It’s an Indian law, so it’s only for Indian companies” is one of the most common assumptions about the DPDP Act — and it’s wrong. Here’s who’s actually covered
In scope
- Digital personal data processed within India, by anyone
- Processing outside India, if it involves offering goods or services to people in India
- Government bodies, private companies, non-profits — any Data Fiduciary
Out of scope
- Personal data that was never digitised — pure paper records
- Data processed for a person's own personal or domestic purposes
- Publicly available personal data that a person has themselves made public
That second row on the left is the one most foreign companies miss: a business with no office in India, no Indian entity, and no Indian employees can still be squarely inside the Act’s reach — simply by selling to Indian customers online. Scope here is about whose data and why, not where the company is registered.
Common misconception — That only Indian-registered companies need to comply. Any organisation, anywhere, offering goods or services to people in India falls within scope.
The Act follows the data and the customer, not the company’s home address.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf