DPDP Compliance, by Sector
The Digital Personal Data Protection Act is activity-based — it applies to every industry that handles personal data. Pick yours for a plain-language guide to what matters and what to keep in mind.
Education & EdTech
Schools, colleges, coaching centres and EdTech platforms process the data of students — most of whom are children — plus guardians and staff. That puts you squarely inside the DPDP Act’s strictest provisions.
Read the guideHealthcare & Life Sciences
Hospitals, clinics, labs, pharmacies and healthtech handle the most sensitive category of personal data there is — patient health information — across a long chain of providers, insurers and vendors.
Read the guideBanking & NBFCs
Banks and NBFCs hold deep financial and identity data on every customer, and sit under both the DPDP Act and a thick layer of RBI rules that already govern how that data is stored and shared.
Read the guideFintech & Payments
Payment apps, lending platforms and neobanks move fast and collect a lot — often more than they need. DPDP plus RBI’s digital-lending rules make data minimisation and consent non-negotiable.
Read the guideInsurance
Insurers and intermediaries collect health, financial and family data to underwrite and settle claims — sensitive information shared across agents, TPAs and reinsurers.
Read the guideRetail & E-commerce
From billing counters to checkout pages, retail runs on customer data — names, numbers, addresses, orders and behaviour. The most common DPDP gap is marketing to people who only came to buy.
Read the guideTelecom & ISPs
Telcos and ISPs hold subscriber identity, call/data records and location for millions of people — the kind of scale and sensitivity that draws the highest level of DPDP scrutiny.
Read the guideSaaS, IT & ITeS
Software and services companies usually process other organisations’ personal data as a Processor — while also being a Data Fiduciary for their own employees and prospects.
Read the guideTravel, Hospitality & Aviation
Airlines, hotels and travel platforms collect identity documents, itineraries and preferences — and move that data across borders and partners as a matter of routine.
Read the guideReal Estate & Housing
Developers, brokers and housing platforms collect KYC, income and contact data on buyers and tenants — and share it liberally with agents, portals and financiers.
Read the guideResident Welfare Associations
A housing society quietly processes a lot of personal data — residents, families, domestic staff, visitors and vendors — which makes your RWA a Data Fiduciary under the DPDP Act.
Read the guideMedia, OTT & Entertainment
Streaming, publishing and entertainment platforms live on audience data — who watches what, for how long — which powers recommendations and advertising, and triggers DPDP consent duties.
Read the guideOnline Gaming
Games attract players of every age — including many children — and collect behaviour, payments and chat. That combination puts gaming under the DPDP Act’s most protective rules.
Read the guideLogistics & Mobility
Delivery, courier and ride-hailing businesses move personal data as much as parcels — sender/receiver details, driver identities and precise location trails.
Read the guideManufacturing
Manufacturers may feel ‘B2B’, but they still process plenty of personal data — employees, contractors, dealers and the individuals behind every distributor and supplier.
Read the guideMSMEs & Small Business
Small does not mean exempt. The DPDP Act has no turnover or size threshold — if you handle customers’, employees’ or vendors’ data, it applies to you from day one.
Read the guideAutomotive & Connected Mobility
Modern vehicles and dealerships generate personal data continuously — telematics and location from connected cars, plus CRM and finance data across the sales journey.
Read the guideProfessional Services
Law, accounting, consulting and agencies hold sensitive client files — often full of third parties’ personal data — plus their own staff and marketing data.
Read the guideMarketing & Adtech
Marketing platforms and adtech run on behavioural data and audience profiles — precisely the processing the DPDP Act asks you to base on genuine, withdrawable consent.
Read the guideHR, Staffing & Recruitment
HR teams and staffing firms hold some of the most detailed personal data an organisation collects — candidates, employees, backgrounds and references.
Read the guideGovernment & PSUs
Government departments and PSUs process citizen and beneficiary data at scale. Some state processing has DPDP exemptions — but they are specific, not a blanket pass.
Read the guideNGOs & Non-profits
Non-profits hold donor and beneficiary data — often about vulnerable people and children — and share it with grantors and partners. A good cause is not an exemption.
Read the guideAgriculture & Agritech
Agritech platforms collect farmer identity, land, financial and device data — often from first-time digital users who need plain-language notice and genuine consent.
Read the guideEnergy & Utilities
Power, gas and water utilities hold consumer identity and billing data — and, increasingly, smart-meter data that quietly reveals when a household is home and what it’s doing.
Read the guideAI & Data Analytics
AI and analytics businesses turn personal data into models and insights — which makes lawful basis, purpose limitation and transparency the difference between a moat and a liability.
Read the guideStartups
Startups are fully liable under the DPDP Act from day one — and building privacy in early is far cheaper than retrofitting it after growth, a breach or a diligence process.
Read the guide