Applicability and roles
Act sections 3 and 4 are scheduled for 13 May 2027.
Scope test
Section titled “Scope test”The Act applies to processing of digital personal data in India where the data is collected in digital form or collected non-digitally and subsequently digitised. It also applies outside India where processing is in connection with offering goods or services to Data Principals within India. It excludes processing by an individual for a personal or domestic purpose and personal data made publicly available by the Data Principal or by another person legally obliged to make it public.
The public-availability exclusion is not a permission to ignore other law, contractual limits, security or provenance. Record who made the data public, the legal obligation if any, the source, capture date and intended purpose.
Role classification
Section titled “Role classification”| Role | Deciding fact | Product treatment |
|---|---|---|
| Data Principal | individual to whom personal data relates; parent/guardian in specified cases | rights identity and subject reference |
| Data Fiduciary | determines purpose and means of processing | accountable entity, purpose and control owner |
| Data Processor | processes on behalf of a Data Fiduciary | instruction, contract, subprocessor and evidence boundary |
| Significant Data Fiduciary | Data Fiduciary notified by Central Government | designation-source field; never inferred as legal status |
| Consent Manager | Board-registered person enabling a Principal to manage consent | separate statutory profile and operating entity |
A supplier can be a processor for one activity and an independent Data Fiduciary for another. A group company is not automatically the same Fiduciary. Classify per processing activity:
Who chooses the purpose?Who determines essential means?Whose notice names the processing?Who receives the Data Principal request?Can the service provider reuse data for its own purpose?Which entity contracts with the Data Principal?Applicability record
Section titled “Applicability record”The minimum record is:
| Field | Requirement |
|---|---|
| legal entity and India nexus | registered name, identifiers, establishments, goods/services offered in India |
| product/channel | web, app, branch, partner, employee, device |
| Data Principal populations | customer, prospect, employee, child, patient, merchant, vendor contact |
| digital-data path | collected digitally or later digitised |
| purpose and decision owner | named accountable business owner |
| processing role | Fiduciary, Processor or other with rationale |
| exclusion/exemption | exact provision, facts, reviewer, expiry/review |
| sector status | licence, regulator, entity category, activity |
| source version | primary source IDs and legal-configuration version |
Processor boundary
Section titled “Processor boundary”The Act makes the Data Fiduciary responsible for processing done on its behalf and requires a valid contract before engaging a Data Processor. OpenDPDP therefore models customer instruction, allowed purpose, data categories, systems, countries, subprocessors, safeguards, incident propagation, return/deletion and audit evidence. It does not claim every processor obligation arises directly under the DPDP Act; sector regulation and contract may add direct or more specific duties.
Acceptance tests
Section titled “Acceptance tests”- Given a group with three Indian entities, when a purpose is approved, then the record names one accountable entity and does not default to the group brand.
- Given a SaaS vendor reusing telemetry for its own product purpose, when classified, then that activity cannot remain only under the customer-processor instruction.
- Given an overseas service with no India establishment, when it targets goods or services to Principals in India, then the extraterritorial assessment is required.
- Given public-profile data, when imported, then provenance and exclusion rationale are mandatory before processing begins.