Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    Does India's DPDP Act Apply to Your Company?

    India's Digital Personal Data Protection Act, 2023 applies to processing that happens entirely outside India. Section 3(b) of the Act says it "shall also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India." There is no revenue threshold and no user-count threshold in that section. The Digital Personal Data Protection Rules, 2025, notified by G.S.R. 846(E) on 13 November 2025, stage the duties: Rule 1 puts Rules 1, 2 and 17 to 21 in force on publication, Rule 4 one year after publication, and Rules 3, 5 to 16, 22 and 23 eighteen months after publication, which is 13 May 2027. Now the correction most coverage needs: the widely repeated line that penalties reach 250 crore rupees "per violation" is not what the Schedule says. That ceiling attaches to one item, failing to take reasonable security safeguards. Failing to notify a breach caps at 200 crore, and a breach of any other provision of the Act or Rules caps at 50 crore.

    This article covers who is caught, what the two staged dates actually require, the breach rule that has no risk threshold, and how to size the work if you have Indian users but no Indian entity.

    Key takeaways

    • Extraterritorial by design: offering goods or services to people in India brings a foreign company inside the Act, with no revenue or headcount threshold.
    • Two dates to plan against: consent manager registration provisions commence 13 November 2026; the core obligations commence 13 May 2027.
    • The breach rule has no materiality or risk threshold. Every personal data breach is notified to every affected Data Principal, without delay.
    • The Board also gets an immediate description and a detailed report within seventy-two hours.
    • The startup relief in section 17(3) exists but is written for Indian-incorporated startups, so a US company should not plan around it.

    Who the Act reaches

    Section 3 does the scoping work in three clauses. Clause (a) covers processing of digital personal data within India, whether collected in digital form or digitised later. Clause (b) is the extraterritorial one quoted above. Clause (c) carves out personal data processed by an individual for a personal or domestic purpose, and personal data made publicly available by the person themselves or by someone under a legal duty to publish it.

    The comparison with GDPR is instructive because the tests are close but not identical. Both reach foreign controllers through an offering-of-goods-or-services trigger. GDPR adds a second trigger for monitoring behaviour that India's section 3(b) does not carry, so a US company that tracks Indian users but does not offer them anything is in a different position under the two regimes. Going the other way, India has no equivalent of the EDPB's intentional-targeting gloss written into the statute, so the safer reading for a foreign company is that the connection to an offering is the operative question and that it should be answered on facts rather than assumed away. If you take payments from Indian customers, ship there, or run an Indian-language funnel, do not spend money on the argument.

    One exemption looks like it applies to outsourcing and does not, quite. Section 17(1)(d) exempts processing of personal data of Data Principals not within India where it is done pursuant to a contract entered into with a person outside India by a person based in India. That is relief for Indian service providers processing foreign data, not for foreign companies processing Indian data.

    The two dates, and what commences on each

    Rule 1 of the notified Rules sets three commencement tranches, and reading them in order is the whole compliance calendar.

    On publication, 13 November 2025. Rules 1, 2 and 17 to 21 came into force. Those establish the Data Protection Board of India and how it functions, which means the enforcement institution exists before the obligations it will enforce do.

    One year after publication, 13 November 2026. Rule 4 commences, covering registration and obligations of Consent Managers. A Consent Manager is a registered intermediary through which a Data Principal can give, manage, review and withdraw consent. If your consent architecture for Indian users is going to route through one, this is when that ecosystem becomes real.

    Eighteen months after publication, 13 May 2027. Rules 3 and 5 to 16, plus 22 and 23, commence. That tranche carries the operational core: the content and form of the notice given to a Data Principal, reasonable security safeguards, breach intimation, retention and erasure, the mechanics for exercising rights, and the additional obligations of Significant Data Fiduciaries.

    These dates agree with the entry we maintain on our regulatory radar, which is the surface we update when a schedule moves.

