeric threshold in Section 3(b). Once you’re knowingly serving Indian data principals, the prudent position is to treat their data as in scope rather than rely on a narrow reading of “offering goods or services.”
We already comply with GDPR — doesn’t that cover India?
Not automatically. The two overlap but diverge on transfers, children’s age thresholds, sensitive-data categories, and specifics of notice and rights. Map DPDP separately against your GDPR programme and close the gaps.
What do we owe Indian users if we’re in scope?
The same core fiduciary duties as an Indian company: compliant notice, a valid processing basis, purpose-limitation, retention limits, security, breach reporting, and working rights-and-grievance handling for your Indian data principals.