Compliance · 23 Sep 2026
DPDP Act for Foreign DSPs Buying Indian Ad Inventory
India’s Digital Personal Data Protection Act can apply to a demand-side platform that never opens an office in India. This is a plain-language guide to what that means when the thing you are buying is an impression.

If you run a DSP outside India and you buy Indian websites, apps, games, or CTV, you are probably processing personal data about people in India. You do not need their name. A phone’s advertising ID is enough.
India’s privacy law for that data is the Digital Personal Data Protection Act, 2023 — usually called the DPDP Act — together with the Digital Personal Data Protection Rules, 2025. The Act was passed in August 2023. The Rules were notified on 13 November 2025. The duties that change how a DSP bids, logs, and targets become enforceable on 13 May 2027.
A foreign DSP is in scope when it processes personal data in connection with offering goods or services to people in India. Buying Indian ad inventory to decide which ad a person in India sees is that kind of activity.
This guide explains the law in ordinary language, then maps it onto the OpenRTB fields a bidder actually receives.
What is the DPDP Act, in plain language?
The DPDP Act is India’s general law for digital personal data. Personal data means any data about an individual who is identifiable by that data, or in relation to it. “Digital” means the data was collected online, or was collected offline and later digitized.
Think of three roles:
- Data Principal — the person. In advertising, that is the user behind the impression, not the brand paying for the campaign.
- Data Fiduciary — whoever decides why the data is processed and how. This is the closest idea to a GDPR “controller.” A DSP that builds audiences, caps frequency, attributes conversions, or trains models is usually deciding the purpose.
- Data Processor — a vendor that handles the data only on the fiduciary’s instructions. A cloud region, a log pipeline, or an identity vendor can sit here. The fiduciary stays responsible for what the processor does.
The law also creates a Consent Manager: a registered intermediary through which a person can give, review, and withdraw consent in one place. Registration of those managers starts on 13 November 2026, six months before the main duties. And it creates a regulator, the Data Protection Board of India, which was established on 13 November 2025. The Board works largely as a digital office. It can inquire into complaints and breaches, issue directions, and impose penalties.
One comparison helps teams that already lived through GDPR. Europe built a broad privacy code with several lawful bases, including legitimate interest. India built a narrower statute: consent, or a short list of specified uses, plus accountability, security, children’s rules, and Board-led penalties. It does not regulate truly anonymised data. It also leaves out personal data that the person themselves made public, or that someone else published because the law required it. A bid-stream advertising ID is not that kind of public data.
When does it actually start to bite?
The government did not switch the whole law on in one day. Three dates matter for a DSP calendar:
| Date | What starts | What a DSP should take from it |
|---|---|---|
| 13 Nov 2025 | Data Protection Board established. Definitions and the Board’s operating rules are live. | The regulator exists. “The law is not real yet” is the wrong planning assumption. |
| 13 Nov 2026 | Consent Manager registration opens. | A channel for giving and withdrawing consent will exist before the penalty regime. Plan to honor withdrawal, not only a one-time SDK prompt. |
| 13 May 2027 | Notice, consent, security, breach notice, children’s data, user rights, cross-border restrictions, Significant Data Fiduciary duties, and penalties. | This is the date the bid path, contracts, retention, and incident process need to be ready. |
Until 13 May 2027, older rules under the Information Technology Act, 2000 still sit in the background for some kinds of sensitive data. That is not a reason to wait. Rebuilding a bidder, a log store, and a stack of SSP contracts takes longer than a quarter.
Why an Indian bid request is personal data
A bid request is the message an SSP or exchange sends so a DSP can decide whether to buy the impression. It looks technical. Legally, several fields are about a person.
On a typical OpenRTB request for Indian in-app or mobile web inventory, watch:
device.ifa— the mobile advertising ID, such as a GAID on Android. It is built to recognize the same device across apps.device.ip— a full IP address can point to a household or a person, especially on mobile networks with other signals attached.device.geo— latitude and longitude, when precise, are personal data. A city or state is a different conversation from a pin on a building.user.idanduser.buyeruid— publisher or buyer user IDs, often from a cookie or an app login.user.eids— extended IDs such as a hashed email or a shared identity token.- The app bundle or site domain plus an advertising ID — together they describe a person using a particular product, not an anonymous “impression.”
You can buy the impression and still be processing personal data if you read, store, or match those fields. Logging “for IVT” or “for billing” is still processing. So is joining today’s request to a profile you already hold.
A useful test for non-lawyers: if you could pick this device out again tomorrow, you are not looking at anonymous traffic.
Does the law apply if the DSP is outside India?
Often, yes. The Act applies in two situations.
First, processing inside India of digital personal data. An Indian SSP, publisher, or cloud region is squarely here.
Second, processing outside India, if it is connected with any activity of offering goods or services to Data Principals in India. The test looks at people in India, not at where your contracting entity sits. A London or Singapore DSP, bidding on US servers, using an Indian user’s advertising ID to choose an ad, is doing something for a person in India.
The brand on the insertion order does not remove that. Your commercial customer may be an agency in New York. The Data Principal is still the person whose phone generated the bid request.
There is a genuine boundary. The Act is not a claim on every packet that merely transits a router, and it is not aimed at a DSP that never targets people in India and never receives their identifiers. If India is a targeted geo, or Indian inventory is a meaningful share of what you buy, assume you are in scope and confirm it with counsel. The expensive mistake is the opposite assumption: “we have no Indian subsidiary, so Indian privacy law cannot see us.”
Repeated penalties can also become a market-access problem. After monetary penalties in two or more cases, the Board can advise the government to block public access in India to the service the fiduciary uses to offer goods or services to people in India.
Consent, not “legitimate interest”
This is the change that surprises GDPR-trained buying teams.
Under the DPDP Act, personal data may be processed only for a lawful purpose, and only on one of two grounds: consent, or a certain legitimate use listed in the Act. Those legitimate uses are specific. They include cases such as data the person voluntarily gave for a particular purpose, certain government functions, employment, medical emergencies, and a few similar situations. They do not include a general right to process data because advertising is a legitimate business interest.
Consent has a statutory shape. It must be free, specific, informed, unconditional, and unambiguous, shown by a clear affirmative action, and limited to data needed for a specified purpose. Silence is not consent. A notice has to come with or before the request, in clear language, and it has to describe the personal data and the purpose. The Rules push that notice further: an itemised description, the specific purposes, and a way to withdraw consent, exercise rights, and complain to the Board. Withdrawal has to be as easy as giving consent. After withdrawal, processing for that purpose has to stop within a reasonable time.
For a foreign DSP, the practical reading is:
- Someone closer to the user — usually the app or the site — has to collect a real consent that covers sharing identifiers with programmatic buyers for advertising.
- A populated
device.ifais not, by itself, proof of that consent. - India does not yet have one universal consent string the way Europe has the TCF. Ask each SSP which signal they send, and what they suppress when consent is missing or withdrawn.
- Using an ID collected to “show a relevant ad” in order to build a permanent identity graph, sell a segment onward, or train a model can be a new purpose. New purposes need their own notice and consent.
Consent Managers, once registered, are how a person will give and take back consent without visiting every app’s settings. A DSP that cannot stop using an ID after withdrawal will be out of step with the design of the law, even if the first prompt happened inside someone else’s SDK.
Who in the ad stack is responsible?
More than one company can be a Data Fiduciary for the same impression, because each can decide its own purpose.
- The publisher or app decides to monetize the user and to call an SDK or an SSP.
- The SSP or exchange decides how to package the request, which IDs to forward, and which buyers to call. See what a good SSP needs to provide a DSP for the commercial side of that job — privacy fields belong on the same list as schain and ads.txt.
- The DSP decides whether to bid, whether to attach the ID to a profile, and how long to keep the log.
- The advertiser can also be a fiduciary when it brings its own audience or uses the exposure for its own measurement.
Calling yourself a “processor for the brand” does not end the analysis if you, in fact, choose the targeting logic and the retention. The Act is explicit that a fiduciary remains responsible for processing done on its behalf. Processors may be used only under a valid contract.
