Deadlines · Data protection

Two dates, and one of them is weeks away.

India's data protection law reaches foreign companies that have no Indian entity at all, which most of them have not registered. This page states the dates and who they catch. It is a reference, not a privacy programme — building the programme is work for a data protection lawyer and we say so below rather than pretending otherwise.

🧾 CA-reviewed · fee quoted upfront
✓13 November 2026 — the consent manager framework becomes operational
✓13 May 2027 — full substantive compliance: notice, consent, safeguards, breach reporting, data principal rights
✓Penalties run to ₹250 crore per breach of an obligation, graded by obligation
✓It applies outside India where you offer goods or services to people in India — no Indian entity needed
✓A significant data fiduciary must appoint a data protection officer based in India
✓A consent manager must be a company incorporated in India with net worth of at least ₹2 crore
✓That entity and that certificate are our work. The privacy programme is not.
Need the Indian entity or the net worth certificate?
Tell us whether you are registering as a consent manager, need an Indian entity to satisfy a data protection requirement, or want a net worth certificate. We will also tell you plainly when what you need is a lawyer instead.
💬 Free consult first·CA-reviewed·No payment to start

What we handle for you

📅

The two dates

The consent manager framework from 13 November 2026, and full substantive compliance by 13 May 2027. The phasing means 2026 is the build year and 2027 is when the Board can act.

🌍

Whether it reaches you at all

It applies to processing outside India where that processing is connected with offering goods or services to people in India. A foreign SaaS product with Indian users is in scope with no Indian entity and no Indian servers.

🏢

The entity requirement

A consent manager has to be a company incorporated in India with a net worth of at least ₹2 crore, registered with the Board. Incorporation, the capital structure and the net worth certificate are ours.

📄

The net worth certificate

A certified statement of assets less liabilities as at a chosen date, on letterhead with a UDIN, issued by a chartered accountant — which is what a regulator asking for a net worth threshold means.

🚧

What we do not do, and will say so

Privacy notices, consent architecture, breach reporting, impact assessments, cross-border transfer analysis and DPO advisory. That is data protection practice and it needs a specialist lawyer.

Who this is for

💻 Foreign SaaS and app companies

With Indian users and no Indian entity.

🔐 Prospective consent managers

Needing the Indian entity and the net worth bar.

🏢 Existing Indian subsidiaries

Of foreign groups working out what applies to them.

Transparent, quoted upfront

Every case is different, so we review yours first and give you a clear price before any work or payment — no charge for the review, no obligation.

Share your details → a CA reviews → you get a fixed quote on WhatsApp.

No hidden charges. You decide after you see the price.

💬 Get my quote →

Common questions

What are the DPDP compliance deadlines?

Two dates do the work. The consent manager framework becomes operational on 13 November 2026, which is the first hard, date-bound obligation in the regime. Full substantive compliance — notice, consent, security safeguards, breach notification and data principal rights — is due by 13 May 2027, widely treated as the hard enforcement date. The rules set an eighteen-month phased window, so 2026 is the year to build and test and 2027 is when the Data Protection Board can act on failures.

Does the DPDP Act apply to a foreign company with no Indian entity?

Yes, in the circumstance that matters to most foreign businesses. The Act reaches processing of digital personal data that happens outside India where that processing is connected with offering goods or services to people in India. So a SaaS product, an app or a website with Indian users can be in scope with no Indian company, no Indian office and no Indian servers. Whether it applies to you is a legal question on your facts — but do not assume you are outside it because you have no presence here.

What are the penalties?

Financial, and large. The schedule runs up to ₹250 crore for a breach of an obligation, graded by which obligation is breached, with failure to take reasonable security safeguards at the top of the range and separate heads for failing to notify a breach and for obligations relating to children's data. The Data Protection Board imposes them. There is no criminal liability under the Act, and there is no cap that scales with your size, which is why smaller foreign companies should not assume the exposure is proportionate to their Indian revenue.

What is a consent manager, and can a foreign company be one?

