DPDP Act applicability checker
section 3 and section 17, in order.
Thirteen questions that walk the Act's own scope tests: personal data, digital form, where the processing happens, the exclusions and the exemptions. You get a verdict, the sections that apply, and what to do next. Nothing you answer leaves your browser.
Your result
- Next: work through the DPDP compliance checklist, starting with the data inventory.
- Notice: draft an itemised notice from the consent notice template.
- Processors: put each vendor on a written contract with security clauses; see the DPDP data processing agreement template.
- Transfers: read the DPDP cross-border transfer guide and check any sector rule that is stricter than the Act.
- Designation: see how the section 10 factors read for you with the Significant Data Fiduciary checker.
Who does the DPDP Act apply to?
The DPDP Act applies to anyone processing digital personal data in India, whether collected digitally or digitised from paper, and to processing outside India connected to offering goods or services to people in India. It does not apply to purely personal or domestic use, or to data the person made public themselves.
That is section 3 of the Act as published in the Gazette. There is no size threshold, no turnover test and no minimum number of users: a two-person company that keeps customer emails in a CRM is in scope in the same way a bank is. What changes with size is not whether the Act applies but whether the government is likely to designate you a Significant Data Fiduciary, which adds duties on top.
| Question | Where the Act answers it | What follows |
|---|---|---|
| Is it personal data? | s.2(t): data about an individual identifiable by or in relation to it | Anonymous aggregates are out; a pseudonymous ID tied to an account is in |
| Is it digital? | s.3(a): collected digitally, or on paper and digitised later | Paper records never digitised are out |
| Is it processed in India? | s.3(a) | In scope, whoever the users are, subject to s.17(1)(d) |
| Is it processed abroad? | s.3(b): in scope if connected to offering goods or services in India | A foreign company selling to Indian users is in scope for that processing |
| Personal or domestic purpose? | s.3(c)(i) | Out, for individuals only |
| Made public by the person? | s.3(c)(ii) | Out, for that data as published |
| Research, archiving, statistics? | s.17(2)(b), Rule 16 | Out, if no individual decisions and the Second Schedule standards are met |
| Contract processing for foreign clients? | s.17(1)(d) | Most duties lifted; security and responsibility remain |
Section numbers are to the Digital Personal Data Protection Act, 2023.
Does the DPDP Act apply to companies outside India?
Yes, where the processing is connected to offering goods or services to people in India. A company incorporated abroad that sells to Indian customers, runs an app used in India or ships goods there is in scope for that processing. Processing abroad with no link to people in India is not covered.
The test is narrower than the GDPR's. The Act has no equivalent of the GDPR's separate monitoring limb, so a foreign company that only tracks Indian visitors without offering them anything sits in a grey zone the Act does not expressly settle. In practice, analytics and advertising are usually part of offering the service, and the safer reading is that they are in scope. The DPDP to GDPR mapping sets the two regimes side by side.
What is exempt under section 17?
Section 17 exempts processing necessary for legal claims, court and regulatory functions, preventing or investigating offences, court-approved mergers, tracing loan defaulters' assets, and contract processing of foreign people's data in India. For those purposes most duties fall away, but responsibility and security safeguards under section 8(1) and 8(5) still apply.
Three further exemptions work differently. Research, archiving and statistics are exempt from the whole Act if no individual decision is taken and the standards in the Second Schedule to the DPDP Rules 2025 are met. The government may exempt notified instrumentalities of the State. And section 17(3) lets it exempt classes of Data Fiduciaries, including startups, from notice, accuracy, erasure, SDF and access duties, but only by notification: the category exists in the Act, and an exemption exists only once a notification names your class.
Each exemption is tied to a purpose, not to a company. A BPO exempt under section 17(1)(d) for its clients' customer data is fully in scope for its own employees' data. Write down which processing each exemption covers and why, because the question will be asked about the processing, not about you.
How the checker reaches its answer
The questions run in the order the Act does. Personal data first, then digital form, then the territorial tests, then the exclusions in section 3(c), then the exemptions in section 17. The first answer that takes processing out of scope ends the check, because nothing after it matters. If nothing does, the result lists the chapters that apply and adds the ones your answers trigger: section 9 if children may be involved, section 8(2) if you use processors, section 16 if data leaves India.
It does not ask whether you are a Significant Data Fiduciary, because that is not something you can answer about yourself. Designation is by government notification; the Significant Data Fiduciary checker explains how the section 10 factors are likely to read for you. Once you know you are in scope, the DPDP compliance checklist turns the result into work, and the DPDP Act guide explains each duty. When you are ready to evidence consent rather than describe it, DPDP compliance on the platform is where that happens.
The things people ask us
Does the DPDP Act apply to small businesses?
Yes. The Act has no size, turnover or user-count threshold. A small business processing customer or employee data digitally in India is a Data Fiduciary with the same core duties as a large one. Section 17(3) allows the government to exempt classes such as startups from some duties, but only by notification, so check for one before relying on it.
Does the DPDP Act apply to employee data?
Yes. Employee data is personal data and is in scope. Section 7(i) makes employment purposes a legitimate use, so much HR processing needs no consent, but only within what that clause covers. Security, breach reporting, retention and the other duties still apply.
Does the DPDP Act apply to B2B companies?
Usually. Business contacts are individuals, so a sales pipeline of names, work emails and phone numbers is personal data. A B2B SaaS company is also typically a Data Processor for the personal data its customers load into the product, and a Data Fiduciary for its own customer account and marketing data.
Does the DPDP Act apply to publicly available data?
Not to personal data made publicly available by the person it relates to, or by someone legally required to publish it: section 3(c)(ii). The Act's own illustration is a person's views posted publicly on social media. It does apply once you combine that data with data you collected yourself, or where the data was made public by someone else without a legal duty to publish it.
Does the DPDP Act apply to paper records?
Only once they are digitised. Section 3(a) covers personal data collected in digital form, or collected in non-digital form and digitised afterwards. A paper register that is never scanned or typed up is outside the Act; the same register photographed for a shared drive is inside it.
Can this checker tell me for certain whether the Act applies?
No. It applies the section 3 and section 17 tests to your answers, and those tests turn on facts a form cannot see: what counts as offering services in India, which purposes an exemption actually covers. Treat the result as a structured first pass, and have counsel confirm any exclusion you intend to rely on.
In scope is where the work starts.
Once you know the Act applies, the job is proof: which notice each person saw, what they agreed to, and when their data fell due for erasure. That is what the platform records.