    Two planning consequences follow. First, the runway is shorter than it looks, because the work that takes longest, data mapping and retention, is the work due last. Second, the staging is a commencement schedule for the Act itself, not only for the Rules: G.S.R. 843(E)(c) places sections 7 to 10 in the eighteen-month tranche, so section 8 is not in force until 13 May 2027. That is a deadline, not a holiday. The work section 8 requires, security safeguards and a breach-notification path, takes longer to build than the runway left once it does commence, which is the reason to start now rather than a reason to wait.

    The notice and consent model is stricter than the US default

    Rule 3 sets what the notice to a Data Principal must contain, and it is written to defeat the layered-privacy-policy pattern most US companies rely on. The notice must "be presented and be understandable independently of any other information that has been, is or may be made available" by the Data Fiduciary. That is a self-contained notice requirement: you cannot satisfy it by cross-referencing a master privacy policy.

    It must give, in clear and plain language, "an itemised description" of the personal data and the specified purpose, with a specific description of the goods or services to be provided or uses to be enabled. Itemised. Categories of the kind US notices use are not obviously enough. And it must give the communication link and other means by which the Data Principal may withdraw consent "with the ease of doing so being comparable to that with which such consent was given," exercise rights under the Act, and complain to the Board.

    Companies that have built a GDPR-grade notice will find this familiar. Companies whose privacy notice is a US state-law compliance artifact will find the itemisation and the standalone requirement to be real work.

    The breach rule has no threshold, and that is the headline

    Rule 7 is where a US incident response plan will need surgery.

    To the affected individuals: "on becoming aware of any personal data breach," the Data Fiduciary must intimate each affected Data Principal, "to the best of its knowledge," in a concise, clear and plain manner and "without delay," through her user account or another registered mode of communication. The intimation must describe the breach including its nature, extent and timing; the consequences likely to arise for her; the mitigation measures implemented and being implemented; the safety measures she may take; and business contact information for a person who can answer her questions.

    Read what is missing. There is no risk threshold, no materiality qualifier, no "unlikely to result in a risk" exemption of the kind GDPR Article 33 provides, and no number-of-records floor of the kind US state statutes use. Any personal data breach, every affected person, without delay.

    To the Board: without delay, a description including nature, extent, timing, location and likely impact; then "within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing," updated and detailed information, the broad facts and reasons, mitigation measures implemented or proposed, any findings about who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.

    If you already run a breach clock discipline, this is one more row with an unusual trigger, and the practical fix is the same one we recommend for every regime: build to the shortest binding clock and instrument the trigger events separately. Our crosswalk of breach notification deadlines covers the US and EU clocks this now sits alongside.

    What the penalties actually cap at

    The Schedule to the Act, referred to by section 33(1), sets seven items and they are not uniform. Failing the section 8(5) obligation to take reasonable security safeguards to prevent a personal data breach "may extend to two hundred and fifty crore rupees." Failing to give the Board or the affected Data Principal notice of a breach under section 8(6) "may extend to two hundred crore rupees." Failing the additional obligations for children under section 9 also tops out at two hundred crore, and the Significant Data Fiduciary obligations under section 10 at one hundred and fifty crore. A breach of a Data Principal's own duties under section 15 caps at ten thousand rupees. A breach of any other provision of the Act or the Rules "may extend to fifty crore rupees."

    Two things follow. The most-quoted number is the security-safeguards number, and repeating it as a general per-violation cap overstates the exposure for most failures by a factor of five. And the second-highest number in the schedule is attached to breach notification, which tells you what the drafters considered serious and where a foreign company with an under-built incident process is most exposed.

    We are giving these in rupees without a dollar conversion on purpose. Converting a statutory ceiling at today's rate produces a figure that is wrong within a quarter and that then gets quoted back as if it were in the statute.

    The startup relief is not for you

    Section 17(3) lets the Central Government notify certain Data Fiduciaries, "including startups," as exempt from section 5, subsections (3) and (7) of section 8, and sections 10 and 11, having regard to the volume and nature of personal data processed. That sounds like the small-business carve-out a US reader is hoping for. Read the explanation attached to it: "startup" means a private limited company, partnership firm or limited liability partnership "incorporated in India" and recognised as a startup under the criteria notified by the relevant department.

    A US company is not eligible on that definition. Plan on the full obligation set, and treat any relief as upside.

    When you should not hire a consultancy like this one

    If your Indian exposure is a handful of self-serve users who found you organically, no Indian-language marketing, no rupee pricing, no Indian entity and no plans to build one, the honest recommendation is to write the scope memo, fix the breach process because you need that anyway, and revisit in the first quarter of 2027. You have until May 2027 for the core obligations and the Consent Manager ecosystem is not built yet. Paying anyone to build an India programme this year is paying for a programme against rules that commence next year, and any part of it that touches consent architecture will be rebuilt once the Consent Manager framework is operating.

    The other honest note: if you already run a mature GDPR programme, a large share of the DPDP work is adaptation rather than new construction. The notice format and the breach rule are genuinely different, but data mapping, retention, rights fulfilment and vendor terms transfer. Anyone quoting you a full new programme when you have that foundation should be asked to show which parts do not reuse.

    Where outside help earns its fee is the fact-heavy scoping call for a company with real Indian revenue and no local entity, the breach-rule redesign, and the Significant Data Fiduciary question if your volumes are large enough that the additional obligations under section 10 might attach.

    Where Top Floor fits

    Our India DPDP service starts with the section 3(b) scoping memo and, if you are in scope, the gap between what you run today and what commences in May 2027. International compliance is where DPDP gets reconciled with the other regimes reaching the same records, so you write one set of controls rather than one per country, and global privacy runs the programme underneath both. If you are also working through whether the European rules reach you, that analysis is in does GDPR apply to my US company.

    How to decide this week

    1. Pull revenue and user counts by country for India. Section 3(b) has no threshold, but the numbers determine how much the answer is worth to you.

    2. Check for the targeting evidence: rupee pricing, Indian-language pages, India-directed advertising spend, shipping or service delivery into India.

    3. Read Rule 7 against your incident response plan and mark the gap. The no-threshold intimation duty and the seventy-two-hour Board report are the two lines most plans do not cover.

    4. Hold your privacy notice against Rule 3. If it depends on a master policy to be understood, or describes categories rather than an itemised list, that is a rewrite.

    5. Put 13 November 2026 and 13 May 2027 in the compliance calendar with owners, and schedule the real build for the first half of 2027 rather than now.

    Frequently asked questions

    Does the DPDP Act apply to a US company with no entity in India?

    Yes, if the processing is connected to offering goods or services to people in India. Section 3(b) extends the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within India, and that clause carries no revenue threshold, no user-count threshold and no exemption keyed to company size. Whether a particular US business is caught turns on the facts of its offering, which is why the scoping analysis should be written down and dated rather than assumed.

    When do the obligations actually start?

    The notified Rules stage them. Rules 1, 2 and 17 to 21 commenced on publication on 13 November 2025 and stand up the Data Protection Board; Rule 4, covering registration and obligations of Consent Managers, commences one year after publication, on 13 November 2026; and Rules 3, 5 to 16, 22 and 23, which carry notice, security safeguards, breach intimation, retention and rights mechanics, commence eighteen months after publication, on 13 May 2027.

    Is there a small-business or startup exemption?

    Not one a US company can use. Section 17(3) permits the Central Government to notify certain Data Fiduciaries, including startups, as exempt from a specific list of provisions having regard to the volume and nature of data processed, but the explanation defines startup as a private limited company, partnership firm or limited liability partnership incorporated in India and recognised as such under the criteria notified by the relevant government department. A foreign company does not meet that definition and should plan on the full obligation set.

    How does the breach rule compare with GDPR?

    It is stricter in the direction that costs the most to operate. GDPR Article 33 lets a controller skip notifying the supervisory authority where a breach is unlikely to result in a risk to individuals, and Article 34 requires telling individuals only where the risk is high, whereas Rule 7 of the DPDP Rules requires intimating every affected Data Principal on becoming aware of any personal data breach, without delay and with no risk threshold. The Board gets a description without delay and a detailed report within seventy-two hours, or a longer period if the Board allows one on a written request.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.