Commentary on Section 3 of the Digital Personal Data Protection Act, 2023 (DPDP Act), Territorial Applicability and Exclusions (with GDPR Mapping)

CHAPTER I - PRELIMINARY
Official text
Subject to the provisions of this Act, it shall,
(a)apply to the processing of digital personal data within the territory of India where the personal data is collected,
(i)in digital form; or
(ii)in non-digital form and digitised subsequently;
(b)also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India;
(c)not apply to,
(i)personal data processed by an individual for any personal or domestic purpose; and
(ii)personal data that is made or caused to be made publicly available by,
(A)the Data Principal to whom such personal data relates; or
(B)any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.
Illustration.X, an individual, while blogging her views, has publicly made available her personal data on social media. In such case, the provisions of this Act shall not apply.

Section 3 of the Digital Personal Data Protection Act, 2023 (DPDP Act) establishes theterritorial scope and applicability of India’s data protection framework. Similar to the approach adopted under theGeneral Data Protection Regulation (GDPR), the provision follows anextraterritorial application model, ensuring that organisations outside India may also be subject to Indian data protection obligations when their activities affect individuals within India.
The objective of this provision is to regulate the processing of digital personal data while balancing privacy protection with practical exclusions for personal activities and voluntarily disclosed information.
2. 1. Processing of Digital Personal Data Within India
Section 3(a) provides that the DPDP Act applies to the processing of digital personal data within the territory of India where:
This means the Act applies not only to information that originates digitally but also to traditional offline records that are later converted into digital databases.
2.1 Illustration:
A hospital in Delhi collects a patient's details through a paper registration form containing name, contact number, medical history, and identification details. Later, the hospital scans and uploads these records into its electronic health record system.
Although the data was initially collected in physical form, once digitised, the processing becomes subject to the DPDP Act.
Similarly, an e-commerce company collecting customer information such as name, address, payment details, and purchase history through an online platform would fall within the scope of the Act because the personal data is collected directly in digital form.
This principle corresponds with:
GDPR applies to processing of personal data:
“in the context of the activities of an establishment of a controller or processor in the Union”
The GDPR focuses on the location of the controller/processor establishment, whereas the DPDP Act focuses primarily on processing of digital personal data within India.
2.3 Example:
A company incorporated in Mumbai operates an online shopping platform collecting Indian users’ personal data. Since processing occurs in India, Section 3(a) applies.
Under GDPR, a similar scenario would fall under Article 3(1) if the company had an establishment within the European Union.
Section 3(b) extends the DPDP Act beyond Indian borders.
It applies where processing occurs outside India but is connected with offering goods or services to Data Principals located in India.
This prevents foreign organisations from avoiding Indian privacy obligations merely because their servers or offices are located outside India.
2.4 Illustration:
A company based in Singapore operates a mobile application offering online financial services to Indian customers. The company collects Indian users’ names, financial information, and transaction details through servers located outside India.
Even though processing occurs outside India, the DPDP Act applies because the company is offering services to individuals within India.
This is closely aligned with:
GDPR applies to organisations outside the EU where processing relates to:
(a) offering goods or services to individuals in the EU; or (b) monitoring their behaviour.
2.6 Example:
A US-based streaming platform offering subscriptions to users in Germany must comply with GDPR even though the company is located outside Europe.
Similarly, under Section 3(b), a foreign company targeting Indian consumers may become subject to DPDP obligations.
Section 3(c)(i) excludes personal data processed by an individual for personal or domestic purposes.
The purpose of this exemption is to avoid regulating ordinary personal activities where there is no commercial or institutional processing.
2.7 Illustration:
A person maintains a private contact list on their mobile phone containing names and phone numbers of family members and friends.
Since the processing is purely personal, the DPDP Act does not apply.
However, if the same person operates a business and maintains a customer database, the exemption would not apply.
This corresponds with:
GDPR does not apply to:
“processing of personal data by a natural person in the course of a purely personal or household activity.”
2.9 Example:
Maintaining a private photo album is outside GDPR.
Uploading customer photographs for a commercial service is not.
Section 3(c)(ii) excludes personal data that has been made publicly available:
The rationale is that where an individual voluntarily places information into the public domain, the DPDP Act does not regulate that specific publicly disclosed information.
2.10 Illustration:
X writes a public blog expressing personal opinions and includes her name, photograph, and professional details.
Since X voluntarily made the information publicly available, the DPDP Act will not apply to that publicly disclosed personal data.
GDPR does not contain an identical broad exemption. Instead, publicly available data remains personal data if an individual can still be identified.
Example
For example, a person’s publicly available LinkedIn profile may still be protected under GDPR if processed by organisations.
Relevant GDPR principles include:
Even publicly available personal data must generally be processed lawfully, fairly, and transparently.
Organisations require a valid legal basis even when information is publicly accessible.
Section 3 forms the foundation of the DPDP Act by defining who and what activities fall within Indian privacy regulation. It adopts a GDPR-inspired extraterritorial approach by regulating foreign entities targeting Indian individuals. However, unlike GDPR, the DPDP Act is narrower because it focuses exclusively ondigital personal data and provides a wider exclusion for publicly available information.
The provision reflects India’s attempt to create a privacy framework that protects individuals in the digital economy while avoiding unnecessary regulation of personal activities and openly available information.
Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.