Does India's DPDP Act apply to a US SaaS company with no Indian entity, and to paper records?
Question as asked: Does the DPDP Act apply to a US SaaS company with no Indian entity that offers services to users in India, and does it cover paper-only records?
Territorial scope: does DPDPA reach a US SaaS company with no Indian entity?
Yes. Section 3(b) of the DPDP Act, 2023 extends the Act to processing of digital personal data outside India where that processing is "in connection with any activity related to offering of goods or services" to Data Principals within the territory of India. There is no requirement for an Indian subsidiary, office, or other local establishment — the trigger is the offering of the service to individuals in India, not the location of the provider.
Practical consequence: a US-incorporated SaaS company with no Indian entity is a Data Fiduciary (s.2(i)) the moment it offers its service to users in India and processes their digital personal data, even if all servers and staff are outside India. It falls under Chapter II (ss.4–10: notice, consent/legitimate-use basis, security safeguards, breach intimation, children's-data rules if applicable) and Chapter III (ss.11–15: Data Principal rights) in the same way an Indian company would, subject to the general commencement timeline below.
One narrow partial exemption exists in the other direction: s.17(1)(d) exempts personal data of Data Principals not within India, processed by a person based in India under a contract with a person outside India (even then, s.8(1) and 8(5) — accountability for processors and security safeguards — still apply). This does not help a foreign company processing the data of its own India-based users; s.17(1)(d) is about an Indian-based processor handling a foreign client's non-Indian data, not about an offshore Fiduciary serving Indian customers.
Timing: Chapter II and III substantive obligations (ss.3–17) are not yet in force — they commence on 13/14 May 2027 under the Central Government's s.1(2) commencement notification. So today (30 September 2026) the obligations exist in law but are not yet enforceable; the company should be preparing for that date rather than treating itself as already in breach.
Does DPDPA cover paper-only records?
No. Section 3(a) limits the Act's scope to digital personal data — data in digital form, or non-digital data that is "subsequently digitised." Purely physical/paper records that are never digitised fall outside the Act entirely. The moment such records are scanned, photographed, or keyed into a system, they become digital personal data and come within scope from that point forward.
This is a material divergence from GDPR, which covers personal data in any medium, including manual filing systems. A compliance program built on a GDPR mental model will over-scope paper records that the DPDPA simply does not reach — though sectoral or other Indian laws (e.g., SPDI Rules under IT Act s.43A, still in force until s.44(2) commences on 13/14 May 2027) may separately apply to such records.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)