/Guides · Businesses & individuals
Who does the DPDP Act apply to?
How section 3 draws the boundary of the DPDP Act, what falls outside it, and every exemption in section 17, explained in plain English.
Two provisions decide whether the DPDP Act touches a given piece of processing. Section 3 draws the outer boundary, and section 17 carves pieces out of it. This guide works through both, and through the definition of personal data that makes the whole question meaningful.
What counts as personal data#
"Personal data" means "any data about an individual who is identifiable by or in relation to such data" (section 2(t)). Two things follow. It is data about an individual, so data about a company or a machine is not personal data on its own. And identifiability can be indirect, because the definition covers an individual identifiable "in relation to" the data as well as "by" it.
The Act does not sort personal data into sensitive and non-sensitive categories. There is one definition, covering a name, an email address, a health record and a location trail alike.
What the Act regulates is narrower again: digital personal data, meaning personal data in digital form (section 2(n)).
Where the Act applies#
Section 3(a) covers processing of digital personal data within the territory of India, where the data was collected either in digital form, or in non-digital form and digitised subsequently. That second branch matters. A paper form scanned into a system brings the resulting digital record inside the Act.
Section 3(b) reaches outside India. It applies to processing of digital personal data outside the territory of India "if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India". A business with no presence in India can be in scope if it offers goods or services to people in India and processes their digital personal data abroad. The trigger is the offering, not the location of the servers.
What falls outside#
Section 3(c) puts two things outside the Act entirely.
The first is "personal data processed by an individual for any personal or domestic purpose", for example an individual keeping a contact list on her own phone.
The second is personal data "made or caused to be made publicly available" either by the Data Principal herself, or by any other person under a legal obligation in India to make it public. The Act's own illustration to section 3 is: "X, an individual, while blogging her views, has publicly made available her personal data on social media. In such case, the provisions of this Act shall not apply."
Who carries the obligations#
Being in scope is one question. Who answers for it is another. The Act puts the duties on the Data Fiduciary, any person who alone or with others "determines the purpose and means of processing of personal data" (section 2(i)). A Data Processor processes on a Data Fiduciary's behalf (section 2(k)), and the Data Fiduciary stays responsible for processing done for it, whatever the contract says (section 8(1)).
"Person" includes an individual, a Hindu undivided family, a company, a firm, an association of persons, the State and every artificial juristic person (section 2(s)). Government bodies can therefore be Data Fiduciaries, subject to the exemptions below.
The exemptions in section 17#
Section 17 has five sub-sections, and each does a different job. Reading them as one list is the most common way to get this wrong.
Section 17(1): most obligations and all rights fall away#
Where one of six situations applies, Chapter II falls away except section 8(1) and section 8(5), and so do Chapter III (the rights of Data Principals) and section 16. The two duties that survive are general responsibility for compliance, and reasonable security safeguards.
The six situations are: processing necessary for enforcing any legal right or claim; processing by a court, tribunal or other body in India entrusted by law with a judicial, quasi-judicial, regulatory or supervisory function, where necessary for that function; processing in the interest of prevention, detection, investigation or prosecution of any offence or contravention of law in India; processing of personal data of Data Principals not within India under a contract entered into with a person outside India by a person based in India; processing for a court-approved scheme of compromise, arrangement, merger, amalgamation, demerger or transfer of undertaking; and processing to ascertain the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution, in line with disclosure provisions in other laws (section 17(1)).
The fourth of those matters for India's outsourcing sector: work done in India on the personal data of people abroad, under a contract with a foreign customer, sits largely outside Chapters II and III.
Section 17(2): the Act does not apply at all#
Two categories are lifted out of the entire Act, not just parts of it.
The first is processing "by such instrumentality of the State as the Central Government may notify, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these", together with the Central Government's processing of any personal data such an instrumentality gives it (section 17(2)(a)). This exemption operates only once the Central Government notifies the instrumentality in question.
The second is processing "necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and such processing is carried on in accordance with such standards as may be prescribed" (section 17(2)(b)). Those standards now exist. Rule 16 applies the Second Schedule, which requires lawful processing, purpose limitation, data minimisation, reasonable efforts at accuracy, retention only as long as needed, security safeguards, and accountability of whoever determines the purpose and means.
Section 17(3): lighter obligations for notified classes, including startups#
The Central Government may, "having regard to the volume and nature of personal data processed", notify Data Fiduciaries or classes of Data Fiduciaries, "including startups", for whom section 5 (notice), section 8(3) and section 8(7) (data accuracy and erasure), section 10 (Significant Data Fiduciary duties) and section 11 (right to access information) do not apply (section 17(3)).
The Explanation defines "startup" as a private limited company, partnership firm or limited liability partnership incorporated in India that is eligible to be and is recognised as such under the criteria notified by the Central Government department handling startups. This is a power, not a self-executing exemption. It works only when a notification is issued, and the Rules do not deal with it.
Section 17(4): narrower carve-outs for the State#
Where the State or an instrumentality of the State is processing, section 8(7) (erasure) and section 12(3) (the right to request erasure) do not apply. Where the processing is for a purpose that does not include making a decision affecting the Data Principal, section 12(2) (correction, completion and updating) also does not apply (section 17(4)).
Section 17(5): a time-limited power to suspend provisions#
Before five years from the commencement of the Act, the Central Government may by notification declare that any provision of the Act does not apply to a Data Fiduciary or class of Data Fiduciaries, for a period specified in the notification (section 17(5)).
When all of this starts to apply#
Both section 3 and section 17 come into force eighteen months after 13 November 2025, which is 13 May 2027, under clause (c) of G.S.R. 843(E). Until then the scope provision and the exemptions are on the statute book but not in force, and neither are the Chapter II obligations they qualify.
Key provisions#
/MYND · DPDP practice
Want help applying this?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.