How DPDP applicability actually works
The Digital Personal Data Protection Act, 2023 is written more simply than most compliance content makes it sound, and it goes wrong in the same few places every time.
- Digital only.Section 3(a), read with the definition of “digital personal data” in section 2(m), keeps paper records that have never been digitised outside the Act entirely — not lower-risk, out of scope.
- Location of processing, not nationality of the person. Processing digital personal data within India brings you into scope under section 3(a) regardless of where the individuals themselves are. Processing that happens outside India is covered separately, and only, under section 3(b), when it connects to offering goods or services to people in India.
- The outsourcing carve-out is named, not implied.Section 17(1)(d) exempts processing the data of individuals outside India, done only because of a contract with someone outside India — but the exemption reaches Chapter II and III duties, not the Data Fiduciary’s overall responsibility (section 8(1)) or its duty to keep reasonable security safeguards (section 8(5)). Those two survive.
- No Significant Data Fiduciary has been notified.Section 10 lists factors the Central Government may weigh — volume and sensitivity of data, risk to individuals, and matters like electoral-process or state-security impact — not a number a business can test itself against. Anything claiming a specific user-count or turnover threshold for this is guessing.
- Applying and being enforceable are different.The DPDP Rules, 2025 switched on the Data Protection Board first; the obligations that actually change how a business runs — notice, consent, security safeguards, breach reporting, data-principal rights — and the penalties behind them commence by 14 May 2027.
None of that is a reason to leave it until 2027. Building a data map, rebuilding consent capture and re-papering processor contracts is slow work in most businesses, and investors and enterprise customers are already asking about DPDP readiness in diligence, well ahead of the legal deadline. See DPDP Act compliance for how CapEasy scopes this for a startup or SME rather than an enterprise security programme.

