
DPDPA Section 1: Short Title, Extent and Commencement
Master DPDP Act compliance with our comprehensive guide for data fiduciaries. Discover key requirements, penalty risks, and steps to protect user privacy.
Written by
Sahil Pugalia
Date
Read time
6 min

Most organizations read the first section of a privacy law and immediately skip ahead to the penalties. That is a mistake. DPDPA Section 1 isn’t just a polite introduction. It defines the blast radius. It answers the only three questions that actually matter: what the law is called, who is caught in its net, and when the clock starts.
If you own, operate, or advise on systems that process personal data connected to India, this is where your compliance reality begins.
Short Title: What the law is
The law is officially the Digital Personal Data Protection Act, 2023. The name itself is a scoping exercise.
Digital limits coverage. Purely paper records sitting in a basement are out of scope. But the moment you scan that paper, you cross the threshold.
Personal data means data tied to an identifiable human. True anonymization is your only escape hatch here.
Protection signals that this is a framework of hard rights and obligations, not a set of suggestions.
And the year 2023 separates this final reality from years of scrapped drafts and theoretical bills.
Territorial and Extraterritorial Extent
Section 1(2) extends to the whole of India, and it does not care where your servers live. DPDPA applicability rests on two distinct pillars.
a) Processing within India
If you process digital personal data within India, you are in scope. This covers data collected directly in digital form, and data collected on paper but digitized later.
Take a local clinic that scans paper intake forms and uploads them to an electronic system. They are covered. A business collecting customer details through a website or app in India is covered, even if the backend database sits in another country.

b) Processing outside India when offering goods or services to people in India
This is the extraterritorial hook. If you process data outside India, but that processing is connected to offering goods or services to individuals inside India, the Act applies.
The connection test is broad. You cannot hide behind a foreign headquarters if your product targets Indian users. Clear signals that you are offering to India include:
- Pricing in INR.
- Acceptance of Indian payment methods.
- Shipping or service availability in India.
- Apps available in Indian app stores.
- Marketing or user interfaces targeted at Indian users.
A website that merely happens to be accessible from India without targeting Indian users is a weaker case. But explicitly geo-blocking Indian users or excluding Indian residents may help demonstrate that the service is not being offered to individuals in India.
Unlike the GDPR, DPDPA Section 1 does not explicitly add a separate test for behavioral monitoring. It focuses purely on the offering of goods and services.
Enforcement considerations for foreign entities
Extraterritorial laws always invite the same cynical question: How will they actually enforce this?
The Act and forthcoming rules have answers. Foreign entities serving Indian users may face compliance obligations under the Act and Rules, and enforcement may occur through a combination of regulatory directions, cooperation mechanisms, and restrictions on operations within India. Ignore the directions, and the consequences get physical: non-compliant foreign services face blocking orders or restrictions through payment channels in India.
Cross-border investigations will rely on information requests and cooperation with foreign authorities. Where there is no local presence, orders may be enforced through alternative measures and reputational pressure. Treat this as a hard operational requirement. If you target India, build for DPDPA compliance.
Commencement and phased implementation: When it applies
Section 1(3) dictates that the Act comes into force on dates notified by the Central Government in the Official Gazette. Notice the plural. Different provisions can start on different dates.
The DPDPA commencement date is not a single flip of a switch. It is a phased rollout. The government needs time to constitute the Data Protection Board. Organizations need time to rewrite contracts and update systems.
Expect core definitions and institutional provisions to go live first, followed by obligations like notice, consent, security, and cross-border transfers. Complex requirements,like those for children’s data, significant data fiduciaries, and audits,are usually staged later.
Crucially, this applies prospectively to processing after commencement. But if you hold legacy data and your old consent models do not meet DPDPA standards, you will need to secure compliant consent to keep using it.
Practical scope boundaries
Use these bright lines to figure out if you are in the blast radius:
- If you never digitize data, the Act does not apply to those paper records.
- If you digitize at any stage, the Act applies to that digital processing.
- If you process data abroad but offer goods or services to people in India, the Act applies to that processing.
Server location is a technical detail, not a legal shield. The context of collection and the target audience carry the weight.

Who is covered in practice
The scope is entirely size-agnostic. It does not care if you are a multinational or a three-person shop. It captures:
- Indian businesses processing digital personal data.
- Foreign entities serving people in India, even without a local entity.
- Professionals and small firms the moment they digitize client data.
- NGOs and not-for-profits that process digital personal data.
- Government and public authorities, subject to specific exemptions elsewhere in the Act.
What this changes for operators
If you operate in India or serve Indian users, the abstract law is now an engineering problem.
Map where and how you collect personal data. Identify exactly what gets digitized and when. Clarify your offering posture toward India,if you accept Indian payments or ship there, assume you are covered. Prepare for potential cross-border transfer obligations under Section 16, which allows transfers with safeguards. Plan for contractual and technical controls.
If you are outside India and want to stay out of scope, you have to mean it. Remove India-facing signals. Drop INR pricing, avoid Indian payment methods, pull out of Indian app stores, and implement geo-blocking.
Immediate preparation checklist
Do not wait for the final enforcement date to start building. Use this staged plan:
Assessment
- Inventory personal data by category and system.
- Map data flows from collection to deletion.
- Identify your legal basis for processing, including consent where required.
- Confirm whether you may be classified as a significant data fiduciary under criteria that will be notified.
Technical and process build-out
- Update notices and consent mechanisms to match DPDPA standards.
- Strengthen security controls and breach detection.
- Define retention periods and deletion routines.
- Set up a channel for individual rights requests where applicable.
Governance and documentation
- Appoint accountable owners. If designated as a significant data fiduciary, prepare for a Data Protection Officer.
- Prepare vendor terms that reflect DPDPA duties.
- Document policies, procedures, and records that actually reflect reality.
- Establish a grievance redressal mechanism accessible to people in India.
Ongoing operations
- Monitor rulemaking and guidance.
- Conduct impact assessments and audits if required.
- Track enforcement signals, especially for cross-border operations.
Legal footing and alignment
Section 1 sits on solid constitutional footing. Parliament can legislate for the whole of India and may provide extraterritorial operation. This aligns with established international practice that allows regulation of foreign conduct with domestic effects, placing the DPDPA alongside major global regimes that apply to foreign providers who target local users.
Closing thoughts
Section 1 is not just formalities to skim past. It defines who must comply, when obligations start, and how far India’s jurisdiction reaches. The most expensive mistakes come from underestimating extraterritorial coverage, ignoring the digitization trigger, or waiting for final enforcement before laying the groundwork.
The cleanest execution starts with a hard look at your data inventory, a targeting analysis, and a plan for staged compliance. Getting this right requires coordination across legal, engineering, security, product, and vendor teams.
At Regodit, we help teams translate statutory text into concrete controls, timelines, and evidence. Because compliance isn’t about having a plan on paper,it’s about having a system that works when the commencement clock starts ticking. If you want a focused discussion on scope, commencement planning, and practical controls, schedule a call with our team.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
