Applicability Guide
Industries & Sectors
The DPDPA 2023 is completely sector-agnostic, meaning it applies uniformly to all entities processing digital personal data within India. However, the practical impact and compliance challenges differ vastly from industry to industry.
Select your sector below to see the specific challenges, exemptions, and compliance priorities that apply to your business.
Healthcare & Pharma
- Medical Emergencies: Consent is explicitly bypassed under Sec 7(b) for responding to medical emergencies or epidemics.
- Data of Children: Requires verifiable parental consent (Sec 9) which can complicate pediatric care apps.
- Significant Data Fiduciary: Large hospitals will likely be designated as SDFs (Sec 10) requiring independent data auditors.
FinTech & Banking
- Consent Managers: Financial institutions will rely heavily on Consent Managers (Sec 6) like the Account Aggregator framework.
- Cross-Border Transfers: Sec 16 allows data transfer outside India, subject to Government blacklists and stricter RBI localization mandates (Sec 38).
EdTech & Schools
- Absolute Ban on Tracking: Sec 9 outright prohibits tracking, behavioral monitoring, or targeted advertising directed at children.
- Parental Consent: Must obtain verifiable consent from parents before processing ANY data of a person under 18.
E-Commerce & Retail
- Consent Withdrawal: Customers have the right to withdraw consent at any time (Sec 6). Systems must stop processing marketing data immediately.
- Data Erasure: DPDPA requires erasing personal data as soon as the specific purpose is served (Sec 8(7)), impacting long-term customer profiles.
HR & Employment
- Legitimate Uses: Employers can process employee data without explicit consent under Sec 7(i) for employment purposes or protecting trade secrets.
- Grievance Redressal: Employees must have a readily available mechanism to register data-related grievances (Sec 13).
IT & BPO Services
- Data Processor Exemption: BPOs acting strictly as Data Processors for foreign clients may be exempt from major compliance requirements (Sec 17(1)(d)).
- Data Processor Contracts: Must establish robust Data Processing Agreements (DPAs) with Data Fiduciaries under Sec 8(2).
Telecom & ISPs
- State Exemptions: Must balance user privacy with lawful interception requests by the State for national security (Sec 17(2)(a)).
- Breach Notifications: Under Sec 8(6), strict requirements to notify both the Board and users of any network data breaches.
Real Estate & Housing
- Tenant & Buyer KYC: Collecting Aadhaar, PAN, and bank details requires explicit consent and strict data security protocols (Sec 8(5)).
Travel & Hospitality
- Guest Passports & ID Data: Mandatory police verification data collection is protected under legitimate use / legal obligation grounds.
Media & Entertainment
- Journalistic Exemption: Sec 17(1)(c) grants exemptions for processing data necessary for journalistic purposes.
AI & Gaming
- Model Training Data: Scraping personal data from the internet to train AI models without consent violates Section 4(1).
Government & PSUs
- Public Interest Exemptions: State entities are granted broad exemptions under Sec 17 for national security, crime prevention, and public welfare.