That contract, with an Indian SSP and with your own subprocessors, should say in operational language:
- who decides each purpose
- which OpenRTB fields are sent only when consent exists
- how child-directed or under-18 inventory is flagged
- where logs are stored, and for how long
- how a breach is reported up the chain
- how an erasure or withdrawal is passed downstream
Supply-path paperwork still matters, but it is not a substitute. A clean schain tells you who sold the impression. It does not tell you whether the user agreed to the use of their advertising ID. Our note on why DSPs reject otherwise good traffic is about quality and transparency. DPDP adds a separate reason to refuse a request: the identifier should not have been sent.
What a DSP should change in the bid stream
You do not need a new auction protocol to get the obvious controls in place. You need a rule for each field, and a place that rule is enforced before the log is written.
- Separate “can I bid?” from “can I recognize this person?” Many campaigns can price a request using format, app, geo at city or state level, floor, and supply path — without storing
ifa. - Default to suppression. If the SSP cannot show a consent basis, drop
device.ifa, precisegeo,buyeruid, andeids. Do not ingest them “just in case” and delete them later. - Truncate or drop IP addresses in any store that does not need the full address for fraud defense, and keep that fraud store short-lived and access-controlled.
- Bind retention to a purpose. A billing dispute window is not a reason to keep raw Indian bid logs for years. Attribution windows should be explicit.
- Stop reuse that the notice never described. Frequency capping for a live campaign, multi-touch attribution, and a lookalike model trained on Indian IDs are different purposes.
- Make withdrawal real in the bidder. An opt-out that only changes a dashboard flag, while yesterday’s ID still matches, is not a withdrawal.
Publishers choosing an SSP in this market should ask the same questions from the other side of the pipe. Our guide to SSPs for app publishers in India covers monetization. From May 2027, “which IDs do you forward, and on what basis?” belongs in that evaluation.
Children means under 18
This is the sharpest difference from US children’s privacy practice.
The Act defines a child as a person who has not completed eighteen years. Before processing that person’s data, the fiduciary must obtain verifiable consent of a parent or lawful guardian. The Rules expect the fiduciary to check that the adult is actually an adult, using reliable identity and age information, details the person provides, or a virtual token mapped to those details.
On top of consent, the Act prohibits:
- processing that is likely to harm a child’s well-being
- tracking of children
- behavioral monitoring of children
- targeted advertising directed at children
The government can prescribe exceptions for classes of fiduciaries or purposes, and it can notify a higher age threshold for a fiduciary that has made processing of children’s data verifiably safe. Those are exceptions to be read, not assumptions to be made. Educational, clinical, and certain health contexts are the examples commentators point to — not open-exchange behavioral buying.
A COPPA flag (regs.coppa) is a US signal about under-13. It does not describe India’s under-18 line, and it does not clear a game or a teen app. If you buy Indian gaming, social, or education inventory, treat child-directed supply as a field you must receive from the SSP, not as a guess from the app category. The penalty for breaking the children’s obligations can reach ₹200 crore.
Can you send Indian bid data to servers abroad?
Yes, unless the government restricts the destination — with two important limits.
Section 16 is a negative list. The Central Government may notify countries or territories to which a Data Fiduciary must not transfer personal data for processing. The Act does not require an adequacy decision or a standard contractual clause for every transfer, the way GDPR does. Rule 15 is written the same way: transfer is allowed except where the government restricts it. As of September 2026, no restricted-country list had been notified, and Section 16 itself is in the set of provisions that commence on 13 May 2027.
That does not mean “send everything, forever.”
- Other Indian laws that are stricter still apply. Section 16 says so. Payment, telecom, and securities rules can require localization even when DPDP does not. Ordinary display and video bidding is rarely in those regimes. A DSP that also touches financial account data might be.
- A company notified as a Significant Data Fiduciary can be required to keep specified personal data and traffic data in India. A global bidder with very large India volume should not assume every log can live only in one overseas region.
- Consent and purpose limitation still apply to the copy that lands in Virginia or Frankfurt. Lawful transfer is not the same as lawful use.
Practically: an Indian advertising ID arriving at a foreign bidder is a cross-border transfer. Document the countries you use. Build the pipeline so a later government notification can turn a destination off without a rewrite of the auction.
What if the government calls you a Significant Data Fiduciary?
