Skip to content

Applicability and roles

DPDP — not yet effective

Act sections 3 and 4 are scheduled for 13 May 2027.

The Act applies to processing of digital personal data in India where the data is collected in digital form or collected non-digitally and subsequently digitised. It also applies outside India where processing is in connection with offering goods or services to Data Principals within India. It excludes processing by an individual for a personal or domestic purpose and personal data made publicly available by the Data Principal or by another person legally obliged to make it public.

The public-availability exclusion is not a permission to ignore other law, contractual limits, security or provenance. Record who made the data public, the legal obligation if any, the source, capture date and intended purpose.

RoleDeciding factProduct treatment
Data Principalindividual to whom personal data relates; parent/guardian in specified casesrights identity and subject reference
Data Fiduciarydetermines purpose and means of processingaccountable entity, purpose and control owner
Data Processorprocesses on behalf of a Data Fiduciaryinstruction, contract, subprocessor and evidence boundary
Significant Data FiduciaryData Fiduciary notified by Central Governmentdesignation-source field; never inferred as legal status
Consent ManagerBoard-registered person enabling a Principal to manage consentseparate statutory profile and operating entity

A supplier can be a processor for one activity and an independent Data Fiduciary for another. A group company is not automatically the same Fiduciary. Classify per processing activity:

Who chooses the purpose?
Who determines essential means?
Whose notice names the processing?
Who receives the Data Principal request?
Can the service provider reuse data for its own purpose?
Which entity contracts with the Data Principal?

The minimum record is:

FieldRequirement
legal entity and India nexusregistered name, identifiers, establishments, goods/services offered in India
product/channelweb, app, branch, partner, employee, device
Data Principal populationscustomer, prospect, employee, child, patient, merchant, vendor contact
digital-data pathcollected digitally or later digitised
purpose and decision ownernamed accountable business owner
processing roleFiduciary, Processor or other with rationale
exclusion/exemptionexact provision, facts, reviewer, expiry/review
sector statuslicence, regulator, entity category, activity
source versionprimary source IDs and legal-configuration version

The Act makes the Data Fiduciary responsible for processing done on its behalf and requires a valid contract before engaging a Data Processor. OpenDPDP therefore models customer instruction, allowed purpose, data categories, systems, countries, subprocessors, safeguards, incident propagation, return/deletion and audit evidence. It does not claim every processor obligation arises directly under the DPDP Act; sector regulation and contract may add direct or more specific duties.

  • Given a group with three Indian entities, when a purpose is approved, then the record names one accountable entity and does not default to the group brand.
  • Given a SaaS vendor reusing telemetry for its own product purpose, when classified, then that activity cannot remain only under the customer-processor instruction.
  • Given an overseas service with no India establishment, when it targets goods or services to Principals in India, then the extraterritorial assessment is required.
  • Given public-profile data, when imported, then provenance and exclusion rationale are mandatory before processing begins.