The DPDP Act for Foreign Companies Operating in India: Consent, Cross-Border Transfers and Significant Data Fiduciary Status (2026)
Written by the Delhi Legal Company India Entry & FDI Advisory team · Last updated August 2026 · Reviewed against the DPDP Act, 2023 and the DPDP Rules, 2025
Introduction
You do not need an Indian entity to be caught by India’s data protection law. You need Indian users.
Even organisations based outside India are covered if they process the personal data of individuals in India in connection with offering goods or services to them.
That is the first thing for a foreign company to absorb, and it puts the DPDP framework alongside significant economic presence as one of two Indian regimes that reach a business with no presence in the country at all.
The second thing is that being GDPR-compliant is not an answer. The DPDP diverges from other global data privacy laws and introduces novel concepts such as the “consent manager” construct. It has no legitimate interest basis, a different breach clock, a narrower set of data principal rights, and a cross-border model that works by exclusion rather than adequacy. A European privacy programme lifted into India will have gaps in specific, identifiable places.
The third is timing, and it is where groups are most likely to misjudge. Full compliance is due 13 May 2027, which sounds distant. But the Data Protection Board has been operational since November 2025, consent manager obligations bite in November 2026, and there has been an active proposal to compress the whole runway.
This guide covers who is caught, where DPDP departs from GDPR, the question that decides your Indian subsidiary’s obligations, and what to do in the time that remains.
About this guide
Delhi Legal Company works exclusively with foreign companies establishing and operating in India. Data protection is the newest item on the India compliance map and the one most groups have not yet placed — usually because the Indian entity is small and nobody thought of it as a data business.
Where a rule is settled we state it with the section or rule. Where a date or a list is not yet fixed — and two important ones are not — we say so, because planning to an unconfirmed date is a different exercise from planning to a notified one.
Primary source: the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, together with the Ministry of Electronics and Information Technology and the Data Protection Board of India.
1. The timeline
The Digital Personal Data Protection Rules, 2025 were officially notified in November 2025, setting an 18-month compliance deadline of 13 May 2027.
| Phase | Date | What takes effect |
|---|---|---|
| Phase I | 13 November 2025 | Provisions establishing the Data Protection Board of India, effective immediately. The Board is operational and complaint mechanisms are live |
| Phase II | 13 November 2026 | Consent manager provisions. Registration becomes mandatory and the associated obligations come into effect |
| Phase III | 13 May 2027 | All other substantive provisions, including specific compliance obligations |
1.1 The Board exists before the obligations do
This ordering is unusual and worth noting. The regulator was stood up first, with complaint machinery live from November 2025, while the substantive duties arrive eighteen months later.
The practical implication is that the institution learning to apply this law will have had eighteen months of practice by the time your obligations begin.
1.2 The acceleration proposal
This is the planning risk, and it is not hypothetical.
A MeitY stakeholder consultation on 23 January 2026 proposed accelerating the deadline from 18 months to 12 months. This has not been formally confirmed by gazette notification. Organisations should plan for the earlier November 2026 target as a prudent baseline.
India’s Data Protection Board has stated these timelines may be accelerated.
So the position is: the notified date is May 2027, an acceleration to November 2026 has been proposed and not confirmed, and the regulator has indicated it is possible.
1.3 Why the runway is shorter than it looks
A typical enterprise DPDP programme requires nine to twelve months to complete a gap assessment, implement controls and achieve audit readiness.
Count backwards. A twelve-month programme starting today lands in August 2027 — past the notified deadline, and well past the accelerated one if it comes.
For a foreign group whose Indian entity is small and whose privacy function sits overseas, the coordination overhead makes it longer, not shorter.
