Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 7 October 2026. Methodology

Does the DPDP Act have a sensitive personal data category? No

Definitions

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read

Does the DPDP Act classify sensitive personal data separately?

The short answer

No. The DPDP Act 2023 has no category of sensitive personal data. The word sensitive does not appear anywhere in the Act, and section 3, which sets the Act's application, has only clauses (a), (b) and (c), so the section 3(d) cited by many articles for a sensitive data category does not exist. Personal data is defined once, in section 2(t), by identifiability alone. Higher duties do arise, but from who is processing and who the data is about rather than from a data type: notification as a Significant Data Fiduciary under section 10, the children's provisions in section 9, and the retention classes in the Third Schedule to the Rules. None of those provisions is in force yet: notification G.S.R. 843(E) and Rule 1(4) place them in the group commencing 18 months after publication, computed to 13 May 2027 and interpretation until officially confirmed, and no notification of a Significant Data Fiduciary has been located in MeitY's published document library or this site's source registry as of 7 October 2026.

More answered questions →

Diagram: The DPDP Act has no sensitive personal data category. The same diagram appears further down this article, where it is described in full.

If you search for DPDP and health data, or DPDP and biometrics, you will find article after article explaining which categories of personal data the Act treats as sensitive. Several cite a provision by number: section 3(d).

Both the category and the provision are inventions. Here is what the official text actually contains, and what really does create heavier duties.

The DPDP Act has no sensitive personal data category. Personal data is defined once, by identifiability, and higher duties attach to who processes and whose data it is. GDPR Article 9 has special categories: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, and sex life and sexual orientation. That is EU law and no duty in India. The DPDP Act 2023 section 2(t) has 1 definition, 1 category and no tiers: personal data means any data about an individual who is identifiable by or in relation to such data. Section 3(d) does not exist, because section 3, the application provision, runs to clause (c), and the word sensitive appears 0 times in the Act. What actually creates higher duties: section 10, where the Central Government notifies a Significant Data Fiduciary, triggered by who processes; section 9, on children and persons with a guardian, triggered by whose data it is; and the Third Schedule with Rule 8, erasure clocks by class and user threshold, triggered by size and class. Sensitivity is named once in the Act, in section 10(1)(a), as 1 factor in assessing an organisation for notification. None of those 3 triggers is in force yet: G.S.R. 843(E) places sections 3, 9 and 10 in the group commencing 18 months after publication, and Rule 1(4) does the same for Rule 8 and the Third Schedule it points to, computed 13 May 2027 and interpretation until officially confirmed, while section 2 is already in force.

The word sensitive is not in the Act

Search the Gazette text of the Digital Personal Data Protection Act 2023 for the word sensitive and you will find it 0 times. The only related word is sensitivity, and it appears once, in section 10(1)(a), which we come to below.

Personal data is defined a single time:

DPDP Act 2023, s. 2(t) · Definitions · verbatim

"“personal data” means any data about an individual who is identifiable by or in relation to such data"

That definition names no categories. It asks 1 question, whether the individual is identifiable, and every kind of personal data that passes that test is governed by the same set of obligations. A blood group and a shipping address sit in the same legal box. Applying that single test to the 2 fields almost every business holds is worked through in is a name or an email address personal data.

There is no section 3(d)

Section 3 is the application provision. It has 3 clauses:

ClauseWhat it does
3(a)Applies the Act to processing of digital personal data within India, whether collected in digital form or digitised later
3(b)Extends it to processing outside India in connection with any activity related to offering of goods or services to Data Principals within India
3(c)Excludes personal data processed by an individual for any personal or domestic purpose, and personal data made publicly available either by the Data Principal herself or by any other person who is under an obligation in Indian law to make it public

After clause (c)(ii)(B) and its illustration, the Gazette moves straight into Chapter II and section 4. There is no clause (d), so any article that cites section 3(d) for a sensitive data category is citing a provision that does not exist. That is a useful test to apply to a DPDP source: check the number, not just the claim.

Where sensitivity really appears

Section 10(1) lets the Central Government notify a Data Fiduciary, or a class of them, as a Significant Data Fiduciary after assessing relevant factors. The first listed factor is:

DPDP Act 2023, s. 10(1) · Additional obligations of Significant Data Fiduciary · verbatim

"the volume and sensitivity of personal data processed"

Read that carefully, because it is the sentence the myth grows out of. Sensitivity is a factor in assessing an organisation for notification. It does not create a class of data, it attaches no obligation by itself, and it does not operate until the Government notifies someone. As of 7 October 2026 no notification of a Significant Data Fiduciary has been located, and section 10, which confers the power to notify, has not commenced, so on this site's reading any notification issued under it before then could not take effect until it does: notification G.S.R. 843(E) places section 10 in the group commencing 18 months from the publication of its gazette, printed 13 November 2025, which computes to 13 May 2027, a computed date that is interpretation until officially confirmed.

