top of page

Does the DPDP Act apply to my business?

6 days ago
6 min read

This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.

Section 3 of the Digital Personal Data Protection Act, 2023 decides who the Act covers. It has no turnover test, no headcount test and no list of sectors. Coverage turns on what you do with personal data and where. Two questions settle it for most businesses, and three exclusions take some data back out.

Four terms you need first

  • Personal data is any data about an individual who is identifiable by or in relation to that data (Section 2(t)). A name, a phone number, an order history tied to a customer ID: all personal data.

  • Processing is any wholly or partly automated operation on digital personal data, including collection, storage, use, sharing and erasure (Section 2(x)). Storing a customer list in software or a spreadsheet is processing.

  • Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing (Section 2(i)). “Person” includes an individual, a Hindu undivided family, a company, a firm, an association of persons and the State (Section 2(s)).

  • Data Principal is the individual the data is about (Section 2(j)). For a child, that includes the parents or lawful guardian.

Question 1: Do you process personal data in digital form?

Section 3(a) applies the Act to digital personal data collected in either of two ways:

  • collected in digital form, such as a web form, an app, an email or a payment page; or

  • collected on paper and digitised later, such as a paper application typed into a spreadsheet or scanned into a document system.

Personal data that stays on paper and is never digitised sits outside this test. Payroll files, customer records and delivery addresses kept in software or a spreadsheet are digital.

Question 2: Is the processing in India, or aimed at people in India?

If you process that data within India, Section 3(a) covers it. If the processing happens outside India, Section 3(b) still covers it when it is “in connection with any activity related to offering of goods or services to Data Principals within the territory of India”.

So a business based abroad that sells to customers in India is covered for that processing. Hosting data abroad does not by itself take processing out of the Act: Section 3(b) reaches offshore processing connected with offering goods or services to people in India. For other offshore processing, such as staff records hosted abroad, the text does not say expressly how it applies, so take advice on that data.

If you answered yes to both questions, the Act will apply to that processing unless an exclusion or exemption below fits.

The three exclusions in Section 3(c)

  1. Personal or domestic purposes. Data an individual processes for a personal or domestic purpose is outside the Act (Section 3(c)(i)). A shopkeeper’s customer list is business use, not domestic use.

  2. Data the person made public. Personal data that the Data Principal herself made publicly available is outside the Act (Section 3(c)(ii)(A)). The Act’s own illustration is an individual who shares her views and personal data publicly on social media while blogging.

  3. Data published under a legal obligation. Personal data that another person is required by Indian law to make public is also outside the Act (Section 3(c)(ii)(B)).

The public-data exclusion is narrow. It covers data made public by the person or under a legal duty. Data that is visible online because it leaked, or because a third party with no legal duty to publish it posted it, does not fit either limb.

Exemptions that are narrower than they look

Section 17(1) lists situations in which most of the Act’s duties do not apply: Chapter II (the Data Fiduciary’s obligations), Chapter III (rights and duties of Data Principals) and Section 16 (transfers abroad). Two of the listed situations are:

  • processing necessary to enforce a legal right or claim (Section 17(1)(a)); and

  • processing, by a person based in India, of the personal data of people not within India, under a contract with a person outside India (Section 17(1)(d)).

Separately, Section 17(2)(b) takes processing necessary for research, archiving or statistical purposes outside the Act, if the data is not used for decisions about a specific person and the processing follows prescribed standards. Rule 16 points to the standards in the Second Schedule.

In the Section 17(1) situations, two duties still apply: overall responsibility for compliance under Section 8(1), and reasonable security safeguards under Section 8(5).

Section 17(3) lets the Central Government notify certain Data Fiduciaries, or classes of them, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply. This is a power to notify. Before you rely on it, check the Gazette for a notification that names your class.

When coverage starts

Section 3 is itself one of the provisions that come into force eighteen months after the commencement notification, G.S.R. 843(E), was published on 13 November 2025. That date is 13 May 2027. The same clause brings in the duties on Data Fiduciaries in Sections 4 to 10 (except Section 6(9)) and the rights in Sections 11 to 14.

So the useful question today is whether you will be covered from 13 May 2027 and what you need in place by then.

Covered? Two follow-up questions

Are you a Data Fiduciary or a Data Processor for this data? If you decide why and how the data is processed, you are the Data Fiduciary. If you process it on someone else’s behalf, you are their Data Processor (Section 2(k)), and they stay responsible for your work under Section 8(1). Many businesses are both, for different data sets.