2. Does it apply to us?
Three routes in, and a foreign group can be caught by any of them independently.
| Route | Who it catches |
|---|---|
| Processing in India | Your Indian subsidiary processing digital personal data in India — including employee data |
| Extraterritorial | Organisations based outside India processing personal data of individuals in India in connection with offering goods or services to them |
| As a processor | Your Indian captive processing personal data on behalf of the group — see section 3 |
2.1 Who is a Data Fiduciary
Any person who alone or jointly with others determines the purpose and means of processing personal data is a Data Fiduciary. This includes companies, government bodies, NGOs and sole proprietors. Processing includes collection, storage, use, sharing and deletion of personal data.
The definition is functional, not size-based. A ten-person Indian subsidiary that decides how its own employee data is handled is a Data Fiduciary in respect of that data.
2.2 Digital only
The DPDP Act is applicable only to personal data in digital form and does not regulate non-personal and non-digital data. It pertains to processing of digital personal data within India, encompassing situations where the personal data is either collected in digital form, or collected in non-digitised form and subsequently converted into digital form.
Note the second limb. Paper records scanned into a system come within scope at the point of digitisation. A group that keeps signed employment forms in a cabinet and also scans them into an HR platform is processing digital personal data.
2.3 The exemptions
Certain exemptions apply for personal or domestic use, journalistic purposes, research, and national security under Sections 17 to 18 of the Act.
None of these assists an ordinary commercial group. Do not plan around them.
3. Fiduciary or Processor? The question that decides everything
For a foreign group with an Indian captive, this is the analysis that determines the shape of the whole obligation, and it is the one most often skipped.
3.1 The distinction
A Data Fiduciary determines the purpose and means of processing. A Data Processor processes on behalf of a Fiduciary, under its instructions.
Fiduciaries carry the substantive obligations — notice, consent, rights handling, breach reporting, retention, and Significant Data Fiduciary duties if designated. Processors carry obligations flowing from their contract with the Fiduciary.
3.2 Where a captive sits
An Indian development or services centre processing the parent’s customer data, under the parent’s instructions, is typically a Processor for that data.
But the same entity is simultaneously a Fiduciary for its own employee data, its vendor contacts, and any data it decides the purpose and means for.
So the answer for most captives is: both, for different datasets. A single-label analysis — “we are just a processor” — is almost always wrong and leaves the employee data obligations unaddressed.
3.3 What follows
Map by dataset rather than by entity. For each category of personal data the Indian entity touches, establish who determines purpose and means, and therefore which role applies.
That mapping is the foundation of everything else and it is the first deliverable of any DPDP programme.
4. GDPR compliance is not a defence
Groups with a mature European privacy programme reasonably assume it travels. It travels partly. Here is where it does not.
| GDPR | DPDP | |
|---|---|---|
| Lawful bases | Six, including legitimate interests | Consent, plus defined “legitimate uses” — no general legitimate interests basis |
| Consent intermediary | No equivalent | The “consent manager” construct — a novel concept |
| Breach notification | 72 hours to the supervisory authority, risk-qualified | 72 hours to the Data Protection Board |
| Cross-border model | Adequacy decisions and transfer mechanisms | Negative list — transfer permitted unless the country is restricted |
| Data subject rights | Access, rectification, erasure, portability, objection, restriction | Narrower set — portability and objection do not have direct equivalents |
| Scope | Personal data generally | Digital personal data only |
| Ceiling on penalties | Percentage of global turnover | Up to ₹250 crore |
4.1 The legitimate interests gap
This is the divergence with the widest practical consequence.
A great deal of European processing runs on legitimate interests — fraud prevention, direct marketing to existing customers, network security, internal administration — supported by a balancing assessment rather than consent.
DPDP has no equivalent general basis. Processing runs on consent, or on the specific legitimate uses the Act defines. Anything that relied on a balancing test in Europe has to be re-mapped to a DPDP basis, and where none fits, it needs consent.
That is not a documentation exercise. It can change what the product does.
4.2 The rights gap runs the other way
DPDP’s rights set is narrower than GDPR’s, which means a group already honouring GDPR rights globally is likely over-delivering rather than under-delivering in India.
