Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Is a name and email address personal data under DPDP?

Definitions

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 2 min read

Is a name or email address personal data under the DPDP Act?

The short answer

Usually yes in ordinary business records. The Act defines personal data as any data about an individual who is identifiable by or in relation to such data, so the test is identifiability, not a list of categories. Customer, employee and account records containing names or email addresses will ordinarily meet that test. Handled digitally, they are digital personal data, which is what the Act applies to.

More answered questions →

Summary infographic headed 'Is name plus email personal data?'
The infographic answers: usually yes, where the details identify an individual. It states that, handled digitally, this is digital personal data, that customer, employee and vendor contact data can be covered, and that this single fact can pull the wider DPDP framework into play. A record card showing an example name and email address is tagged personal data.

Some definitional questions are genuinely hard. In ordinary business records this one is not, and it is worth seeing why from the official text itself.

The definition turns on identifiability

DPDP Act 2023, s. 2(t) · Definitions · verbatim

"“personal data” means any data about an individual who is identifiable by or in relation to such data"

Three things matter in that sentence. It says any data, without listing categories. It ties the concept to an individual. And it asks one question: is the individual identifiable by the data or in relation to it?

A name is the plainest identifier there is. An email address both identifies a person and provides a way to reach them, and most email addresses contain a name besides. In any real record, both are data about an identifiable individual, so both are personal data.

The test is contextual at the margin. A common first name held with nothing else may not make anyone identifiable, while a full name in an email address identifies its owner on its face. The definition resolves the marginal cases by asking whether the individual is identifiable by the data or in relation to it, which pulls in the surrounding records. In an ordinary business system a name sits beside an order, an account or a support thread, and the identifiability test is met.

Digital form is what brings the Act in

The Act applies to digital personal data, which is simply personal data in digital form. Names and email addresses in your CRM, sign up database, mailing list, spreadsheet or support inbox are all in digital form. Collected on paper and typed in later also counts, because the application section covers data digitised subsequently.

What follows

If your organisation holds names and email addresses of customers, users, employees or vendors and handles them on computers, you hold digital personal data. That single fact is what makes the applicability question worth settling properly, because everything else in the framework hangs off it.

What to do

Check whether the framework applies to your organisation; the answer traces to the exact definitions quoted above. The full definition list lives at Section 2, official text.

Section 2, official definitions →

Personal dataDefinitions

Share this: