DPDPA Section 3: Application of the Act and Core Exemptions

DPDPA Section 3: Application of the Act and Core Exemptions

Determine if your business falls under India’s privacy law. Explore DPDPA Section 3 to understand DPDP Act applicability, core rules, and DPDP exemptions.

Priyanka Choudhury

Written by

Priyanka Choudhury

Date

Read time

6 min

Compliance does not start with a checklist. It starts with a boundary. Before you can build a privacy program, you need to know if you are even standing inside the blast radius.

That is what DPDPA Section 3 does. It defines exactly when India’s Digital Personal Data Protection Act applies to your operations,and more importantly, when it does not. It is the starting point for scoping your entire compliance effort.

What DPDPA Section 3 Actually Covers

The rule is brutally simple. Section 3 applies to the processing of digital personal data within India where the personal data is collected either:

  • in digital form, or
  • in non-digital form and then digitised.

It also applies to the processing of digital personal data outside India, provided the processing is in connection with any activity related to offering goods or services to individuals in India.

In short: if you process personal data in India and it touches a hard drive, the Act applies. If you process it outside India but the processing is tied to goods or services offered to people in India, the Act still applies.

Two core ideas dictate this boundary:

  • Digital personal data means personal data in digital form.
  • Processing includes any operation on data,collection, storage, use, sharing, or deletion.

The Core DPDP Exemptions (Clear Carve-Outs)

Section 3 does not apply to everything. It offers two clear carve-outs:

  • Personal data processed by an individual for any personal or domestic purpose.
  • Personal data made publicly available by the individual to whom the data relates, or by any other person who is under a legal obligation in India to make it public.

If an individual publicly posts her own personal data on social media, the Act does not apply to that posted data.

Processing Within India: The Default Rule

The threshold for DPDP Act applicability is not about profit; it is about pixels. If you process personal data in India and the data exists in digital form at any point, the Act applies by default.

Your reason or business model does not matter. Whether you are a commercial operator, a nonprofit, or a local club, the test is strictly about where the processing occurs and whether the data is digital.

Key implications:

  • Internal systems, customer platforms, HR tools, marketing databases, and logs are all in scope if operated in India and holding digital personal data.
  • If you collect personal data on paper in India and later scan or enter it into a system, it is in scope the second it is digitised.

Extraterritorial Reach: Borders Won’t Save You

A server in Frankfurt does not grant you immunity. If processing takes place outside India but is in connection with offering goods or services to people in India, the Act applies. The physical location of your servers or offices does not remove this obligation if your activity targets individuals within India.

Representing the extraterritorial reach of DPDPA Section 3.

Practical signals that you are connected:

  • You onboard or support individuals located in India.
  • You price, localize, or market to India-based users.
  • You deliver services to India-based accounts, even if the service is free.

The Personal or Domestic Use Exemption

The law is not interested in your diary. Personal or domestic use by an individual falls outside the Act. But this is a narrow, household exemption.

It typically covers personal notes, diaries, and lists kept by an individual. It covers personal photo albums, communication with family or friends, and home CCTV used for private security without wider sharing.

Where people lose the exemption:

The moment an activity becomes business or public-facing, the exemption evaporates. Examples include:

  • A blogger who starts running ads and tracking visitors.
  • A creator analyzing follower data to monetize content.
  • An individual renting rooms and collecting guest IDs.
  • Sharing home CCTV footage publicly or as a routine feed.

The principle for teams is simple: do not treat data you receive from individuals as household use. The exemption is for individuals processing their own data for personal life, not for organizations running commercial activities.

The Publicly Available Data Exemption

The Act ignores personal data that is already public,but only if it was made public through specific, authorized channels. It must be made public by the individual themselves, or by another person legally required to do so.

Two boundaries matter:

  • Voluntary public disclosure by the individual qualifies. This includes a person making a public profile, publishing a bio on a personal site, or posting public comments.
  • Public disclosure under a legal obligation also qualifies. This includes company registry information, electoral rolls, court judgments, property records, or intellectual property filings when the law mandates publication.

What does not qualify?

Data leaked in a breach. A breach is neither a voluntary nor a legally mandated disclosure. Data taken from private or limited-access profiles, or data made public by someone who had no legal duty to publish it, remains fully in scope.

Use caution with aggregation. Processing personal data that is truly public may be outside the Act. But once you combine that data with non-public data, or process it in a way that goes beyond reasonable expectations, your wider processing can fall right back into scope.

Addressing Common Misreads

People like to read things into the law that aren’t there. Some summaries attribute additional exemptions to Section 3, claiming it covers processing for enforcing legal rights or for journalistic, academic, artistic, or literary purposes.

Read the statutory text. Section 3 lists exactly two exemptions: personal or domestic use, and publicly available data made public by the individual or under legal obligation.

Other exemptions and partial exemptions appear elsewhere in the Act. Do not rely on Section 3 to cover legal claims or journalism. Scope your exemptions with the actual text you are applying.

How to Run a DPDP Act Applicability Test

A flowchart illustrating the applicability of the DPDP Act based on processing location.

Use a simple decision flow to determine your exposure:

1) Where is processing happening?

  • In India: If personal data is or becomes digital, the Act applies unless a carve-out fits.
  • Outside India: Check if the processing connects to offering goods or services to people in India. If yes, the Act applies.

2) Do you qualify for a carve-out?

  • Is the processing purely personal or domestic by an individual? If yes, it is outside scope.
  • Is the data made public by the individual or under a legal obligation? If yes, that public data is outside scope.

3) Mixed use or mixed sources?

  • Treat the non-exempt parts as fully in scope.
  • If in doubt, assume applicability and document exactly why.

Practical Implications for Teams

  • Treat Section 3 as your gatekeeper. If you process digital personal data in India, you are likely in.
  • Extraterritorial claims do not shield you if you target Indian individuals. Your compliance posture must reflect operational reality.
  • Do not stretch the personal or domestic exemption. It does not cover side hustles, monetized content, or membership operations.
  • Handle public data with discipline. It may be exempt as public, but combining it with non-public data can bring the processing within the Act.

A clean, documented applicability assessment is the first control auditors look for. Keep records of your determination, the data flows considered, and the basis for any carve-outs.

The Boundary is Just the Beginning

Section 3 is straightforward to read, but execution rarely is. Real data flows cross borders, blend public and non-public sources, and involve third parties. The risk is not in reading the section. It is in proving your scoping decisions and keeping them current as your operations evolve.

At Regodit, we give teams a structured way to model data flows, document DPDPA Section 3 applicability, and maintain evidence that withstands scrutiny. Because a scoping decision you cannot prove is just a guess. If operationalizing DPDP scope decisions and tracking exemptions is on your plate, schedule a conversation with us and see how to make it manageable.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →