Core Concepts

Personal Data

Defined in §2(t), DPDPA 2023

Any data about an individual who is identifiable by or in relation to such data.

What does “Personal Data” mean?

Personal data means any data about an individual who is identifiable by or in relation to such data. This covers both directly identifying information like names and Aadhaar numbers, and indirectly identifying data like IP addresses or device IDs when linked to an individual. The DPDPA specifically governs digital personal data — personal data in digital form.

Why does this matter for your business?

Understanding what constitutes personal data determines the scope of your compliance obligations. If you process any data that can identify a person, DPDPA applies to that processing activity.

Real example

A Pune-based HR tech startup stores employee names, phone numbers, PAN cards, and performance reviews. All of this is personal data under DPDPA, triggering consent, retention, and security obligations for each data element.

Common misconception

Business email addresses and work phone numbers are still personal data under DPDPA. There is no blanket "business contact" exemption like some other jurisdictions provide.

Related terms

DPDPA Shield automates Data Inventory & RoPA. See how →