What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first standalone legislation dedicated to the protection of personal data. It was passed by both Houses of Parliament in August 2023 and received Presidential assent on 11 August 2023. The Ministry of Electronics and Information Technology (MeitY) is the nodal ministry responsible for its implementation.
The Act sat on the statute book without an operating framework until 13 November 2025, when MeitY notified the final Digital Personal Data Protection Rules 2025 (Gazette notification G.S.R. 846(E)). The Rules give the Act practical teeth — they set out how consent, breach reporting, children's data verification, Significant Data Fiduciary duties and the Data Protection Board will actually work. The compliance countdown is now live, with most obligations becoming enforceable on 13 May 2027.
Before the DPDP Act, India had no dedicated data privacy statute — businesses relied on a patchwork of provisions under the Information Technology Act 2000, the IT (Reasonable Security Practices) Rules 2011, and sector-specific guidelines from regulators such as RBI and SEBI. The DPDP Act 2023 replaces this fragmented framework with a principles-based, rights-oriented law modelled on global best practices, while retaining India-specific carve-outs.
The Act introduces clear concepts: a Data Principal (the individual whose data is collected), a Data Fiduciary (the entity that determines the purpose and means of processing), and a Data Processor (a third party that processes data on behalf of the fiduciary). Understanding which role your business plays is the starting point for any compliance programme.
Who Does the DPDP Act Apply To?
The Act has a broad territorial reach. It applies to:
- Processing of digital personal data within India, where such data is collected online or is digitised after offline collection.
- Processing of personal data outside India if it relates to the offering of goods or services to individuals within India.
In plain terms, any Indian company — from a bootstrapped startup in Bengaluru to a large NBFC in Mumbai — that collects a customer's name, phone number, email, or Aadhaar-linked details is a Data Fiduciary and falls squarely under the Act. Similarly, a foreign e-commerce platform serving Indian consumers must comply even if it has no physical presence in India.
Exemptions are limited. Processing for national security, prevention of crime, or research, archiving and statistical purposes may be exempt by Central Government notification. Certain notice and erasure obligations are relaxed for specified classes such as startups (as notified) and for processing of employee data for limited purposes — but the core duties of lawful processing and security still apply.
Key Definitions Every Business Must Know
| Term | What It Means in Practice |
|---|---|
| Personal Data | Any data about an identifiable individual — name, mobile number, PAN, the GSTIN of a sole proprietor, IP address, location data, biometrics. |
| Data Fiduciary | Your company — any entity that decides why and how personal data is processed. You bear the primary compliance burden, including for processing done on your behalf by a processor. |
| Data Principal | Your customer, employee, or website visitor — the natural person whose data you process. They hold statutory rights. |
| Consent Manager | A registered intermediary through which Data Principals can give, manage, review, and withdraw consent across fiduciaries. Registration with the Board opens from 13 November 2026. |
| Significant Data Fiduciary (SDF) | Entities notified by the Central Government based on volume of data processed, sensitivity, national security risk, or systemic impact. Higher compliance obligations apply. |
| Data Protection Board | The adjudicatory body established under the Act and the 2025 Rules to receive complaints, investigate breaches, and impose penalties. |
Core Obligations for All Data Fiduciaries
Every business that qualifies as a Data Fiduciary under the DPDP Act must fulfil the following baseline obligations. These become enforceable on 13 May 2027, but the build-out should start now.
1. Notice and Consent
Before collecting any personal data, you must provide a clear, plain-language notice to the Data Principal specifying what data is being collected, the purpose of processing, the rights of the individual, and how to lodge a complaint with the Board. The notice must be made available in English or any of the 22 languages listed in the Eighth Schedule to the Constitution.
Consent must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action. Pre-ticked boxes, bundled consents, and consent buried in dense terms-and-conditions clauses will not satisfy this standard. Consent can be withdrawn at any time, and the withdrawal must be as easy as giving it.
2. Purpose Limitation
You may process personal data only for the specific purpose for which consent was obtained or for a purpose explicitly permitted by law (a "legitimate use"). Processing for a new, incompatible purpose requires fresh consent. This has direct implications for businesses that repurpose customer data for marketing or share data with third parties.
3. Data Minimisation and Accuracy
Collect only the personal data that is necessary for the specified purpose. Data held must be kept accurate and updated, especially where it is used to make a decision affecting the Data Principal or is shared with another fiduciary.
4. Storage Limitation and Erasure
Personal data must not be retained beyond the period necessary to fulfil its purpose. Once the purpose is served — or when consent is withdrawn — you must erase the data and instruct your processors to do the same, unless retention is required by law. The Rules also fix a hard retention limit for notified large fiduciaries: e-commerce platforms with 2 crore or more registered users, online gaming intermediaries with 50 lakh or more, and social media intermediaries with 2 crore or more must erase a user's personal data three years after the user last approached them, after giving the user at least 48 hours' advance notice of the erasure.
