DPDPAcademyKnow the law. Prove it.
Home/Applicability
§ 3 · Application of the Act

Five Questions Decide Whether It Applies.

Scope is the first thing to settle and the easiest to get wrong. Section 3 sets two limbs that bring processing in and two exclusions that take it out - and none of them turns on how large you are or how much data you hold.

Question 1

Is any of it data about an individual who can be identified by it, or in relation to it?

That is the whole definition of personal data. A name, an account number, a device identifier tied to a person. Aggregate figures about no one in particular are not.

Nothing you answer leaves your browser - the checker holds its state in the page and stores nothing. Every branch below is also written out in full, so the same reasoning is available without running the tool.

The tests in full

What section 3 actually asks

Two limbs bring processing into the Act. Two exclusions take it back out. The checker walks these in order; here they are in one place.

§ 2(t)It has to be personal dataAny data about an individual who is identifiable by or in relation to that data. If nobody is identifiable, the Act is not engaged at all, however commercially sensitive the data may be.
§ 3(a)It has to be digitalCollected in digital form, or collected non-digitally and digitised subsequently. Paper that stays on paper is outside the Act; the act of scanning it brings it inside.This is a trigger worth diarising rather than assuming. A backlog digitisation project changes the answer for every record it touches.
§ 3(a)–(b)It has to happen in India, or be aimed at IndiaProcessing within the territory of India is covered. So is processing outside India, where it is in connection with any activity related to offering goods or services to Data Principals within India.Note what is absent. GDPR Article 3 also catches monitoring the behaviour of people in the EU; section 3(b) has no monitoring limb, so analytics on Indian visitors is not by itself a trigger.
§ 3(c)(i)Unless it is purely personal or domesticPersonal data processed by an individual for any personal or domestic purpose is excluded outright.The exclusion attaches to the purpose, not the person. A sole trader keeping customer records is not processing for a domestic purpose.
§ 3(c)(ii)Unless she published it, or the law required it publishedData made or caused to be made publicly available by the Data Principal herself, or by any person under a legal obligation in India to publish it, is outside the Act.Leaked data is not publicly available in this sense, and neither is data a third party republished without being obliged to. GDPR has no comparable carve-out.
After scope

Being in scope is the beginning of the question

A yes here means the Act reaches your processing. It does not tell you which obligations apply, and two provisions can change that substantially. Section 7 lists nine certain legitimate uses that provide a lawful basis without consent. Section 17 exempts whole grounds - legal claims, courts and regulators, offences, non-resident data under a foreign contract, mergers and demergers, and defaulter asset tracing.

Even inside an exemption, sections 8(1) and 8(5) survive: accountability, and reasonable security safeguards. There is no route through this Act that leaves you free to hold personal data insecurely.

Read it yourself: section 3, section 7 and section 17.

FAQ

Applicability, answered

Does the DPDP Act apply to a company outside India?

It can. Section 3(b) reaches processing carried out wholly outside India where it is connected with offering goods or services to Data Principals within India. There is no establishment requirement and no user-number threshold.

Does the Act apply to employee data?

Yes - employee data is digital personal data like any other. What changes is the lawful basis: section 7(i) is a certain legitimate use covering employment purposes and safeguarding the employer from loss or liability, so consent is not always required.

Does it apply to paper records?

Not while they stay on paper. The Act covers personal data collected in digital form, and personal data collected non-digitally and digitised subsequently. Scanning a paper file brings it into scope from that point.

Does the Act apply to publicly available data?

No, where the individual made it public herself or someone was legally obliged to publish it. That is section 3(c)(ii), and it is one of the clearest differences from GDPR, which applies regardless of public availability.

If the Act applies, when do the obligations actually bite?

Sections 3 to 17 sit in the eighteen-month tranche of the commencement notification, which falls in mid-May 2027. Until then the SPDI Rules, 2011 continue to apply alongside.

Is this checker legal advice?

No. It walks the tests in section 3 and cites the provision behind each answer so you can check it against the text. Scope is only the first question, and section 17 can switch off large parts of the Act for particular grounds or notified classes.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →