DPDP Act 2023: A Complete Guide to India’s Digital Personal Data Protection Law
Data has become one of the most valuable assets in the digital economy. Every time a person creates an account, makes an online purchase, uses a healthcare application, applies for a financial service, or interacts with a digital platform, personal information may be collected and processed.
To strengthen privacy and establish a comprehensive framework for digital personal data in India, the Government introduced the Digital Personal Data Protection Act, 2023 (DPDP Act).
The Act establishes obligations for organizations that process digital personal data while giving individuals rights over their personal information. The framework was supplemented by the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025.
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India's central legislation governing the processing of digital personal data.
The Act aims to balance two objectives:
Protecting individuals' rights concerning their personal data.
Allowing organizations to process personal data for lawful purposes.
The legislation was enacted on 11 August 2023. Importantly, the Act was designed for phased commencement rather than having every provision become effective immediately.
What Is Personal Data Under the DPDP Act?
The Act broadly deals with digital personal data.
Personal data is information about an individual who can be identified through or in relation to that information.
Examples may include:
Name
Mobile number
Email address
Identification information
Location information
Online identifiers
Customer account information
Financial or transaction-related information
Other information associated with an identifiable individual
The Act is specifically focused on personal data in digital form and certain personal data that is subsequently digitised.
Who Is a Data Principal?
Under the DPDP framework, the individual to whom personal data relates is called the Data Principal.
For example, if a customer creates an account on an e-commerce platform, the customer is the Data Principal.
The Act gives Data Principals specific rights relating to their personal data, including rights concerning access, correction, erasure, grievance redressal, and nomination.
Who Is a Data Fiduciary?
A Data Fiduciary is a person or organization that determines the purpose and means of processing personal data.
In practical terms, an organization may be a Data Fiduciary when it decides:
What personal data to collect
Why the data is needed
How the data will be processed
How the data will be used
With whom the data may be shared
Examples can include banks, e-commerce companies, healthcare organizations, educational platforms, technology companies, and other organizations that determine how personal data is processed.
Consent Under the DPDP Act
Consent is one of the central concepts of the DPDP framework.
Where consent is the basis for processing, it must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action by the Data Principal.
Organizations should therefore avoid relying on confusing consent mechanisms or burying important information in lengthy and unclear notices.
The 2025 Rules further specify requirements for notices, including presenting information in clear and understandable language and providing details about the personal data being processed and the purpose of processing.
Withdrawal of Consent
The DPDP framework also provides individuals with the ability to withdraw consent.
The Rules require organizations to provide mechanisms through which a Data Principal can withdraw consent, with the ease of withdrawal being comparable to the ease with which consent was given.
For businesses, this means consent management should not be treated as a one-time checkbox. Organizations need processes for recording consent, managing changes, and responding appropriately when consent is withdrawn.
Notice Requirements
Before or at the time of requesting consent, organizations need to provide an appropriate notice.
Under the 2025 Rules, the notice must be understandable independently and provide clear information, including:
The personal data being processed
The purpose of processing
Relevant goods, services, or uses enabled by the processing
Information about how individuals can withdraw consent
Information about exercising their rights
This creates an important compliance requirement for websites, mobile applications, digital platforms, and other services that collect personal information.
Rights of Data Principals
The DPDP Act provides several important rights to individuals.
1. Right to Access Information
Data Principals have the right to obtain information about their personal data and its processing, subject to the provisions of the Act.
2. Right to Correction and Erasure
Individuals can request correction of inaccurate or misleading personal data and, where applicable, erasure of personal data.
3. Right to Grievance Redressal
Data Principals have the right to seek grievance redressal regarding the processing of their personal data.
4. Right to Nominate
An individual can nominate another person who may exercise the Data Principal's rights in accordance with the Act, particularly in circumstances provided for by the law.
Duties of Data Principals
The DPDP Act does not only impose obligations on organizations. It also establishes certain duties for Data Principals.
Individuals are expected, among other things, to comply with applicable laws while exercising their rights and provide authentic information where required.
This reflects the Act's approach of creating responsibilities for both organizations processing personal data and individuals whose data is being processed.
Children's Personal Data
The DPDP Act provides additional protections for children's personal data.
Under the Act, a child is an individual who has not completed 18 years of age.
