Free tool

DPDP Act applicability checker

Answer a few questions to see whether the Digital Personal Data Protection Act, 2023 applies to your business, the role you occupy, and what follows.

Your role
Rough scale (optional — for the flag below only)
The Act appliess.3(a) — processing happens within India

You process digital personal data within India, so the Act applies regardless of where the individuals themselves are.

You act as a Data Fiduciary here.

  • Give notice before or with the request for consent — s.5.
  • Process only on valid consent or a recognised legitimate use — ss.6–7.
  • Keep data accurate and complete where it is used to decide about someone, or shared onward — s.8(3).
  • Take reasonable security safeguards against a personal data breach — s.8(5).
  • Notify the Data Protection Board and every affected individual of a breach without delay, then file a detailed report to the Board within 72 hours — no severity threshold, so every breach is reportable — s.8(6).
  • Erase data once consent is withdrawn or the purpose is served, unless retention is required by law — s.8(7)–(8).
  • Publish contact details for a grievance point of contact (a DPO where one is appointed) — s.8(9).
  • Run an effective grievance-redressal mechanism — s.8(10), s.13.
  • Honour Data Principal rights on request — access (s.11), correction/erasure (s.12), nomination (s.14).

Timing: The Data Protection Board is already operational, but the day-to-day duties below — notice, consent, security safeguards, breach reporting, children’s consent, data-principal rights — are being switched on in phases under the DPDP Rules, 2025. The Act applying to you and being fully compliant today are different questions. Full compliance is due by 14 May 2027.

An estimate, not a quote. The Data Protection Board of India, and your own legal counsel produces the figure that actually applies to you — check there before you rely on a number. This checker orients you toward the right chapter of the Act — it cannot see your contracts, your actual data flows, or facts that change the answer.

What this checker deliberately leaves out

It does not test you against a Significant Data Fiduciary threshold — none has been published; only the Central Government can make that designation. It does not cover the narrower s.17(1) exemptions for legal claims, courts and tribunals, offence investigation, court-approved mergers or defaulter due-diligence — those are fact-specific and rare for a founder or SME. It does not check cross-border transfer restrictions under s.16, since none had been notified as of this checker’s last update. Section 17(3) lets the Central Government exempt startups specifically from notice, accuracy, erasure, Significant Data Fiduciary and access-request duties — no such notification has been issued yet, so this checker does not test for it, but it is worth watching if you are a recognised startup. And it never treats CapEasy, or anyone else, as a registered Consent Manager — that is a specific status registered with the Board, not a compliance service.

Want this checked properly?Getting the notice, consent flow and breach process right the first time is cheaper than redoing it after the Board asks a question.

How DPDP applicability actually works

The Digital Personal Data Protection Act, 2023 is written more simply than most compliance content makes it sound, and it goes wrong in the same few places every time.

  • Digital only.Section 3(a), read with the definition of “digital personal data” in section 2(m), keeps paper records that have never been digitised outside the Act entirely — not lower-risk, out of scope.
  • Location of processing, not nationality of the person. Processing digital personal data within India brings you into scope under section 3(a) regardless of where the individuals themselves are. Processing that happens outside India is covered separately, and only, under section 3(b), when it connects to offering goods or services to people in India.
  • The outsourcing carve-out is named, not implied.Section 17(1)(d) exempts processing the data of individuals outside India, done only because of a contract with someone outside India — but the exemption reaches Chapter II and III duties, not the Data Fiduciary’s overall responsibility (section 8(1)) or its duty to keep reasonable security safeguards (section 8(5)). Those two survive.
  • No Significant Data Fiduciary has been notified.Section 10 lists factors the Central Government may weigh — volume and sensitivity of data, risk to individuals, and matters like electoral-process or state-security impact — not a number a business can test itself against. Anything claiming a specific user-count or turnover threshold for this is guessing.
  • Applying and being enforceable are different.The DPDP Rules, 2025 switched on the Data Protection Board first; the obligations that actually change how a business runs — notice, consent, security safeguards, breach reporting, data-principal rights — and the penalties behind them commence by 14 May 2027.

None of that is a reason to leave it until 2027. Building a data map, rebuilding consent capture and re-papering processor contracts is slow work in most businesses, and investors and enterprise customers are already asking about DPDP readiness in diligence, well ahead of the legal deadline. See DPDP Act compliance for how CapEasy scopes this for a startup or SME rather than an enterprise security programme.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.