Free DPDP applicability checker

DPDP Act applicability checker
section 3 and section 17, in order.

Thirteen questions that walk the Act's own scope tests: personal data, digital form, where the processing happens, the exclusions and the exemptions. You get a verdict, the sections that apply, and what to do next. Nothing you answer leaves your browser.

What you process

Section 2(t). Names, emails, phone numbers, device IDs tied to an account, and employee records all count.
Section 3(a). Paper collected and later scanned or typed in counts as digital.
Sections 2(i) and 2(k). A SaaS vendor is usually the Fiduciary for its own customer accounts and a Processor for data it hosts for customers.

Where

Section 3(a) and (b). Where your servers and teams are, not where your users are.
Section 3(b). Selling to, or running a service used by, people in India. Answer this even if you process in India.
Section 17(1)(d). The outsourcing and BPO case.

Exclusions and exemptions

Section 3(c)(i). A personal address book, a family photo album. Not a business, however small.
Section 3(c)(ii). A person's own public post; a register a law requires to be published.
Section 17(2)(b) and Rule 16. Only if carried on to the Second Schedule standards.
Section 17(1)(a)-(c), (e) and (f). Exempt from most duties for that processing only.

What else applies

Section 2(f). Under 18 is a child for every purpose of the Act.
Section 8(2). Almost everyone does.
Section 16 and Rule 15.
Open the DPDP checklist
Worked example: an Indian SaaS company

Your result

An indication from your answers, not a legal opinion. Scope turns on facts this form cannot see; have counsel confirm it before you rely on an exclusion.
In scopeThe DPDP Act applies to this processing, and you are the Data Fiduciary for it. The duties apply from 13 May 2027.
Notice and consent, or a listed legitimate uses.4–7
Security, accuracy, breach reporting, erasure, contact details, grievancess.8
Access, correction and erasure, grievance, nominations.11–14
Processor contracts, and your responsibility for what processors dos.8(1)–(2)
Transfers outside India: check for any restricted countrys.16
Extra duties only if notified as a Significant Data Fiduciarys.10
01

Who does the DPDP Act apply to?

The DPDP Act applies to anyone processing digital personal data in India, whether collected digitally or digitised from paper, and to processing outside India connected to offering goods or services to people in India. It does not apply to purely personal or domestic use, or to data the person made public themselves.

That is section 3 of the Act as published in the Gazette. There is no size threshold, no turnover test and no minimum number of users: a two-person company that keeps customer emails in a CRM is in scope in the same way a bank is. What changes with size is not whether the Act applies but whether the government is likely to designate you a Significant Data Fiduciary, which adds duties on top.

QuestionWhere the Act answers itWhat follows
Is it personal data?s.2(t): data about an individual identifiable by or in relation to itAnonymous aggregates are out; a pseudonymous ID tied to an account is in
Is it digital?s.3(a): collected digitally, or on paper and digitised laterPaper records never digitised are out
Is it processed in India?s.3(a)In scope, whoever the users are, subject to s.17(1)(d)
Is it processed abroad?s.3(b): in scope if connected to offering goods or services in IndiaA foreign company selling to Indian users is in scope for that processing
Personal or domestic purpose?s.3(c)(i)Out, for individuals only
Made public by the person?s.3(c)(ii)Out, for that data as published
Research, archiving, statistics?s.17(2)(b), Rule 16Out, if no individual decisions and the Second Schedule standards are met
Contract processing for foreign clients?s.17(1)(d)Most duties lifted; security and responsibility remain

Section numbers are to the Digital Personal Data Protection Act, 2023.

02

Does the DPDP Act apply to companies outside India?

Yes, where the processing is connected to offering goods or services to people in India. A company incorporated abroad that sells to Indian customers, runs an app used in India or ships goods there is in scope for that processing. Processing abroad with no link to people in India is not covered.

