Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+
Learn

One test, and then the sector you are in

Last updated

Published

Follow this on Google — add MyConsent+ to your preferred sources

Who the DPDP Act 2023 covers: schools, colleges, hospitals, banks, employers, startups and firms outside India — and the two things it does not reach.

Short answer: almost certainly yes. The DPDP Act applies to any organisation that decides why and how digital personal data is processed — in India, or outside India where the processing is connected with offering goods or services to people in India. There is no revenue floor, no employee-count threshold and no sector exemption. The only carve-outs are purely personal or domestic use, and data the person has made public herself. Startups can be exempted from five provisions, but only once the government notifies their class.

There is one test, and it has nothing to do with your sector. Sec. 3 applies the Act to digital personal data processed within India — collected digitally, or collected on paper and later digitised. If you determine the purpose and means of that processing, Sec. 2 makes you a Data Fiduciary and the duties are yours.

It reaches outside India too. Processing done abroad is covered where it is connected with offering goods or services to Data Principals in India, so a company with no Indian office and Indian customers is in scope.

The two ways out, and they are narrower than they sound

Sec. 3 excludes two things. Personal data processed by an individual for purely personal or domestic purposes — your own contacts, not your company's. And personal data the Data Principal has made publicly available herself, or that someone is under a legal obligation to publish.

Neither is a business exemption. "It was on their LinkedIn" only holds where the person put it there and you are using it in that form; it does not license scraping it into a marketing database for a purpose she never saw a notice about.

Schools and colleges

This is the sector where the answer changes most, and the reason is the age line. A child under the Act is anyone who has not completed eighteen years. For a school, that is nearly the whole roll.

Sec. 9 does three things for children. It requires verifiable parental consent before processing. It forbids processing likely to have a detrimental effect on a child's well-being. And it prohibits tracking, behavioural monitoring, and targeted advertising directed at children outright.

Read alone, that would stop a school taking attendance on a device or running a safeguarding system. It does not, because Sec. 9(4) lets the Rules exempt classes of Data Fiduciary, and Rule 12 with the Fourth Schedule does exactly that. Educational institutions are relieved of verifiable parental consent and of the tracking prohibition — but only for processing limited to educational activities and the safety of enrolled students. Crèches and childcare centres get a similar carve-out for safety, and school transport providers for location tracking during travel.

What those exemptions do not cover is analytics, profiling, or anything monetised. A school running behavioural monitoring for student safety is inside the carve-out. The same school passing that data to an edtech vendor who builds engagement scores is not.

Colleges sit differently. Most undergraduates have completed eighteen, so Sec. 9 does not reach them and ordinary consent applies. But intake at seventeen is common, and the obligation follows the individual rather than the institution — which means a college needs to know which of its students are still children, and cannot answer that with a policy that assumes none of them are.

Hospitals, clinics and diagnostics

Health data is personal data. The Act has no equivalent of the GDPR's special categories, so there is no higher bar for a diagnosis than for a mailing address — and, more to the point, no separate lawful basis to fall back on either.

For children, the Fourth Schedule exempts clinical establishments, mental health establishments, healthcare professionals and allied healthcare professionals from verifiable parental consent, confined to processing that is necessary to protect the child's health or to support a treatment and referral plan. Outside that, a paediatric record is a child's personal data and Sec. 9 applies in full.

Two things catch providers regardless of age. Sec. 7(f) and 7(g) cover medical emergencies and public health measures as legitimate uses, so consent is not the basis in a crisis — but those clauses are narrow and do not extend to the billing, marketing or research use of the same record. And the onward flow to labs, insurers, teleconsultation platforms and billing processors is a set of purposes the patient has to have been noticed about.

Banks, NBFCs and insurers

In scope, and largely already building. The account aggregator framework has accustomed the sector to purpose-scoped, revocable, machine-readable consent, which is the shape the Act wants. The exposure is everything outside those rails: marketing databases, app analytics, call recordings, support transcripts, and the bundled tick at onboarding that covered account operation, credit checks and partner offers in one action.

Employers

Employee data is personal data, but most of it does not run on consent. Sec. 7(i) makes employment a legitimate use, covering processing for the purposes of employment and for safeguarding the employer from loss or liability. That removes the consent question for payroll, attendance and the like. It does not remove Sec. 8 — safeguards under Sec. 8(5), breach reporting under Sec. 8(6), erasure once the purpose is no longer served under Sec. 8(7), and the grievance mechanism under Sec. 8(10).

Two rights follow the consent rather than the employment. Sec. 11(1) gives access against a Data Fiduciary to whom the Data Principal has previously given consent, including consent as referred to in Sec. 7(a), and Sec. 12(1) limits correction and erasure the same way, so neither reaches processing resting on Sec. 7(i) alone. Grievance redressal under Sec. 13 and nomination under Sec. 14 are unaffected.

Startups and small businesses

In scope today. Sec. 17(3) empowers the Central Government to notify classes of Data Fiduciary, startups expressly among them, to whom Sec. 5, Sec. 8(3), Sec. 8(7), Sec. 10 and Sec. 11 do not apply. That is a real carve-out covering notice and access, and it is conditional: it needs a notification, and it names classes rather than granting itself. Plan on the full duty set until one applies to you.

Your sector in detail

What applies to everyone

Whatever the sector, if the test at the top is met: where you rely on consent, notice under Sec. 5 and valid consent under Sec. 6(1), with withdrawal at parity under Sec. 6(4); reasonable security safeguards under Sec. 8(5) and breach reporting under Sec. 8(6) whatever the basis; grievance redressal under Sec. 13 and nomination under Sec. 14, which carry no such limit; access and correction under Sec. 11 and Sec. 12 for processing she consented to, including under Sec. 7(a); and the cross-border conditions in Sec. 16. Those commence together on 13 May 2027.

Questions people ask

Is the DPDP Act applicable to me?
If you decide why and how digital personal data is processed, yes. Sec. 3 covers processing in India, and processing outside India connected with offering goods or services to people in India. The only exclusions are purely personal or domestic use, and data the person made public herself.
Does the DPDP Act apply to schools?
Yes. Most school students are under 18, so they are children under Sec. 2, and Sec. 9 requires verifiable parental consent. Rule 12 and the Fourth Schedule exempt educational institutions from that requirement and from the tracking ban, but only for educational activities and student safety.
Does the DPDP Act apply to hospitals?
Yes. Health data is ordinary personal data under the Act — there is no sensitive category. Clinical and healthcare establishments are exempted from verifiable parental consent for a child, but only where processing is limited to health services necessary to protect that child's health.
Does the DPDP Act apply to small businesses and startups?
Yes, unless the Central Government notifies otherwise. Sec. 17(3) lets it exempt classes of Data Fiduciary, startups included, from Sec. 5, Sec. 8(3), Sec. 8(7), Sec. 10 and Sec. 11. Until a notification names you, every duty applies.
Does the DPDP Act apply to companies outside India?
Yes, where the processing is connected with offering goods or services to Data Principals in India. Sec. 3 reaches processing outside India on that basis, so a foreign SaaS company with Indian customers is in scope.
Is employee data covered by the DPDP Act?
Yes, but much of it does not run on consent. Sec. 7(i) makes employment a legitimate use, covering processing for employment purposes and for safeguarding the employer from loss or liability. The Sec. 5 notice duty attaches to a request for consent, so it is not triggered by that processing, while Sec. 8 applies regardless.