Skip to main content
Budget & Policy

DPDP Act Phase 1: What Every Foreign Company Must Do

India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 impose far-reaching data privacy obligations on foreign companies processing Indian personal data. This guide covers the phased compliance timeline, extraterritorial application, consent requirements, breach notification rules, and penalties up to INR 250 crore per violation.

March 18, 20268 min read
8 min readLast updated September 4, 2026
Written by Shreya Pandey, Associate, Corporate ComplianceReviewed by Priyanka Khurana, Company Secretary

Why Foreign Companies Cannot Ignore the DPDP Act

India's Digital Personal Data Protection Act, 2023 (DPDP Act) — combined with the DPDP Rules notified in November 2025 — creates the country's first comprehensive data privacy framework. For foreign companies with Indian subsidiaries, branch offices, or even just customers in India, this law applies with full force and carries penalties of up to INR 250 crore per violation.

The DPDP Act's extraterritorial reach means it applies not only to entities processing personal data within India but also to foreign companies processing data outside India if such processing is connected to offering goods or services to individuals in India. If your company has an Indian wholly owned subsidiary, employs people in India, sells to Indian customers through an e-commerce platform, or processes data of Indian citizens through an outsourcing arrangement, you are within scope.

This guide breaks down the three-phase compliance timeline, the specific obligations for foreign companies, and the practical steps to achieve compliance before the May 2027 final deadline.

Phased Compliance Timeline

The DPDP Rules, 2025 establish three distinct implementation stages. Foreign companies must understand which obligations are already in effect and which are approaching.

PhaseEffective DateKey Obligations
Stage 1November 13, 2025Rules 1, 2 and 17–21 in force: constitution of the Data Protection Board of India, appointment and service terms of its Chairperson and Members, its meeting procedure and its functioning as a digital office
Stage 2November 13, 2026Rule 4 in force: Consent Manager registration opens; only companies incorporated in India with a net worth of not less than INR 2 crore qualify (First Schedule, Part A)
Stage 3May 13, 2027Rules 3, 5–16, 22 and 23 in force — privacy notices, consent systems, security safeguards, breach protocols, data retention, children's protections and data principal rights infrastructure all become operative

Stage 1 is already in effect. What it activated, however, is the machinery of the Data Protection Board — its constitution, the appointment and service conditions of its Chairperson and Members, its meeting procedure and its operation as a digital office — not the substantive duties of Data Fiduciaries. Those duties (rules 3 and 5 to 16) only bind from 13 May 2027, so a foreign company's exposure between now and then comes from preparation risk rather than live enforcement. The commencement dates come from rule 1(2) to (4) of the DPDP Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025.

Article illustration

Extraterritorial Application: Does It Apply to You?

The DPDP Act applies to foreign companies in two scenarios:

Scenario 1: Processing Data Within India

If your company has an Indian subsidiary, branch office, or liaison office that collects or processes personal data of individuals in India — including employee data, customer data, or vendor data — the Act applies in full. This covers HR records, payroll data, CRM systems, marketing databases, and any other processing activity involving identifiable Indian individuals.

Scenario 2: Processing Data Outside India

Even without a physical presence in India, the Act applies if your company processes personal data outside India in connection with offering goods or services to individuals in India. This covers e-commerce companies selling to Indian customers, SaaS companies with Indian users, and any digital service accessible to people in India.

Important Exception: Outsourcing

There is a significant carve-out for certain outsourcing arrangements. Companies based in India that process personal data of people outside India under a contract with a foreign company are largely exempt from core DPDP obligations (including data principal access and erasure rights). These companies need only comply with data security obligations. However, this exemption does not protect the foreign parent company from its own obligations regarding data of Indian individuals.

Core Compliance Obligations for Foreign Companies

1. Lawful Basis for Processing

Under the DPDP Act, personal data can only be processed based on two lawful grounds: (a) consent of the Data Principal, or (b) certain legitimate uses specified in the Act (such as voluntary provision of data, state functions, medical emergencies, and employment purposes). Unlike the EU's GDPR, there is no "legitimate interest" ground. Foreign companies accustomed to relying on legitimate interest under GDPR must restructure their processing basis for Indian data.