A consent manager is a registered intermediary through which a person can give, manage, review and withdraw consent across data fiduciaries. It has to be registered with the Board, and the eligibility conditions are specific: a company incorporated in India, with a net worth of at least ₹2 crore, and a platform meeting the standards the Board publishes. A foreign company cannot be one directly — it would need an Indian company that meets the net worth bar. That is the part of this we can actually do for you.

What does the ₹2 crore net worth requirement mean in practice?

It means the Indian company has to be capitalised, not just incorporated, and be able to prove it. Net worth is assets less liabilities as at a stated date, evidenced by a certificate from a chartered accountant carrying a UDIN, which the recipient can verify. For a foreign group this usually means remitting capital as foreign direct investment, allotting shares within sixty days, and filing FC-GPR within thirty days of allotment — so the FEMA sequence and the net worth position have to be planned together rather than in that order. Working backwards from 13 November 2026, that is not a lot of time.

Do we need a data protection officer in India?

If you are notified as a significant data fiduciary, yes — that category carries additional obligations including a data protection officer based in India and answerable to the board, an independent data auditor, and periodic data protection impact assessments. Whether you fall into that category depends on factors including the volume and sensitivity of the data you handle. Who to appoint and what the role actually requires is advice we are not qualified to give; the employment and payroll side of having that person on an Indian payroll is.

Can you make us DPDP compliant?

No, and we would rather say so on the page than in a meeting after you have paid us. Building a privacy programme — the notices, the consent architecture, the breach response plan, the impact assessments, the cross-border transfer analysis — is data protection practice and it belongs with a lawyer who does it. What we do is the part that is genuinely ours: incorporating and capitalising the Indian entity, the net worth certificate, the FEMA reporting on the capital, and the ongoing compliance for that company. We will work alongside whoever you appoint for the rest.

More on entering India

Talk to us about registering your Indian company
A foreign company or individual can own 100% of an Indian private limi...
Which structure fits your plan for India?
Not every foreign company should incorporate. A liaison office cannot...
Tell us what you are planning in India
Entering India means dealing with the Registrar of Companies, the inco...
Set up your Indian subsidiary
A wholly owned subsidiary is a separate Indian company, owned entirely...
Is a branch office right for you?
A branch office is not a separate company. It is the foreign company i...
Open or regularise a liaison office
A liaison office lets a foreign company maintain a presence in India w...
Would an LLP work for your India plan?
An LLP is lighter to run than a company and is attractive to professio...
Tell us where your FEMA position stands
Nothing goes wrong on the day a FEMA filing is missed. It goes wrong t...
Tell us about your India headcount
Hiring in India is not only a contract. Depending on headcount and sal...
Not sure which of these apply to you?
Most India-entry pages imply one firm can do everything. It cannot. Th...
Tell us why you need the PAN
Almost nobody wants a PAN for its own sake. They want it because an In...
Tell us what the business actually does
Almost every India-entry decision follows from this one. If your secto...
Want this as a calendar for your own entity?
A foreign-owned Indian company answers to four different authorities o...
Tell us about your India team
We are not an employer of record and we do not resell one, so we have...
Tell us what you are planning in India
The trade agreement gets the coverage; the Double Contribution Convent...
Tell us about the structure
Since Rule 25A was amended in September 2024, a foreign holding compan...
Tell us what the company needs and who is putting it in
This is the question we are asked most often by foreign owners and the...
Tell us how your company is set up
Almost every foreign founder asks a version of this, usually quietly,...
Tell us how you are engaged and paid
This page is for the person receiving the money rather than the compan...
Tell us about the investment
Most pages on this still warn about angel tax, which was abolished for...
Tell us who you want on the board
Resident director, independent director, woman director, nominee direc...
Tell us about the centre
A centre serving only your own group has no Indian customers, so almos...
Tell us what you export and to whom
Most software exporters meet this the same way: a payment arrives, the...
Tell us what the unit would do
GIFT City is India's only International Financial Services Centre, wit...
Tell us what you hold
Nobody tells you which of your Indian accounts and investments survive...
Full NRI / foreign-income ITR filing
The complete return — DTAA, Form 67, Schedule FA. ₹4,999 all-inclusive.
💬