The commercial conversation about hiring an overseas search agency usually stalls on three questions from finance and legal rather than anything marketing cares about. Who pays which tax. Whether sending data abroad is allowed. What happens when the rules change halfway through the contract.
All three have clear answers as at August 2026, and all three are national Indian law. There is no city-level digital marketing or data regulation in Pune, and any vendor implying otherwise has invented one. That is worth stating plainly, because a surprising amount of location-specific marketing content gestures at local compliance requirements that do not exist.
What follows is the mechanics in one place, with the dates and the rule numbers. It is orientation rather than advice, and anything with money attached should be confirmed with an Indian tax adviser or counsel before signing. But you should be able to read a proposal and know whether the vendor understands what they are asking you to sign.
India's Data Protection Rules, Phase by Phase
The Rules were notified on 13 November 2025. They did not all commence at once, and the phase that matters most for an overseas vendor is the last one.
13 November 2025, in force
Rules 1, 2 and 17 to 21
Definitions and procedural framework. The Data Protection Board of India is constituted and complaints can already be filed. This part is live today.
13 November 2026
Rule 4, Consent Manager registration
The registration regime for Consent Managers opens. Relevant if your programme touches consent infrastructure, not otherwise.
13 May 2027
Rules 3, 5 to 16, 22 and 23
Notice and consent, data principal rights, security safeguards, breach reporting, retention and erasure, children's data, Significant Data Fiduciary duties, and cross-border transfer under Rule 15. This is the phase that governs an overseas processing arrangement.
A live variable. In January 2026 the ministry consulted on compressing the eighteen-month window to twelve and bringing transfer restrictions forward. As at August 2026 that had not been confirmed by gazette notification. Contracts should be drafted so an earlier commencement does not force a renegotiation.
Sources: Digital Personal Data Protection Rules, 2025, gazette notification and commencement schedule • Ministry consultation, January 2026, status unconfirmed as at 21 August 2026. Orientation, not legal advice.
Created by Arfadia • arfadia.com/blog
Cross-border transfer, and the thing vendors get wrong
India uses a negative-list model for transferring personal data abroad. Transfer is permitted unless the Central Government restricts a specific destination by order. That is a considerably more permissive design than a whitelist system, and it is the correct starting point for any conversation about processing data outside India.
Two details are consistently misstated in the material circulating on this. First, the relevant provision is Rule 15 of the 2025 Rules, operationalising Section 16 of the Act. We encountered research asserting Rule 14, which is wrong. Second, and more consequentially, Rule 15 sits in the group commencing 13 May 2027, and no country list has been notified.
So a vendor telling you today that your cross-border transfers are DPDP compliant under the negative-list model is describing a regime that has not commenced. The claim is not merely premature, it is the wrong tense, and it appears in commercial material often enough that it is worth checking for specifically. The correct posture is that this is something to write into a contract now rather than a compliance state to claim today.
Note also that the Act reaches beyond India's borders. It applies to processing outside India where that processing relates to offering goods or services to individuals inside India. An overseas agency is not outside the framework by virtue of its address.
Penalties, in proportion
The penalty schedule gets quoted a lot, usually as a scare tactic, so it is worth setting out accurately along with the parts that never get quoted.
Section 33 read with the Schedule sets fixed rupee ceilings rather than a share of turnover, which is a meaningful design difference from the European approach. The headline figure is up to ₹250 crore for failure to implement reasonable security safeguards resulting in a breach. Failure to notify a breach carries up to ₹200 crore, as do the additional obligations concerning children's data. Significant Data Fiduciary duties carry up to ₹150 crore. A data principal breaching their own obligations faces ₹10,000.
Now the parts usually left out. Penalties are assessed per instance, so a single incident breaching several duties can accumulate. But the Board is required to weigh the nature, gravity and duration of the breach and any mitigation before fixing an amount, which means a documented programme materially affects exposure. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal within sixty days. And the core obligations these penalties attach to commence in May 2027.
