The Digital Personal Data Protection Act applies to all digital personal data, but its operational impact varies wildly depending on your business model. Select your industry below to see what changes for you.
E-commerce heavily relies on targeted marketing, profiling, and abandoned cart emails. The DPDP Act forces a shift from implicit tracking to explicit, granular consent.
Companies process massive amounts of employee data (bank details, biometrics, health records). Section 7(i) of the Act provides relief under "Certain Legitimate Uses" for employment purposes.
Employers do not need explicit consent to process data for managing employment, preventing corporate espionage, or maintaining IP confidentiality. However, this exemption is narrow.
If an employer uses biometric data (fingerprint attendance) or monitors personal devices, explicit consent is likely still required. HR teams must draft a separate "Employee Privacy Notice".
Unlike the old IT Rules, DPDP does not explicitly classify "Health Data" as Sensitive Personal Data. However, due to its nature, the Data Protection Board will likely scrutinize healthcare breaches strictly.
Under Section 7(c), hospitals do not need consent for responding to a medical emergency involving a threat to the life or immediate threat to the health of the Data Principal.
This sector faces the highest regulatory burden due to strict provisions regarding children's data (individuals under 18 years of age).
EdTech platforms must implement verifiable parental consent mechanisms before collecting data from anyone under 18. Age-gating mechanisms must be robust, not just a simple checkbox.
Banks and financial institutions process highly sensitive financial data. While RBI guidelines already enforce strict data localization, DPDP adds an extra layer of user consent requirements.
Banks can no longer use data collected for a savings account to automatically send credit card or loan offers without explicit, granular consent for marketing purposes.
FinTechs using SMS reading, contact list scraping, or social media profiling for credit scoring face existential compliance risks. Consent must be absolutely clear and strictly limited to the stated purpose.
India is the IT outsourcing hub of the world. Software providers and call centers generally act as Data Processors rather than Fiduciaries.
Section 17 provides relief: if an Indian BPO processes data of foreign citizens under a contract with a foreign company, many strict provisions of the DPDP Act do not apply to them.