Could you be a Significant Data Fiduciary? You cannot designate yourself one. The Central Government notifies Significant Data Fiduciaries after assessing factors listed in Section 10(1), including the volume and sensitivity of personal data processed and the risk to Data Principals’ rights. A notified Significant Data Fiduciary has extra duties under Section 10(2), such as appointing a Data Protection Officer based in India.

A first pass through your data

  1. List every place your business collects personal data: website, app, store counter, HR, vendors.

  2. For each, note whether it is digital or digitised, and where it is processed.

  3. Mark anything that clearly fits a Section 3(c) exclusion, and write down why.

  4. Flag anything you think falls under Section 17, and have counsel confirm it.

  5. For everything else, assume the Act applies from 13 May 2027 and start mapping the duties.

Sources

Every section, rule and date above was checked against the official text on 4 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

  • Section 2(i): Data Fiduciary

  • Section 2(j): Data Principal

  • Section 2(k): Data Processor

  • Section 2(s): "Person"

  • Section 2(t): Personal data

  • Section 2(x): Processing

  • Section 3(a): Digital or digitised data processed within India

  • Section 3(b): Processing outside India linked to offering goods or services in India

  • Section 3(c): Exclusions: personal or domestic use; data made public by the person or under a legal obligation

  • Sections 4 to 14: Duties on Data Fiduciaries, Sections 4 to 10 (except 6(9)), and rights, Sections 11 to 14

  • Section 8(1): Overall responsibility, still applies under Section 17(1)

  • Section 8(5): Security safeguards, still applies under Section 17(1)

  • Section 10(1): Significant Data Fiduciary notified by the Central Government

  • Section 10(2): Additional duties, including a Data Protection Officer based in India

  • Section 16: Transfers outside India; disapplied in the Section 17(1) situations

  • Section 17(1): Exemptions, including clauses (a) and (d)

  • Section 17(2)(b): Research, archiving or statistical purposes, under prescribed standards

  • Section 17(3): Power to notify Data Fiduciaries, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 16: Research, archiving or statistical purposes: standards in the Second Schedule

Notifications

  • G.S.R. 843(E), clause (c): Section 3 and Sections 4 to 17 in force eighteen months from 13 November 2025

Check coverage in plain language, then see which duties you already meet

How-to 01 starts with a plain-language "does this apply?" guide, then a Reality Check workbook rates the six Section 10(1) factors and walks you through 20 duties, each with its section or rule.

The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.

Drafting aid, not legal advice.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Cyber Security Services

           CynorSense Solution Pvt. Ltd. is your dedicated partner in the ever-evolving domain of cybersecurity. We are committed to delivering cutting-edge cybersecurity solutions, tailored to meet the unique needs of each client. Our comprehensive suite of services includes DPDPA, Penetration Testing, SOC & SIEM Services, Incident Response, and Cyber Security Consultation.

​

Our expertise extends across Secure Code Review, Vulnerability Assessment and Penetration Testing (VAPT) Services, Security Audits, Risk and Threat Assessment, and Vulnerability Scanning. In addition, we offer services in Malware Analysis, Phishing Simulation, Social Engineering Testing, Web Application Testing, Mobile Application Testing, Network Security Testing, Infrastructure Security Testing, Application Security Testing, and Data Security Testing. 

​

We understand the importance of compliance in today's regulatory environment. Our Compliance Testing services are designed to help your organization navigate the complex landscape of regulations such as DPDPA, ISO 27001, PCI DSS, HIPAA, SOX, GLBA, NERC CIP, FISMA, and the NIST Cybersecurity Framework. 

​

At CynorSense, we blend innovative technology with a robust understanding of the cybersecurity landscape to provide you with the tools and knowledge needed to safeguard your digital assets. Let us be your trusted guide in the realm of cybersecurity, providing the assurance you need in an increasingly interconnected world.

ISO 27001 and ISO 9001 certified company

TELEPHONE:

 +91 80 62 181 669

 ADDRESS: 

 Cynor Sense Solutions Pvt. Ltd.

 Vijay Krishna Towers,   Nanakramguda, Hyderabad,

 Telangana, India - 500032

© 2026 CynorSense Solutions Pvt. Ltd. All rights reserved.

bottom of page