The Central Government can notify any Data Fiduciary, or a class of them, as a Significant Data Fiduciary. The factors include the volume and sensitivity of the data, the risk to people’s rights, and the impact on the sovereignty and integrity of India, electoral democracy, security, and public order. A DSP is not automatically on that list. A DSP that processes a large, continuous stream of Indian identifiers is the sort of business the criteria were written to allow the government to examine.
Once notified, the extra duties include:
- a Data Protection Officer based in India, who represents the company
- an independent data auditor
- a Data Protection Impact Assessment and an audit, once every twelve months, with significant observations reported to the Board
- due diligence that algorithmic software used to process personal data is not likely to pose a risk to people’s rights
Failure to meet those additional obligations can draw a penalty of up to ₹150 crore. The annual assessment is a reason to inventory your India bid stream now: which fields, which models, which countries, which vendors.
What happens if bid logs leak?
A personal data breach is broader than a hacker story. The Act includes unauthorized processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access that compromises confidentiality, integrity, or availability.
A Data Fiduciary must protect personal data with reasonable security safeguards. Failing at that can cost up to ₹250 crore. Failing to notify the Board or the affected person can cost up to ₹200 crore.
The Rules split the notice in two. Affected people must be told without delay, in clear language: what happened, the likely consequences, what you are doing, what they can do, and how to reach you. The Board must be told within 72 hours of the fiduciary becoming aware, unless the Board allows longer. A later update covers the facts, the cause, and what you told users.
For a DSP, “affected person” may be millions of device IDs and almost no email addresses. That is a product problem, not only a legal one. You need a path — often back through the publisher or a contact point you publish — and you need logs that are minimized enough that a leak is not your entire India identity graph.
Other breaches of the Act or the Rules can draw up to ₹50 crore. Penalties are decided by the Board. An appeal goes to the Telecom Disputes Settlement and Appellate Tribunal, generally within 60 days.
What can an Indian user ask you to do?
From 13 May 2027, a Data Principal can:
- Access a summary of personal data being processed and the processing activities
- Ask for correction, completion, updating, and erasure, unless you must keep the data for the purpose or for law
- Use a grievance channel that you actually staff
- Nominate someone to exercise those rights if they die or become unable to
They are expected to use your grievance path, or the Consent Manager’s, before they go to the Board. You must publish a contact — a Data Protection Officer if you have one, or another person who can answer — and you must respond. The Act also puts duties on users: they must not impersonate someone else or file false complaints. That is not a reason to ignore a real request.
A foreign DSP that has never had an India-facing privacy contact will feel this first as a workflow. Decide who receives the email, how you find an advertising ID in your stores, and how you confirm you are deleting the right device.
GDPR versus DPDP, for a DSP team
| Question | GDPR habit | DPDP reading for India inventory |
|---|---|---|
| Who is protected? | People in the EU, in most targeting cases | People in India whose digital personal data you process for an offering aimed at them |
| Lawful basis for behavioral ads | Consent, or a debated legitimate interest | Consent. No general legitimate-interest basis |
| Cross-border transfer | Adequacy, SCCs, or another Chapter V tool | Allowed unless the government restricts the country. Extra localization possible for a Significant Data Fiduciary |
| Child | Often under 16, with member-state variation | Under 18. No tracking, behavioral monitoring, or targeted ads directed at children |
| Special category data | A defined sensitive list | No equivalent Article 9 list. Identifiers in the bid stream are still personal data |
| Regulator and penalty | National authority, turnover-based fines | Data Protection Board. Caps in rupees, including ₹250 crore for weak security |
| Consent infrastructure | TCF and CMPs | Notice plus consent, and registered Consent Managers from November 2026. No single mandated bid-stream string yet |
If your India plan is “we will copy the EU consent mode,” copy the discipline — purpose limits, suppression, records — and do not copy the legal labels. Legitimate interest and TCF strings will not answer a Board question about an Indian advertising ID.
Questions to ask an Indian SSP before you bid
- Which OpenRTB fields can identify a person, and which of those are sent only after consent?
- Where is that consent collected, and what does the notice say about programmatic buyers?
- How do you represent consent or refusal on the request? What do you send when the user withdraws?
- How do you flag child-directed apps and users under 18, given India’s age line is not COPPA’s?
