Is It Legal Sid? Book a consultation

§ For foreign digital platforms

Serving users in India? Two Indian laws already reach you.

If you sell digital services to people in India, or hold their personal data, India's data protection law (DPDP) and its GST rules for online services (OIDAR) apply to you — wherever you are headquartered. We tell you exactly where you stand, and fix what needs fixing.

DPDP duties from 13 May 202718% IGST · no thresholdIndia & New York

Scroll

§ 1 — The two laws

One is about your invoices. The other is about your data.

GST · OIDAR

Online services are taxed where the customer is

  • Covers SaaS, AI credits, streaming, subscriptions, e-books and other digital access delivered online
  • 18% IGST on supplies to anyone in India who is not GST-registered — consumers and unregistered businesses alike, since 1 October 2023
  • No turnover threshold for a supplier outside India
  • Simplified registration on Form GST REG-10 and a monthly GSTR-5A return

DPDP Act, 2023

Personal data of people in India, wherever it is processed

  • Applies outside India when you offer goods or services to people in India
  • Clear notice and consent that users can withdraw; stricter rules for children
  • Security safeguards, and breach reports to the Data Protection Board and the people affected
  • Access, correction and erasure requests, and a named contact for data questions
  • Penalties up to INR 250 crore (about US$30 million); main duties apply from 13 May 2027

§ 2 — Who it's for

For platforms that found an Indian audience before an Indian compliance plan.

Most of our clients in this work are headquartered in the US, the UK, the EU, Singapore, the UAE, Australia or Canada.

AI companies

Credit packs and subscriptions sold to people in India are online services taxed under OIDAR. Prompts, uploads and outputs tied to an account are personal data under DPDP.

Web3 & crypto

Premium tiers, paid features and fiat on-ramps can be OIDAR supplies. Wallet-linked profiles, KYC records and IP logs are personal data.

Social & creator apps

In-app purchases, tips and paid badges are digital supplies. The media, messages and location data of Indian users fall under DPDP.

Subscription apps

Auto-renewing plans charged to Indian cards carry 18% IGST under OIDAR, and the account and billing records are personal data.

B2C & micro-SaaS

There is no turnover threshold for a foreign OIDAR supplier: the first Indian subscriber counts. User accounts bring DPDP notice and consent duties.

D2C e-commerce

The shipping addresses, phone numbers and payment details of customers in India are personal data under DPDP — whatever the product.

EdTech & streaming

Pre-recorded courses and streamed content are OIDAR services. Learner data — and children's data, which needs verifiable parental consent — sits under DPDP.

AdTech & analytics

Pixels, device identifiers and profiles of people in India are personal data, and processing them for services offered in India brings DPDP into play.

§ 3 — Signals

What we look for first.

None of these settles the question on its own. Together they tell us where to look.

  • Prices shown in INR, or Indian cards and UPI accepted at checkout
  • Auto-renewing plans, credit packs or in-app purchases bought from India
  • Sign-ups with +91 phone numbers or Indian email and billing addresses
  • Prompts, uploads, messages, location or usage telemetry stored per user
  • Wallet connections or fiat on-ramps that take Indian cards
  • Invoices to Indian customers without 18% IGST or a GST registration number
  • A privacy notice with no India-specific consent flow or named data contact

§ 4 — India exposure check

Nine questions. Two minutes. No sign-up.

Answer for how your product works today. Nothing leaves your browser unless you choose to book.

OIDAR · what you sell

Do people in India pay you for digital access — a subscription, credits, downloads, streaming or in-app items?

Is it self-serve — they check out online (card, UPI, wallet or app store) with no one delivering the service by hand?

Do you show prices in INR, or accept Indian cards or UPI?

Do your invoices to customers in India show 18% IGST and an Indian GST registration?

DPDP · whose data you hold

Do people in India create accounts or give you their email or phone number?

Do you store what they create or do — prompts, uploads, messages, location, device IDs or usage telemetry?

Do you run analytics or ad pixels on them, or send their data to vendors in other countries?

Could some of your users in India be under 18?

Does your privacy notice give people in India a clear notice, a way to consent and withdraw, and a named contact for data questions?

Indicators from your own answers — not a legal determination. Whether a law applies, and what it requires of you, is decided only after our lawyers review the facts.

§ 5 — What we do

From exposed to in order.

Exposure assessment

The facts first: what you sell into India, whose data you hold and where it goes — with a written view of what applies, rated by confidence, before any work is quoted.

OIDAR registration & filings

Simplified registration on Form GST REG-10, IGST on your invoices and checkout, monthly GSTR-5A returns, and coordination with your representative or filing partner in India.

DPDP compliance programme

A map of the personal data you hold, notices and consent flows that work in your product, retention rules, breach response, and a process for access, correction and erasure requests.

Contracts & policies

Privacy notices and terms written for Indian users, and data-processing terms with your vendors and processors so their obligations match yours.

Back-periods & regulators

If you have been selling or collecting data in India for a while, we work out the exposure and the cleanest way to regularise — and handle correspondence with authorities.

We work alongside your own counsel and accountants, from our offices in India and New York.

§ 6 — How it works

Five steps, facts first.

Run the exposure check

Two minutes, on this page. Nothing is stored until you choose to book.

Assessment call

A 60-minute call with our team, by video from anywhere; the fee is credited if we go on to work together.

Written findings

What applies, what does not, and what is uncertain — each point rated High, Medium or Low confidence.

Fix it

Registration, invoice and checkout changes, notices, consent flows and contracts, in the order that removes the most risk first.

Stay compliant

A filing calendar for GSTR-5A and a DPDP review before the 13 May 2027 deadline and after major product changes.

§ 7 — Questions

What foreign teams ask us

Often, yes. The DPDP Act applies to processing outside India when it is connected with offering goods or services to people in India (section 3). For GST, the place of supply of an online service is where the customer is, so a foreign supplier selling to unregistered customers in India registers under a simplified scheme — no Indian entity is needed.

No. Unlike Indian businesses, a supplier of OIDAR services from outside India to customers in India who are not GST-registered has no turnover threshold: the obligation starts with the first such supply.

IGST at 18% on the supply. The supplier registers on Form GST REG-10 and files a return in Form GSTR-5A every month, by the 20th of the following month. Since 1 October 2023 this covers supplies to any unregistered recipient in India, not only individuals using the service for personal purposes.

It is common, especially since the October 2023 change widened the scope. We work out the back-period, the tax and interest involved, and the cleanest way to regularise — ideally before an authority raises it.

The DPDP Rules were notified on 13 November 2025 and phase in over eighteen months. The Data Protection Board is already constituted, the consent-manager framework follows from November 2026, and the remaining obligations — notices, consent, security safeguards, breach reporting and user rights — apply from 13 May 2027.

Only if the government designates you a Significant Data Fiduciary, based on the volume and sensitivity of the data and the risk involved; those must appoint a DPO based in India. Every other business must still publish the contact details of someone who can answer questions about how it processes personal data.

Yes. Many clients bring us in alongside their US, EU or Singapore counsel and their accountants. We have an office in New York as well as in India, and schedule calls in your time zone.

The exposure check on this page is free. A consultation is $150 (or the equivalent in INR) for a 60-minute session, paid before the call through the secure link we send when we confirm your slot. It is credited toward your legal fees if the matter proceeds.

§ 8 — Get started

Know where you stand before 13 May 2027.

A 60-minute assessment call, by video from anywhere, with a written view of what applies to you.