Does India's DPDP Act Apply to Foreign SaaS Companies? Almost Certainly Yes
India's DPDP Act has extraterritorial reach under Section 3(b). Foreign SaaS companies serving Indian users must comply by November 2026 — GDPR compliance alone isn't enough.

#Does India's DPDP Act Apply to Foreign SaaS Companies? Almost Certainly Yes
India's Digital Personal Data Protection Act doesn't stop at the border. Any foreign SaaS company that offers services to users in India and processes their personal data falls squarely under the DPDP Act — regardless of where its servers are located, where it's incorporated, or whether it has a single employee on Indian soil. With the Act's Consent Manager framework activating on November 13, 2026, and active enforcement from May 2027, this is no longer a hypothetical compliance question for global software vendors. It's an urgent operational one.
The week of July 20, 2026 saw Indian privacy professionals actively debating a question that has circulated since the DPDP Rules were notified in November 2025: does the law actually apply to a foreign SaaS company? The short answer, rooted in the Act's own text, is almost always yes — and most foreign software vendors haven't begun to prepare.
#The Extraterritorial Clause Nobody Is Talking About
Section 3(b) of the Digital Personal Data Protection Act, 2023 is where India's jurisdictional ambition lives. The Act applies not only to personal data processed within India but also to "processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India."
Read that again. A U.S.-headquartered HR software company whose product is licensed by Indian corporations, processes employee personal data — names, salaries, health information — on AWS servers in Virginia. Under Section 3(b), that company is a Data Fiduciary under Indian law. It must obtain valid consent, implement reasonable security safeguards, honour erasure requests, and report breaches to the Data Protection Board of India.
This is not novel in global privacy law — the EU's GDPR has exercised similar extraterritorial jurisdiction since 2018. But the DPDP Act differs from GDPR in ways that make GDPR compliance an inadequate substitute. Foreign vendors who assume their EU data protection posture covers India are taking a significant legal risk.
#What "Offering Services to Indians" Actually Means
The jurisdictional hook — "offering goods or services to Data Principals within India" — is deliberately broad. Indian regulators and legal practitioners now largely agree it covers:
- B2C SaaS platforms with Indian user accounts (project management tools, e-commerce platforms, streaming services, edtech apps)
- B2B SaaS vendors whose Indian corporate customers use the platform to process the personal data of Indian employees or consumers
- Cloud infrastructure providers when they are the Data Processor for Indian-facing workloads — though the primary obligations flow to the Data Fiduciary (the Indian or foreign entity deciding why to collect data)
- Any foreign company with Indian language localisation, an INR pricing tier, or Indian customer support — these details evidence intent to serve the Indian market
Notably, the Act does not require a physical presence in India. This means foreign companies that have deliberately avoided setting up Indian subsidiaries to stay outside regulatory reach can no longer use that argument.
#What Foreign SaaS Companies Must Actually Do
Unlike the GDPR, where organisations can lean on multiple legal bases — legitimate interests, contractual necessity, legal obligation — the DPDP Act treats consent as the primary lawful basis for data processing. This creates real operational work for foreign platforms that have historically processed user data under "legitimate interests" clauses in their privacy policies.
Under the DPDP Rules 2025, consent must be:
- Free, specific, informed, unconditional, and unambiguous — obtained through a clear affirmative action
- Granular by purpose — a single checkbox for all data uses doesn't meet the standard
- Available in English and any Scheduled Indian language — the Act requires that consent notices and privacy information be offered in at least one of India's 22 Scheduled languages, not just English
- Withdrawable at any time — and withdrawal must be as easy as giving consent
Beyond consent, foreign SaaS companies processing Indian personal data must:
- Report all breaches to the Data Protection Board of India — unlike GDPR (which has a risk-based threshold), the DPDP Act requires notification for every personal data breach, regardless of severity
- Honour Data Principal rights — Indian users have rights to access information about their data, correct inaccuracies, and seek erasure, and companies must respond to these requests
- Implement reasonable security safeguards — the Act and Rules set a performance standard rather than a prescriptive checklist, but failing to meet it and experiencing a breach exposes the company to penalties up to ₹250 crore (approximately $30 million)
- Delete personal data when the purpose is fulfilled — the DPDP Act's data retention limits apply regardless of the company's home country data retention policies
Companies that process children's data — defined as anyone under 18 in the DPDP Act — face additional obligations including verifiable parental consent. This threshold is higher than GDPR's 16-year-old standard and will affect many consumer platforms.
#The Consent Manager Deadline: Your Countdown Starts Now
November 13, 2026 is now four months away. On that date, Rule 4 of the DPDP Rules 2025 comes into force, activating India's Consent Manager framework. This is the first hard, date-bound operational milestone in India's phased DPDP implementation.
Consent Managers are registered intermediaries — incorporated in India, with a minimum ₹2 crore net worth — through which Data Principals will be able to manage, review, and withdraw consent across multiple digital services from a single platform. Think of it as India's answer to cookie banners, except far more structurally integrated into the data processing ecosystem.
For foreign SaaS companies, the Consent Manager framework has two implications:
First, if their Indian users will manage consent through a registered Consent Manager, the SaaS platform must ensure its consent mechanisms are technically interoperable with the Consent Manager's APIs. This is not a documentation exercise; it requires engineering work.
Second, foreign platforms cannot themselves become registered Consent Managers, as the registration framework is limited to India-incorporated entities. This means their Indian compliance architecture depends partly on infrastructure they don't control.
Companies that delay integrating Consent Manager compatibility until the November 13 deadline are already behind. Industry estimates suggest that building compliant consent infrastructure — especially for legacy platforms — takes between nine and eighteen months. The countdown, in practical terms, has already passed for many organisations.
