For global companies
Selling to India? The DPDP Act applies to you.
The short answer: Section 3 of India's DPDP Act applies to processing outside India whenever it is connected to offering goods or services to people in India. If Indians can sign up, buy, or subscribe — you are a data fiduciary under Indian law, with the same duties and the same penalties (up to ₹250 crore ≈ $30M per instance) as a Mumbai company.
Who this catches
- Global SaaS — Indian workspaces on your product mean Indian data principals in your database.
- E-commerce & D2C — shipping to Indian addresses or accepting UPI/₹ payments is "offering goods" squarely.
- Gulf & Southeast Asian businesses — serving the Indian diaspora usually means serving people in India too: remittances, travel, family purchases.
- Apps & platforms — Indian installs with accounts, analytics, or notifications are processing Indian personal data.
What compliance means from abroad
The duties don't shrink with distance: notice before consent (English or any of 22 Indian languages), purpose-wise consent, withdrawal as easy as consent, statutory handling of access/correction/erasure requests — and evidence for all of it. The Act also carries a penalty foreign companies should weigh more than the fines: the power to block your services in India. Non-compliance can mean losing the market entirely.
ProofKosh gives you the whole stack without an Indian entity: a consent widget that auto-detects 15 languages, a hosted data-rights portal, a tamper-evident evidence ledger with a publicly verifiable chain, and audit exports — with data hosted in India, satisfying residency expectations.
Common questions
Does India's DPDP Act apply to companies outside India?
Yes. Section 3(b) extends the Act to processing outside India when it is connected to offering goods or services to data principals within India. A US SaaS with Indian users, a Gulf e-commerce site shipping to India, or a European app with Indian sign-ups all have the same obligations as an Indian company.
What does a foreign company have to do?
The same core duties as Indian fiduciaries: give notice in English or a Schedule-8 Indian language, obtain purpose-wise consent, honour withdrawal as easily as consent was given, handle access/correction/erasure requests within statutory timelines, and be able to prove all of it.
What are the penalties for foreign companies?
The same schedule — up to ₹250 crore (~$30M) per instance for failing security safeguards, ₹200 crore for breach-notification and children's-data violations. The Act also empowers blocking access to a non-compliant fiduciary's services in India — market cut-off, not just fines.
When does this become enforceable?
The DPDP Rules were notified on 14 November 2025. Core obligations become mandatory around May 2027 (18 months from notification), with the Data Protection Board operational from around November 2026.
Do I need an office in India to comply?
No office is required to be covered by the Act — and none is required to comply. You need working consent capture for Indian users, a rights-request channel, and evidence. ProofKosh provides all three as a service, with data hosted in India.
Find out where you stand — in 3 minutes
The free Readiness Score works for foreign fiduciaries too. No signup, no sales call.
Related: the DPDP deadline timeline · Purposes & Notices explained