IT and SaaS is the friendliest sector India offers a foreign entrant – 100% FDI, automatic route, no licence to operate. But “no licence” no longer means “no rulebook”: the DPDP data-protection regime now has hard deadlines (full compliance by May 2027, penalties to ₹250 crore), payment-touching SaaS carries RBI localisation, and the export machinery (SoftEx, LUT, transfer pricing) starts with invoice one. Here is the 2026 compliance map for an IT/SaaS company or GCC entering India.
The entry position
| Item | Position |
|---|---|
| FDI | 100% automatic – no sectoral conditions; only the land-border screening overlay applies to specific investors |
| Entity | Private limited WOS is the standard; DTA premises the default (see STPI vs SEZ vs DTA) |
| Operating licence | None for software/SaaS. Voice BPO operations touching the phone network keep light OSP conditions; data OSPs were fully deregulated in 2020-21 – no registration, no bank guarantees, work-from-anywhere permitted |
| Export machinery | Non-STP registration + SoftEx (EDF from Oct 2026), GST LUT, cost-plus TP for captives |
DPDP – the compliance programme every SaaS company now needs
- Applies extraterritorially – processing outside India connected to offering goods/services to persons in India is covered, so the parent’s platform is in scope, not just the Indian entity;
- Consent architecture: itemised notice, verifiable consent, withdrawal as easy as giving it;
- Breach reporting: intimation to affected users + a detailed report to the Data Protection Board within 72 hours;
- Cross-border transfers: a negative-list model – free flow except to countries the government blacklists (none notified yet). Far lighter than GDPR adequacy – a genuine selling point for India GCC data work;
- Significant Data Fiduciaries (to be notified by government): annual DPIA + audit, India-based DPO, algorithmic due diligence – and a hook for future localisation of specified data categories;
- Penalties: up to ₹250 crore for security-safeguard failures, ₹200 crore for breach-notification failures.
The rest of the 2026 rulebook
| Layer | What it demands |
|---|---|
| Intermediary rules (platforms/UGC) | IT Rules 2021 duties; significant platforms at 50 lakh users; February 2026 amendments added AI-content labelling and ~3-hour takedowns for flagged deepfakes |
| Employment | Shops & Establishment, PF/ESI at thresholds, POSH committee at 10+ staff, professional tax – the standard calendar |
| Tax posture | ~25% corporate tax on the cost-plus margin; 15.5% safe harbour or APA for certainty; zero-rated exports under LUT |
| Incentive layer | No income-tax holiday (STPI ended 2011); the play is state GCC policies (Karnataka, Gujarat, UP, Telangana) + DPIIT benefits where the entity qualifies as a startup |
The setup sequence for an IT/SaaS entrant
- 1. Incorporate the WOS and run the first-90-days sequence (capital → FC-GPR → INC-20A → GST/LUT → STPI);
- 2. Sign the intercompany agreement and TP policy before the first invoice;
- 3. Start the DPDP readiness programme (data mapping, consent flows, DPO decision) against the May 2027 deadline;
- 4. If the product touches payments – read the fintech licence map before writing a line of integration code.
Standing up an IT subsidiary or GCC?
We run the incorporation, FEMA, export machinery and the DPDP readiness plan as one programme – with the TP posture decided up front.
Talk to My Cloud AccountantFrequently asked questions
Does a foreign SaaS company need any licence to operate in India?
No operating licence – software and SaaS are unlicensed activities with 100% automatic FDI. The obligations are horizontal: company law, GST, FEMA reporting, DPDP data protection, and OSP conditions only for voice operations using the phone network.
When does DPDP compliance become mandatory?
The substantive obligations take effect around May 2027 (18 months from the November 2025 Rules), with consent-manager registration from November 2026. Penalties run up to ₹250 crore, so 2026 is the year to build the consent and breach-response architecture.
Does India require data localisation for SaaS?
Not generally – DPDP uses a negative-list model for cross-border transfers with no countries blacklisted yet. Localisation applies in sectors: payment-system data (RBI, India-only storage), insurance and telecom – and future government notifications could localise specified categories for Significant Data Fiduciaries.
Can our India team work fully remote?
Yes – the 2020-21 OSP deregulation removed location conditions for data services (work-from-anywhere is expressly permitted), and DTA entities have no premises conditions. Only SEZ units need the Rule 43A hybrid-work permission (extended to end-2027).
Based on the Consolidated FDI Policy, the DPDP Act 2023 and DPDP Rules 2025 (November 2025), DoT OSP Guidelines 2020-21 and the IT Rules 2021 as amended February 2026. Last reviewed: July 2026.
