Does DPDP Apply to My Company? Section 3, Answered Directly
Almost certainly yes. The exclusions in section 3 are narrower than most people expect, and there is no threshold for company size, revenue or data volume.
The short answer
Section 3 of the DPDP Act says it applies to:
- The processing of digital personal data within the territory of India, where the personal data is collected in digital form, or in non-digital form and digitised subsequently.
- Processing of digital personal data outside the territory of India, if that processing is in connection with any activity related to offering goods or services to Data Principals within India.
It does not apply to personal data processed by an individual for a personal or domestic purpose, or to personal data made publicly available by the Data Principal herself, or by someone under a legal obligation to publish it.
The paper records point people miss
Section 3(a)(ii) catches personal data collected in non-digital form and digitised subsequently. A paper form that gets scanned, or details typed off a physical document into a system, is inside the Act from the moment it is digitised.
Organisations that still collect on paper often assume the Act is about their app or website. It is about the data, not the collection channel.
What the exclusions actually cover
The personal or domestic purpose exclusion is about individuals, not businesses. An individual keeping a contacts list is outside; a sole proprietor processing customer data for the business is not.
The publicly available exclusion is narrower than it sounds. It covers data made public by the Data Principal, or by a person under a legal obligation to publish it. The Act gives the example of an individual who publishes her own details while blogging. Data that became public through a leak, or that someone else published without obligation, is not covered.
Scraping publicly visible profiles and treating the result as exempt is a common and expensive misreading. The exclusion asks who made the data public and why, not whether you could see it.
Infosek Team
If you are outside India
Section 3(b) reaches processing that happens entirely outside India, provided it is connected with offering goods or services to Data Principals in India. There is no requirement for an Indian entity, an Indian server or a rupee transaction.
A SaaS company incorporated elsewhere, hosting elsewhere, with Indian customers, is within scope.
So what actually varies between companies?
Not whether the Act applies, but how much of it applies:
- Every Data Fiduciary carries the core obligations: notice under Rule 3, security safeguards under Rule 6, breach intimation under Rule 7, erasure under Rule 8, and rights handling under Rule 14.
- Significant Data Fiduciaries, notified by the Central Government under section 10, additionally appoint an India-based Data Protection Officer and an independent data auditor, and under Rule 13 undertake a Data Protection Impact Assessment and audit every twelve months.
- Data Processors act on behalf of a Data Fiduciary and are bound largely through the contract that Rule 6(1)(f) requires.
- Startups may be exempted from certain provisions under section 17(3), but only where the Central Government notifies them as such. The power exists; it is not automatic.
The practical test
Do you hold any information about identifiable individuals in digital form, whether customers, employees, users, leads or vendor contacts, and are you not an individual doing it for personal reasons? Then the Act applies to you, and the question worth spending time on is which obligations bite hardest, not whether you are in scope.
Common questions
Does the DPDP Act apply to small companies?
Yes. Section 3 sets no threshold for company size, revenue or volume of personal data. It applies to the processing of digital personal data within India, and to processing outside India where that processing is connected with offering goods or services to Data Principals in India. Company size affects whether you are notified as a Significant Data Fiduciary, not whether the Act applies.
What is excluded from the DPDP Act?
Section 3(c) excludes two things: personal data processed by an individual for a personal or domestic purpose, and personal data made publicly available either by the Data Principal herself or by someone under a legal obligation to make it public.
Not sure what applies to you?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment