The DPDP Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to Data Principals in India. It covers personal data collected in digital form, and personal data collected in non-digital form that is subsequently digitised. It does not apply to personal data processed by an individual for purely personal or domestic purposes, or to personal data that a Data Principal has made publicly available themselves or that is required by law to be made public.
The extraterritorial reach is the part overseas companies most often miss: serving Indian customers brings you within scope regardless of where you are incorporated or where your servers sit.
The digitisation point matters too. A paper form is outside scope until you scan or key it in, at which moment the data becomes subject to the Act.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →