DPDPAcademyKnow the law. Prove it.
Home/Implementation
Nine sectors · each anchored to a provision

The Act Is Sector-Neutral. Except Where It Isn't.

The DPDP Act defines a Data Fiduciary by what it does with personal data, not by what industry it is in. But the Rules name three classes outright, and six more sectors have a provision written around them. These are those sectors.

Most sector guidance on this Act is the same checklist with a different logo, and it is worth saying why. The statute is deliberately drafted to be sector-neutral: obligations attach to the processing of digital personal data, so a hospital, a bank and a bookshop owe substantially the same duties. Writing nine versions of that is not useful to anyone.

What is useful is the set of places where the framework does distinguish. There are more of them than the Act alone suggests, because most sit in the Rules: the Third Schedule names e-commerce, online gaming and social media with their own retention clocks and user-count thresholds, and the Fourth Schedule switches the children’s provisions off for clinical care. The Act itself reserves section 17(1)(f) for lenders, section 17(1)(d) for offshore IT services, section 17(3) for startups and sections 7(b) and 17(2)(a) for the State.

Each guide below names the provision it rests on. If your sector is not here, that is the answer rather than an omission - the general regime applies, and the eleven obligations are the right place to start.

The nine at a glance

Each sector, what it also covers, the number that matters and the provision that sets it
SectorAlso coversThe number that matters
E-commerce & retailonline stores, marketplaces, D2C brands, quick commerce, retail chains2 croreregistered users in IndiaThird Schedule
Online gamingreal money gaming, fantasy sports, mobile games, esports platforms50 lakhregistered users in IndiaThird Schedule
Social mediasocial networks, content platforms, community apps, creator platforms2 croreregistered users in IndiaThird Schedule
Healthcarehospitals, clinics, diagnostic labs, telemedicine, pharmacies, mental health servicesPart Aclasses exempt from § 9(1) and 9(3)rule 12
Banking & financial servicesbanks, NBFCs, fintech, lending apps, insurance, wealth platforms10 yearsclient identity records, by law§ 8(7)
EdTech & educationschools, colleges, coaching centres, test prep, K-12 platforms, training institutes18age below which a learner is a child§ 2(f)
SaaS & IT servicesB2B software, IT services, BPO, cloud platforms, developer tools2roles at once: Fiduciary, Processor§ 2
StartupsDPIIT-recognised startups, early stage companies, seed and Series A teams5provisions § 17(3) could disapply§ 17(3)
Government & public sectorcentral and state departments, municipal bodies, public sector undertakings, welfare schemes§ 7(b)subsidies and services, no consent§ 7(b)

Every provision cited across these guides can be read in context in the full text of the Act or verified against the MeitY publication.

Implementation

Applying the Act by sector

Does the DPDP Act have different rules for different industries?

Mostly no, and that is the point worth understanding first. The Act defines a Data Fiduciary by what it does with personal data rather than by sector, and almost every obligation applies identically everywhere. The exceptions are specific and findable: the Third Schedule to the Rules names three classes with their own retention thresholds, the Fourth Schedule disapplies the children's provisions for defined classes, and sections 17(1)(d), 17(1)(f), 17(2)(a), 17(3) and 7(b) carve out particular situations.

Which industries are actually named in the Act or the Rules?

E-commerce entities, online gaming intermediaries and social media intermediaries are named in the Third Schedule with user-count thresholds. Clinical establishments, mental health establishments and healthcare professionals begin Part A of the Fourth Schedule. Financial institutions appear in section 17(1)(f). Startups are named in section 17(3). The State and its instrumentalities appear in sections 7(b) and 17(2)(a).

My sector is not listed here. What applies to me?

The whole Act, without sector-specific modification - which is the ordinary case rather than a gap. Start with the eleven obligations in Chapter II and the rights in Chapter III, then check whether you cross a Significant Data Fiduciary threshold under section 10. We have not written a page for sectors with no distinct statutory treatment, because it would be the same guidance with a different heading.

Do these guides replace legal advice?

No. They are educational summaries anchored to specific provisions so you can verify each claim against the statute yourself, and every page links to the section text and to the MeitY publication. Applying them to your organisation's facts - particularly on the exemptions, which are all bounded by purpose - is work for a qualified adviser.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against industry implementation guides. Educational information, not legal advice.

Review standards and attribution →