You are on DataProtectionAct2023.com Venture of JurisTatva DPDP Compliance Specialists
Home / Applicability
Applicability of the DPDP Act, 2023

Does the DPDP Act, 2023 apply to you?

For almost every Indian business, the answer is yes. If your organisation holds the digital personal data of even one employee, customer, member, donor or vendor, you are a Data Fiduciary — and the obligations already apply. This page walks you through the exact tests, the territorial scope, sector-by-sector applicability, and the narrow exemptions.

Quick Answer

When does the DPDP Act, 2023 apply?

The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data — personal data collected in digital form, or collected on paper and later digitised — within India.

It also applies to processing carried out outside India when that processing is connected with offering goods or services to individuals (Data Principals) located in India.

If your organisation decides why and how personal data is processed, you are a Data Fiduciary and must comply — irrespective of your size, turnover, legal form or industry.

The Two-Part Test

Two questions decide it

Applicability turns almost entirely on two simple tests. If the answer to both is yes, the DPDP Act applies to you today — no exceptions for size, sector or turnover.

Data FiduciaryDecides the purpose & means
Data ProcessorActs only on instructions
1

Do you process digital personal data? Any information about an identifiable person — name, phone, email, PAN, address, photo or IP — stored in digital form (or scanned from paper) clears this test.

2

Do you decide the purpose & means? If you determine why the data is collected and how it is used, you are a Data Fiduciary and carry the compliance duty.

Within India. Any processing of digital personal data inside India is covered — whether born digital or digitised from physical records later.

Outside India. Businesses abroad are covered when processing relates to offering goods or services to Data Principals located in India.

Territorial Scope

The reach follows the data

The DPDP Act is not limited to companies physically located in India. Its reach follows the personal data of individuals in India — which is why even a foreign SaaS, e-commerce or service business can fall within scope.

Sector-by-Sector

Does DPDPA apply to your industry?

The DPDP Act is sector-neutral. Below is how it lands across the industries we most often advise — each processes exactly the kind of personal data the Act governs.

Hospitality

Hotels and restaurants collect guest IDs, contact details, payment and stay history at check-in.

Guest KYCBookings

Real Estate

Builders and brokers hold buyer KYC, financials, loan papers and prospect databases.

Buyer KYCLeads

Banking & NBFC

Among the most data-intensive sectors — account KYC, transactions, credit and biometric data.

Account KYCCredit

Healthcare & Pharma

Patient records, prescriptions and health history are highly sensitive personal data.

Patient dataHealth

Fintech

Apps and wallets process identity, financial and behavioural data continuously.

IdentityFinancial

SaaS & IT Services

You process both your own users' data and, often, your clients' end-user data as a processor.

User dataDPAs

EdTech

Learner profiles frequently include children's data — triggering stricter consent duties.

LearnersChildren

Manufacturing

Employee, workforce, vendor and channel-partner records all sit within scope.

WorkforceVendors

Tourism & Travel

Traveller IDs, passports, itineraries and payment data flow across many partners.

PassportsItineraries

E-commerce & D2C

Every checkout captures addresses, contacts, order history and payment identifiers.

CheckoutOrders

Retail Sector

Loyalty programmes, memberships and CRM databases are full of personal data.

LoyaltyCRM

Telecom

Subscriber KYC, call records and usage data make telecom a core covered sector.

Subscriber KYCUsage
The Narrow Exits

When it does not apply

A small set of exemptions exists — but for most organisations they are narrow and rarely remove you from scope entirely.

Personal or domestic use

Personal data processed by an individual purely for their own personal or household purposes is outside the Act. This is not a business exemption.

Data made public by the individual

Personal data that a Data Principal has voluntarily made publicly available — or that is made public under a legal obligation — is not covered. Data you collect directly from people is not "made public" and remains in scope.

Certain State & notified processing

Specific processing by the State and instrumentalities, and processing for research, archiving or statistical purposes, may be exempted or relaxed subject to conditions and notifications by the Central Government.

Anonymised / non-personal data

Truly anonymised data that can no longer identify an individual falls outside the Act. In practice, most business records remain identifiable and therefore covered.

This is a plain-English overview, not legal advice. Exemptions depend on rules and notifications issued under the Act. A short diagnostic call maps your exact position.

Applicability FAQ

Common applicability questions

Does the DPDP Act, 2023 apply to small businesses and startups?
Yes. The Act applies to any Data Fiduciary that determines the purpose and means of processing digital personal data — regardless of size, turnover or sector. A sole proprietor, startup, LLP, society or trust holding employee, customer or vendor data in digital form is covered. Smaller entities may receive certain relaxations if notified by the Central Government, but the core obligations still apply.
Does the DPDP Act apply to companies located outside India?
Yes, in defined cases. The Act applies to processing of digital personal data outside India if that processing is in connection with offering goods or services to Data Principals located within India. A foreign SaaS, e-commerce or service business with Indian users can therefore fall within scope.
What kind of data does the DPDP Act cover?
The Act covers digital personal data — personal data collected in digital form, or collected on paper and later digitised. Personal data is any data about an identifiable individual. Purely anonymised data, and data processed by an individual for personal or domestic use, fall outside the Act.
Who is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is any person — company, LLP, society, trust or individual — who alone or with others determines the purpose and means of processing personal data. If your organisation decides why and how personal data is processed, you are a Data Fiduciary and must comply.
Is my business exempt if the data is publicly available?
The Act does not apply to personal data that a Data Principal has made publicly available themselves, or that is made public under a legal obligation. However, most business processing involves data collected directly from individuals, so this exemption is narrow and rarely removes an organisation from scope entirely.
Which sectors need to comply with the DPDP Act?
The DPDP Act is sector-neutral. Banking and NBFCs, healthcare and pharma, fintech, SaaS and IT services, e-commerce and D2C, hospitality, real estate, EdTech, manufacturing, retail, telecom and travel are all covered wherever they process the digital personal data of individuals in India.
Not Sure Where You Stand?

Get a clear applicability verdict — free.

A short diagnostic call maps your data flows against the DPDP Act and its 44-instrument checklist, so you know exactly what applies and what to build next.

DPDP Assistant
Online — Ask about applicability
✕
👋 Hi! I'm the DPDP compliance assistant from JurisTatva. Ask me whether the Digital Personal Data Protection Act, 2023 applies to your business — who is a Data Fiduciary, the territorial scope, your sector, or the exemptions. How can I help?
Does it apply to me? Who must comply? Outside India? Exemptions? Contact?

Compliance Partner

Collaborative Service Model

JurisTatva works through a collaborative model with professionals. Where secretarial or statutory execution is required, services are delivered by professional firms — including our compliance partner S & S Associates, Company Secretaries.

Visit sns18.in
×
Limited Time Offer

Free Consulting

Speak with our DPDP compliance experts and get a personalised diagnostic of your data-protection exposure — no cost, no obligation.

Consultation Fee

₹5,000 INR Now FREE

Book your one-on-one consultation today — absolutely free.

Expert Guidance

Talk to certified DPDP experts

100% Confidential

Your information is secure with us

No Obligation

Get clarity with zero commitment

Tell us about your enquiry

Your details are safe and secure with us.