5. Security Safeguards
Data Fiduciaries must implement reasonable technical and organisational security safeguards to prevent personal data breaches. The Rules spell these out to include encryption, masking or tokenisation, access controls, logging and monitoring, data backups, and contractual security obligations on processors. A failure here carries the single largest penalty under the Act.
6. Breach Notification
On becoming aware of a personal data breach, you must intimate each affected Data Principal without delay, describing the breach, its likely consequences and your remedial measures. You must also notify the Data Protection Board without delay, and then submit a detailed report to the Board within 72 hours (or a longer period the Board allows) covering the broad facts, the events leading to the breach, the mitigation taken and the notifications sent to Data Principals.
7. Grievance Redressal
Every Data Fiduciary must publish the contact details of a person who can answer questions about its processing, and must operate a grievance-redressal mechanism. Complaints from Data Principals must be resolved within the period the fiduciary publishes, subject to a statutory cap of 90 days. Unresolved complaints can be escalated to the Data Protection Board.
Significant Data Fiduciaries — Enhanced Compliance
The Central Government will designate certain entities as Significant Data Fiduciaries based on factors including the volume and sensitivity of personal data processed, risk to electoral democracy, the security of the State, and potential impact on public order. Large tech platforms, major e-commerce companies, digital lenders, and health-tech firms are most likely to be designated.
Under Rule 13 of the DPDP Rules 2025, SDFs carry additional obligations beyond the baseline:
- Data Protection Officer (DPO): Must appoint a DPO based in India, who reports to the board of directors and is the point of contact for grievance redressal.
- Annual DPIA and audit: Must, once every twelve months, undertake a Data Protection Impact Assessment and an independent audit, and furnish a report of significant observations to the Data Protection Board.
- Algorithmic diligence: Must verify that algorithmic software used for processing is not likely to harm Data Principals.
- Restricted localisation: Must ensure that personal data and traffic data specified by a Central Government committee is not transferred outside India. All other personal data continues to follow the general cross-border rules.
Even if your business is not an SDF today, building DPO-level accountability into your governance structure is good practice — the list of SDFs may expand over time as the Board gains experience.
Children's Data — Special Obligations
The DPDP Act treats data of persons below 18 years of age as a special category requiring heightened protection, and the 2025 Rules retained this threshold without lowering it. If your platform, app, or service is likely to be accessed by children, you must:
- Obtain verifiable parental consent before processing any personal data of the child. Verification relies on identity and age details already held by the fiduciary, or on a virtual token mapped to such details issued by an authorised entity, such as a DigiLocker service provider.
- Refrain from processing that is likely to cause any detrimental effect on the well-being of the child.
- Not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
Certain classes — such as healthcare providers, schools and child-welfare bodies — get limited exemptions for specified processing. Businesses in ed-tech, gaming, and social media should watch this area closely, as failure to comply with children's-data obligations can attract penalties of up to ₹200 crore.
Rights of Data Principals
The Act grants every individual (Data Principal) the following rights against businesses that hold their data:
- Right to Information: Know what personal data the fiduciary holds and the identities of any other fiduciaries or processors with whom it has been shared.
- Right to Correction and Erasure: Require the fiduciary to correct inaccurate data, complete incomplete data, or erase data no longer needed for the original purpose.
- Right to Grievance Redressal: Lodge complaints with the fiduciary's grievance mechanism, and escalate unresolved complaints to the Data Protection Board.
- Right to Nominate: Nominate another individual to exercise rights on their behalf in the event of death or incapacity.
Businesses should build a Data Subject Rights (DSR) request workflow — ideally a self-service portal — that allows individuals to raise requests and receive timely responses. Manual handling of rights requests at scale is operationally risky and costly.
Cross-Border Data Transfers
Unlike earlier drafts of the Personal Data Protection Bill that proposed strict data localisation for sensitive categories, the enacted DPDP Act 2023 takes a more permissive approach. Cross-border transfer of personal data is permitted, except to countries the Central Government restricts by notification — a negative list rather than a positive whitelist. The 2025 Rules add that a fiduciary must meet any conditions the Government specifies for making personal data available to a foreign State or its agencies.
The one firm restriction is for Significant Data Fiduciaries under Rule 13: categories of personal and traffic data specified by a Government-appointed committee must stay within India. Businesses that rely on cloud infrastructure hosted outside India (AWS, Azure, GCP), use global HR platforms, or share customer data with foreign group entities should document their data flows, keep contractual safeguards in place, and track the Government's notifications.