That is fine as a matter of compliance. It is worth knowing so that Indian operations are not redesigned to add rights the Indian law does not require.
5. Notice and consent
Rule 3 specifies the form and manner of notice and consent.
The notice must be clear, standalone and in plain language, describing the personal data and the purpose, and must tell the data principal how to withdraw consent, how to exercise rights, and how to complain to the Board.
5.1 Withdrawal
The data principal may withdraw consent at any time, and withdrawal does not affect processing carried out before withdrawal.
Two build requirements follow. Withdrawal must be as easy as giving consent. And the system must actually stop the downstream processing when it happens — which for a group with data replicated across systems and vendors is an architecture question, not a policy question.
5.2 The consent manager
This is the construct with no international equivalent, and it becomes operational first.
From 13 November 2026, registration for consent managers becomes mandatory and the associated obligations come into effect.
Organisations may register as third-party intermediaries to manage user consent and permissions, with the Data Protection Board handling registration.
For most foreign groups the relevant question is not whether to become a consent manager, but whether their consent architecture can interoperate with one where a data principal chooses to manage consent through it.
6. Employee data: the application groups overlook
Foreign groups think about customer data. The Indian subsidiary’s largest and most sensitive personal data holding is usually its own staff.
| Processing | Data involved |
|---|---|
| Recruitment | CVs, interview notes, references |
| Onboarding and background checks | Identity documents, education and employment verification, criminal record checks |
| Payroll | Salary, bank details, PAN, PF and tax data |
| Benefits and insurance | Dependants, medical information |
| Performance and HR systems | Reviews, disciplinary records, grievances |
| Global HR platforms | All of the above, replicated to group systems outside India |
| Monitoring | Access logs, device management, productivity tooling |
6.1 The employment basis
The Act recognises employment-related processing among its legitimate uses, covering purposes connected with employment and safeguarding the employer from loss or liability.
That basis is real but it is not unlimited. Processing that goes beyond what the employment relationship reasonably requires — extensive monitoring, secondary uses, sharing with group entities for purposes unconnected with the employment — needs its own analysis rather than sheltering under the employment label.
6.2 Where the group platform bites
Most foreign-owned Indian subsidiaries run their people on a global HR system hosted outside India, with group HR having access.
That is a cross-border transfer and a sharing arrangement, and it needs to be documented as such — notice to the employee, a basis, and a processor arrangement with the platform provider.
It also sits alongside the employment documentation itself — see employment contracts in India for foreign employers.
7. Cross-border transfers
The best news in the framework, and the most misreported.
The framework adopts a “negative list” approach, allowing personal data to be transferred outside India unless the Central Government explicitly restricts a country or territory via notification.
The Rules lock in a blacklist-based cross-border transfer model rather than data localisation.
7.1 What this means
The draft Rules published in January 2025 generated significant concern about localisation. The final position is the opposite of localisation: transfer is permitted by default, and restriction requires an affirmative government act naming the country.
For a foreign group with global systems, this removes what would have been the single most expensive compliance item.
7.2 The contingency
The approved country list has not yet been notified by the Central Government. Transfer restrictions will come into effect once this list is published. Organisations should begin mapping cross-border data flows now to prepare.
So the permission is currently unqualified in practice, and the restriction mechanism exists but has not been used.
The prudent response is not to assume it never will be. Map your flows now — which data goes where, to which providers, in which countries — so that if a restriction is notified you can identify your exposure in days rather than months.
7.3 Sectoral rules survive
DPDP’s permissive cross-border position does not displace sector-specific localisation requirements that already exist in areas such as payments. Where your Indian entity operates in a regulated sector, check the sectoral position separately.
8. Significant Data Fiduciary status
Significant Data Fiduciary designation is dealt with under Rule 13.
Designation is by the Central Government based on factors including the volume and sensitivity of personal data processed, risk to data principals, and potential impact on sovereignty, electoral democracy and public order.