So handling health records may well make your organisation a candidate for notification. It does not put your health records into a statutory category, because there is no category to put them in.

What actually creates higher duties

3 mechanisms do most of that work, and none of them is a data type.

MechanismTriggerWhere
Significant Data Fiduciary duties: an India based Data Protection Officer answerable to the board, an independent data auditor, and periodic Data Protection Impact Assessment and auditCentral Government notification after assessing factors including volume and sensitivitySection 10
Children's duties: verifiable consent of the parent or lawful guardian, no processing likely to cause a detrimental effect on the well being of a child, and no tracking, no behavioural monitoring of children and no targeted advertising directed at children, subject to the exemptions in Rule 12 and the Fourth ScheduleThe Data Principal is a child, or a person with disability who has a lawful guardianSection 9
Shorter retention and erasure clocksBeing a named class of Data Fiduciary at or above a stated user thresholdThird Schedule, read with Rule 8

Every trigger is about who processes, or whose data it is, or how large the operation is. None asks what kind of data it is.

All 3 also sit ahead of us rather than behind us. Notification G.S.R. 843(E) places sections 3, 9 and 10 in the group that commences 18 months from the publication of its gazette, and Rule 1(4) does the same for Rule 8, and so for the Third Schedule that Rule 8(1) points to. Computed from the printed publication date of 13 November 2025, that lands on 13 May 2027, and the computed calendar date is interpretation until officially confirmed: the official text states a period, not a date. What is in force today is set out in what is in force in 2026.

Why the myth is so persistent

2 reasons, both understandable.

The GDPR does have special categories. Article 9(1) lists racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and data on sex life or sexual orientation, and prohibits processing them subject to the exceptions set out in Article 9(2). Anyone who learned privacy through the GDPR expects the same architecture and reads it into the Indian Act.

India's own pre DPDP privacy vocabulary, built around the Information Technology Act 2000 and the rules made under it, is the other half of the habit: writers who worked with that framework carry its terms forward. Note the tense, though. The DPDP Act has not displaced that framework yet. Section 44(2)(a) omits section 43A of the Information Technology Act 2000 and section 44(2)(c) omits the rule making power in section 87(2)(ob), but section 44(2) sits in the same 18 month commencement group as sections 3, 9 and 10, computed at 13 May 2027 and interpretation until officially confirmed. Section 43A of that Act, including how its Explanation treats the words sensitive personal data or information, is now quoted on this site, in can I sue under the DPDP Act. The rules made under that power are the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, and rule 3 of them is where a sensitive personal data category really does exist in the older framework, in 8 clauses with a proviso that defines the term for the purposes of those Rules. That Gazette print is now on file and is read in full in the SPDI Rules 2011 and the DPDP Act. The point here is only that the DPDP Act does not import that category.

Neither history changes the DPDP text. If you are mapping a GDPR programme onto India, the sensitive data tier is 1 of the places where the 2 regimes genuinely diverge, and assuming it carries over will produce controls the Act does not require while leaving the duties it does require unmapped.

What this means in practice

Do not build a DPDP data classification scheme around sensitivity tiers and expect it to satisfy the Act. The Act asks for the same core things across all personal data: a lawful basis, notice, security safeguards, breach intimation, retention discipline and a route for rights requests.

Sensitivity is still worth recording internally, for 2 reasons that are about risk rather than classification: it feeds the section 10 factors if your organisation is ever assessed, and it shapes how much harm a breach would cause, which is exactly what your security safeguards are sized against.

What to do

Work out what applies to your organisation with the applicability checker and your position for a given activity with the role and actor checker. The official text is at Section 3 and Section 10, and the definition itself at Section 2. For the GDPR mapping, see DPDP vs GDPR; for the notification factors and the invented thresholds that circulate alongside them, see Significant Data Fiduciary explained.

Section 3, application of the Act →Is a name or email address personal data? →Significant Data Fiduciary: factors, not thresholds →DPDP vs GDPR: the differences that matter →Children's data: the section 9 duties and the Rule 12 exemptions →DPDP for healthcare →

Personal dataDefinitionsCorrectionsHealthcare

Share this: