IT & SaaS Company in India: Compliance Map for Foreign Founders

IT and SaaS is the friendliest sector India offers a foreign entrant – 100% FDI, automatic route, no licence to operate. But “no licence” no longer means “no rulebook”: the DPDP data-protection regime now has hard deadlines (full compliance by May 2027, penalties to ₹250 crore), payment-touching SaaS carries RBI localisation, and the export machinery (SoftEx, LUT, transfer pricing) starts with invoice one. Here is the 2026 compliance map for an IT/SaaS company or GCC entering India.

The entry position

ItemPosition
FDI100% automatic – no sectoral conditions; only the land-border screening overlay applies to specific investors
EntityPrivate limited WOS is the standard; DTA premises the default (see STPI vs SEZ vs DTA)
Operating licenceNone for software/SaaS. Voice BPO operations touching the phone network keep light OSP conditions; data OSPs were fully deregulated in 2020-21 – no registration, no bank guarantees, work-from-anywhere permitted
Export machineryNon-STP registration + SoftEx (EDF from Oct 2026), GST LUT, cost-plus TP for captives

DPDP – the compliance programme every SaaS company now needs

The clock: the DPDP Rules 2025 were notified in November 2025 with phased commencement – consent-manager registration opens from November 2026, and the substantive obligations (notice, consent, security, breach reporting, retention) take effect May 2027. 2026 is the build year.
  • Applies extraterritorially – processing outside India connected to offering goods/services to persons in India is covered, so the parent’s platform is in scope, not just the Indian entity;
  • Consent architecture: itemised notice, verifiable consent, withdrawal as easy as giving it;
  • Breach reporting: intimation to affected users + a detailed report to the Data Protection Board within 72 hours;
  • Cross-border transfers: a negative-list model – free flow except to countries the government blacklists (none notified yet). Far lighter than GDPR adequacy – a genuine selling point for India GCC data work;
  • Significant Data Fiduciaries (to be notified by government): annual DPIA + audit, India-based DPO, algorithmic due diligence – and a hook for future localisation of specified data categories;
  • Penalties: up to ₹250 crore for security-safeguard failures, ₹200 crore for breach-notification failures.
Sectoral overlays that already localise: RBI’s April 2018 payments circular (payment-system data stored only in India – bites any SaaS touching payment flows), insurance records, telecom licence conditions and government-cloud empanelment. Pure B2B SaaS with no payment leg currently faces no localisation.

The rest of the 2026 rulebook

LayerWhat it demands
Intermediary rules (platforms/UGC)IT Rules 2021 duties; significant platforms at 50 lakh users; February 2026 amendments added AI-content labelling and ~3-hour takedowns for flagged deepfakes
EmploymentShops & Establishment, PF/ESI at thresholds, POSH committee at 10+ staff, professional tax – the standard calendar
Tax posture~25% corporate tax on the cost-plus margin; 15.5% safe harbour or APA for certainty; zero-rated exports under LUT
Incentive layerNo income-tax holiday (STPI ended 2011); the play is state GCC policies (Karnataka, Gujarat, UP, Telangana) + DPIIT benefits where the entity qualifies as a startup

The setup sequence for an IT/SaaS entrant

  • 1. Incorporate the WOS and run the first-90-days sequence (capital → FC-GPR → INC-20A → GST/LUT → STPI);
  • 2. Sign the intercompany agreement and TP policy before the first invoice;
  • 3. Start the DPDP readiness programme (data mapping, consent flows, DPO decision) against the May 2027 deadline;
  • 4. If the product touches payments – read the fintech licence map before writing a line of integration code.

Standing up an IT subsidiary or GCC?

We run the incorporation, FEMA, export machinery and the DPDP readiness plan as one programme – with the TP posture decided up front.

Talk to My Cloud Accountant

Frequently asked questions

Does a foreign SaaS company need any licence to operate in India?

No operating licence – software and SaaS are unlicensed activities with 100% automatic FDI. The obligations are horizontal: company law, GST, FEMA reporting, DPDP data protection, and OSP conditions only for voice operations using the phone network.

When does DPDP compliance become mandatory?

The substantive obligations take effect around May 2027 (18 months from the November 2025 Rules), with consent-manager registration from November 2026. Penalties run up to ₹250 crore, so 2026 is the year to build the consent and breach-response architecture.

Does India require data localisation for SaaS?

Not generally – DPDP uses a negative-list model for cross-border transfers with no countries blacklisted yet. Localisation applies in sectors: payment-system data (RBI, India-only storage), insurance and telecom – and future government notifications could localise specified categories for Significant Data Fiduciaries.

Can our India team work fully remote?

Yes – the 2020-21 OSP deregulation removed location conditions for data services (work-from-anywhere is expressly permitted), and DTA entities have no premises conditions. Only SEZ units need the Rule 43A hybrid-work permission (extended to end-2027).

Your next step: the vehicle – foreign subsidiary guide · the export plumbing – SoftEx guide · the tax engine – 15.5% safe harbour

Based on the Consolidated FDI Policy, the DPDP Act 2023 and DPDP Rules 2025 (November 2025), DoT OSP Guidelines 2020-21 and the IT Rules 2021 as amended February 2026. Last reviewed: July 2026.

Disclaimer: educational guide, not legal advice. DPDP phase dates and SDF notifications are evolving – verify current notifications before building compliance programmes.
Scroll to Top