The test is narrower than the GDPR's. The Act has no equivalent of the GDPR's separate monitoring limb, so a foreign company that only tracks Indian visitors without offering them anything sits in a grey zone the Act does not expressly settle. In practice, analytics and advertising are usually part of offering the service, and the safer reading is that they are in scope. The DPDP to GDPR mapping sets the two regimes side by side.

03

What is exempt under section 17?

Section 17 exempts processing necessary for legal claims, court and regulatory functions, preventing or investigating offences, court-approved mergers, tracing loan defaulters' assets, and contract processing of foreign people's data in India. For those purposes most duties fall away, but responsibility and security safeguards under section 8(1) and 8(5) still apply.

Three further exemptions work differently. Research, archiving and statistics are exempt from the whole Act if no individual decision is taken and the standards in the Second Schedule to the DPDP Rules 2025 are met. The government may exempt notified instrumentalities of the State. And section 17(3) lets it exempt classes of Data Fiduciaries, including startups, from notice, accuracy, erasure, SDF and access duties, but only by notification: the category exists in the Act, and an exemption exists only once a notification names your class.

Each exemption is tied to a purpose, not to a company. A BPO exempt under section 17(1)(d) for its clients' customer data is fully in scope for its own employees' data. Write down which processing each exemption covers and why, because the question will be asked about the processing, not about you.

04

How the checker reaches its answer

The questions run in the order the Act does. Personal data first, then digital form, then the territorial tests, then the exclusions in section 3(c), then the exemptions in section 17. The first answer that takes processing out of scope ends the check, because nothing after it matters. If nothing does, the result lists the chapters that apply and adds the ones your answers trigger: section 9 if children may be involved, section 8(2) if you use processors, section 16 if data leaves India.

It does not ask whether you are a Significant Data Fiduciary, because that is not something you can answer about yourself. Designation is by government notification; the Significant Data Fiduciary checker explains how the section 10 factors are likely to read for you. Once you know you are in scope, the DPDP compliance checklist turns the result into work, and the DPDP Act guide explains each duty. When you are ready to evidence consent rather than describe it, DPDP compliance on the platform is where that happens.

Questions

The things people ask us

Does the DPDP Act apply to small businesses?

Yes. The Act has no size, turnover or user-count threshold. A small business processing customer or employee data digitally in India is a Data Fiduciary with the same core duties as a large one. Section 17(3) allows the government to exempt classes such as startups from some duties, but only by notification, so check for one before relying on it.

Does the DPDP Act apply to employee data?

Yes. Employee data is personal data and is in scope. Section 7(i) makes employment purposes a legitimate use, so much HR processing needs no consent, but only within what that clause covers. Security, breach reporting, retention and the other duties still apply.

Does the DPDP Act apply to B2B companies?

Usually. Business contacts are individuals, so a sales pipeline of names, work emails and phone numbers is personal data. A B2B SaaS company is also typically a Data Processor for the personal data its customers load into the product, and a Data Fiduciary for its own customer account and marketing data.

Does the DPDP Act apply to publicly available data?

Not to personal data made publicly available by the person it relates to, or by someone legally required to publish it: section 3(c)(ii). The Act's own illustration is a person's views posted publicly on social media. It does apply once you combine that data with data you collected yourself, or where the data was made public by someone else without a legal duty to publish it.

Does the DPDP Act apply to paper records?

Only once they are digitised. Section 3(a) covers personal data collected in digital form, or collected in non-digital form and digitised afterwards. A paper register that is never scanned or typed up is outside the Act; the same register photographed for a shared drive is inside it.

Can this checker tell me for certain whether the Act applies?

No. It applies the section 3 and section 17 tests to your answers, and those tests turn on facts a form cannot see: what counts as offering services in India, which purposes an exemption actually covers. Treat the result as a structured first pass, and have counsel confirm any exclusion you intend to rely on.

Book a walkthrough

In scope is where the work starts.

Once you know the Act applies, the job is proof: which notice each person saw, what they agreed to, and when their data fell due for erasure. That is what the platform records.