2. Privacy Notice Requirements

Before or at the time of collecting personal data, the Data Fiduciary must provide a clear, plain-language notice specifying: the personal data being collected, the purpose of processing, how the Data Principal can exercise their rights, and how to file complaints with the Data Protection Board. Under section 5(3) of the DPDP Act, the Data Fiduciary must give the Data Principal the option to access the contents of the notice in English or in any language specified in the Eighth Schedule to the Constitution.

3. Consent Management

Consent must be free, specific, informed, unconditional, and unambiguous, with a clear affirmative action. Data Principals must be able to withdraw consent as easily as they gave it. For foreign companies, this means implementing granular consent mechanisms for different processing purposes — blanket consent is not valid.

From November 2026, registered Consent Managers can facilitate consent management. However, only India-incorporated entities with a minimum net worth of INR 2 crore qualify as registered Consent Managers. Foreign platforms like OneTrust and TrustArc cannot serve as registered Consent Managers under the Indian framework, though they can still be used as technology tools behind a registered Indian Consent Manager entity.

4. Data Security Safeguards

Data Fiduciaries must implement reasonable security safeguards including encryption (at rest and in transit), access controls, access logging and monitoring, data backups, and measures to detect and respond to unauthorised access. The specific technical standards are expected to evolve through subsequent Board directives, but the baseline expectation aligns with ISO 27001 and similar international standards.

5. Breach Notification

Rule 7 of the DPDP Rules, 2025 sets two different clocks. On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay — describing the breach, its likely consequences for that individual, the mitigation measures taken, the steps she can take to protect herself, and a contact who can answer her questions. Separately, it must intimate the Board without delay with a description of the breach, its nature, extent, timing, location and likely impact, and then furnish the detailed report — the facts and circumstances, mitigation measures, findings on who caused the breach, remedial steps and a report on the intimations given to Data Principals — within 72 hours of becoming aware, or within such longer period as the Board may allow on a written request. The 72-hour clock therefore governs the detailed report to the Board, not the first intimation, and it is extendable only on a request the Board grants. Foreign companies still need incident response plans and communication templates ready before a breach occurs.

6. Data Retention and Erasure

Personal data must be erased once the purpose for which it was collected is fulfilled and retention is no longer necessary. The Data Fiduciary must also erase data when consent is withdrawn, unless retention is required by law. This requires implementing automated data lifecycle management — a significant infrastructure investment for companies not already GDPR-compliant.

7. Children's Data Protection

Processing personal data of children (under 18 in India) requires verifiable parental consent. The Act prohibits behavioural monitoring and targeted advertising directed at children. Foreign companies with platforms accessible to Indian minors — including gaming, social media, and educational technology — must implement age-gating and parental consent verification mechanisms.

Article illustration

Significant Data Fiduciary Obligations

Foreign companies or their Indian subsidiaries may be classified as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to data principal rights, and potential impact on India's sovereignty and security. SDF designation triggers additional obligations:

  • Data Protection Officer (DPO): Must appoint a DPO based in India who is answerable to the organisation's Board of Directors. The DPO is the point of contact for the Data Protection Board and for data principal grievances.
  • Data Protection Impact Assessment (DPIA): Must conduct a DPIA every 12 months from the date of SDF designation, reviewing how personal data is processed and identifying privacy risks.
  • Independent Data Audit: Must appoint an independent data auditor and conduct an audit every 12 months. The audit checks whether the organisation complies with the DPDP Act and its rules.
  • Data Localisation: The Central Government may specify categories of personal data that SDFs must process only within India. Such data, along with associated traffic data, cannot be transferred outside India unless explicitly permitted.

The penalty for failing to meet SDF-specific obligations is up to INR 150 crore per instance.

Cross-Border Data Transfers

Section 16(1) of the DPDP Act adopts a "blacklist" approach to cross-border data transfers: personal data can flow to any country unless the Central Government notifies a restriction on transfers to that country or territory. Check the current MeitY notifications before relying on the position for any particular destination. Rule 15 of the DPDP Rules, 2025 (in force from 13 May 2027) adds a second condition — a transfer is subject to any requirements the Central Government specifies, by general or special order, for making personal data available to a foreign State or to a person, entity or agency under that State's control. So the regime is not a pure blacklist once the rule bites.