We do not use these numbers as a sales argument, and you should be wary of anyone who does. A vendor leading with ₹250 crore is selling fear rather than a method.
| Question | Position as at August 2026 | What to put in the contract |
|---|---|---|
| Who charges GST? | Nobody adds it to the invoice. A service supplied from outside India to a recipient in India, with place of supply in India, is an import of service. The recipient self-assesses 18 percent IGST under reverse charge | State that fees are exclusive of Indian indirect tax and that reverse charge applies |
| Can the IGST be paid with existing credit? | No. Liability under reverse charge must be discharged in cash through the electronic cash ledger. The same amount is then claimed as input tax credit in the same return | Nothing, but plan the cash timing rather than assuming a net-nil month |
| Do we need a special invoice? | Yes. The recipient issues a self-invoice for the imported service | Assign responsibility explicitly so it is not discovered at audit |
| Does turnover exempt us? | No. Anyone liable under reverse charge must register for GST regardless of turnover | Confirm registration status before the first invoice |
| Must we withhold tax? | Section 195 applies to payments to non-residents. The domestic rate for fees for technical services is 20 percent plus surcharge and cess, and 20 percent also applies without a PAN. Treaty relief is available at a lower rate | State whether fees are gross or net of Indian withholding. This is the single most common contract omission |
| What is the treaty rate? | Published sources currently disagree for India and Indonesia. Treaty relief requires a Tax Residency Certificate and Form 10F from the vendor | Require the certificate and Form 10F as a condition, and confirm the rate with your adviser |
| Is there still a 6 percent levy on digital ads? | No. Abolished by the Finance Act 2025 with effect from 1 April 2025. The separate 2 percent e-commerce levy was abolished with effect from 1 August 2024 | Nothing, but ignore any guidance predating those dates |
| Is sending data abroad allowed? | Yes, under a negative-list model. Rule 15 commences 13 May 2027 and no country list has been notified | Processor role, purpose limitation, retention and erasure, breach cooperation, drafted for the 2027 regime now |
The withholding clause that saves an argument
Of everything on this page, the clause most often missing is also the cheapest to add. Contracts routinely state a fee and say nothing about Indian withholding, and then somebody withholds twenty percent and both sides believe they are right.
Say it explicitly. Either the fee is gross and the Indian party withholds from it, or the fee is net and the Indian party grosses up. Both are normal commercial positions. What is not workable is silence, because the default assumption differs on each side of the transaction and the disagreement surfaces on the first invoice.
Attach the documentation requirement in the same clause. Treaty relief requires a Tax Residency Certificate and Form 10F from the vendor, and if those arrive late the withholding happens at the domestic rate regardless of what the treaty would have allowed. Making delivery of both a condition of the first invoice removes the problem entirely.
One thing we deliberately do not do is print a treaty rate. Published sources currently disagree on the applicable figure for India and Indonesia, and a marketing page is the wrong place to resolve a tax question. Get the rate from an Indian adviser and write it into the contract, rather than taking it from any vendor's website including ours.
What Actually Happens to a Cross-Border Invoice
Mapped so finance can confirm it in one reading rather than three emails.
Vendor invoices without Indian GST
A foreign supplier does not charge Indian indirect tax. The invoice states the fee and the tax treatment.
Vendor supplies tax residency documents
Tax Residency Certificate and Form 10F, ideally before the first invoice rather than after it.
Recipient issues a self-invoice
Required for an imported service. Frequently forgotten and surfaces at audit rather than at payment.
Recipient pays 18 percent IGST in cash
Reverse charge liability is discharged through the electronic cash ledger and cannot be settled with existing credit.
Recipient claims the same amount as input tax credit
In the same return. Net cash effect is usually nil where output liability is sufficient to absorb it, but the timing is real.
Recipient withholds under Section 195
At the treaty rate where the certificate and Form 10F are in hand, otherwise at the domestic rate.
Recipient issues the withholding certificate
The vendor needs it to claim relief in its own jurisdiction. Contracts should require it within a stated period.
General information based on published tax authority guidance as at 21 August 2026, not tax advice. Confirm the applicable withholding rate and your specific treatment with an Indian tax adviser.
Created by Arfadia • arfadia.com/blog
What governs data protection in the meantime
A staged commencement raises an obvious question that vendors rarely address: if the substantive obligations arrive in May 2027, what applies today.
The answer is that the earlier framework has not vanished. Until the new regime commences, the older rules governing sensitive personal data remain relevant, and the Information Technology Act framework they sit under is still in force. A contract drafted as though nothing applies until 2027 is drafted against the wrong baseline.
The practical approach is to contract to the higher standard now, since almost everything the 2027 regime will require is good practice today: a defined processor role, purpose limitation, named retained fields, retention and erasure periods, breach cooperation and security commitments. Doing that removes the transition entirely. There is no cutover, because the contract already meets the standard.
It also removes the argument. When a vendor tells you their arrangement is already compliant with a regime that has not commenced, the useful response is not to correct them but to ask what their contract actually says about retained fields and erasure. Compliance claims are cheap. Clause text is not.
One GST exception worth knowing about
The reverse charge position above holds for a business-to-business professional services engagement, which covers essentially every agency retainer. There is a carve-out that occasionally causes confusion, and it is worth understanding so you can rule it out rather than worry about it.
Where a service is classified as an online information and database access or retrieval service and the recipient is unregistered, meaning a consumer rather than a business, the position flips. The foreign supplier must obtain non-resident registration and remit the tax itself rather than the recipient self-assessing under reverse charge.
That classification generally does not apply to a professional retainer where a named team delivers work for a registered Indian business. It matters if you are buying a self-service tool subscription alongside the retainer, because the tool may fall on the other side of the line even though the retainer does not. Two line items on one invoice can carry two different treatments.
Ask the question once at contracting rather than discovering it at audit. If a vendor cannot say which classification applies to each line of their invoice, that is a reasonable thing to resolve before signing rather than after.
The consent manager phase, and whether it concerns you
The middle phase of the commencement schedule, arriving 13 November 2026, covers registration of Consent Managers. It attracts attention out of proportion to how many engagements it touches.
A Consent Manager is a specific regulated intermediary through which individuals can give, manage, review and withdraw consent. Registration involves conditions set by the framework, including corporate and financial thresholds. If your programme does not operate consent infrastructure, this phase changes nothing for you.
Where it becomes relevant is if a marketing stack starts brokering consent across properties, or if a vendor proposes something that functionally performs that role while calling it something else. The label a vendor uses does not determine the classification. What the system does determines it.
For a search and citation programme built around category-level prompts and page-level content work, the answer is almost always that this phase is not applicable. Note it in the contract as not applicable rather than leaving it unaddressed, so that a later reviewer can see it was considered.
What a search programme actually touches
A lot of compliance anxiety in this category is misdirected, because the heaviest obligations attach to personal data and much search and citation work does not involve any.
A prompt asking an assistant to shortlist suppliers in a category contains no personal data. Coding which sources an answer cited involves no personal data. Rewriting a specification page, fixing entity records, building trade-press authority: none of it touches an individual. The compliance surface of that work is small, and treating it as though it were customer-data processing wastes effort that should go elsewhere.
Where the surface genuinely appears is narrower and identifiable. Ingesting reviews or user-generated content that carries author names. Prompt logs tied to identified users. Lead data flowing through a form into an overseas system. Enrichment of individual contacts. Those are real, and the boundary is set by which fields are retained rather than by what the service is called.
So the useful contract discipline is field-level rather than categorical. Name what will be retained, pseudonymise before anything crosses a border, keep identifiers out of prompt panels unless they are genuinely necessary, and define retention and erasure. That handles the actual risk without pretending a category-level prompt panel is a customer database.
Five clauses worth insisting on
Reduced to a checklist, the contract needs the following. State whether fees are gross or net of Indian withholding, and require the Tax Residency Certificate and Form 10F as a condition of the first invoice. Confirm the client's GST registration status before invoicing, since reverse charge liability applies regardless of turnover. Assign self-invoicing responsibility explicitly.
Then define the data relationship: processor role, the specific fields retained, purpose limitation, retention and erasure periods, and breach cooperation obligations, drafted against the regime commencing May 2027 rather than the position today. Add a change-of-law clause so that if the proposed acceleration is notified, the arrangement adapts without a renegotiation.
