Does DPDP apply to data of foreign clients' customers?
Short answer: Mostly exempt for offshore data; security still applies
Mostly not. Section 17(1)(d) exempts processing of personal data of people outside India when you do it under a contract with a party outside India. Security safeguards and responsibility for your processors still apply. The exemption does not cover your Indian staff, Indian customers, or Indian data mixed into the same work.
Section 17(1)(d) sets the exemption. Section 8(5) and 8(1) still apply. Section 17(1)(d) · Section 8(5) · Rule 6 · Section 8(1)–(2)
- Tag each project by where the people live.
- Find mixed projects with Indian data.
- Keep security controls the same for all.
- Record which contracts rely on the exemption.
- Review when projects change.
- Project tagging
- Contract list
- Assuming all client work is exempt
- Lower security for exempt data
- Missing Indian data in global data sets