Chapter I — Preliminary
Section 3 — Application of Act
3. Subject to the provisions of this Act, it shall—
(a) apply to the processing of digital personal data within the territory of India where the personal data is collected––
(i) in digital form; or
(ii) in non-digital form and digitised subsequently;
(b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;
(c) not apply to—
(i) personal data processed by an individual for any personal or domestic purpose; and
(ii) personal data that is made or caused to be made publicly available by— (A) the Data Principal to whom such personal data relates; or (B) any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.
Illustration. X, an individual, while blogging her views, has publicly made available her personal data on social media. In such case, the provisions of this Act shall not apply. CHAPTER II OBLIGATIONS OF DATA FIDUCIARY
Source: The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Act No. 22 of 2023, Gazette of India Extraordinary, 11 August 2023; SHA-256 4deb23981d30… — verified copy
Plain-language note
Plain-language note pending
Questions people ask about this provision
- Who needs to comply with the DPDP Act?
- What is the DPDP Act 2023?
- Does the DPDP Act apply to small businesses and various sectors like MSMEs, law firms, fintechs, and educational institutions?
- Is data localization mandatory for all companies under the DPDP Act?
- What are the compliance requirements under the DPDP Act?
- Does the DPDP Act apply to foreign entities processing data related to Indian users or operations?
- What is a Data Processor under the DPDP Act?
- Can a company be both a Data Fiduciary and a Data Processor under the DPDP Act?
Taught in What Is Dpdpa