Finally, agree the deliverable definitions in the same document. Prompt panel version, baseline date, metric definitions, and who owns the content, schema and prompt library at termination. That last point is commercial rather than regulatory, and it is the one clients most often discover they never settled.
None of this is difficult. It is a page of contract and one conversation with an adviser, and it removes the three objections that otherwise stall the engagement for a month.
Frequently Asked Questions
Is it legal for an Indian company to use an overseas search agency?
Yes. India uses a negative-list model for cross-border transfer of personal data, meaning transfer abroad is permitted unless the Central Government restricts a specific destination by order. No country list has been notified. Separately, the relevant provision, Rule 15 of the Digital Personal Data Protection Rules 2025 operationalising Section 16 of the Act, sits in the group commencing 13 May 2027. Note also that the Act reaches processing outside India where it relates to offering goods or services to individuals in India, so an overseas agency is not outside the framework because of its address.
Are India's data protection rules fully in force right now?
No, and this is widely misstated. The Rules were notified on 13 November 2025 with a staged commencement. Rules 1, 2 and 17 to 21 are in force, so the Data Protection Board of India is constituted and complaints can be filed. Rule 4, covering Consent Manager registration, commences 13 November 2026. The substantive obligations, including notice and consent, security safeguards, breach reporting, retention and cross-border transfer under Rule 15, commence 13 May 2027. A vendor claiming your cross-border transfers are already DPDP compliant is describing a regime that has not commenced.
Could the timeline move?
Possibly. In January 2026 the ministry consulted on compressing the eighteen-month window to twelve months and bringing transfer restrictions forward, which would shift the substantive date earlier. As at August 2026 that had not been confirmed by gazette notification. The practical response is a change-of-law clause so an earlier commencement does not require renegotiating the contract.
Who pays Indian GST on an overseas agency's invoice?
The Indian recipient, under reverse charge, and then recovers it. A service supplied from outside India to a recipient in India with the place of supply in India is an import of service, so the recipient self-assesses 18 percent IGST rather than the foreign supplier charging Indian GST. Three details catch people out: the liability must be discharged in cash through the electronic cash ledger and cannot be settled with existing credit, a self-invoice is required, and anyone liable under reverse charge must register for GST regardless of turnover. The same amount is claimed as input tax credit in the same return.
Do we have to withhold tax on payments to a foreign agency?
Section 195 applies to payments to non-residents. The domestic rate for fees for technical services is 20 percent plus surcharge and cess, and 20 percent also applies where the recipient holds no PAN. Treaty relief is available at a lower rate, conditional on the vendor providing a Tax Residency Certificate and Form 10F. Make delivery of both a condition of the first invoice, because late documentation means withholding happens at the domestic rate regardless of what the treaty would have permitted.
What is the India to Indonesia treaty withholding rate?
We deliberately do not state a figure. Published sources currently disagree on the applicable rate, with older treaty text and more recent commentary pointing to different numbers, and a marketing page is the wrong place to resolve a tax question. Obtain the rate from an Indian tax adviser and write it into the contract rather than taking it from any vendor's website.
Is the 6 percent equalisation levy still payable on digital services?
No. It was abolished by the Finance Act 2025 with effect from 1 April 2025, and the separate 2 percent e-commerce levy was abolished with effect from 1 August 2024. Payments for digital services now fall under ordinary Section 195 and treaty analysis rather than a standalone levy. A good deal of guidance still online predates those changes, so check the date on anything you read.
How large are the penalties under India's data protection regime?
Section 33 read with the Schedule sets fixed rupee ceilings rather than a share of turnover. Up to ₹250 crore for failure to implement reasonable security safeguards resulting in a breach, up to ₹200 crore for failure to notify a breach and for children's data obligations, and up to ₹150 crore for Significant Data Fiduciary duties. Penalties are assessed per instance so a single incident can accumulate. Two things usually get left out: the Board must weigh nature, gravity, duration and mitigation before fixing an amount, and appeals go to the Telecom Disputes Settlement and Appellate Tribunal within sixty days.
Does a search or citation programme even involve personal data?
Often very little. A prompt asking an assistant to shortlist suppliers in a category contains no personal data, and neither does coding which sources an answer cited, rewriting a specification page or fixing entity records. The surface appears where a programme ingests reviews or user-generated content carrying author names, retains prompt logs tied to identified users, moves lead data into an overseas system, or enriches individual contacts. The boundary is set by which fields are retained rather than by what the service is called, so contract at field level rather than by category.
Are there any Pune-specific regulations we need to consider?
No. Everything discussed here is national Indian law. There is no city-level digital marketing or data protection regulation in Pune, and a vendor implying otherwise has invented a requirement. What varies locally is commercial practice rather than regulation.
Sources & References:
- Digital Personal Data Protection Rules, 2025, gazette notification dated 13 November 2025, with staged commencement: Rules 1, 2 and 17 to 21 on notification; Rule 4 after one year; Rules 3, 5 to 16, 22 and 23 after eighteen months, that is on or about 13 May 2027. Cross-border transfer of personal data is governed by Rule 15, operationalising Section 16 of the Digital Personal Data Protection Act 2023, under a negative-list model. No restricted-country list had been notified as at 21 August 2026.
- Ministry of Electronics and Information Technology stakeholder consultation, January 2026, proposing compression of the eighteen-month compliance window to twelve months and earlier application of transfer restrictions. Not confirmed by gazette notification as at 21 August 2026.
- Extraterritorial application: the Digital Personal Data Protection Act 2023 applies to processing of digital personal data outside India where such processing relates to any activity of offering goods or services to data principals within India.
- Penalties: Section 33 of the Digital Personal Data Protection Act 2023 read with the Schedule. Up to ₹250 crore for failure to take reasonable security safeguards resulting in a personal data breach; up to ₹200 crore for failure to notify a breach and for additional obligations concerning children's data; up to ₹150 crore for Significant Data Fiduciary obligations; ₹10,000 for a data principal breach. Assessed per instance. The Board must consider nature, gravity, duration and mitigation. Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal within sixty days.
- Goods and Services Tax on imported services: Central Board of Indirect Taxes and Customs guidance on imports under GST. Where the supplier is outside India, the recipient is in India and the place of supply is in India, the transaction is an import of service and the recipient discharges tax under the reverse charge mechanism at 18 percent IGST. Reverse charge liability must be discharged in cash through the electronic cash ledger and cannot be set off against input tax credit. A self-invoice is required. Registration is mandatory for any person liable to pay tax under reverse charge irrespective of turnover.
- Withholding tax: Section 195 of the Income Tax Act 1961 applies to payments to non-residents. The domestic rate for fees for technical services is 20 percent plus applicable surcharge and cess, and 20 percent applies where the payee has no PAN. Treaty relief requires a Tax Residency Certificate and Form 10F. The applicable India and Indonesia treaty rate is stated inconsistently across published sources reviewed for this article and is deliberately not restated here.
- Equalisation levy: the 6 percent levy on online advertisement services was abolished by the Finance Act 2025, effective 1 April 2025. The 2 percent levy on e-commerce supply of services was abolished effective 1 August 2024. Some published guidance predating these changes remains online and has not been corrected.
- Interim position before DPDP substantive commencement: the earlier rules governing sensitive personal data under the Information Technology Act framework remain relevant until the new regime commences. Noted in the reviewed research as the applicable interim baseline.
- OIDAR carve-out: where a service is classified as an online information and database access or retrieval service supplied to an unregistered recipient, the foreign supplier must obtain non-resident registration and remit tax, rather than the recipient self-assessing under reverse charge. Generally not applicable to business-to-business professional retainers supplied to registered Indian entities.
- Consent Manager registration under Rule 4 of the Digital Personal Data Protection Rules 2025, commencing 13 November 2026. Registration is subject to conditions set out in the framework, including corporate and financial thresholds. Applicable only where an entity operates consent infrastructure.
- No city-level digital marketing or data protection regulation applicable to Pune was identified. All obligations described in this article are national Indian law.
- This article is general orientation as at 21 August 2026 and is not legal or tax advice. Engagements involving Indian personal data or cross-border payments should be reviewed by qualified Indian counsel and an Indian tax adviser before signing.