DPDPAcademyKnow the law. Prove it.
Home/Overview & Scope
Chapter I · Sections 1–3

What the Act Governs, And Where It Stops

The Digital Personal Data Protection Act, 2023 received the President's assent on 11 August 2023. It regulates the processing of digital personal data - data about an identifiable individual, held in digital form - and balances the individual's right to protect it against lawful needs to use it.

Act No. 22 of 2023Assented 11 August 2023In force on notified dates

The four ideas that carry the law

01A lawful basis is requiredPersonal data may be processed only for a lawful purpose - with consent, or under one of the certain legitimate uses in section 7. There is no open-ended business-interest ground.
02Notice comes firstEvery consent request is accompanied or preceded by a notice: the data, the purpose, how to exercise rights, how to complain - in English or any Eighth Schedule language.
03The individual holds rightsAccess a summary of what is held and who it was shared with, correct or erase it, raise a grievance, and nominate someone to act on your behalf.
04A digital regulator enforces itThe Data Protection Board of India inquires into breaches as a digital office, may accept undertakings or direct mediation, and imposes the penalties in the Schedule.
Where it appliesInside India - to digital personal data collected in digital form, or collected on paper and digitised later.Outside India - where the processing is connected to offering goods or services to Data Principals within India.Section 3(a)–(b)
Where it does notPersonal or domestic use - data an individual processes for her own purposes.Lawfully public data - data the Data Principal made public herself, or that someone was legally obliged to publish.Section 3(c)
Illustration from the ActX, an individual, while blogging her views, has publicly made available her personal data on social media. In such case, the provisions of this Act shall not apply.

Exemptions worth remembering

Section 17 switches off most of Chapters II and III in defined situations. The exemptions are conditional, not a blanket carve-out.

Legal claims & courtsEnforcing a legal right, and processing by courts, tribunals or regulatory bodies performing their functions. § 17(1)(a)–(b)
Crime & investigationPrevention, detection, investigation or prosecution of any offence or contravention. § 17(1)(c)
Research & statisticsAllowed if no decision specific to a Data Principal is taken and prescribed standards are met. § 17(2)(b)
Notified State instrumentalitiesIn the interests of sovereignty, security of the State, friendly relations or public order. § 17(2)(a)
Startups, if notifiedGovernment may exempt notified classes from §§ 5, 8(3), 8(7), 10 and 11. § 17(3)
Cross-border transfersTransfers are open unless the Central Government restricts a country or territory by notification. § 16
FAQ

The DPDP Act, answered

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 is India's first standalone data protection law. It received the President's assent on 11 August 2023 as Act No. 22 of 2023, and runs to 9 chapters, 44 sections and one Schedule of penalties. It governs the processing of digital personal data - data about an identifiable individual, held in digital form.

Who does the DPDP Act apply to?

It applies to anyone who determines the purpose and means of processing digital personal data - the Data Fiduciary - whether that data was collected in digital form or collected on paper and digitised later. Accountability sits with the Data Fiduciary irrespective of any agreement to the contrary.

Does the DPDP Act apply outside India?

Yes, where the processing is connected to offering goods or services to Data Principals within India. A company with no Indian presence is still within scope if it offers goods or services to people in India. This is section 3(b).

What is not covered by the DPDP Act?

Two things. Personal data processed by an individual for a purely personal or domestic purpose, and personal data the Data Principal made publicly available herself or that someone was legally obliged to publish. This is section 3(c).

What are the lawful grounds for processing under the DPDP Act?

Only two: the consent of the Data Principal, or one of the nine certain legitimate uses listed in section 7. There is no open-ended legitimate-interest ground of the kind found in the GDPR.

What are the exemptions under section 17?

Section 17 switches off most of Chapters II and III for enforcing legal rights, courts and tribunals, prevention and investigation of offences, notified State instrumentalities, and research or statistical purposes where no decision specific to a Data Principal is taken. The exemptions are conditional, not a blanket carve-out.

Know this chapter? Prove it in ten questions.The practice test is free, unlimited, and shows the governing provision after every answer.
§ 3(c) · Out of scope

Two situations the Act never reaches

Before asking which obligations apply, check whether the Act applies at all. These are exclusions from scope, not exemptions within it - nothing survives them.

§ 3(c)(i)Personal or domestic purposePersonal data processed by an individual for any personal or domestic purpose falls outside the Act entirely. A contacts list, a family photo library, a personal address book.The exclusion attaches to the purpose, not to the person. An individual processing for a business purpose is not covered by it.
§ 3(c)(ii)Data she made public, or that law required publishedPersonal data made or caused to be made publicly available either by the Data Principal herself, or by any person under a legal obligation in India to publish it.This is one of the sharpest divergences from GDPR, which has no general public-availability carve-out. A blogger's own published contact details, or a directors' register published under company law, sit outside this Act.
§ 17 · Beyond the grounds

What an exemption does not switch off

The grounds are above. These four points decide how an exemption actually behaves - including two powers the Government holds and has not yet used.

§ 17(1)What survives an exemptionWhere a section 17(1) ground applies, Chapter II is disapplied - except sub-sections (1) and (5) of section 8. Chapter III and section 16 go too.So accountability and reasonable security safeguards continue to apply even to exempt processing. An exemption is never a licence to hold data insecurely.
§ 17(3)The startup exemption nobody plans forHaving regard to the volume and nature of personal data processed, the Central Government may notify Data Fiduciaries or classes of them - expressly including startups - for whom section 5, sections 8(3) and 8(7), and sections 10 and 11 do not apply.That is notice, data accuracy, erasure, Significant Data Fiduciary duties and the right of access, switched off by notification. It is not automatic and no class has been notified, so it is something to watch rather than to rely on.
§ 17(4)The State keeps its dataFor processing by the State or its instrumentalities, the erasure duty in section 8(7) and the erasure right in section 12(3) do not apply - and where the processing does not involve a decision affecting the Data Principal, neither does the correction duty in section 12(2).A citizen has no right under this Act to have her data erased from a government system.
§ 17(5)A five-year power to suspend any provisionBefore five years from commencement, the Central Government may by notification declare that any provision of the Act shall not apply to any Data Fiduciary or class of them, for a period it specifies.A broad transitional power with no stated criteria. It expires; until then it sits over the whole framework.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →