Readiness assessment
Share this chapter
Home / The DPDP Act / Chapter I
Chapter I · Preliminary · Sections 1 to 3

Chapter I of the DPDP Act: When Does the Act Apply?

Chapter I sets the foundations of the Digital Personal Data Protection Act, 2023: what the Act is called and when it starts (Section 1), the vocabulary the whole Act runs on (Section 2), and the scope of what the Act applies to (Section 3). You read this chapter first to answer one question before any obligation matters: does the Act apply to what we do?

In short

Chapter I is the Act's front door. Section 1 fixes the name and the staggered start dates. Section 2 defines the 28 terms every later section relies on. Section 3 draws the boundary of the Act: it covers digital personal data processed in India, and processing done abroad when it targets people in India, while carving out purely personal or domestic use and certain publicly available data. If Section 3 does not bring your processing into scope, the rest of the Act does not apply to it.

Commencement status of this chapter

StatutoryChapter I does not commence as a single block. Under Section 1, the Central Government may appoint different dates for different provisions, and it has. Do not assume the whole chapter is either in force or not.

Section 1 – Short title and commencement In force
Effective 13 November 2025
Section 2 – Definitions In force
Effective 13 November 2025 (all definitions legally operative)
Section 3 – Application of the Act Not yet commenced
Scheduled to commence 13 May 2027 (Phase 3 substantive provisions)

Good practiceThe definitions are already live and the Data Protection Board is operational, so complaints can be filed now. The scope section commences with the main compliance obligations on 13 May 2027. Treat the period until then as build time, not a deferral: scoping whether the Act applies to you is a Section 3 exercise you should complete well before the deadline. Source: commencement notification G.S.R. 843(E) dated 13 November 2025.

The sections in this chapter

How these three sections work together

1
Is it in force yet, and when?

Section 1 tells you the Act starts on dates the Government appoints, and it has appointed a staggered timeline. This is why the definitions can be live while the scope section is not.

2
What do the words mean?

Section 2 fixes the vocabulary. Whether you are a Data Fiduciary, whether something is personal data, and what counts as processing are all Section 2 questions that decide how Section 3 reads for you.

3
Does the Act apply to us?

Section 3 uses those definitions to draw the boundary. Only once you are inside Section 3 do Chapter II obligations, Chapter III rights and the rest become relevant to your processing.

InterpretationThe practical sequence is Section 2 then Section 3: you cannot decide whether the Act applies without first knowing what its defined terms mean. Section 1 sits above both as the timing switch.

What a plain reading of Chapter I misses

The statutory text is short. The parts that trip organisations up are not on the page:

Definitions live, scope later

Section 2 is in force now but Section 3 is not until 2027. The Board and its complaint machinery already exist while the scope-defining provision is still pending. Plan to the earliest real obligation, not the latest.

Offline data can pull you in

Section 3(a)(ii) brings non-digital data into scope once it is digitised. Paper forms and records that are later scanned or keyed into a system become digital personal data. Many teams scope only their obviously digital systems.

The public-data carve-out is narrow

Section 3(c)(ii) excludes data made public by the Data Principal, or by someone under a legal obligation to publish it. It is not a general "anything on the internet is fair game" exception.

Personal use is genuinely personal

Section 3(c)(i) covers an individual using data for their own household purposes. Once activity becomes commercial or is monetised, it tends to fall outside this carve-out, even if it started as a personal account.

Does the DPDP Act apply to you?

A quick reading of Section 3. This is a starting screen, not a legal opinion; the detail and edge cases live on the Section 3 page.

1
Is the data digital, or will it be? Data collected in digital form, or collected on paper and later digitised, is in scope. Purely non-digital data that is never digitised is not.
2
Is it processed in India, or aimed at India from abroad? Processing within India is caught. Processing outside India is also caught if it is connected with offering goods or services to people in India.
3
Is it more than purely personal or domestic use? An individual handling data for their own household purposes is carved out. Commercial or organisational processing is not.
4
Is it outside the public-data carve-out? If the data was not made public by the person it is about, or by someone legally obliged to publish it, the carve-out generally does not apply.

Good practiceIf you answered "yes" through the gate, the Act likely applies and Chapter II obligations become relevant. If you are unsure, the readiness assessment and the full Section 3 analysis will sharpen the answer.

Primary sources

The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) – enacted text, Sections 1 to 3, via India Code and the Ministry of Electronics and Information Technology.
Commencement notification G.S.R. 843(E), dated 13 November 2025 – the phased commencement of the Act.
Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), dated 13 November 2025) – the operative Rules under the Act.

Last reviewed: August 2026. This page is guidance, not legal advice, and is not affiliated with the Government of India or the Data Protection Board. See our editorial policy and disclaimer.

Continue through the Act

Chapter I sets scope. Next comes what you must actually do once you are in scope.

Start readiness assessment