India's data protection law reaches foreign companies that have no Indian entity at all, which most of them have not registered. This page states the dates and who they catch. It is a reference, not a privacy programme — building the programme is work for a data protection lawyer and we say so below rather than pretending otherwise.
The consent manager framework from 13 November 2026, and full substantive compliance by 13 May 2027. The phasing means 2026 is the build year and 2027 is when the Board can act.
It applies to processing outside India where that processing is connected with offering goods or services to people in India. A foreign SaaS product with Indian users is in scope with no Indian entity and no Indian servers.
A consent manager has to be a company incorporated in India with a net worth of at least ₹2 crore, registered with the Board. Incorporation, the capital structure and the net worth certificate are ours.
A certified statement of assets less liabilities as at a chosen date, on letterhead with a UDIN, issued by a chartered accountant — which is what a regulator asking for a net worth threshold means.
Privacy notices, consent architecture, breach reporting, impact assessments, cross-border transfer analysis and DPO advisory. That is data protection practice and it needs a specialist lawyer.
With Indian users and no Indian entity.
Needing the Indian entity and the net worth bar.
Of foreign groups working out what applies to them.
Every case is different, so we review yours first and give you a clear price before any work or payment — no charge for the review, no obligation.
No hidden charges. You decide after you see the price.
💬 Get my quote →Two dates do the work. The consent manager framework becomes operational on 13 November 2026, which is the first hard, date-bound obligation in the regime. Full substantive compliance — notice, consent, security safeguards, breach notification and data principal rights — is due by 13 May 2027, widely treated as the hard enforcement date. The rules set an eighteen-month phased window, so 2026 is the year to build and test and 2027 is when the Data Protection Board can act on failures.
Yes, in the circumstance that matters to most foreign businesses. The Act reaches processing of digital personal data that happens outside India where that processing is connected with offering goods or services to people in India. So a SaaS product, an app or a website with Indian users can be in scope with no Indian company, no Indian office and no Indian servers. Whether it applies to you is a legal question on your facts — but do not assume you are outside it because you have no presence here.
Financial, and large. The schedule runs up to ₹250 crore for a breach of an obligation, graded by which obligation is breached, with failure to take reasonable security safeguards at the top of the range and separate heads for failing to notify a breach and for obligations relating to children's data. The Data Protection Board imposes them. There is no criminal liability under the Act, and there is no cap that scales with your size, which is why smaller foreign companies should not assume the exposure is proportionate to their Indian revenue.
A consent manager is a registered intermediary through which a person can give, manage, review and withdraw consent across data fiduciaries. It has to be registered with the Board, and the eligibility conditions are specific: a company incorporated in India, with a net worth of at least ₹2 crore, and a platform meeting the standards the Board publishes. A foreign company cannot be one directly — it would need an Indian company that meets the net worth bar. That is the part of this we can actually do for you.
It means the Indian company has to be capitalised, not just incorporated, and be able to prove it. Net worth is assets less liabilities as at a stated date, evidenced by a certificate from a chartered accountant carrying a UDIN, which the recipient can verify. For a foreign group this usually means remitting capital as foreign direct investment, allotting shares within sixty days, and filing FC-GPR within thirty days of allotment — so the FEMA sequence and the net worth position have to be planned together rather than in that order. Working backwards from 13 November 2026, that is not a lot of time.
If you are notified as a significant data fiduciary, yes — that category carries additional obligations including a data protection officer based in India and answerable to the board, an independent data auditor, and periodic data protection impact assessments. Whether you fall into that category depends on factors including the volume and sensitivity of the data you handle. Who to appoint and what the role actually requires is advice we are not qualified to give; the employment and payroll side of having that person on an Indian payroll is.
No, and we would rather say so on the page than in a meeting after you have paid us. Building a privacy programme — the notices, the consent architecture, the breach response plan, the impact assessments, the cross-border transfer analysis — is data protection practice and it belongs with a lawyer who does it. What we do is the part that is genuinely ours: incorporating and capitalising the Indian entity, the net worth certificate, the FEMA reporting on the capital, and the ongoing compliance for that company. We will work alongside whoever you appoint for the rest.
Leave your number — our team calls you back. Free, no obligation.