Scope

DPDP Act: does it apply to you? There is no size cutoff

A woman holding a tablet on a small factory floor, workers at sewing machines behind her.

Yes, if your business handles digital personal data in India, or handles it abroad while offering goods or services to people in India. The Act sets no turnover or headcount test, so small businesses are covered too. Personal use and data a person made public are excluded. Coverage starts on 13 May 2027.

Last checked against the official text: Updated 6 min read

On this page
  1. Four terms you need first
  2. Question 1: Do you process personal data in digital form?
  3. Question 2: Is the processing in India, or aimed at people in India?
  4. The three exclusions in Section 3(c)
  5. Exemptions that are narrower than they look
  6. When coverage starts
  7. Covered? Two follow-up questions
  8. A first pass through your data
  9. Common questions
  10. In the news
  11. Sources

Section 3 of the Digital Personal Data Protection Act, 2023 decides who the Act covers. It has no turnover test, no headcount test and no list of sectors. Coverage turns on what you do with personal data and where. Two questions settle it for most businesses, and three exclusions take some data back out.

Four terms you need first

  • Personal data is any data about an individual who is identifiable by or in relation to that data (Section 2(t)). A name, a phone number, an order history tied to a customer ID: all personal data.
  • Processing is any wholly or partly automated operation on digital personal data, including collection, storage, use, sharing and erasure (Section 2(x)). Storing a customer list in software or a spreadsheet is processing.
  • Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing (Section 2(i)). “Person” includes an individual, a Hindu undivided family, a company, a firm, an association of persons and the State (Section 2(s)).
  • Data Principal is the individual the data is about (Section 2(j)). For a child, that includes the parents or lawful guardian.

Question 1: Do you process personal data in digital form?

Section 3(a) applies the Act to digital personal data collected in either of two ways:

  • collected in digital form, such as a web form, an app, an email or a payment page; or
  • collected on paper and digitised later, such as a paper application typed into a spreadsheet or scanned into a document system.

Personal data that stays on paper and is never digitised sits outside this test. Payroll files, customer records and delivery addresses kept in software or a spreadsheet are digital.

Question 2: Is the processing in India, or aimed at people in India?

If you process that data within India, Section 3(a) covers it. If the processing happens outside India, Section 3(b) still covers it when it is “in connection with any activity related to offering of goods or services to Data Principals within the territory of India”.

A woman working on a laptop beside open books and papers.

So a business based abroad that sells to customers in India is covered for that processing. Hosting data abroad does not by itself take processing out of the Act: Section 3(b) reaches offshore processing connected with offering goods or services to people in India. For other offshore processing, such as staff records hosted abroad, the text does not say expressly how it applies, so take advice on that data.

If you answered yes to both questions, the Act will apply to that processing unless an exclusion or exemption below fits.

The three exclusions in Section 3(c)

  1. Personal or domestic purposes. Data an individual processes for a personal or domestic purpose is outside the Act (Section 3(c)(i)). A shopkeeper’s customer list is business use, not domestic use.
  2. Data the person made public. Personal data that the Data Principal herself made publicly available is outside the Act (Section 3(c)(ii)(A)). The Act’s own illustration is an individual who shares her views and personal data publicly on social media while blogging.
  3. Data published under a legal obligation. Personal data that another person is required by Indian law to make public is also outside the Act (Section 3(c)(ii)(B)).

The public-data exclusion is narrow. It covers data made public by the person or under a legal duty. Data that is visible online because it leaked, or because a third party with no legal duty to publish it posted it, does not fit either limb.

Exemptions that are narrower than they look

Section 17(1) lists situations in which most of the Act’s duties do not apply: Chapter II (the Data Fiduciary’s obligations), Chapter III (rights and duties of Data Principals) and Section 16 (transfers abroad). Two of the listed situations are:

  • processing necessary to enforce a legal right or claim (Section 17(1)(a)); and
  • processing, by a person based in India, of the personal data of people not within India, under a contract with a person outside India (Section 17(1)(d)).

Separately, Section 17(2)(b) takes processing necessary for research, archiving or statistical purposes outside the Act, if the data is not used for decisions about a specific person and the processing follows prescribed standards. Rule 16 points to the standards in the Second Schedule.

