Core Concept
Personal Data
Personal data under India’s Digital Personal Data Protection Act, 2023 is any data about an individual who is identifiable by, or in relation to, that data. It covers direct identifiers such as a name or mobile number, and indirect identifiers like account, device or online data that can be linked back to a person.
TL;DR
Personal data under India’s DPDP Act, 2023 is any data about an individual who can be identified by it, or in relation to it, held in digital form.
- Covers direct identifiers (name, mobile, Aadhaar, PAN) and indirect ones (account, device, cookie, IP) that link to a person.
- The Act regulates digital personal data: information born digital, or collected on paper and later digitised.
- There is no separate “sensitive personal data” category under the DPDP Act.
- Practical test: if you can identify or single out a person from it, treat it as personal data.
What Does the DPDP Act Say About Personal Data?
“personal data” means any data about an individual who is identifiable by or in relation to such data.
What Is Personal Data in Simple Words?
If a piece of information can be tied back to a specific person, on its own or combined with other data you hold, it is personal data. The law is not limited to obvious identifiers like a name or phone number. The real test is whether the data relates to someone who can be identified.
Identification can be direct, through a name, email, Aadhaar or PAN, or indirect, through an account, device, login or record that links to a person. The phrase “by or in relation to” matters: data is not outside the Act simply because it is pseudonymous, coded or incomplete on its own.
When Does the DPDP Act Apply to Personal Data?
The Act governs digital personal data: information collected in digital form, or collected on paper and later digitised. It can also apply outside India where personal data is processed in connection with offering goods or services to people in India.
Personal Data vs Digital Personal Data: What Is the Difference?
The two are closely linked. Personal data is any information about an identifiable person. Digital personal data is that same information in digital form, and that is what the Act regulates. Lead lists, webinar sign-ups, contact-enrichment data and email-engagement records almost always involve digital personal data.
Personal Data: Common Examples
Personal data appears across almost every system a business runs. Common categories include:
| Category | Typical data |
|---|---|
| Identity | Name, age, date of birth, address, photograph, signature |
| Contact | Mobile number, personal and work email, social handle |
| Government IDs | Aadhaar, PAN, passport, voter ID, driving licence, employee ID |
| Financial | Bank details, UPI ID, card data, transactions, credit information |
| Customer | CRM profiles, purchase history, support tickets, chat and call logs |
| Employment | Salary, performance reviews, attendance, job-applicant records |
| Health & biometric | Health records, biometric data, insurance, disability information |
| Online | IP address, cookie and device IDs, precise location, usage logs |
| Recorded media | CCTV footage, voice recordings, facial images, access logs |
Is This Personal Data? Common Edge Cases
Whether something is personal data depends on whether you can identify a person in your real context, not on the label attached to it.
| Data element | Personal data? | Why |
|---|---|---|
| Work email (name@company.com) | Yes | Identifies a specific individual |
| Employee ID (E-10458) | Usually | The employer can map it to one person |
| IP address with login times | Often | Can be linked to an account or user |
| Device ID tied to an app account | Yes | Identification through the account record |
| Cookie or advertising ID | Often | Used to recognise, profile or target a person |
| Company registration number | No | Identifies an entity, not an individual |
| Users in a city (aggregate) | Not usually | No individual is singled out |
| Genuinely anonymised analytics | Usually no | Only if re-identification is not reasonably possible |
Avoid blanket claims that every IP address or cookie is always personal data. The Act’s test is identifiability in the context in which you actually process the information.
Does the DPDP Act Have a Sensitive Personal Data Category?
Unlike some earlier Indian proposals and certain foreign laws, the DPDP Act does not create a distinct statutory category of sensitive personal data. That does not mean health, financial, biometric or identity data can be treated casually. These carry a greater risk of harm, so organisations should apply stronger, risk-based safeguards, access controls, retention limits and governance.
Why the Personal Data Definition Matters for Compliance
Identifying personal data correctly is the starting point for DPDP compliance. Once a dataset meets the definition, an organisation (acting as a data fiduciary) should be able to say why it is collected, on what legal basis such as consent, who can access it, how long it is kept, and how it will honour Data Principal rights and breach-response duties.
Operational rule
If a person can be recognised, singled out, contacted, profiled or linked to a record through information you hold or can reasonably obtain, treat it as personal data until a formal assessment shows otherwise.
See how this term differs from the one it is most often confused with.
Personal Data vs Digital Personal Data →Related terms
Related sections of the Act
Related Rules
Primary sources
Frequently Asked Questions About Personal Data
Does the Act cover paper records?
It covers digital personal data, including information first collected on paper and later digitised. Purely offline records that are never digitised sit outside its scope.
Is anonymised data personal data?
No, if it genuinely cannot identify anyone. Once it can be linked back to a person, it becomes personal data again.
Is a business email address personal data?
Usually yes, where it identifies an individual, such as firstname.lastname@company.com. A generic address like info@company.com may not.
Is an employee ID personal data?
Usually yes, because the employer can map the ID to a specific employee through its records.
Are IP addresses and cookies always personal data?
Not always. They are personal data when they can be linked to an account, device or individual. The test is identifiability in your actual processing context.