However, foreign companies should note three important caveats:

  • The restricted countries list can be updated at any time through a notification under section 16(1) — monitor for changes.
  • SDFs face additional data localisation requirements that override the general transfer permission.
  • Even where transfers are permitted, the Data Fiduciary remains responsible for the security of data transferred overseas. A breach of transferred data still triggers the rule 7 intimation obligations and potential penalties.

For companies managing cross-border fund flows alongside data transfers, understanding FEMA compliance is equally important. Our FEMA & RBI compliance services can help coordinate both regulatory frameworks.

Article illustration

Penalty Framework

ViolationMaximum Penalty
Failure to take reasonable security safeguardsINR 250 crore (~USD 30 million)
Failure to notify the Board and Data Principals of a breachINR 200 crore (~USD 24 million)
Non-compliance with obligations regarding children's dataINR 200 crore (~USD 24 million)
Failure to comply with SDF-specific obligationsINR 150 crore (~USD 18 million)
Any other non-compliance with the Act or RulesINR 50 crore (~USD 6 million)

Penalty determination considers the nature, gravity, and duration of the breach, plus the company's remedial actions. There is no concept of a warning or grace period — penalties can be imposed from the first instance of non-compliance once the relevant phase is in effect.

Practical Compliance Roadmap for Foreign Companies

Immediate (Now — Already Due)

  • Conduct a data mapping exercise: identify all personal data of Indian individuals your company processes, where it is stored, and who has access
  • Establish a breach response team and draft incident response procedures that can intimate affected Data Principals without delay and deliver the Board's detailed report inside the rule 7 window
  • Appoint an internal privacy lead for India operations (this can be formalised as a DPO later if SDF designation applies)

By November 2026

  • Implement granular consent management mechanisms for all Indian data processing activities
  • Prepare privacy notices in English (and additional Indian languages if serving consumers directly)
  • Evaluate whether your Indian subsidiary qualifies for or requires SDF designation
  • If using third-party consent management tools, identify or establish an India-incorporated entity to serve as the registered Consent Manager

By May 2027

  • Full operational compliance: all consent systems, privacy notices, security safeguards, breach protocols, data retention/erasure mechanisms, and children's data protections must be live
  • If SDF-designated: DPO appointed, first DPIA completed, independent data auditor engaged
  • Ongoing: annual DPIA and audit (for SDFs, once in every twelve months under rule 13(1)), continuous breach monitoring, and retention of processing logs for at least one year where rule 8(3) applies. The seven-year record-keeping obligation in the First Schedule, Part B falls on registered Consent Managers, not on every Data Fiduciary — but where you use one, confirm it is meeting that obligation

For companies registering a new entity in India, building DPDP compliance into the private limited company setup from day one is significantly cheaper than retrofitting later. Our company registration services include privacy compliance advisory as part of the incorporation package.

Article illustration

How DPDP Interacts with Other Indian Regulations

Foreign companies operating in India face a web of overlapping compliance obligations. The DPDP Act does not exist in isolation — it intersects with several other regulatory frameworks that foreign companies must navigate simultaneously.

FEMA and RBI Reporting

Companies transferring personal data as part of cross-border financial transactions must comply with both FEMA current account transaction rules and DPDP data transfer provisions. For example, processing payroll for Indian employees through a foreign parent's global HR system involves both FEMA compliance (for salary remittances) and DPDP compliance (for processing employee personal data). Our FEMA and RBI compliance services help coordinate these overlapping obligations.

Companies Act and Corporate Governance

Indian subsidiaries structured as private limited companies already have board-level governance obligations under the Companies Act, 2013. The DPDP Act's requirement that the Data Protection Officer report to the Board of Directors aligns with existing corporate governance frameworks, but requires explicit board agenda items for data protection reviews and incident escalation protocols.

GST and Tax Compliance

If a foreign company engages an Indian entity as a Data Processor, the data processing services may attract GST under the reverse charge mechanism. Similarly, engaging a registered Consent Manager in India involves a service contract that may have GST implications. Factor these costs into your overall DPDP compliance budget.

