Does the DPDP Act, 2023 apply to you?
For almost every Indian business, the answer is yes. If your organisation holds the digital personal data of even one employee, customer, member, donor or vendor, you are a Data Fiduciary — and the obligations already apply. This page walks you through the exact tests, the territorial scope, sector-by-sector applicability, and the narrow exemptions.
When does the DPDP Act, 2023 apply?
The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data — personal data collected in digital form, or collected on paper and later digitised — within India.
It also applies to processing carried out outside India when that processing is connected with offering goods or services to individuals (Data Principals) located in India.
If your organisation decides why and how personal data is processed, you are a Data Fiduciary and must comply — irrespective of your size, turnover, legal form or industry.
Two questions decide it
Applicability turns almost entirely on two simple tests. If the answer to both is yes, the DPDP Act applies to you today — no exceptions for size, sector or turnover.
Do you process digital personal data? Any information about an identifiable person — name, phone, email, PAN, address, photo or IP — stored in digital form (or scanned from paper) clears this test.
Do you decide the purpose & means? If you determine why the data is collected and how it is used, you are a Data Fiduciary and carry the compliance duty.
Within India. Any processing of digital personal data inside India is covered — whether born digital or digitised from physical records later.
Outside India. Businesses abroad are covered when processing relates to offering goods or services to Data Principals located in India.
The reach follows the data
The DPDP Act is not limited to companies physically located in India. Its reach follows the personal data of individuals in India — which is why even a foreign SaaS, e-commerce or service business can fall within scope.
Does DPDPA apply to your industry?
The DPDP Act is sector-neutral. Below is how it lands across the industries we most often advise — each processes exactly the kind of personal data the Act governs.
Hospitality
Hotels and restaurants collect guest IDs, contact details, payment and stay history at check-in.
Real Estate
Builders and brokers hold buyer KYC, financials, loan papers and prospect databases.
Banking & NBFC
Among the most data-intensive sectors — account KYC, transactions, credit and biometric data.
Healthcare & Pharma
Patient records, prescriptions and health history are highly sensitive personal data.
Fintech
Apps and wallets process identity, financial and behavioural data continuously.
SaaS & IT Services
You process both your own users' data and, often, your clients' end-user data as a processor.
EdTech
Learner profiles frequently include children's data — triggering stricter consent duties.
Manufacturing
Employee, workforce, vendor and channel-partner records all sit within scope.
Tourism & Travel
Traveller IDs, passports, itineraries and payment data flow across many partners.
E-commerce & D2C
Every checkout captures addresses, contacts, order history and payment identifiers.
Retail Sector
Loyalty programmes, memberships and CRM databases are full of personal data.
Telecom
Subscriber KYC, call records and usage data make telecom a core covered sector.
When it does not apply
A small set of exemptions exists — but for most organisations they are narrow and rarely remove you from scope entirely.
Personal or domestic use
Personal data processed by an individual purely for their own personal or household purposes is outside the Act. This is not a business exemption.
Data made public by the individual
Personal data that a Data Principal has voluntarily made publicly available — or that is made public under a legal obligation — is not covered. Data you collect directly from people is not "made public" and remains in scope.
Certain State & notified processing
Specific processing by the State and instrumentalities, and processing for research, archiving or statistical purposes, may be exempted or relaxed subject to conditions and notifications by the Central Government.
Anonymised / non-personal data
Truly anonymised data that can no longer identify an individual falls outside the Act. In practice, most business records remain identifiable and therefore covered.
This is a plain-English overview, not legal advice. Exemptions depend on rules and notifications issued under the Act. A short diagnostic call maps your exact position.
Common applicability questions
Does the DPDP Act, 2023 apply to small businesses and startups?
Does the DPDP Act apply to companies located outside India?
What kind of data does the DPDP Act cover?
Who is a Data Fiduciary under the DPDP Act?
Is my business exempt if the data is publicly available?
Which sectors need to comply with the DPDP Act?
Get a clear applicability verdict — free.
A short diagnostic call maps your data flows against the DPDP Act and its 44-instrument checklist, so you know exactly what applies and what to build next.