India Data Law

Who does the DPDP Act apply to?

Verified August 2026

Section 3 applies the Act to digital personal data processed inside India, and to processing outside India where it is connected with offering goods or services to people in India. The obligations fall on the Data Fiduciary, which is whoever decides the purpose and the means of processing. Section 3 itself does not start until 13 May 2027.

s.3(a)Inside India
s.3(b)Outside India
s.3(c)Excluded
s.2(i)Data Fiduciary
s.17Exemptions

Processing inside India

Section 3(a) applies the Act to the processing of digital personal data within India where the personal data is collected in digital form, or is collected in non-digital form and digitised afterwards.

The second limb matters. A paper form scanned into a system falls inside the Act from the moment it is digitised. A paper form that stays in a filing cabinet does not.

Processing outside India

Section 3(b) applies the Act to processing of digital personal data outside India if the processing is in connection with any activity related to offering goods or services to Data Principals within India.

Note what this does not say. There is no separate limb for monitoring the behaviour of people in India. The General Data Protection Regulation of the European Union has one, at Article 3(2)(b). The Indian Act does not. A company outside India that profiles Indian users without offering them goods or services is outside section 3(b) on its wording.

What the Act does not apply to

Section 3(c) excludes two things. The first is personal data processed by an individual for a personal or domestic purpose. The second is personal data that the Data Principal has made publicly available themselves, or that another person is required by a law in force in India to make publicly available.

The Act carries an illustration of the second exclusion. A person who publishes her own personal data on social media while blogging her views takes that data outside the Act.

The test that decides who carries the duty

Section 2(i) (see every defined term) defines a Data Fiduciary as any person who alone or together with others determines the purpose and the means of processing personal data. The test is the decision, not the contact. A Data Fiduciary is whoever decides why personal data is collected and how it is processed. It is a Data Fiduciary whether or not it holds the data itself.

Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. A processor does not decide the purpose. Section 8(2) requires the Data Fiduciary to hold a valid contract with every processor it engages.

The first official statement about Common Service Centres

A written answer in the Lok Sabha on 12 August 2026 states that Village Level Entrepreneurs at Common Service Centres are not authorised to collect or store citizen data. The answer does not say whether they are Data Fiduciaries. India has more than 5.8 lakh Common Service Centres. The operators are not authorised to collect or store Aadhaar records, banking records or health records. On the section 2(i) test, an operator who decides nothing about the purpose or the means is not a Data Fiduciary. The obligations then sit with the government department whose service the centre delivers. That is a reading of the Act and not a statement by the Government.

The reasoning is the section 2(i) test applied to a delivery agent. The operator handles the data and decides nothing about it. The department decides both.

Exemptions in section 17

Section 17 removes parts of the Act in defined cases. Section 17(1) disapplies Chapter II other than section 8(1) and 8(5), Chapter III, and section 16, in six situations. These include enforcing a legal right or claim, processing by a court or a regulator performing its function, processing for the prevention or investigation of an offence, processing of the personal data of people outside India under a contract with a person outside India, processing for an approved merger or similar scheme, and processing to ascertain the assets of a loan defaulter.

Section 17(2) removes the Act entirely in two cases. The first is processing by an instrumentality of the State that the Central Government notifies, in the interests of the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, the maintenance of public order, or preventing incitement to a cognizable offence relating to any of these. The second is processing necessary for research, archiving or statistical purposes, where the data is not used to take a decision about a particular person.

Section 17(3) gives the Central Government power to notify Data Fiduciaries, including startups, to whom section 5, section 8(3), section 8(7), section 10 and section 11 will not apply. The Explanation to section 17(3) defines a startup by reference to recognition by the department that handles startups. No startup has been notified. The exemption is in the Act and no Data Fiduciary can rely on it.

Section 17(5) lets the Central Government, at any time before five years from commencement, declare that a provision does not apply to a Data Fiduciary or a class of them for a stated period.

When any of this starts to bind

Sections 3 to 17 are in the group that comes into force on 13 May 2027. Until then the applicability rules are law that binds nobody, and a Data Fiduciary working out whether it is caught is preparing rather than complying. See the status tracker.

What would change this page

A notification under section 17(2)(a) naming an instrumentality of the State. A notification under section 17(3) exempting a class of startup. A notification under section 17(5). Any further official statement about who is or is not a Data Fiduciary. A judgment interpreting section 3.