8.1 What SDF status adds
An SDF must appoint an India-based Data Protection Officer, run a Data Protection Impact Assessment and algorithmic due-diligence audit, and file an annual compliance report under Rule 13.
| Obligation | Practical cost |
|---|---|
| India-based Data Protection Officer | A person in India, reporting to the board — not the group DPO in Europe |
| Data Protection Impact Assessment | Periodic, documented |
| Algorithmic due diligence | Verification that algorithmic systems do not pose risk to data principals |
| Independent audit | Periodic |
| Annual compliance report | Filed under Rule 13 |
8.2 The India-based DPO is the one that matters
For a foreign group this is the obligation with the clearest operational consequence. A group DPO sitting in London or Frankfurt does not satisfy it.
Groups likely to be designated should plan for an Indian appointment, and should think about it before designation rather than after, because the role needs seniority and independence rather than a nominal title.
8.3 Self-assess early
A sensible sequence is to self-assess against the SDF threshold in the period before full compliance, and if SDF, appoint an India-based DPO, run the first DPIA and algorithmic due-diligence audit, and prepare the annual compliance report.
A group that discovers it is an SDF three months before the deadline has three months to build a function that takes longer than that.
9. Breach notification
Breach notification to the Data Protection Board is required within 72 hours.
9.1 What makes this hard for a foreign group
The clock is short and the incident is likely to be detected by a global security team on a different continent, operating to a different playbook, in a different timezone.
Three things need to exist before an incident, not during one:
- A named person in India with authority to notify
- A trigger in the group’s incident process that asks “does this involve Indian data principals” at the point of detection, not at the review stage
- A pre-drafted notification template and a tested route to the Board
Groups that fold India into a global breach process without an India-specific trigger will discover the 72 hours has run while the incident was being triaged.
9.2 Notification to data principals
Beyond the Board, affected data principals must be informed. For an Indian consumer-facing business that is a communications exercise with its own preparation requirement.
10. Rights and grievances
Data Fiduciaries must respond to data principal requests within the period specified in the Rules under Rule 14, and grievance redressal must be completed within 90 days of receiving a complaint.
10.1 The build requirement
Rights handling is a workflow, not a policy. It needs an intake channel, an identity verification step, a search capability across systems, a decision process and a response within the period.
For a group whose Indian data sits across a CRM, an HR platform, a support system and a data warehouse, the search capability is the hard part and it is what takes months to build.
10.2 The 90-day grievance limit
Ninety days is generous as a maximum and dangerous as a target. A complaint unresolved at day ninety becomes a matter the data principal can escalate to a Board that has been operational and taking complaints since November 2025.
11. Retention
The Rules lock in a minimum one-year data-retention mandate, and three years for Schedule 3 entities.
This cuts against the instinct trained by GDPR, which pushes toward minimisation and prompt deletion. Indian retention requirements interact with a range of other obligations — tax records, employment records, statutory registers — and a deletion policy designed for Europe can conflict with Indian record-keeping duties.
Build the retention schedule against Indian requirements rather than porting the European one. See statutory registers under the Companies Act for the record-keeping side.
12. Penalties and the Board
Non-compliance carries penalties up to ₹250 crore.
The Data Protection Board of India was operationalised under Rule 16 of the DPDP Rules, 2025, with procedural rules under Rule 17. The Section 33 penalty matrix sits within the phased timeline ending 13 May 2027.
12.1 The penalty is per-breach and matrixed
Section 33 sets differentiated maxima by category of failure — security safeguards, breach notification, children’s data, SDF obligations and others — rather than a single ceiling for everything.
The headline ₹250 crore figure attaches to the most serious categories. What matters for planning is that the matrix distinguishes, and the categories with the highest exposure are the ones a foreign group is most likely to under-build: security safeguards and breach notification.
