Skip to content
Got a notice? Emergency response

Business, Compliance

A new data law, and an exemption written for exactly your kind of company

You run an Indian dev shop, back-office, or outsourcing business processing a foreign client's end-user data. The Digital Personal Data Protection Act carves this out, but neither the obligation nor the carve-out is fully live yet.

Most coverage of India's new data protection law is written for consumer-facing Indian platforms, an app or website collecting Indian users' data directly. That leaves a genuinely different business unaddressed: an Indian company processing data that belongs to a foreign client's own end users, under a services contract, with no direct relationship to those end users at all. Generic DPDPA explainers don't tell you whether the law even reaches this, or whether there's something built in for exactly this arrangement.
Last reviewed: 6 September 20265 min readReviewed by Preetesh Maloo, CA

The short answer

There is. Section 17(1)(d) of the Digital Personal Data Protection Act, 2023 exempts processing of personal data of Data Principals not within India, where that processing happens in India under a contract with a person outside India, the standard outsourcing or BPO fact pattern. Where it applies, Chapter II (except Section 8(1) and Section 8(5)), Chapter III, and Section 16 stop applying, meaning most of the Act's individual-rights and consent machinery falls away, but your baseline accountability for complying with the Act (Section 8(1)) and your duty to keep reasonable security safeguards (Section 8(5)) do not. The real catch is timing: Section 17 itself, along with most of the Act's substantive obligations, has not yet been brought into force. Only the Data Protection Board's own setup provisions commenced on 14 November 2025, a narrow consent-manager provision follows on 14 November 2026, and the remaining provisions, including Section 17, are scheduled for 14 May 2027. So this is a real, well-targeted exemption to plan around, not yet a live compliance question either way.

Is this your situation? Get a senior CA on it.

Free 15-minute call. We list the filings and their cost, then you decide. No India trip.

Senior CA who specialises in NRI-owned Indian companies · we handle the regulator, you stay abroad

Chat with a CA on WhatsApp

Section 3 gets you into the Act. Section 17 is where you might get carved back out

The Act's extraterritorial reach is broad on paper, it applies even to data processed outside India if that processing relates to offering goods or services to people in India, and applies within India regardless of where the data principal sits. That's the section most generic coverage stops at, which is why an Indian outsourcing business reading only the applicability section comes away thinking the law reaches everything it touches. The exemptions live in a separate section, and one of them is written for almost exactly this business.

The outsourcing exemption, and what it doesn't switch off

Section 17(1)(d) exempts processing personal data of people who are not in India, done in India under a contract with someone outside India, the standard dev-shop, BPO, or back-office arrangement. Where it applies, most of the Act's rights-and-consent machinery (Chapter II barring two sub-sections, Chapter III, Section 16) stops applying. What survives on purpose: Section 8(1)'s baseline rule that you're still accountable for complying with the Act even under a contract, and Section 8(5)'s duty to keep reasonable security safeguards. In plain terms, the exemption removes the consent-and-rights paperwork, not the basic duty to keep the data secure.

Why this isn't something to act on yet, in either direction

The Act commenced in three tranches. Only the Data Protection Board's own setup came into force on 14 November 2025. A narrow provision follows in November 2026. Everything else, the substantive Chapter II and III obligations this exemption would carve you out of, and Section 17 itself, is scheduled for 14 May 2027. So there's no live obligation to be exempt from yet, and no exemption to formally invoke yet either. The useful thing to do now is classify your own data flows honestly (which of your processing is genuinely foreign-client-only, and which touches an India-based employee or an India-facing customer) so you know where you'll stand once the remaining provisions actually commence.

What's involved

What the CA actually does

  1. 1

    We map your actual data flows against the exemption

    We look at your client contracts and whose data you actually process, to see honestly whether your business genuinely fits the foreign-contract, non-resident-data-principal pattern the exemption is written for.

  2. 2

    We flag the slice of your business that doesn't qualify

    Your own India-based employees' personal data, and any India-facing customers you also serve, sit outside this exemption regardless of how the rest of your business is structured.

  3. 3

    We keep you positioned correctly as commencement rolls out

    With the substantive provisions phased in through 2027, we track what's actually live and help you get your data-handling practices in shape before they are, rather than scrambling once they commence.

What to have ready

Documents you'll typically need

  • The services contract with your foreign client
  • A description of whose personal data you actually process under that contract, and where those individuals are located
  • Your current data-security practices and any sub-processors or vendors involved
  • A list of any India-based employees or India-facing customers whose data might also pass through the same systems

References on this page

  • Section 17(1)(d), Digital Personal Data Protection Act, 2023: exempts processing where personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India, from Chapter II (other than sub-sections (1) and (5) of section 8), Chapter III, and section 16
  • Section 8(1), DPDPA 2023: a Data Fiduciary remains responsible for complying with the Act regardless of any contrary agreement, including processing done on its behalf by a Data Processor, this duty is not disapplied by the 17(1)(d) exemption
  • Section 8(5), DPDPA 2023: the duty to take reasonable security safeguards to prevent a personal data breach, also not disapplied by the exemption
  • MeitY commencement notification, Official Gazette, 14 November 2025: brought into force sections 1(2), 2, 18 to 26, 35, 38 to 43, and sub-sections (1) and (3) of section 44 (the Data Protection Board's own establishment); section 6(9) and section 27(1)(d) follow on 14 November 2026; the remaining provisions of the Act, which include section 17, are scheduled to commence on 14 May 2027

Frequently asked questions

Common questions

No. Even where the exemption applies, the duty to keep reasonable security safeguards (Section 8(5)) and the baseline accountability for complying with the Act (Section 8(1)) both remain in force. What falls away is the consent-and-individual-rights machinery, not basic security obligations.

Not as a live compliance question either way. Section 17, which contains this exemption, has not itself been brought into force yet, and neither have most of the obligations it would exempt you from. Treat this as something to plan your data classification around before the remaining provisions commence on the government's own stated timeline, not an active filing or defence to invoke right now.

Not for those individuals. The exemption specifically covers Data Principals not within the territory of India. A foreign contract doesn't extend the carve-out to any India-based individuals whose data you also handle under the same arrangement.

No. The exemption is about the data of people outside India processed under a foreign contract. Your own India-based employees' personal data sits outside that description and would be subject to the Act's ordinary obligations once those provisions actually commence.

It's Section 17(1)(d). Some early commentary discussed this in the context of the Act's broader applicability provisions (Section 3), which is a related but different question, what brings you into the Act's scope in the first place, not what exempts you once you're in it.

Running an Indian dev shop or back-office serving a foreign client?

Tell us who you process data for and where their users are based. A practising CA will map your data flows against the DPDPA's outsourcing exemption and flag anything that doesn't qualify, on a free call, no obligation.

No card, no obligation. All certification and filing work is handled by ICAI-registered practising Chartered Accountants.