In the Section 17(1) situations, two duties still apply: overall responsibility for compliance under Section 8(1), and reasonable security safeguards under Section 8(5).

Section 17(3) lets the Central Government notify certain Data Fiduciaries, or classes of them, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply. This is a power to notify. Before you rely on it, check the Gazette for a notification that names your class.

When coverage starts

Section 3 is itself one of the provisions that come into force eighteen months after the commencement notification, G.S.R. 843(E), was published on 13 November 2025. That date is 13 May 2027. The same clause brings in the duties on Data Fiduciaries in Sections 4 to 10 (except Section 6(9)) and the rights in Sections 11 to 14.

So the useful question today is whether you will be covered from 13 May 2027 and what you need in place by then.

Covered? Two follow-up questions

Are you a Data Fiduciary or a Data Processor for this data? If you decide why and how the data is processed, you are the Data Fiduciary. If you process it on someone else’s behalf, you are their Data Processor (Section 2(k)), and they stay responsible for your work under Section 8(1). Many businesses are both, for different data sets.

Could you be a Significant Data Fiduciary? You cannot designate yourself one. The Central Government notifies Significant Data Fiduciaries after assessing factors listed in Section 10(1), including the volume and sensitivity of personal data processed and the risk to Data Principals’ rights. A notified Significant Data Fiduciary has extra duties under Section 10(2), such as appointing a Data Protection Officer based in India.

A first pass through your data

  1. List every place your business collects personal data: website, app, store counter, HR, vendors.
  2. For each, note whether it is digital or digitised, and where it is processed.
  3. Mark anything that clearly fits a Section 3(c) exclusion, and write down why.
  4. Flag anything you think falls under Section 17, and have counsel confirm it.
  5. For everything else, assume the Act applies from 13 May 2027 and start mapping the duties.

Two situations come up often. See the DPDP Act for clinics and hospitals and the DPDP Act for small businesses that collect customer or lead data.

Common questions

Does the DPDP Act apply to small businesses and startups?

The Act sets no turnover or headcount test for coverage. The Central Government may notify certain Data Fiduciaries, including startups, based on the volume and nature of the personal data they handle, so that some duties do not apply to them. Those duties are notice, accuracy of data, erasure, the extra duties of Significant Data Fiduciaries and the right of access. Check the Gazette before assuming you are exempt.

Does the Act apply to a business based outside India?

Yes, when it processes digital personal data outside India in connection with offering goods or services to people in India.

Does the Act cover paper records?

It covers digital personal data. That includes data collected on paper and digitised afterwards.

Is personal data I use at home covered?

No. Personal data an individual processes for a personal or domestic purpose is excluded. So is personal data that the person made public, or that a law in India requires someone to make public.

When does the Act start to apply to my business?

The coverage rule and most duties on businesses start on 13 May 2027, counted as eighteen months from the notification published on 13 November 2025.

Next steps

In the news

Sources

Every section, rule and date above was checked against the official text on 5 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(i)Data Fiduciary
  • Section 2(j)Data Principal
  • Section 2(k)Data Processor
  • Section 2(s)"Person"
  • Section 2(t)Personal data
  • Section 2(x)Processing
  • Section 3(a)Digital or digitised data processed within India
  • Section 3(b)Processing outside India linked to offering goods or services in India
  • Section 3(c)Exclusions: personal or domestic use; data made public by the person or under a legal obligation
  • Sections 4 to 14Duties on Data Fiduciaries, Sections 4 to 10 (except 6(9)), and rights, Sections 11 to 14
  • Section 8(1)Overall responsibility, still applies under Section 17(1)
  • Section 8(5)Security safeguards, still applies under Section 17(1)
  • Section 10(1)Significant Data Fiduciary notified by the Central Government
  • Section 10(2)Additional duties, including a Data Protection Officer based in India
  • Section 16Transfers outside India; disapplied in the Section 17(1) situations
  • Section 17(1)Exemptions, including clauses (a) and (d)
  • Section 17(2)(b)Research, archiving or statistical purposes, under prescribed standards
  • Section 17(3)Power to notify Data Fiduciaries, including startups, to whom Section 5, Sections 8(3) and 8(7), Section 10 and Section 11 will not apply

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 16Research, archiving or statistical purposes: standards in the Second Schedule

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Section 3 and Sections 4 to 17 in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.