DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ All questions

Does it apply to me

Does DPDP apply to companies outside India?

Short answer
Yes, in one specific situation. The Act reaches processing outside India where it relates to offering goods or services to Data Principals within India. A foreign company with Indian users is in scope even with no Indian entity or servers.

This is the extra territorial reach in Section 3. What triggers it is offering goods or services to people in India, not where the company or its infrastructure sits.

There is a mirror provision that runs the other way. Where an Indian entity processes only the personal data of people outside India, under a contract with a person outside India, most of the Act's obligations are lifted for that processing, though the general responsibility and security duties remain.

That second point matters to Indian IT services firms and BPOs, whose offshore work may sit largely outside the Chapter II and Chapter III obligations while their domestic work does not.

Where this comes from

The mistake people make

Assuming that hosting data abroad places the processing outside the Act. Location of servers is not the test.

Related