DPDP Wiki Talk to us

/The Act · Chapter I · Preliminary

Section 3: Application of Act

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter I: Preliminary
Provision
Section 3 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
None identified
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 3. Application of Act

Verbatim from the Gazette of India

Subject to the provisions of this Act, it shall—

(a)

apply to the processing of digital personal data within the territory of India where the personal data is collected––

(i)

in digital form; or

(ii)

in non-digital form and digitised subsequently;

(b)

also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;

(c)

not apply to—

(i)

personal data processed by an individual for any personal or domestic purpose; and

(ii)

personal data that is made or caused to be made publicly available by—

(A)

the Data Principal to whom such personal data relates; or

(B)

any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalIndividuals

Section 3 sets out when the Digital Personal Data Protection Act applies. It covers the processing of digital personal data within India. This includes personal data that is collected in a digital format right from the start, as well as data collected in a non-digital form and later digitized. (A Data Principal is the individual to whom the personal data relates). The Act also reaches beyond India's borders. It applies to the processing of digital personal data outside of India if that processing is connected to offering goods or services to Data Principals located within India. Finally, the Act specifically excludes certain types of data processing. It does not apply when an individual processes personal data purely for personal or domestic purposes. It also does not apply to personal data that has been made publicly available by the Data Principal themselves. For example, if an individual publicly shares their own personal data on a social media blog, the Act does not apply to that data. The Act also does not apply if a person is required by an Indian law to make the personal data publicly available.

Key points

  • The Act applies to processing digital personal data in India, whether collected digitally or digitized later [(a)].
  • It applies to processing outside India if connected to offering goods or services to Data Principals in India [(b)].
  • The Act does not apply to personal data processed by an individual for personal or domestic purposes [(c)(i)].
  • The Act does not apply to personal data made publicly available by the Data Principal themselves [(c)(ii)(A)].
  • The Act does not apply to personal data made publicly available by someone legally obligated under Indian law to do so [(c)(ii)(B)].

Common misreadings

  • One might assume the Act applies to all paper records, but it only applies to non-digital data if it is subsequently digitized.
  • One might think the Act protects data that a Data Principal voluntarily publishes on a public blog, but the Act explicitly excludes data made publicly available by the Data Principal.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.