- Do you pass precise latitude and longitude by default?
- How long do you keep bid logs that contain Indian identifiers, and in which country?
- Who is the Data Fiduciary for the bid request, and who is only a processor?
- What is the breach notice path, and can you support a 72-hour report to the Board?
- Will your contract be updated for the DPDP Act, or does it only mention GDPR?
The same list is a reasonable scorecard for curated or direct Indian supply. Selection of inventory, which we covered in why advertisers are moving toward curated programmatic supply, gets harder if the curated pool is also the pool that ignored consent.
What to finish before 13 May 2027
A workable program for a foreign DSP is smaller than a full privacy transformation, and larger than a policy paragraph.
- Map every store that can hold an Indian advertising ID, IP, precise geo, or extended ID — bidder, logs, identity graph, warehouse, model features.
- Write down the purpose of each store. Delete the ones you cannot explain in a notice.
- Turn on field suppression when consent is absent, and test it with a live India request.
- Split child-directed and under-18 inventory out of behavioral buying.
- Put DPDP terms into SSP and subprocessor contracts: roles, fields, retention, deletion, breach, audit.
- Publish an India contact for rights requests and staff a queue.
- Write a breach note that can go to users and to the Board inside the statutory clock.
- Decide, with counsel, whether your India volume could support a Significant Data Fiduciary notification. If it could, budget for an India-based DPO, an annual assessment, and a review of model use.
- Watch MeitY notifications on restricted countries and on Consent Managers. Do not hard-code today’s “no blacklist” as a permanent architecture.
The short version
India did not ban foreign DSPs. It did decide that an advertising ID is personal data, that behavioral use of it needs consent, that a child is anyone under 18, and that a company abroad can still be accountable when it targets people in India.
The enforcement date for those duties is 13 May 2027. The work is the bid request in front of you: which fields you accept, why you keep them, who you share them with, and how fast you can stop.
FAQ
Does India’s DPDP Act apply to a foreign DSP with no office in India?
It can. The Act covers processing outside India when that processing is connected to offering goods or services to people in India. A DSP that buys Indian inventory and uses Indian users’ advertising IDs, IP addresses, or similar identifiers to decide which ad to show is the kind of activity the law was written to reach, even if the bidder and the servers sit abroad.
Is an advertising ID or IP address personal data under the DPDP Act?
Yes, when it relates to an identifiable person. The Act defines personal data as any data about an individual who is identifiable by or in relation to that data. A mobile advertising ID, a full IP address, a precise location, or an extended ID in an OpenRTB bid request can meet that test even when the DSP never learns the person’s name.
Can a DSP use legitimate interest for Indian ad targeting the way it does under GDPR?
No. The DPDP Act does not copy GDPR’s legitimate-interest basis. Personal data may be processed for a lawful purpose with consent, or for a short list of specified legitimate uses such as voluntary provision for a stated purpose, certain state functions, employment, or emergencies. Behavioral advertising across open programmatic inventory is a consent problem, not a legitimate-interest problem.
When do the main DPDP obligations for DSPs start?
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. The Data Protection Board was set up then. Consent Manager registration starts on 13 November 2026. The core duties — notice, consent, security, breach notice, children’s data, rights, cross-border transfer limits, Significant Data Fiduciary duties, and penalties — commence on 13 May 2027.
How is children’s data different for Indian programmatic buying?
Under the DPDP Act a child is anyone who has not completed 18 years of age, not 13 as under US COPPA. Before processing a child’s personal data, a Data Fiduciary needs verifiable consent from a parent or lawful guardian. Tracking, behavioral monitoring, and targeted advertising directed at children are prohibited, with limited exceptions the government may prescribe.
Are cross-border bid requests from India banned?
No. Section 16 lets the Central Government restrict transfers to notified countries. It does not ban overseas processing by default. As of September 2026 no restricted-country list had been notified, and the transfer section itself is part of the 13 May 2027 commencement. A foreign DSP should still treat an Indian advertising ID on a US or EU bidder as a cross-border transfer and watch for later notifications, including extra limits that can apply to a Significant Data Fiduciary.
← All posts · What is a DSP? · What is OpenRTB? · Privacy notice · Demand partners