Does the DPDP Act apply to my company?

Does the DPDP Act apply to my company?
Applicability

Does the DPDP Act apply to my company?

The short answer for almost every Indian business is yes. Here is how to tell — and what it means when the answer is yes.

Quick Answer: The Digital Personal Data Protection Act 2023 applies to your company if it processes the digital personal data of individuals in India — and there is no exemption for small businesses or startups. A five-person company that stores customer names, emails, or phone numbers carries the same core obligations as a large enterprise. It also applies to companies based outside India if they offer goods or services to people in India. The only narrow carve-outs are purely personal or domestic use, and certain government processing. If you hold any customer, employee, or user data in digital form, assume the Act applies and plan for the 13 May 2027 enforcement deadline.

The test in one sentence

The DPDP Act applies whenever you process "digital personal data" of a "data principal" — that is, any information in digital form that can identify a living individual. Names, email addresses, phone numbers, login credentials, customer records, employee files, CCTV footage tied to a person, and order histories all qualify. Because almost every organisation collects at least some of this, the practical answer for the overwhelming majority of Indian companies is that the Act applies to them.

Crucially, the law does not scale its applicability to your size or revenue. There is no turnover threshold and no employee-count threshold below which you are exempt. A neighbourhood clinic, a single-location SaaS startup, a mid-sized BPO, and a listed enterprise are all Data Fiduciaries the moment they decide why and how personal data is processed.

What counts as "processing in India"

The Act covers processing of digital personal data that takes place within India. It also reaches outside India's borders: if your company is based abroad but offers goods or services to people in India, you are covered for that processing. So an overseas SaaS platform with Indian users, or a foreign e-commerce brand shipping to Indian addresses, falls within scope even without an Indian office.

Two situations sit outside the Act. The first is data processed by an individual for a purely personal or domestic reason — your own contacts list, for example. The second is specific government processing in the interest of matters like national security. Neither of these helps a normal commercial business, which is why the safe default is to assume coverage.

Fiduciary or processor — and why it matters

If your company decides the purpose and means of processing — you collect customer data to run your own service — you are a Data Fiduciary, with the full set of obligations. If instead you only process personal data on instructions from another organisation, you are a Data Processor, and your obligations flow through your contract with that fiduciary. Many companies are both: a fiduciary for their own employees and customers, and a processor when they handle a client's data. Sorting out which hat you wear for each data flow is one of the first things a readiness assessment establishes.

What "yes" actually obligates you to do

Once the Act applies, the core duties are consistent regardless of size. You must give individuals a clear, itemised notice of what you collect and why, and obtain valid consent or rely on a recognised legitimate use. You must process only for the stated purpose, keep data no longer than necessary, and delete it when the purpose ends. You must put reasonable security safeguards in place, honour data principal rights such as access, correction, and erasure, and notify the Data Protection Board and affected individuals if a breach occurs. Significant Data Fiduciaries — organisations the government designates based on data volume and risk — carry extra duties such as appointing a Data Protection Officer and running annual audits and impact assessments.

The penalties give these duties weight: failures around security safeguards can attract penalties of up to ₹250 crore. With substantive obligations enforceable from 13 May 2027, the realistic planning window is now, because a typical compliance programme takes several months to inventory data, close gaps, and reach audit readiness.

How to confirm your position in five minutes

Rather than guess, you can run a quick structured check on whether and how the Act applies to your specific business, what role you play in each data flow, and where your biggest exposures sit. That turns an abstract legal question into a concrete starting point for a readiness plan.

Frequently asked questions

Does the DPDP Act exempt small businesses or startups?

No. The Act contains no general exemption based on company size, turnover, or headcount. A small startup or a single proprietor that processes customer or employee personal data is a Data Fiduciary with the same core obligations as a large company. The government may later prescribe lighter obligations for certain notified classes of fiduciary, but no business should assume it is exempt by default.

Does the DPDP Act apply to a company based outside India?

Yes, if the company offers goods or services to individuals in India. The Act has extra-territorial reach: a foreign SaaS provider, e-commerce brand, or app with Indian users is covered for processing connected to that offering, even without a physical presence in India.

When do I actually have to be compliant?

The DPDP Rules 2025 set a phased timeline. The Data Protection Board and the penalty framework are already operational, Consent Manager registration opens around 13 November 2026, and the substantive obligations — notices, consent, security safeguards, breach reporting, retention limits, and data principal rights — become fully enforceable on 13 May 2027. Because programmes take months to implement, most organisations should already be in gap-assessment mode.

Find out exactly where your company stands

Run Niti Bharat's free DPDP Applicability Checker to confirm whether the Act applies, what role your business plays, and your top exposure areas — then get a clear next step.

Check DPDP Applicability (Free)
Previous Post Next Post

Get Free DPDP Checklist