Legal Register
Visual Infographic
I-15 Perimeter & Scope ๐Ÿ‘ค Legal Counsel & Product Architecture Leads

The Applicability Decision Tree

Five-Stage Perimeter Sieve: Personal Data, Digital Form, Territorial Nexus, Exclusions, and Section 17

Determining whether an enterprise activity falls under the DPDP Act requires traversing a 5-stage logical decision tree. Stage 1: Is the data personal data (identifiable natural person)? Stage 2: Is it collected in digital form or digitized subsequently? Stage 3: Does it meet the territorial nexus (processed in India, or offshore targeting Indian principals)? Stage 4: Is it excluded (purely personal/domestic or made publicly available by the principal)? Stage 5: Does a Section 17 statutory exemption apply?

Statutory Source: Ch. 3 ยง3, Applicability Tree Tool
Archetype: decision tree
I-15 DiagramArchetype: DECISION TREE

The Applicability Decision Tree

Five-Gate Applicability Sieve Logic
Gate 1
Is it Personal Data?
Ref: s.2(t)
YES: Proceed to Gate 2NO: OUT OF SCOPE (Non-Personal Data)
Gate 2
Is it in Digital Form (or digitized)?
Ref: s.3(a)
YES: Proceed to Gate 3NO: OUT OF SCOPE (Non-Digitized Physical)
Gate 3
Territorial Nexus (In India or Offering Goods/Services in India)?
Ref: s.3(a),(b)
YES: Proceed to Gate 4NO: OUT OF SCOPE (Foreign Nexus Extraterritorial)
Gate 4
Is it Personal/Domestic Use or Publicly Available by Principal?
Ref: s.3(c)
YES: EXCLUDED (s.3(c))NO: Proceed to Gate 5
Gate 5
Does a Section 17 Statutory Exemption Apply?
Ref: s.17
YES: EXEMPTED (s.17)NO: FULL DPDP COMPLIANCE MANDATORY

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ Non-digitized physical paper records remain outside DPDP until digitized into electronic systems.
โœฆ Offshore SaaS vendors serving Indian consumers are fully subject to extraterritorial DPDP reach.
โœฆ Publicly available data is only excluded if made public by the Data Principal themselves.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 2(t)Section 2(i)Section 3(a) to (c)Section 4(2)Section 17(1) to (5)

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Run the 5-gate questionnaire on all new product features during architecture reviews.
  2. Document the formal legal rationale for any processing claimed under Section 17 exemptions.
  3. Maintain a perimeter boundary inventory updated on every major product release.

Enterprise Traps & Failure Modes

  • โš ๏ธ Assuming B2B employee data is exempt (employee data is fully personal data under DPDP).
  • โš ๏ธ Scraping social media and claiming it is exempt without verifying the principal made it public.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Applicability Decision Tree Output Dossier (/tools/applicability-tree/)
๐Ÿ“„ Legal Perimeter Scope Memorandum
๐Ÿ“„ Section 17 Exemption Register