Back to Blog DPDP Act Applicability: Does it Apply to Offline Data?

DPDP Act Applicability: Does it Apply to Offline Data?

A
Admin

Introduction

When businesses think of "data privacy," images of cloud servers, cookies, mobile apps, and hackers typically come to mind. However, a significant portion of personal data processing in India still occurs on paper—from visitor logbooks at office receptions to physical KYC forms at banks, and patient intake forms at local clinics.

With the enforcement of the Digital Personal Data Protection (DPDP) Act, 2023, a common question arises among traditional, brick-and-mortar businesses: "If we only use paper, does this digital privacy law apply to us?"

The answer is nuanced, depending entirely on the lifecycle of that paper document. This article explores the applicability of the DPDP Act to offline data and how traditional businesses must adapt.

The Scope of Applicability: Section 3

To understand if the DPDP Act applies to your offline data, we must look at Section 3 of the Act, which defines its scope. The Act applies to the processing of digital personal data within the territory of India where the personal data is:

  1. Collected in digital form. (e.g., an online registration form)
  2. Collected in non-digital form and digitized subsequently. (e.g., a paper form that is scanned or manually entered into a computer system)

Therefore, the DPDP Act does not apply to personal data that is collected offline and remains entirely offline in physical files or cabinets. If a doctor keeps handwritten patient notes in a locked filing cabinet and never enters them into a computer, the DPDP Act does not govern those physical files.

The "Digitized Subsequently" Catch

While purely offline data is exempt, the reality of modern business makes this exemption incredibly narrow. Almost all offline data eventually touches a digital system.

Consider these common scenarios:

  • The Visitor Logbook: A visitor writes their name and phone number in a physical register at your office reception. If that register is just stored in a drawer, it is exempt. But if the receptionist later types those names into an Excel sheet to track visitor frequency or email them a marketing brochure, that data has been "digitized subsequently." The DPDP Act now applies to it.
  • Physical KYC Forms: A customer fills out a paper form to open a bank account. The bank teller then scans this form to upload it to the bank's centralized server. The moment it is scanned, the DPDP Act applies.
  • Business Cards: Collecting business cards at a conference is an offline activity. However, using a mobile app to scan the card and save the details into your CRM software digitizes the data, triggering DPDP compliance requirements.

Compliance Strategies for Traditional Businesses

If your business collects data on paper and digitizes it, you must treat the initial physical collection point as the beginning of your DPDP compliance journey. You cannot wait until the data is in the computer to apply the law.

1. Physical Notice and Consent

Since you are collecting data that will be digitized, you must provide a Privacy Notice and obtain Consent at the point of collection. This means your physical paper forms must be updated.

  • Add a clear, printed notice on the physical form explaining why you are collecting the data and how it will be used (e.g., "We will digitize this form to process your application.").
  • Include a physical checkbox for the individual to sign or check, explicitly granting consent for the processing and digitization of their data.

2. Secure the Transition Point

The physical-to-digital transition is a major vulnerability point. How are paper forms transported to the scanning department? Who has access to the physical scanner? Ensure that the physical security of the documents matches the digital security of your servers.

3. Data Minimization on Paper

Review all your physical forms. Are you asking for a mother's maiden name or marital status on a form where it isn't strictly necessary? The principle of data minimization applies equally here. Redesign your physical intake forms to collect only the absolute minimum data required for the service.

4. Managing Erasure (The Shredder Protocol)

When a Data Principal exercises their Right to Erasure, they are requesting the deletion of their personal data. If you have digitized their paper form, you must delete the digital record. But what about the original paper copy?

While the DPDP Act strictly governs the digital copy, maintaining the physical copy after the purpose has been served (and digital consent withdrawn) is poor practice and could run afoul of other regulations or general privacy principles. Implement a strict physical document retention policy—once a document is digitized and verified, the physical copy should be securely shredded unless required by a specific sectoral law (e.g., tax records).

Conclusion

The word "Digital" in the DPDP Act's title can be deceiving for traditional businesses. In an era where a smartphone camera can digitize a document in seconds, the boundary between offline and online data is virtually non-existent. Businesses must assume that any personal data collected on paper will eventually be digitized, and must build DPDP compliance directly into their physical clipboards and forms.

Share this insight

X (Twitter) LinkedIn WhatsApp

Related Articles

The Privacy Paradox: Why Indians Care but Click 'Agree'

The Privacy Paradox: Why Indians Care but Click 'Agree'

Aug 12, 2026
Vendor Risk Management and DPDP Compliance for Enterprises

Vendor Risk Management and DPDP Compliance for Enterprises

Aug 12, 2026
Stop Using GDPR Templates for Indian DPDP Compliance

Stop Using GDPR Templates for Indian DPDP Compliance

Aug 12, 2026