What counts as personal data under the DPDP Act?
A simple test for what is — and isn't — personal data under the Act.
The identifiability test
The deciding question is whether an individual can be identified by the data or in relation to it. A standalone, truly anonymous statistic is not personal data. But a customer ID, an IP address tied to an account, or a CCTV still that shows a recognisable face all identify someone, so they qualify.
Common examples people miss
Teams often overlook online identifiers (cookies, device IDs, login tokens), CCTV and call-recording data, vehicle numbers, and 'pseudonymised' records that can still be re-linked to a person. All of these are personal data and carry obligations.
Sensitive data and children
The Act does not create a long separate 'sensitive data' category the way some laws do, but financial, health, biometric and children's data carry higher real-world risk and attract stricter handling and heavier penalties in practice. Treat them with extra care.
Frequently asked questions
Is anonymised data covered by DPDP?
No — if data is genuinely anonymous and cannot identify anyone, it falls outside the Act. But weak 'pseudonymisation' that can be reversed is still personal data.
Are IP addresses and cookies personal data?
Generally yes, when they can be linked to an individual or an account. Online identifiers are treated as personal data.
Is business or company data personal data?
Data about a company as an entity is not, but data identifying individuals within it — employees, contacts, directors — is personal data.
Know your data, then map it
Start with the DPDP Glossary, then build a data inventory to see every place personal data lives in your business.
DPDP Glossary