AMLEGALS — Strategic Lawyering

Sector Repository

DPDPA Impact Decoded — How the DPDP Act 2023 & Rules 2025 Apply, Sector by Sector

A statute-mapped view of how India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 land in each industry. Every brief traces obligations to the exact Section and Rule, sets out the personal data typically in play, the recurring risks, and the actions that follow.

Act assented 11 August 2023Rules notified 13 November 20258 sector briefs
In short

DPDPA Impact Decoded is a sector-by-sector repository mapping how India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 apply to eight industries. Each brief traces the obligation to the exact Section and Rule, sets out the personal data typically processed, the recurring compliance risks, and the actions that follow.

The DPDP Act applies wherever digital personal data is processed in India, and to processing outside India that involves offering goods or services to Data Principals in India.
Core obligations are common across sectors — lawful notice and consent (Sections 5–6), purpose limitation, a valid processor contract under Section 8(2), security safeguards under Section 8(5) read with Rule 6, and breach handling under Section 8(6) read with Rule 7.
Sector context changes how those obligations are met, not whether they apply — the eight briefs decode that difference industry by industry.
Logistics & Supply Chain — DPDPA sector briefSECTOR BRIEF

Impact on Logistics & Supply Chain

Logistics and last-mile operators sit on dense flows of consignee names, addresses, phone numbers and location trails — much of it processed on behalf of e-commerce and enterprise clients as a Data Processor.

Read the brief
Advertising & AdTech — DPDPA sector briefSECTOR BRIEF

Impact on Advertising & AdTech

Advertising and adtech rely on identifiers and behavioural signals that, when linked to an identifiable individual, are personal data — bringing consent, purpose limitation and the children’s-advertising bar squarely into scope.

Read the brief
Telemarketing & Tele-calling — DPDPA sector briefSECTOR BRIEF

Impact on Telemarketing & Tele-calling

Outbound tele-calling depends on large contact databases and recorded calls — both of which are personal data requiring a lawful basis, notice and disciplined retention under the Act.

Read the brief
OTT & Digital Media — DPDPA sector briefSECTOR BRIEF

Impact on OTT & Digital Media

OTT and digital-media platforms process subscriber identities, payment references and rich viewing-behaviour data used for recommendations — with distinct duties where profiles belong to children.

Read the brief
Workplace Monitoring & Investigations — DPDPA sector briefSECTOR BRIEF

Impact on Employee Monitoring & Investigations

Employee monitoring, device and communications surveillance and internal investigations all process employee personal data — engaging notice, purpose limitation, security and data-principal rights.

Read the brief
EdTech & Online Learning — DPDPA sector briefSECTOR BRIEF

Impact on EdTech & Online Learning

EdTech platforms routinely process the personal data of learners who are children — placing verifiable parental consent and the prohibition on behavioural monitoring at the centre of compliance.

Read the brief
SaaS & Cloud (Data Processors) — DPDPA sector briefSECTOR BRIEF

Impact on SaaS & Cloud Processors

SaaS and cloud providers typically process personal data on behalf of customers as Data Processors — a role defined by the Section 8(2) contract, strong security and breach-support duties.

Read the brief
Retail & Loyalty Programmes — DPDPA sector briefSECTOR BRIEF

Impact on Retail & Loyalty Programmes

Retail and loyalty programmes build detailed member profiles from enrolment and purchase history — used for marketing and personalisation, all of which turn on notice, consent and purpose limitation.

Read the brief

Frequently asked questions

What is DPDPA Impact Decoded?

It is a repository of sector briefs that map the DPDP Act, 2023 and DPDP Rules, 2025 to specific industries. Each brief explains when the Act applies to that sector, the personal data typically processed, the mapped Section and Rule obligations, the recurring risks, and the practical actions.

Which sectors are covered?

Eight sectors: logistics and supply chain, advertising and adtech, telemarketing and tele-calling, OTT and digital media, workplace monitoring and investigations, edtech and online learning, SaaS and cloud data processors, and retail and loyalty programmes.

When does the DPDP Act apply to my sector?

The DPDP Act, 2023 applies whenever digital personal data is processed in India. It also applies to processing outside India where that processing is in connection with offering goods or services to Data Principals in India. If your sector handles customer, employee or user data digitally, it is in scope.

Do the same obligations apply to every sector?

The core obligations are common — notice and consent under Sections 5 and 6, purpose limitation, a valid processor contract under Section 8(2), security safeguards under Section 8(5) read with Rule 6, and breach handling under Section 8(6) read with Rule 7. What changes by sector is the factual context in which those obligations are discharged.

These briefs are general legal information on the DPDP Act, 2023 and the DPDP Rules, 2025, not legal advice. How the law applies turns on the facts of each engagement.