Does the DPDP Act apply to my business?
This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.
Section 3 of the Digital Personal Data Protection Act, 2023 decides who the Act covers. It has no turnover test, no headcount test and no list of sectors. Coverage turns on what you do with personal data and where. Two questions settle it for most businesses, and three exclusions take some data back out.
Four terms you need first
Personal data is any data about an individual who is identifiable by or in relation to that data (Section 2(t)). A name, a phone number, an order history tied to a customer ID: all personal data.
Processing is any wholly or partly automated operation on digital personal data, including collection, storage, use, sharing and erasure (Section 2(x)). Storing a customer list in software or a spreadsheet is processing.
Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing (Section 2(i)). “Person” includes an individual, a Hindu undivided family, a company, a firm, an association of persons and the State (Section 2(s)).
Data Principal is the individual the data is about (Section 2(j)). For a child, that includes the parents or lawful guardian.
Question 1: Do you process personal data in digital form?
Section 3(a) applies the Act to digital personal data collected in either of two ways:
collected in digital form, such as a web form, an app, an email or a payment page; or
collected on paper and digitised later, such as a paper application typed into a spreadsheet or scanned into a document system.
Personal data that stays on paper and is never digitised sits outside this test. Payroll files, customer records and delivery addresses kept in software or a spreadsheet are digital.
Question 2: Is the processing in India, or aimed at people in India?
If you process that data within India, Section 3(a) covers it. If the processing happens outside India, Section 3(b) still covers it when it is “in connection with any activity related to offering of goods or services to Data Principals within the territory of India”.
So a business based abroad that sells to customers in India is covered for that processing. Hosting data abroad does not by itself take processing out of the Act: Section 3(b) reaches offshore processing connected with offering goods or services to people in India. For other offshore processing, such as staff records hosted abroad, the text does not say expressly how it applies, so take advice on that data.
If you answered yes to both questions, the Act will apply to that processing unless an exclusion or exemption below fits.
The three exclusions in Section 3(c)
Personal or domestic purposes. Data an individual processes for a personal or domestic purpose is outside the Act (Section 3(c)(i)). A shopkeeper’s customer list is business use, not domestic use.
Data the person made public. Personal data that the Data Principal herself made publicly available is outside the Act (Section 3(c)(ii)(A)). The Act’s own illustration is an individual who shares her views and personal data publicly on social media while blogging.
Data published under a legal obligation. Personal data that another person is required by Indian law to make public is also outside the Act (Section 3(c)(ii)(B)).
The public-data exclusion is narrow. It covers data made public by the person or under a legal duty. Data that is visible online because it leaked, or because a third party with no legal duty to publish it posted it, does not fit either limb.
Exemptions that are narrower than they look
Section 17(1) lists situations in which most of the Act’s duties do not apply: Chapter II (the Data Fiduciary’s obligations), Chapter III (rights and duties of Data Principals) and Section 16 (transfers abroad). Two of the listed situations are:
processing necessary to enforce a legal right or claim (Section 17(1)(a)); and
processing, by a person based in India, of the personal data of people not within India, under a contract with a person outside India (Section 17(1)(d)).
Separately, Section 17(2)(b) takes processing necessary for research, archiving or statistical purposes outside the Act, if the data is not used for decisions about a specific person and the processing follows prescribed standards. Rule 16 points to the standards in the Second Schedule.
In the Section 17(1) situations, two duties still apply: overall responsibility for compliance under Section 8(1), and reasonable security safeguards under Section 8(5).
Section 17(3) lets the Central Government notify certain Data Fiduciaries, or classes of them, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply. This is a power to notify. Before you rely on it, check the Gazette for a notification that names your class.
When coverage starts
Section 3 is itself one of the provisions that come into force eighteen months after the commencement notification, G.S.R. 843(E), was published on 13 November 2025. That date is 13 May 2027. The same clause brings in the duties on Data Fiduciaries in Sections 4 to 10 (except Section 6(9)) and the rights in Sections 11 to 14.
So the useful question today is whether you will be covered from 13 May 2027 and what you need in place by then.
Covered? Two follow-up questions
Are you a Data Fiduciary or a Data Processor for this data? If you decide why and how the data is processed, you are the Data Fiduciary. If you process it on someone else’s behalf, you are their Data Processor (Section 2(k)), and they stay responsible for your work under Section 8(1). Many businesses are both, for different data sets.
Could you be a Significant Data Fiduciary? You cannot designate yourself one. The Central Government notifies Significant Data Fiduciaries after assessing factors listed in Section 10(1), including the volume and sensitivity of personal data processed and the risk to Data Principals’ rights. A notified Significant Data Fiduciary has extra duties under Section 10(2), such as appointing a Data Protection Officer based in India.
A first pass through your data
List every place your business collects personal data: website, app, store counter, HR, vendors.
For each, note whether it is digital or digitised, and where it is processed.
Mark anything that clearly fits a Section 3(c) exclusion, and write down why.
Flag anything you think falls under Section 17, and have counsel confirm it.
For everything else, assume the Act applies from 13 May 2027 and start mapping the duties.
Sources
Every section, rule and date above was checked against the official text on 4 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Section 2(i): Data Fiduciary
Section 2(j): Data Principal
Section 2(k): Data Processor
Section 2(s): "Person"
Section 2(t): Personal data
Section 2(x): Processing
Section 3(a): Digital or digitised data processed within India
Section 3(b): Processing outside India linked to offering goods or services in India
Section 3(c): Exclusions: personal or domestic use; data made public by the person or under a legal obligation
Sections 4 to 14: Duties on Data Fiduciaries, Sections 4 to 10 (except 6(9)), and rights, Sections 11 to 14
Section 8(1): Overall responsibility, still applies under Section 17(1)
Section 8(5): Security safeguards, still applies under Section 17(1)
Section 10(1): Significant Data Fiduciary notified by the Central Government
Section 10(2): Additional duties, including a Data Protection Officer based in India
Section 16: Transfers outside India; disapplied in the Section 17(1) situations
Section 17(1): Exemptions, including clauses (a) and (d)
Section 17(2)(b): Research, archiving or statistical purposes, under prescribed standards
Section 17(3): Power to notify Data Fiduciaries, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
Rule 16: Research, archiving or statistical purposes: standards in the Second Schedule
Notifications
G.S.R. 843(E), clause (c): Section 3 and Sections 4 to 17 in force eighteen months from 13 November 2025
Check coverage in plain language, then see which duties you already meet
How-to 01 starts with a plain-language "does this apply?" guide, then a Reality Check workbook rates the six Section 10(1) factors and walks you through 20 duties, each with its section or rule.
The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.
Drafting aid, not legal advice.




Comments