/The Act · Chapter I · Preliminary
Section 3: Application of Act
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 3 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
Subject to the provisions of this Act, it shall—
apply to the processing of digital personal data within the territory of India where the personal data is collected––
also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;
Section 3 sets out when the Digital Personal Data Protection Act applies. It covers the processing of digital personal data within India. This includes personal data that is collected in a digital format right from the start, as well as data collected in a non-digital form and later digitized. (A Data Principal is the individual to whom the personal data relates). The Act also reaches beyond India's borders. It applies to the processing of digital personal data outside of India if that processing is connected to offering goods or services to Data Principals located within India. Finally, the Act specifically excludes certain types of data processing. It does not apply when an individual processes personal data purely for personal or domestic purposes. It also does not apply to personal data that has been made publicly available by the Data Principal themselves. For example, if an individual publicly shares their own personal data on a social media blog, the Act does not apply to that data. The Act also does not apply if a person is required by an Indian law to make the personal data publicly available.
Key points
- The Act applies to processing digital personal data in India, whether collected digitally or digitized later [(a)].
- It applies to processing outside India if connected to offering goods or services to Data Principals in India [(b)].
- The Act does not apply to personal data processed by an individual for personal or domestic purposes [(c)(i)].
- The Act does not apply to personal data made publicly available by the Data Principal themselves [(c)(ii)(A)].
- The Act does not apply to personal data made publicly available by someone legally obligated under Indian law to do so [(c)(ii)(B)].
Common misreadings
- One might assume the Act applies to all paper records, but it only applies to non-digital data if it is subsequently digitized.
- One might think the Act protects data that a Data Principal voluntarily publishes on a public blog, but the Act explicitly excludes data made publicly available by the Data Principal.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.