Penalties for Non-Compliance
The DPDP Act's penalty framework is among the most significant in India's regulatory history. The Schedule to the Act lists the maximum financial penalties the Data Protection Board may impose after an inquiry:
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach (Section 8(5)) | Up to ₹250 crore |
| Failure to notify the Board and affected Data Principals of a breach (Section 8(6)) | Up to ₹200 crore |
| Breach of additional obligations relating to children (Section 9) | Up to ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary (Section 10) | Up to ₹150 crore |
| Breach of duties by a Data Principal (e.g., false particulars, impersonation) | Up to ₹10,000 |
| Breach of a term of a voluntary undertaking accepted by the Board | Up to the penalty applicable to the underlying breach |
| Any other non-compliance with the Act or the Rules | Up to ₹50 crore |
Note that the Act imposes no separate penalty directly on a Data Processor — the Data Fiduciary remains liable for processing carried out on its behalf, so you cannot outsource the risk to a vendor. These are per-instance ceilings, not annual caps; where a single inquiry reveals several distinct violations, the Board can impose separate penalties for each. The Board may also direct remedial action, including deletion of illegally held data.
Building Your DPDP Compliance Programme
Compliance with the DPDP Act is not a one-time filing — it is an ongoing governance programme. The steps below apply to businesses of all sizes, with the depth of implementation scaling to your data footprint, and should be substantially complete before the 13 May 2027 deadline.
Step 1: Conduct a Data Audit
Map every category of personal data your organisation collects — customer KYC, employee records, lead forms, CRM entries, website cookies, payment details. For each data stream, document what is collected, why, where it is stored, who has access, and with which third parties it is shared. This data inventory is the foundation of every other compliance activity.
Step 2: Identify Your Role
Determine whether your organisation is a Data Fiduciary, a Data Processor (processing data on behalf of another fiduciary), or both (common in SaaS and BPO businesses). Your obligations differ significantly. If you are a processor, ensure your contracts with fiduciaries include standard data processing and security clauses.
Step 3: Update Your Privacy Notice
Your existing privacy policy almost certainly does not meet the DPDP Act's notice requirements. Rewrite it in plain language, specify each processing purpose clearly, explain rights and how to exercise them, give a contact for queries and complaints, and publish it prominently. Offer it in the scheduled languages your users request.
Step 4: Rebuild Your Consent Flows
Audit every touchpoint where you collect personal data — signup forms, checkout flows, contact forms, cookie banners, third-party API integrations. Each must present a clear notice and a genuine consent choice before data is collected. Remove pre-checked boxes and bundled consents, and provide a withdrawal mechanism as accessible as the original consent.
Step 5: Appoint a Grievance / Contact Person
Publish the contact details of the person who handles data-protection queries and grievances, and document the resolution process within the 90-day cap. SDFs must additionally appoint a resident DPO who reports to the board of directors.
Step 6: Set Up a Breach Response Protocol
Draft a written incident response plan covering detection and containment, internal escalation, breach assessment, intimation to affected Data Principals without delay, notification to the Board, and the detailed 72-hour report to the Board. Run a tabletop exercise so your team knows the playbook.
Step 7: Review Third-Party Vendor Contracts
Any vendor that processes personal data on your behalf (cloud hosting, payroll software, analytics platform, CRM vendor) is a Data Processor. Your contract must bind them to equivalent security standards and prohibit sub-processing without your authorisation. Review and update all Data Processing Agreements accordingly — remember the liability stays with you.
Step 8: Address Children's Data if Applicable
If your platform may be used by persons under 18 — especially in ed-tech, gaming, social media, or health — implement age assurance, verifiable parental consent (using identity details or a DigiLocker-issued virtual token), and disable behavioural profiling or targeted advertising for this cohort.
Current Regulatory Status (2026)
The DPDP Act 2023 is enacted law, and its operating framework — the DPDP Rules 2025 — was notified on 13 November 2025. The Rules come into force in phases:
- 13 November 2025: Provisions establishing and operating the Data Protection Board of India took effect; the Board is being constituted.
- 13 November 2026: Registration and obligations of Consent Managers come into force.
- 13 May 2027: The substantive obligations — notice and consent, security safeguards, breach notification, retention and erasure, Data Principal rights, and SDF duties — become enforceable.
Businesses should treat the period to May 2027 as a compliance build-out window, not a free pass. Penalty powers attach once the substantive rules bite, and a credible programme cannot be assembled overnight. Starting now avoids the scramble — and legal exposure — of a last-minute rush.
For businesses that also need to verify corporate identity, director details, or company filings as part of their customer onboarding or KYC workflows, WeeDoo's free company search gives instant access to data on over 27 lakh MCA-registered entities — a practical complement to your data protection due-diligence process.