Explainer 6 min read · 1 July 2026

Does the DPDP Act Apply to My Business? A 2-Minute Test

Not sure if India's DPDP Act 2023 applies to you? Run this quick test based on Section 3. Covers who’s in, the narrow exclusions, whether there’s a small-business exemption, and employee data.

S

Sedhu

Founder, EasyDP · Published 1 July 2026

Download the free one-page guide

Branded PDF summary with a QR code back to this guide — print it for your desk or team.

PDF →

One of the most common questions Indian business owners ask is simple: does this law even apply to me? The answer is set by Section 3 of the DPDP Act 2023, and for most businesses it's a quick yes. Run the two-minute test below.

Quick Answer: Does DPDP Apply to You?

If your business collects any personal data of individuals in India in digital form — names, phone numbers, addresses, emails, payments — the DPDP Act 2023 applies to you (Section 3). It applies regardless of your size or turnover; there is no small-business exemption. The only carve-outs (Section 3(c)) are purely personal/domestic processing and data that is already lawfully public.

The 2-Minute Test

QuestionIf yes…
Do you collect customer names, phones, emails, or addresses digitally (website, app, WhatsApp, Instagram, a form)?Covered — Section 3(a)
Do you write customer details on paper and then enter them into any software, phone or spreadsheet?Covered — Section 3(a) (digitised)
Are you based outside India but sell goods/services to people in India?Covered — Section 3(b)
Do you store staff/employee records digitally?Covered — the Act applies (see below)
Is the only "data" you handle your own personal contacts, for personal use?Not covered — Section 3(c)(i)

Answered "yes" to any of the first four? The DPDP Act applies to you. For a personalised read, run the free DPDP checker.

Who Is Covered (Section 3(a) and 3(b))

The Act covers digital personal data collected in digital form, and personal data collected on paper that is later digitised — so the moment you type a customer's number into a phone or billing software, you're in. It also reaches businesses outside India whose processing is connected to offering goods or services to individuals in India.

Who Is Excluded (Section 3(c))

Only two narrow situations fall outside the Act:

  • Personal or domestic purpose (3(c)(i)): an individual processing data for their own personal or household use — for example, your personal phone contacts.
  • Publicly available data (3(c)(ii)): personal data made public by the individual themselves, or by someone legally obliged to publish it. The Act's own illustration: a blogger who publicly shares their own details online.

Neither exclusion helps an ordinary business processing customers' data.

Is There a Small-Business or Startup Exemption?

No — not currently. The Act does not exempt businesses by size or turnover. Section 17(3) gives the government the power to notify certain classes of Data Fiduciary — expressly including startups — to whom some provisions (such as notice and certain Section 8 duties) won't apply, and Section 17(5) allows time-limited exemptions. But no such notification has been issued, so every business processing digital personal data is fully covered today. Don't wait for an exemption that may never come.

What About Employee Data?

Yes, the Act applies to how you handle staff data. Employment-related processing is a "legitimate use" under Section 7(i), which means you don't need separate consent to process employee data for employment purposes — but every other obligation (security, transparency, honouring rights, breach reporting, deletion) still applies.

You're Covered — Now What?

If the Act applies to you, the practical next steps are the same for almost every business: a compliant notice, valid consent, basic security, a way to handle data requests, and a breach plan. Our 14-step SMB checklist walks through all of it, and your responsibilities as a business covers the legal detail.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Section 3 application; Section 7 legitimate uses; Section 17 exemptions).
  2. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.

This article is general information about the DPDP Act 2023, not legal advice. Section references are cited from the official text; verify against the current notified version for your specific situation.

DPDP ApplicabilitySection 3Small BusinessDPDPCompliance

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.