Back to Key Provisions

Personal Data - Scope and Meaning

Detailed analysis of what constitutes personal data under the DPDPA, its digital-only scope, and how it differs from global data protection frameworks.

9 min read

Understanding Personal Data Under the DPDPA

The DPDPA's applicability begins with a threshold question: is the data in question "personal data" within the Act's meaning? Section 2(t) defines personal data as any data about an individual who is identifiable by or in relation to such data. This definition, while seemingly straightforward, carries significant interpretive nuances that determine the Act's reach.

Digital-Only Scope

The Act applies exclusively to digital personal data - data that is: 1. Collected in digital form (e.g., online forms, app interactions, IoT sensors), or 2. Collected in non-digital form and subsequently digitised (e.g., paper forms that are scanned and stored electronically) This digital-only scope is a deliberate departure from frameworks like the GDPR, which apply to both automated and certain manual filing systems. The practical effect is that purely paper-based records that are never converted to digital format remain outside the DPDPA's scope. However, given the pervasiveness of digitisation in modern business, the vast majority of personal data processing activities will fall within scope.

The Identifiability Test

For data to qualify as "personal data," the individual must be identifiable "by or in relation to" the data. This creates a broad test: - Direct identification: Data that on its own identifies a person (e.g., name, Aadhaar number, photograph) - Indirect identification: Data that in combination with other available information can identify a person (e.g., location data combined with behavioural patterns) The phrase "in relation to" extends the scope beyond data that directly names an individual to encompass any data that could lead to identification when cross-referenced with other datasets. In practice, this means organisations must assess identifiability not just based on the data they hold but considering what other data is reasonably accessible.

Data Outside the Act's Scope

Several categories of data fall outside the DPDPA's scope: - Anonymised data: Data that has been processed in such a manner that the Data Principal is no longer identifiable. The Act does not prescribe a specific anonymisation standard. - Data made publicly available: Personal data that the Data Principal has made publicly available, or that is required to be made publicly available under any law. - Non-digital data: Data in purely physical form that has not been digitised. Organisations should carefully evaluate whether their data genuinely falls into these exclusions, particularly for anonymisation claims. Pseudonymisation alone is typically insufficient - the data must be irreversibly anonymised such that no re-identification is possible.

Absence of a "Sensitive Data" Category

Unlike the GDPR (which distinguishes "special categories of personal data") and India's earlier SPDI Rules (which defined "sensitive personal data or information"), the DPDPA does not create a separate category for sensitive personal data. All personal data receives the same level of protection under the Act. However, the Central Government may consider the "sensitivity" of data when designating Significant Data Fiduciaries, and the Data Protection Board may consider the nature of data affected when determining penalties. This unified approach simplifies compliance but has drawn criticism from commentators who argue that health data, financial data, and biometric data warrant heightened protections.

Practical Implications for Organisations

Organisations should: 1. Conduct a data inventory to identify all digital personal data they process 2. Assess identifiability risk for datasets they consider anonymised 3. Evaluate whether any non-digital data collection workflows result in subsequent digitisation (bringing them within scope) 4. Map data flows across their operations to understand which processing activities involve personal data 5. Document their scope assessment decisions as part of their accountability framework The absence of a sensitivity distinction simplifies the data classification exercise but does not eliminate the need for thorough data mapping.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.