Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Core Concept

Personal Data

Personal data under India’s Digital Personal Data Protection Act, 2023 is any data about an individual who is identifiable by, or in relation to, that data. It covers direct identifiers such as a name or mobile number, and indirect identifiers like account, device or online data that can be linked back to a person.

TL;DR

Personal data under India’s DPDP Act, 2023 is any data about an individual who can be identified by it, or in relation to it, held in digital form.

  • Covers direct identifiers (name, mobile, Aadhaar, PAN) and indirect ones (account, device, cookie, IP) that link to a person.
  • The Act regulates digital personal data: information born digital, or collected on paper and later digitised.
  • There is no separate “sensitive personal data” category under the DPDP Act.
  • Practical test: if you can identify or single out a person from it, treat it as personal data.
Defined inSection 2(t)
CategoryCore Concepts
ScopeDigital personal data
Applies toAll personal data an organisation handles in digital form

What Does the DPDP Act Say About Personal Data?

DPDP Act, 2023 · Section 2(t)

“personal data” means any data about an individual who is identifiable by or in relation to such data.

What Is Personal Data in Simple Words?

If a piece of information can be tied back to a specific person, on its own or combined with other data you hold, it is personal data. The law is not limited to obvious identifiers like a name or phone number. The real test is whether the data relates to someone who can be identified.

Identification can be direct, through a name, email, Aadhaar or PAN, or indirect, through an account, device, login or record that links to a person. The phrase “by or in relation to” matters: data is not outside the Act simply because it is pseudonymous, coded or incomplete on its own.

When Does the DPDP Act Apply to Personal Data?

The Act governs digital personal data: information collected in digital form, or collected on paper and later digitised. It can also apply outside India where personal data is processed in connection with offering goods or services to people in India.

ⓘA paper form on its own may sit outside the Act. Once its details are entered into a CRM, HRMS, spreadsheet or marketing tool, they become digital personal data within scope.

Personal Data vs Digital Personal Data: What Is the Difference?

The two are closely linked. Personal data is any information about an identifiable person. Digital personal data is that same information in digital form, and that is what the Act regulates. Lead lists, webinar sign-ups, contact-enrichment data and email-engagement records almost always involve digital personal data.

Personal Data: Common Examples

Personal data appears across almost every system a business runs. Common categories include:

CategoryTypical data
IdentityName, age, date of birth, address, photograph, signature
ContactMobile number, personal and work email, social handle
Government IDsAadhaar, PAN, passport, voter ID, driving licence, employee ID
FinancialBank details, UPI ID, card data, transactions, credit information
CustomerCRM profiles, purchase history, support tickets, chat and call logs
EmploymentSalary, performance reviews, attendance, job-applicant records
Health & biometricHealth records, biometric data, insurance, disability information
OnlineIP address, cookie and device IDs, precise location, usage logs
Recorded mediaCCTV footage, voice recordings, facial images, access logs

Is This Personal Data? Common Edge Cases

Whether something is personal data depends on whether you can identify a person in your real context, not on the label attached to it.

Data elementPersonal data?Why
Work email (name@company.com)YesIdentifies a specific individual
Employee ID (E-10458)UsuallyThe employer can map it to one person
IP address with login timesOftenCan be linked to an account or user
Device ID tied to an app accountYesIdentification through the account record
Cookie or advertising IDOftenUsed to recognise, profile or target a person
Company registration numberNoIdentifies an entity, not an individual
Users in a city (aggregate)Not usuallyNo individual is singled out
Genuinely anonymised analyticsUsually noOnly if re-identification is not reasonably possible

Avoid blanket claims that every IP address or cookie is always personal data. The Act’s test is identifiability in the context in which you actually process the information.

Does the DPDP Act Have a Sensitive Personal Data Category?

Unlike some earlier Indian proposals and certain foreign laws, the DPDP Act does not create a distinct statutory category of sensitive personal data. That does not mean health, financial, biometric or identity data can be treated casually. These carry a greater risk of harm, so organisations should apply stronger, risk-based safeguards, access controls, retention limits and governance.

Why the Personal Data Definition Matters for Compliance

Identifying personal data correctly is the starting point for DPDP compliance. Once a dataset meets the definition, an organisation (acting as a data fiduciary) should be able to say why it is collected, on what legal basis such as consent, who can access it, how long it is kept, and how it will honour Data Principal rights and breach-response duties.

Operational rule

If a person can be recognised, singled out, contacted, profiled or linked to a record through information you hold or can reasonably obtain, treat it as personal data until a formal assessment shows otherwise.

Compare

See how this term differs from the one it is most often confused with.

Personal Data vs Digital Personal Data →

Related terms

Related sections of the Act

Related Rules

Primary sources

Frequently Asked Questions About Personal Data

Does the Act cover paper records?

It covers digital personal data, including information first collected on paper and later digitised. Purely offline records that are never digitised sit outside its scope.

Is anonymised data personal data?

No, if it genuinely cannot identify anyone. Once it can be linked back to a person, it becomes personal data again.

Is a business email address personal data?

Usually yes, where it identifies an individual, such as firstname.lastname@company.com. A generic address like info@company.com may not.

Is an employee ID personal data?

Usually yes, because the employer can map the ID to a specific employee through its records.

Are IP addresses and cookies always personal data?

Not always. They are personal data when they can be linked to an account, device or individual. The test is identifiability in your actual processing context.

Continue learning

ⓘThis page is general information about the DPDP Act, not legal advice. For decisions on your specific situation, obtain qualified legal advice.