Definition
Under Section 2(t) of the DPDPA, 2023, personal data is any data about an individual who is identifiable by or in relation to that data. If a record points to a specific person — directly or when combined with something else you hold — it is personal data. Section 3 limits the Act to digital personal data: information collected in digital form, or collected on paper and later digitised. So a signed consent form in a file cabinet sits outside the Act, but the moment you scan it, upload it, or type its contents into a spreadsheet, the Act applies.
What this covers in an SMB
- Customer names, addresses and WhatsApp numbers in your CRM or phone
- KYC PDFs, PAN copies and cancelled cheques on a shared drive
- Employee Excel sheets: salary, bank details, leave records, attendance
- Website enquiry forms, chatbot transcripts, appointment bookings
- Photographs, biometric attendance logs, CCTV footage tied to identifiable people
- Patient records, prescriptions and lab reports
Note what the DPDPA does not do: it drops the old SPDI Rules' "sensitive personal information" category and has no equivalent of GDPR's Article 9 special-category tier. Health data, salary, biometrics and phone numbers are simply personal data. There is no lower-protection tier — Section 8(5) requires reasonable security safeguards across all of it. The Schedule ceiling for failing that duty is up to ₹250 crore, applied by the Board on the facts — not an automatic invoice.
How this matters in practice
Most SMBs underestimate their footprint because they only think of Aadhaar. In practice the exposure sits in sales spreadsheets, WhatsApp Business chats, old vendor emails and staff drives nobody owns. Privigo starts with a data inventory that maps every system holding personal data — including data your processors and channel partners hold on your behalf — then attaches purpose, consent basis and retention to each.
Frequently asked questions
Is a customer's phone number really "personal data"? It feels harmless.
Yes. A phone number identifies a specific individual, so it falls squarely within Section 2(t). The DPDPA has no tiering — there's no category of personal data that gets lighter treatment. A WhatsApp number in your sales sheet carries the same notice, consent, security and deletion obligations as a health record. Sensitivity affects your risk, not your legal duties.
Our paper registers and physical files aren't digital. Are we outside the Act?
Only while they stay on paper. Section 3 covers digital personal data and non-digital data that is subsequently digitised. Photographing a register, scanning KYC documents, or entering visitor details into a system brings that data into scope immediately. Since almost every business eventually digitises something for billing, GST or audit, treating paper as permanently exempt is a poor assumption.
Company data — GST numbers, firm addresses, our distributors' details. Is that personal data too?
Data about a company as an entity isn't personal data, since a company is not an individual. But most B2B records aren't purely entity data. A distributor's proprietor name, a partner's PAN, or the mobile number of a purchase manager all identify individuals and are personal data in your hands. The same applies to data held for you by an agency, vendor or franchise partner — you remain the fiduciary for it.
Inventory what you actually hold
Book a 30-minute call. We walk CRM, WhatsApp, KYC folders and payroll — and mark what is personal data under Section 2(t) versus what is only a company record.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.