Territorial scope: when the DPDPA applies to MNCs
Section 3 of the DPDPA applies to the processing of digital personal data within the territory of India, whether collected online or offline and subsequently digitised. It also applies to processing outside India if it is in connection with offering goods or services to Data Principals in India.
For an MNC with an Indian subsidiary, branch office or GCC, this means:
- The Indian entity is subject to the DPDPA for all personal data it processes in India
- The parent company is subject to the DPDPA if it offers goods or services to individuals in India (e.g. an e-commerce platform serving Indian customers)
- A GCC processing data of individuals outside India on Indian soil is still processing within India—the Act applies to the processing activity, not the nationality of the Data Principal
Group-wide compliance: parent, subsidiary and GCC
MNC group structures create compliance questions that the DPDPA does not explicitly address:
- Indian subsidiary as Data Fiduciary: if the Indian entity determines the purpose and means of processing, it is the Data Fiduciary (Section 2(i)) and bears primary accountability
- Indian GCC as Data Processor: if the GCC processes data on instructions from the parent company, it may be a Data Processor (Section 2(k))—but the parent must engage it under a valid contract (Section 8(2))
- Dual roles: a GCC may be a Data Fiduciary for its own employee data and a Data Processor for data processed on behalf of the parent
- Group-wide consent: consent obtained by the parent company for one purpose does not automatically extend to processing by the Indian subsidiary for a different purpose
Cross-border data flows within the group
MNCs routinely transfer data between jurisdictions—HR data to a global HRIS, customer data to a central CRM, analytics data to a global data lake. Under the DPDPA:
- Section 16(1): transfers are permitted to any country unless restricted by Central Government notification. No country has been restricted as of October 2026
- Section 16(2): sector-specific restrictions survive—RBI payment-data localisation, SEBI and IRDAI regulations
- GDPR interaction: data flowing from the EU to an Indian GCC must comply with GDPR transfer mechanisms (SCCs, adequacy decisions) regardless of the DPDPA’s permissiveness
- Intra-group agreements: MNCs should execute DPDPA-aligned data-transfer agreements (or update existing GDPR DPAs) to cover Indian-law obligations
DPO requirement: India-based, not group headquarters
If an MNC’s Indian entity is designated as a Significant Data Fiduciary under Section 10, it must appoint a Data Protection Officer based in India (Section 10(2)(a)). The group DPO sitting in London, Frankfurt or New York does not satisfy this requirement.
The India-based DPO must be a senior officer answerable to the board of the Indian entity. This is distinct from any foreign-representative requirement—the DPDPA does not impose a foreign-representative obligation (unlike the GDPR’s Article 27 representative for non-EU controllers).
How AMLEGALS assists MNCs
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises multinational corporations and Global Capability Centres on structuring DPDPA compliance programmes, mapping group-wide data flows to Indian-law obligations, preparing for SDF designation and executing DPDPA-aligned intra-group data-transfer agreements.