#How This Compares to GDPR — and Why GDPR Compliance Isn't a Substitute
The most dangerous assumption a foreign SaaS vendor can make is that its GDPR compliance posture automatically satisfies the DPDP Act. It does not, in several important ways.
Lawful basis: GDPR offers six lawful bases for processing. DPDP Act leans almost exclusively on consent, with a narrow set of "certain legitimate uses" (such as processing for employment purposes or by courts). If your privacy policy relies on legitimate interests, contractual necessity, or vital interests to process Indian user data, you likely need to rebuild that legal basis from scratch for India.
Breach notification: GDPR requires notification to supervisory authorities within 72 hours for breaches that pose a risk to data subjects, and notification to affected individuals only for high-risk breaches. The DPDP Act requires notification to both the Data Protection Board and affected individuals for every breach — there is no risk-based threshold. Your breach response procedures must be adapted for the Indian market.
Cross-border transfers: GDPR prohibits transfers to countries without adequacy decisions unless additional safeguards (SCCs, BCRs) are in place. The DPDP Act inverts this: transfers are permitted to all countries except those on a government-notified negative list. As of July 2026, no negative list has been published, meaning cross-border data transfers from India are broadly permitted. This is operationally more permissive than GDPR — but the list can be updated by notification, potentially restricting specific countries with limited notice.
Children's data: GDPR sets the age of digital consent at 16 (with member state flexibility down to 13). DPDP Act sets it at 18 across the board, with no exceptions. Platforms that allow users as young as 13 in the EU may need to implement stricter age-gating for Indian users.
Penalties: GDPR fines are turnover-based — up to 4% of global annual revenue. DPDP Act fines are fixed per-violation, up to ₹250 crore regardless of company size. For a small foreign startup, the maximum DPDP penalty may exceed a comparable GDPR penalty; for a large tech company, it may be lower in absolute terms. The key difference is that penalties accrue per violation category, and a single breach touching multiple obligation buckets creates stacked exposure.
#What Indian Businesses Must Do About Their Foreign Vendors
The extraterritorial reach of the DPDP Act doesn't only create obligations for foreign SaaS companies. It creates obligations for the Indian enterprises that use them.
Under the DPDP Act, the entity deciding why personal data is collected and processed is the Data Fiduciary — and that's usually the Indian company, even when a foreign SaaS vendor does the actual processing. The Data Fiduciary is responsible for ensuring that its Data Processors (including foreign SaaS vendors) only process data according to written contracts that are consistent with the DPDP Act's requirements.
This means Indian enterprises need to:
- Audit their SaaS vendor stack to identify which foreign vendors process personal data of Indian users or employees
- Update data processing agreements to include DPDP-compliant terms — the vendor must be contractually obligated to implement security safeguards, support breach notification timelines, and honour Data Principal rights requests
- Verify consent mechanisms — the Indian business is responsible for ensuring the consent obtained from Data Principals is legally valid under the DPDP Act, even if a foreign platform collects it
- Assess Significant Data Fiduciary implications — businesses processing data of five million or more Indian individuals, or handling sensitive categories, may be designated as Significant Data Fiduciaries, with mandatory Data Protection Officers and impact assessments
The Data Protection Board of India, now operational under Chairperson Mr. Ghosal Pankaraj IMS, has the authority to investigate complaints and impose penalties on Data Fiduciaries. Indian businesses that cannot demonstrate appropriate vendor due diligence are exposed if a foreign vendor's data handling falls short.
#Penalties That Apply Regardless of Where You're Headquartered
The DPDP Act's penalty framework doesn't distinguish between domestic and foreign entities. A foreign SaaS company found to have failed to implement reasonable security safeguards — leading to a breach of Indian personal data — faces the same maximum penalty of ₹250 crore ($30 million) as an Indian company. Failing to notify the Data Protection Board of a breach carries a separate fine of up to ₹200 crore. Mishandling children's data can attract up to ₹200 crore per violation.
The Board can impose penalties for repeat violations at double the standard rate, with exposure theoretically reaching ₹500 crore per violation in egregious cases.
More immediately, the Board can issue remediation directions — ordering a foreign company to stop processing Indian personal data until compliance is demonstrated. For a SaaS business with Indian ARR, that's an existential enforcement action, not just a financial penalty.
#The Clock Is Running
India's digital economy is too large and too fast-growing for global SaaS companies to treat the DPDP Act as a future concern. With 850 million internet users, growing enterprise SaaS adoption, and a regulator that has just appointed its Chairperson and is actively building its enforcement capability, the window for proactive compliance is narrowing.
The November 13, 2026 Consent Manager deadline is four months away. The full enforcement date of May 13, 2027 is ten months away. Neither timeline is long enough to build a compliant consent architecture from scratch.
For foreign SaaS companies serving Indian users: assess your exposure under Section 3(b), map the consent you hold for Indian Data Principals, and begin engineering Consent Manager compatibility now. The question is no longer whether the DPDP Act applies to you. It's whether you'll be compliant when enforcement arrives.
For Indian businesses relying on foreign SaaS vendors: your compliance obligation doesn't transfer to your vendor. You remain the Data Fiduciary. Audit your stack, update your data processing agreements, and ensure your foreign processors can meet India's standards — before the Board's first enforcement wave makes that lesson expensive.
DPDPBot's consent manager is built for exactly this compliance transition. If you're assessing your vendor stack's DPDP readiness or building consent infrastructure ahead of the November deadline, visit /resources for implementation guides and compliance checklists.