Data Fiduciaries must comply with additional requirements relating to children's data, including obtaining verifiable parental consent where required and observing restrictions concerning certain processing activities involving children.
The 2025 Rules provide additional requirements concerning mechanisms for verifying the identity and age of the child and parent in specified circumstances.
Significant Data Fiduciaries
The DPDP Act creates a special category known as a Significant Data Fiduciary (SDF).
The Central Government may designate an organization as an SDF based on factors such as:
The volume and sensitivity of personal data processed
Risk to the sovereignty and integrity of India
Risk to electoral democracy
Security of the State
Public order
Other relevant factors
Significant Data Fiduciaries have additional obligations compared with ordinary Data Fiduciaries.
These can include requirements relating to:
Data Protection Officers
Independent data audits
Periodic assessments
Compliance with additional measures prescribed under the framework
Security Safeguards
Data Fiduciaries are expected to implement appropriate technical and organizational measures to protect personal data.
The 2025 Rules provide more detailed requirements relating to security safeguards, including measures such as appropriate security controls, encryption or other protective measures, access controls, logging and monitoring, backups, and measures to detect and respond to security incidents.
For businesses, this means data protection needs to be integrated into technology and operational processes rather than being treated solely as a legal or documentation exercise.
Data Breaches and Incident Response
A personal data breach can occur when personal data is compromised through unauthorized access, disclosure, alteration, loss, or similar incidents.
Organizations should therefore establish processes for:
Detecting security incidents
Investigating potential breaches
Containing the incident
Assessing affected data
Notifying the relevant parties where required
Documenting the incident
Taking corrective measures
The DPDP Rules establish requirements concerning notifications to affected Data Principals and the Data Protection Board in specified circumstances.
Data Retention and Erasure
Organizations should think carefully about how long they retain personal data.
The DPDP framework connects processing to specified purposes and establishes obligations around erasure in applicable circumstances.
The 2025 Rules also prescribe certain time periods and requirements relating to erasure of personal data by specified classes of Data Fiduciaries when the data is no longer required for the specified purpose, subject to applicable requirements and exceptions.
Businesses should therefore maintain a clear data retention and deletion policy rather than retaining personal information indefinitely.
Cross-Border Transfer of Personal Data
The DPDP Act permits the transfer of personal data outside India, subject to restrictions that may be prescribed by the Central Government.
This approach differs from a framework that simply prohibits all international transfers.
Organizations operating internationally should therefore monitor applicable government notifications and ensure that their cross-border data flows comply with the DPDP framework and any other applicable laws.
Data Protection Board of India
The DPDP framework establishes the Data Protection Board of India as the regulatory body responsible for exercising powers and performing functions under the Act.
The Central Government formally established the Board through a notification dated 13 November 2025. The Government also notified that the Board would consist of four members.
The Board has an important role in dealing with matters such as breaches of obligations and imposing penalties under the statutory framework.
Penalties Under the DPDP Act
The DPDP Act provides for significant financial penalties for certain breaches.
The maximum penalty specified under the Schedule to the Act can reach ₹250 crore for a breach relating to taking reasonable security safeguards to prevent personal data breaches.
Other breaches can also attract substantial penalties depending on the nature of the violation.
The actual consequences depend on the applicable provision and circumstances of the case. Organizations should therefore treat data protection as an ongoing compliance responsibility.
DPDP Act vs. GDPR
The DPDP Act is sometimes compared with the European Union's General Data Protection Regulation (GDPR).
Although both frameworks focus on personal data protection, they are not identical.
| Area | DPDP Act | GDPR |
|---|---|---|
| Jurisdiction | India-focused framework with specified extraterritorial application | European Union/EEA framework with specified extraterritorial reach |
| Key terminology | Data Principal, Data Fiduciary | Data Subject, Controller, Processor |
| Consent | One lawful basis under the framework | One of several legal bases |
| Children's protection | Special requirements for children | Special rules, including requirements concerning children's consent |
| Regulatory body | Data Protection Board of India | National supervisory authorities and the European Data Protection Board framework |
| Cross-border transfers | Governed through the DPDP framework and government-prescribed restrictions | Subject to GDPR transfer mechanisms and requirements |
| Penalties | Statutory penalties specified under the DPDP Act | Significant administrative fines under GDPR |
Organizations operating in both India and Europe should not assume that compliance with one automatically means compliance with the other.
DPDP Act Compliance Checklist for Businesses
Organizations can begin preparing with the following checklist:
Data Discovery
Identify what personal data is collected.
Determine where the data is stored.
Identify systems, applications, databases, and vendors processing the data.
Map data flows across the organization.
Consent and Notices
Review consent mechanisms.
Make privacy notices clear and understandable.
Record consent where consent is the applicable basis.
Provide practical mechanisms for withdrawing consent.
Individual Rights
Establish processes for access requests.
Create procedures for correction and erasure.
Establish grievance-handling mechanisms.
Define internal responsibilities and response workflows.
Security
Implement appropriate technical safeguards.
Apply access controls.
Monitor systems and maintain appropriate logs.
Protect data against unauthorized access.
Maintain backup and incident-response procedures.
Vendor Management
Identify third parties that process personal data.
Review contractual arrangements.
Assess vendor security practices.
Monitor data-sharing and processing arrangements.
Data Retention
Establish retention periods.
Identify data that is no longer required.
Automate deletion where practical.
Document exceptions and legal retention requirements.
Governance
Assign clear responsibility for privacy compliance.
Conduct periodic reviews.
Maintain documentation.
Monitor regulatory developments and applicable notifications.
DPDP Act Implementation Timeline
One of the most important developments is that the DPDP Act and Rules are being implemented in phases.
On 13 November 2025, the Government notified the commencement schedule for the Act. Certain provisions came into force immediately, some are scheduled to take effect one year later, and a substantial group of provisions is scheduled to take effect 18 months after 13 November 2025.
The Rules follow a similar phased approach. Rules 1, 2 and 17–21 came into force upon publication; Rule 4 is scheduled for one year after publication; and Rules 3, 5–16, 22 and 23 are scheduled for 18 months after publication.
This phased approach gives organizations time to build and operationalize their privacy programs.
How Businesses Can Prepare
DPDP compliance should ideally be approached as a structured program rather than a last-minute legal exercise.
A practical approach is to:
Step 1: Map personal data
Understand what information is collected, why it is collected, where it goes, and who can access it.
Step 2: Review privacy notices
Make notices clear, concise, and aligned with actual data-processing practices.
Step 3: Review consent management
Ensure that consent is appropriately obtained, recorded, managed, and withdrawn.
Step 4: Build individual-rights workflows
Create processes for access, correction, erasure, grievance redressal, and other applicable requests.
Step 5: Strengthen security
Review access controls, encryption, monitoring, incident response, backups, and other safeguards.
Step 6: Review vendors
Identify third parties handling personal data and assess contractual and operational arrangements.
Step 7: Establish retention and deletion controls
Avoid retaining personal data longer than necessary for applicable purposes and requirements.
Step 8: Monitor compliance
Keep policies, procedures, contracts, and technical controls updated as the DPDP framework develops.
Why the DPDP Act Matters
The DPDP Act represents an important development in India's data-protection framework.
For individuals, it establishes a statutory framework for rights concerning digital personal data.
For businesses, it creates a more structured approach to privacy governance, requiring organizations to understand what personal data they process, why they process it, how they protect it, and how they respond to individual rights and regulatory requirements.
For India's digital economy, the framework is intended to support responsible data processing while protecting individuals' personal information.
Conclusion
The Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025, creates India's current statutory framework for digital personal data protection.
Compliance is not simply about publishing a privacy policy. Organizations need to consider the entire data lifecycle—from collection and consent to processing, sharing, security, retention, deletion, and response to individual requests or data breaches.
With the framework being implemented through a phased timeline, organizations should use this period to understand their data practices, identify compliance gaps, strengthen governance, and build privacy into their products and business processes.
Disclaimer: This article is for general informational purposes and does not constitute legal advice. Organizations should assess their specific obligations under the DPDP Act, the 2025 Rules, applicable notifications, and other laws, and seek qualified professional advice where appropriate.
Sources
Ministry of Electronics and Information Technology (MeitY) — Digital Personal Data Protection Rules, 2025
Ministry of Electronics and Information Technology — DPDP Act and policies
India Code — Digital Personal Data Protection Act, 2023
Government of India notification on commencement of the DPDP Act, 2023
Government of India notification establishing the Data Protection Board of India