13. What to do now
| Phase | Work |
|---|---|
| Now to end 2026 | Data mapping by dataset; role determination Fiduciary or Processor for each; gap assessment against DPDP specifically, not against GDPR |
| Through 2026 | Notice and consent redesign; rights workflow build; breach runbook with an India trigger; retention schedule against Indian requirements; processor contracts |
| By late 2026 | SDF self-assessment; India-based DPO appointment if indicated; consent manager interoperability |
| Into 2027 | DPIA and algorithmic due diligence if SDF; breach simulation; rights workflow dry run; cross-border architecture ready for a restriction notification |
13.1 The first deliverable
The data map. Not the policy, not the notice — the map.
Every other decision depends on knowing what personal data the Indian entity touches, for what purpose, who determines it, where it goes and who processes it. Groups that start with a policy end up rewriting it once the map exists.
14. Two situations, worked through
Scenario A — The SaaS business with no Indian entity
A European SaaS company sells subscriptions to Indian businesses from Europe. No Indian entity, no Indian staff, no Indian servers.
The assumption. Indian data law does not apply.
The position. Organisations outside India are covered where they process personal data of individuals in India in connection with offering goods or services to them. The company processes personal data of Indian users of its product.
What follows. Notice and consent for Indian data principals, a rights workflow, breach notification to the Indian Board, and a retention position — alongside the significant economic presence analysis it already needs after the equalisation levy withdrawal, which is a different Indian regime reaching the same business for the same reason. See equalisation levy and digital taxation in India.
Scenario B — The captive that called itself a processor
A US group’s Indian development centre processes the parent’s customer data under the parent’s instructions. The group’s privacy counsel concludes the Indian entity is a Processor and moves on.
What was missed. The Indian entity has 300 employees. It determines the purpose and means of processing their personal data — recruitment, payroll, benefits, performance, monitoring. For that dataset it is a Fiduciary, with the full obligation set.
The exposure. No notice to employees, no basis analysis, no rights workflow, no retention schedule, and a global HR platform transferring Indian employee data abroad without documentation.
The fix. Map by dataset rather than by entity. The answer for most captives is both roles, for different data.
15. Twelve mistakes
- Assuming no Indian entity means no application. The Act reaches organisations outside India offering goods or services to individuals in India.
- Treating GDPR compliance as sufficient. No legitimate interests basis, a consent manager construct, and a different cross-border model.
- Porting European lawful bases where processing ran on a balancing test that DPDP does not recognise.
- Labelling the Indian captive a Processor and missing that it is a Fiduciary for its own employee data.
- Planning to May 2027 when acceleration to November 2026 has been proposed and the Board has said timelines may move.
- Underestimating the programme. Nine to twelve months is typical, and cross-border coordination makes it longer.
- Starting with a policy instead of a data map.
- Ignoring employee data, which is usually the Indian entity’s largest personal data holding.
- Not documenting the global HR platform as a cross-border transfer and a processor arrangement.
- Assuming the cross-border permission is permanent. The restriction mechanism exists and the list has simply not been published.
- Folding India into a global breach process with no India trigger, so the 72 hours runs during triage.
- Porting a European deletion policy that conflicts with Indian minimum retention and record-keeping duties.
16. Checklist
Assessment
- Application confirmed — Indian entity, extraterritorial reach, or processing for the group
- Data map completed by dataset: what, why, who decides, where it goes, who processes
- Role determined per dataset: Data Fiduciary or Data Processor
- Digital scope confirmed, including non-digital records subsequently digitised
- Lawful basis mapped for each processing activity, with anything that relied on legitimate interests re-based
- Gap assessment run against DPDP specifically, not against an existing GDPR programme
Build
- Notice redesigned to Rule 3 requirements — standalone, plain language, withdrawal and complaint routes
- Consent capture and withdrawal mechanics, with withdrawal as easy as consent and downstream processing actually stopping
- Rights workflow: intake, identity verification, cross-system search, decision, response within the period
- Grievance process with resolution well inside 90 days
- Breach runbook with a named India notifier, an India trigger at detection, and a tested route to the Board within 72 hours
- Retention schedule built against Indian requirements including the minimum retention mandate
- Processor contracts in place with vendors and with group entities
- Employee privacy notice and HR data documentation
Significant Data Fiduciary
- Self-assessment against the designation factors
- India-based Data Protection Officer identified, with seniority and independence
- DPIA methodology established
- Algorithmic due diligence scope defined
- Independent audit arrangements
- Annual compliance report process under Rule 13
Watch list
- Acceleration of the compliance deadline — proposed, not confirmed
- Notification of restricted countries for cross-border transfer — mechanism exists, list not published
- Consent manager framework operational from November 2026
- Sectoral localisation requirements applicable to your industry
Selling into India, or running an Indian entity?
Either way this applies, and the runway is shorter than the May 2027 date suggests. Tell us what your Indian operation does and where your data sits and we will tell you whether you are a Fiduciary, a Processor or both, whether SDF designation is likely, and what a realistic programme looks like from here.
17. Frequently asked questions
Q1. Does the DPDP Act apply to a company with no Indian entity?
It can. Organisations based outside India are covered where they process the personal data of individuals in India in connection with offering goods or services to them. A foreign SaaS or platform business selling into India is therefore within scope without any Indian presence, in the same way significant economic presence reaches it for tax.
Q2. When is compliance actually due?
The notified deadline is 13 May 2027, being 18 months from notification of the Rules in November 2025. The Data Protection Board has been operational since 13 November 2025, and consent manager provisions take effect from 13 November 2026.
Q3. Could the deadline be brought forward?
It has been proposed. A MeitY stakeholder consultation on 23 January 2026 proposed accelerating from 18 months to 12 months, which has not been confirmed by gazette notification, and the Board has indicated timelines may be accelerated. Planning to November 2026 as a prudent baseline is the safer approach.
Q4. How long does a DPDP programme take?
A typical enterprise programme requires nine to twelve months to complete a gap assessment, implement controls and achieve audit readiness. For a foreign group whose Indian entity is small and whose privacy function sits overseas, coordination makes it longer rather than shorter.
Q5. Does the Act cover paper records?
Only once digitised. The Act applies to personal data in digital form, covering data collected digitally and data collected in non-digitised form and subsequently converted to digital form. Paper records scanned into a system come within scope at the point of digitisation.
Q6. Is being GDPR-compliant enough for India?
No. The DPDP diverges in identifiable places: there is no general legitimate interests basis, it introduces a consent manager construct with no international equivalent, the cross-border model works by exclusion rather than adequacy, and the rights set is narrower. A European programme lifted into India will have specific gaps.
Q7. What is the biggest gap between GDPR and DPDP?
The absence of a legitimate interests basis. A great deal of European processing — fraud prevention, marketing to existing customers, network security, internal administration — runs on legitimate interests supported by a balancing assessment. DPDP has no equivalent, so that processing must be re-mapped to consent or to a defined legitimate use.
Q8. Is our Indian captive a Data Fiduciary or a Data Processor?
Usually both, for different datasets. Processing the parent’s customer data under the parent’s instructions makes it a Processor for that data. Determining the purpose and means for its own employee data, vendor contacts and internal records makes it a Fiduciary for those. Map by dataset rather than labelling the entity.
Q9. Why does that distinction matter so much?
Because Fiduciaries carry the substantive obligations — notice, consent, rights handling, breach reporting, retention and SDF duties if designated — while Processors carry obligations flowing from their contract. A group that concludes “we are just a processor” leaves the entire employee data obligation unaddressed.
Q10. Does DPDP require data localisation?
No. The framework adopts a negative list approach, permitting transfer of personal data outside India unless the Central Government explicitly restricts a country or territory by notification. This is the opposite of the localisation regime the January 2025 draft Rules had raised concerns about.
Q11. Which countries are restricted?
None yet. The list has not been notified by the Central Government, and transfer restrictions take effect once it is published. The mechanism exists but has not been used, so the prudent response is to map cross-border data flows now so exposure can be identified quickly if a restriction is notified.
Q12. Do sectoral localisation rules still apply?
Yes. DPDP’s permissive cross-border position does not displace sector-specific requirements that already exist in areas such as payments. Where the Indian entity operates in a regulated sector, the sectoral position needs checking separately.
Q13. What is a consent manager?
A construct with no international equivalent — a registered third-party intermediary through which a data principal can give, manage, review and withdraw consent. Registration becomes mandatory from 13 November 2026 and is handled by the Data Protection Board. For most foreign groups the question is interoperability rather than registration.
Q14. What is a Significant Data Fiduciary?
A Data Fiduciary designated by the Central Government based on factors including the volume and sensitivity of personal data processed, risk to data principals, and potential impact on sovereignty, electoral democracy and public order. Designation is dealt with under Rule 13.
Q15. What does SDF designation add?
An India-based Data Protection Officer, a Data Protection Impact Assessment, algorithmic due diligence, an independent audit, and an annual compliance report under Rule 13. The India-based DPO is the obligation with the clearest operational consequence for a foreign group — a group DPO in London or Frankfurt does not satisfy it.
Q16. When should we assess SDF status?
Well before the compliance deadline. A group that discovers it is an SDF three months out has three months to build a function that takes longer than that, including appointing a DPO with genuine seniority and independence rather than a nominal title.
Q17. What is the breach notification timeline?
72 hours to the Data Protection Board, with affected data principals also to be informed. For a foreign group the difficulty is that the incident is likely detected by a global security team on another continent, so an India-specific trigger is needed at the point of detection rather than at review.
Q18. What should exist before a breach happens?
A named person in India with authority to notify, a trigger in the group’s incident process asking whether Indian data principals are involved, and a pre-drafted notification with a tested route to the Board. Groups without these find the 72 hours ran while the incident was being triaged.
Q19. How long do we have to handle rights requests and grievances?
Data Fiduciaries must respond to data principal requests within the period specified under Rule 14, and grievance redressal must be completed within 90 days of receiving a complaint. Ninety days is generous as a maximum and dangerous as a target, given the Board has been taking complaints since November 2025.
Q20. Does DPDP require deletion, like GDPR?
The position is more complex. The Rules lock in a minimum one-year retention mandate, three years for Schedule 3 entities, and Indian retention interacts with tax, employment and corporate record-keeping duties. A European deletion policy ported into India can conflict with Indian record-keeping obligations, so the schedule should be built against Indian requirements.
Q21. What are the penalties?
Up to ₹250 crore. Section 33 sets differentiated maxima by category of failure — security safeguards, breach notification, children’s data, SDF obligations and others — rather than a single ceiling. The categories carrying the highest exposure tend to be the ones foreign groups under-build: security safeguards and breach notification.
Q22. What should we do first?
The data map, before any policy. Every other decision depends on knowing what personal data the Indian operation touches, for what purpose, who determines it, where it goes and who processes it. Groups that start with a policy end up rewriting it once the map exists.
Related reading
- Employment contracts in India for foreign employers — where employee data documentation belongs
- Equalisation levy and digital taxation in India — the other Indian regime reaching businesses with no Indian entity
- Statutory registers under the Companies Act — the record-keeping duties your retention schedule has to accommodate
- Best business structures in India for foreign companies — whether to have an Indian entity at all
Talk to us before the runway closes
Delhi Legal Company works exclusively with foreign companies establishing and operating in India. Data mapping and role determination, DPDP gap assessment against your existing privacy programme, notice and consent redesign, employee data documentation, breach runbooks and Significant Data Fiduciary readiness — handled alongside the employment and corporate workstreams the same data touches.
How we usually start. Tell us what your Indian operation does, how many people it employs, where your systems are hosted and whether you sell to Indian consumers. We come back with whether you are a Fiduciary, a Processor or both, whether SDF designation is likely, where your existing programme falls short of DPDP, and a realistic sequence from here.