Does the DPDP Act have a sensitive personal data category? No
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 6 min read
The short answer
No. The DPDP Act 2023 has no category of sensitive personal data. The word sensitive does not appear anywhere in the Act, and section 3, which sets the Act's application, has only clauses (a), (b) and (c), so the section 3(d) cited by many articles for a sensitive data category does not exist. Personal data is defined once, in section 2(t), by identifiability alone. Higher duties do arise, but from who is processing and who the data is about rather than from a data type: notification as a Significant Data Fiduciary under section 10, the children's provisions in section 9, and the retention classes in the Third Schedule to the Rules. None of those provisions is in force yet: notification G.S.R. 843(E) and Rule 1(4) place them in the group commencing 18 months after publication, computed to 13 May 2027 and interpretation until officially confirmed, and no Significant Data Fiduciary had been notified as of 24 August 2026.

If you search for DPDP and health data, or DPDP and biometrics, you will find article after article explaining which categories of personal data the Act treats as sensitive. Several cite a provision by number: section 3(d).
Both the category and the provision are inventions. Here is what the official text actually contains, and what really does create heavier duties.
The word sensitive is not in the Act
Search the Gazette text of the Digital Personal Data Protection Act 2023 for the word sensitive and you will find it 0 times. The only related word is sensitivity, and it appears once, in section 10(1)(a), which we come to below.
Personal data is defined a single time:
"“personal data” means any data about an individual who is identifiable by or in relation to such data"
That definition names no categories. It asks 1 question, whether the individual is identifiable, and every kind of personal data that passes that test is governed by the same set of obligations. A blood group and a shipping address sit in the same legal box.
There is no section 3(d)
Section 3 is the application provision. It has 3 clauses:
| Clause | What it does |
|---|---|
| 3(a) | Applies the Act to processing of digital personal data within India, whether collected in digital form or digitised later |
| 3(b) | Extends it to processing outside India in connection with any activity related to offering of goods or services to Data Principals within India |
| 3(c) | Excludes personal data processed by an individual for any personal or domestic purpose, and personal data made publicly available either by the Data Principal herself or by any other person who is under an obligation in Indian law to make it public |
After clause (c)(ii)(B) and its illustration, the Gazette moves straight into Chapter II and section 4. There is no clause (d), so any article that cites section 3(d) for a sensitive data category is citing a provision that does not exist. That is a useful test to apply to a DPDP source: check the number, not just the claim.
Where sensitivity really appears
Section 10(1) lets the Central Government notify a Data Fiduciary, or a class of them, as a Significant Data Fiduciary after assessing relevant factors. The first listed factor is:
"the volume and sensitivity of personal data processed"
Read that carefully, because it is the sentence the myth grows out of. Sensitivity is a factor in assessing an organisation for notification. It does not create a class of data, it attaches no obligation by itself, and it does not operate until the Government notifies someone. As of 24 August 2026 no Significant Data Fiduciary has been notified, and the power to notify is not live yet either: notification G.S.R. 843(E) places section 10 in the group commencing 18 months from the publication of its gazette, printed 13 November 2025, which computes to 13 May 2027, a computed date that is interpretation until officially confirmed.
So handling health records may well make your organisation a candidate for notification. It does not put your health records into a statutory category, because there is no category to put them in.
What actually creates higher duties
3 mechanisms do most of that work, and none of them is a data type.
| Mechanism | Trigger | Where |
|---|---|---|
| Significant Data Fiduciary duties: an India based Data Protection Officer answerable to the board, an independent data auditor, and periodic Data Protection Impact Assessment and audit | Central Government notification after assessing factors including volume and sensitivity | Section 10 |
| Children's duties: verifiable consent of the parent or lawful guardian, no processing likely to cause a detrimental effect on the well being of a child, and no tracking, no behavioural monitoring of children and no targeted advertising directed at children, subject to the exemptions in Rule 12 and the Fourth Schedule | The Data Principal is a child, or a person with disability who has a lawful guardian | Section 9 |
| Shorter retention and erasure clocks | Being a named class of Data Fiduciary at or above a stated user threshold | Third Schedule, read with Rule 8 |
Every trigger is about who processes, or whose data it is, or how large the operation is. None asks what kind of data it is.
All 3 also sit ahead of us rather than behind us. Notification G.S.R. 843(E) places sections 3, 9 and 10 in the group that commences 18 months from the publication of its gazette, and Rule 1(4) does the same for Rule 8, and so for the Third Schedule that Rule 8(1) points to. Computed from the printed publication date of 13 November 2025, that lands on 13 May 2027, and the computed calendar date is interpretation until officially confirmed: the official text states a period, not a date. What is in force today is set out in what is in force in 2026.
Why the myth is so persistent
2 reasons, both understandable.
The GDPR does have special categories. Article 9(1) lists racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and data on sex life or sexual orientation, and prohibits processing them subject to the exceptions set out in Article 9(2). Anyone who learned privacy through the GDPR expects the same architecture and reads it into the Indian Act.
India's own pre DPDP privacy vocabulary, built around the Information Technology Act 2000 and the rules made under it, is the other half of the habit: writers who worked with that framework carry its terms forward. Note the tense, though. The DPDP Act has not displaced that framework yet. Section 44(2)(a) omits section 43A of the Information Technology Act 2000 and section 44(2)(c) omits the rule making power in section 87(2)(ob), but section 44(2) sits in the same 18 month commencement group as sections 3, 9 and 10, computed at 13 May 2027 and interpretation until officially confirmed. This article makes no claim about what the older rules require; the point is only that the DPDP Act does not import a sensitive data category.
Neither history changes the DPDP text. If you are mapping a GDPR programme onto India, the sensitive data tier is 1 of the places where the 2 regimes genuinely diverge, and assuming it carries over will produce controls the Act does not require while leaving the duties it does require unmapped.
What this means in practice
Do not build a DPDP data classification scheme around sensitivity tiers and expect it to satisfy the Act. The Act asks for the same core things across all personal data: a lawful basis, notice, security safeguards, breach intimation, retention discipline and a route for rights requests.
Sensitivity is still worth recording internally, for 2 reasons that are about risk rather than classification: it feeds the section 10 factors if your organisation is ever assessed, and it shapes how much harm a breach would cause, which is exactly what your security safeguards are sized against.
What to do
Work out what applies to your organisation with the applicability checker and your position for a given activity with the role and actor checker. The official text is at Section 3 and Section 10, and the definition itself at Section 2. For the GDPR mapping, see DPDP vs GDPR; for the notification factors and the invented thresholds that circulate alongside them, see Significant Data Fiduciary explained.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Role and Actor Checker
Work out your likely role for a processing activity, such as Data Fiduciary or Data Processor.
Open
Section 3, application of the Act →Is a name or email address personal data? →Significant Data Fiduciary: factors, not thresholds →DPDP vs GDPR: the differences that matter →Children's data: the section 9 duties and the Rule 12 exemptions →