Sector-Specific Regulations

Companies in financial services must also comply with RBI's data localisation directives for payment data. Healthcare companies processing health data face additional restrictions under sector-specific guidelines. Telecom companies are subject to TRAI's data protection requirements alongside the DPDP Act. The DPDP Act explicitly states that it supplements rather than replaces sector-specific data protection requirements.

For companies evaluating whether to enter India through a subsidiary or branch office, the DPDP compliance burden is an important factor in the entity structure decision. A subsidiary provides more flexibility in appointing a local DPO and managing Indian data processing obligations. See our branch office vs subsidiary comparison for a detailed analysis of how entity structure affects regulatory compliance.

Key Takeaways

  • The DPDP Act applies extraterritorially — if you process data of Indian individuals or offer goods/services to people in India, you are in scope regardless of your company's location.
  • Stage 1 activated the Data Protection Board's constitution and procedure, not the substantive obligations. Full compliance is mandatory by May 13, 2027.
  • Penalties reach up to INR 250 crore per violation with no warning period, making early preparation essential.
  • Foreign companies cannot use global consent management platforms like OneTrust as registered Consent Managers under Indian law — an India-incorporated entity is required.
  • Rule 7 runs two clocks: affected individuals and the Board must be told without delay, and the Board's detailed report is due within 72 hours of awareness unless the Board allows longer on a written request. Invest in incident response infrastructure now.

Need help with Budget & Policy? Our team handles it.

Tax Advisory for Foreign Investors in India
FAQ

Frequently Asked Questions

Does the DPDP Act apply to foreign companies without an office in India?

Yes. The DPDP Act applies extraterritorially to any company that processes personal data of Indian individuals in connection with offering goods or services to people in India, regardless of whether the company has a physical presence in India.

When is the final compliance deadline for the DPDP Act?

Full substantive compliance is mandatory by May 13, 2027, when rules 3 and 5 to 16 of the DPDP Rules, 2025 come into force. The stage that began on November 13, 2025 brought in rules 1, 2 and 17 to 21 — the constitution, appointment, procedure and digital-office provisions for the Data Protection Board — rather than the substantive duties of Data Fiduciaries.

What is the maximum penalty under the DPDP Act?

The maximum penalty is INR 250 crore per violation for failure to take reasonable security safeguards. Other violations carry penalties ranging from INR 50 crore to INR 200 crore depending on the nature of the breach.

Can foreign consent management platforms like OneTrust operate as Consent Managers in India?

No. Under the First Schedule, Part A of the DPDP Rules, 2025, a Consent Manager must be a company incorporated in India with a net worth of not less than INR 2 crore, among other conditions. Foreign platforms can still provide the technology backend but must operate through a registered Indian entity.

How quickly must a data breach be reported under the DPDP Act?

Rule 7 of the DPDP Rules, 2025 sets two clocks. Each affected Data Principal must be intimated without delay. The Data Protection Board must also be intimated without delay with an initial description of the breach, and then given the detailed report within 72 hours of the Data Fiduciary becoming aware — or within such longer period as the Board may allow on a written request. The 72-hour deadline is therefore for the detailed report to the Board, and it is extendable only with the Board's permission.

What is a Significant Data Fiduciary and does it apply to foreign subsidiaries?

A Significant Data Fiduciary (SDF) is designated by the Central Government based on volume of data processed, sensitivity, and risk factors. Foreign subsidiaries processing large volumes of Indian personal data may be designated as SDFs, triggering additional obligations including appointing a DPO based in India, annual DPIAs, and independent data audits.

Are there restrictions on transferring Indian personal data outside India?

India uses a blacklist approach under section 16(1) — data can flow to any country unless the Central Government notifies a restriction on that country or territory, so check the current MeitY notifications for the destination you use. From 13 May 2027, rule 15 adds a second condition: transfers must also meet any requirements the Central Government specifies by general or special order. SDFs face additional data localisation requirements where the Central Government directs them under rule 13(4).

This article is for general information only and is not legal, tax, or investment advice. Confirm current rules with the relevant authority or a qualified professional — or ask our team. See our full disclaimer.

Topics
dpdp actdata protectioncomplianceforeign companiesprivacy lawindia regulations

Put this guide to work

Our Chartered Accountants and Company Secretaries handle registrations and filings for founders in 80+ countries.

Chat NowBook My Free Consultation