Step 3 of 4 in the reading path · Previous: What are the DPDP Rules
Who does the DPDP Act apply to?
Verified August 2026
If your business handles the personal data of people in India in digital form, the Act almost certainly applies to you. It covers businesses of every size, inside and outside India. The duties fall on whoever decides why the data is collected and how it is used. The section that sets this scope starts on 13 May 2027.
The Act applies if you…
- Process personal data in digital form inside India
- Collect data on paper and digitise it later
- Operate outside India and offer goods or services to people in India
- Are a business of any size. There is no revenue or headcount threshold
- Handle customer, employee or vendor data and decide why and how it is used
It does not apply to…
- Data an individual processes for a personal or domestic purpose
- Data the person has made publicly available themselves, or that a law requires to be made public
- Records that stay on paper and are never digitised
- Processing only on another company's instructions, as a Data Processor. The duties then sit with the company that instructs you
The rest of this page walks through the same test in the words of the Act, provision by provision.
Processing inside India
Section 3(a) applies the Act to the processing of digital personal data within India where the personal data is collected in digital form, or is collected in non-digital form and digitised afterwards.
In practice this means a paper form scanned into a computer is covered by the Act from the moment it is digitised, while a paper form that stays in a filing cabinet is not.
Processing outside India
Section 3(b) applies the Act to processing of digital personal data outside India if the processing is in connection with any activity related to offering goods or services to Data Principals within India.
Unlike the European GDPR, which separately covers monitoring the behaviour of people in the EU at Article 3(2)(b), the Indian Act has no monitoring limb. A company outside India that profiles Indian users without offering them goods or services is outside section 3(b) on its wording.
What the Act does not apply to
Section 3(c) excludes two things. The first is personal data processed by an individual for a personal or domestic purpose. The second is personal data that the Data Principal has made publicly available themselves, or that another person is required by a law in force in India to make publicly available.
The Act carries an illustration of the second exclusion. A person who publishes her own personal data on social media while blogging her views takes that data outside the Act.
The test that decides who carries the duty
Section 2(i) (see every defined term) defines a Data Fiduciary as any person who alone or together with others determines the purpose and the means of processing personal data. In other words, the Data Fiduciary is whoever decides why personal data is collected and how it is processed, whether or not it holds the data itself.
Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. A processor does not decide the purpose. Section 8(2) requires the Data Fiduciary to hold a valid contract with every processor it engages.
The first official statement about Common Service Centres
A written answer in the Lok Sabha on 12 August 2026 states that Village Level Entrepreneurs at Common Service Centres, of which India has more than 5.8 lakh, are not authorised to collect or store citizen data, including Aadhaar, banking and health records. The answer does not say whether they are Data Fiduciaries. On the section 2(i) test, an operator who decides nothing about the purpose or the means of processing is not a Data Fiduciary, and the obligations sit with the government department whose service the centre delivers. That is a reading of the Act, not a statement by the Government.
Exemptions in section 17
Section 17 removes parts of the Act in defined cases. Section 17(1) disapplies Chapter II other than section 8(1) and 8(5), Chapter III, and section 16, in six situations. These include enforcing a legal right or claim, processing by a court or a regulator performing its function, processing for the prevention or investigation of an offence, processing of the personal data of people outside India under a contract with a person outside India, processing for an approved merger or similar scheme, and processing to ascertain the assets of a loan defaulter.
Section 17(2) removes the Act entirely in two cases. The first is processing by an instrumentality of the State that the Central Government notifies, in the interests of the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, the maintenance of public order, or preventing incitement to a cognizable offence relating to any of these. The second is processing necessary for research, archiving or statistical purposes, where the data is not used to take a decision about a particular person.
Section 17(3) gives the Central Government power to notify Data Fiduciaries, including startups, to whom section 5, section 8(3), section 8(7), section 10 and section 11 will not apply. The Explanation to section 17(3) defines a startup by reference to recognition by the department that handles startups. No startup has been notified. The exemption is in the Act and no Data Fiduciary can rely on it.
Section 17(5) lets the Central Government, at any time before five years from commencement, declare that a provision does not apply to a Data Fiduciary or a class of them for a stated period.
When any of this starts to bind
Sections 3 to 17 are in the group that comes into force on 13 May 2027. Until then the applicability rules are law that binds nobody, and a Data Fiduciary working out whether it is caught is preparing rather than complying. See the status tracker.
A notification under section 17(2)(a) naming an instrumentality of the State. A notification under section 17(3) exempting a class of startup. A notification under section 17(5). Any further official statement about who is or is not a Data Fiduciary. A judgment interpreting section 3.
Next in the reading path: What are the deadlines →