DPDP Fundamentals

What Is the DPDP Act? A Practical Guide for Indian Businesses

Understand India's Digital Personal Data Protection Act 2023: scope, key concepts, obligations, and what compliance means for your business.

By: ConsentLog Research
Published: 7 September 2026
Last reviewed: 7 September 2026
12 min read

Executive Summary

India's Digital Personal Data Protection Act, 2023 (DPDP Act) is a comprehensive law governing how organizations collect, process, and protect personal data. Enacted on August 11, 2023, it began partial implementation on November 13, 2025, with full compliance required by May 13, 2027.

The Act establishes a consent-based framework, grants specific rights to individuals ("Data Principals"), and imposes obligations on organizations ("Data Fiduciaries") that process personal data within India.

What Is the DPDP Act?

The Digital Personal Data Protection Act is India's primary law regulating the processing of digital personal data. It applies to any organization that collects, uses, shares, or stores personal data of individuals in India—regardless of where the organization is located.

The Act was passed by Parliament and received Presidential assent on August 11, 2023. The government notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025, which operationalize the Act's provisions.

The Act replaces the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 as the primary framework for personal data protection in India.

Key Definitions You Need to Know

Data Principal

Any natural person to whom personal data relates. In other words, the individual whose data is being processed. The DPDP Act grants specific rights to Data Principals.

Data Fiduciary

The entity that determines the purpose and manner of personal data processing. The Data Fiduciary bears primary responsibility for DPDP compliance, including obtaining consent, providing notices, securing data, and responding to individual rights requests.

Data Processor

An entity that processes personal data on behalf of the Data Fiduciary, acting purely on the Fiduciary's instructions. Data Processors have limited direct obligations under the Act but must implement reasonable security measures. The Data Fiduciary remains responsible for the Processor's compliance.

Personal Data

Any data that relates to a natural person and can identify or could reasonably identify that person. This includes digital and non-digital information processed digitally. The definition is broad and includes names, email addresses, phone numbers, identification numbers, location data, and more.

Consent

Freely given, specific, informed, unambiguous, and clearly affirmative action signifying agreement to process personal data for a particular purpose. Under the DPDP Act, consent is typically the legal basis for processing personal data.

Scope and Application

The DPDP Act applies to:

  • All personal data processing in India: Any organization collecting, using, or storing personal data of individuals in India, regardless of where the organization is located
  • All types of personal data: Digital personal data processed by digital means
  • Most sectors: Fintech, e-commerce, SaaS, BFSI, healthcare, consumer internet, and virtually all sectors that handle personal data

Implementation Timeline

The Act has a phased implementation:

Phase 1 (November 13, 2025)

Data Protection Board establishment and core governance provisions

Phase 2 (November 13, 2026)

Most operational obligations take effect for all Data Fiduciaries

Full Compliance (May 13, 2027)

Complete 18-month implementation period concludes

Core Obligations

1. Obtain and Prove Consent

Data Fiduciaries must obtain verifiable consent from Data Principals before processing personal data. The consent must be:

  • Specific to the purpose of processing
  • Informed (based on a clear notice)
  • Free from coercion or undue pressure
  • Unambiguous and clearly affirmative

Data Fiduciaries must be able to prove that consent was obtained in compliance with the Act's requirements.

2. Provide Clear Notices

Before requesting consent, Data Fiduciaries must provide Data Principals with a clear notice that includes:

  • The personal data category and processing purpose
  • How Data Principals can exercise their rights
  • How to file complaints with the Data Protection Board
  • Any other information prescribed in the rules

3. Implement Security

Data Fiduciaries must implement "reasonable security safeguards" appropriate to the nature and sensitivity of the personal data. This includes:

  • Encryption and tokenization where appropriate
  • Access controls and authentication
  • Regular security assessments
  • Breach response procedures

4. Report Breaches

In the event of a data breach involving personal data, Data Fiduciaries must:

  • Notify the Data Protection Board "without undue delay"
  • Provide a detailed report within 72 hours
  • Notify affected Data Principals as soon as practicable
  • Document the breach and response measures

5. Honor Data Principal Rights

Data Fiduciaries must respond to Data Principal requests for:

  • Access: Know what personal data is being processed and why
  • Correction: Correct inaccurate personal data
  • Erasure: Delete personal data (subject to exceptions)
  • Grievance Redressal: File complaints about violations

6. Establish Grievance Mechanisms

Data Fiduciaries must appoint a Grievance Officer and establish a process for Data Principals to file complaints about violations of their rights.

Data Principal Rights

The DPDP Act grants individuals four key rights:

1. Right to Know

Data Principals can request information about what personal data is being processed, why it's being processed, who has access, and for how long it will be retained.

2. Right to Correct

Data Principals can request correction of inaccurate or incomplete personal data. This right applies where consent was given or data was voluntarily provided.

3. Right to Erasure

Data Principals can request deletion of their personal data, subject to exceptions for legal obligations, public interest, or where a legitimate use exception applies.

4. Right to Grievance

Data Principals can file complaints with the Data Fiduciary's Grievance Officer and, if unresolved, escalate to the Data Protection Board.

Special Categories of Data

Children's Data

Special protections apply to processing data of children (individuals under 18):

  • Parental/guardian consent is required with verification of identity
  • The guardian must be verified to be an adult and authorized
  • Additional safeguards apply; different from adult data processing

Sensitive Personal Data

Certain categories receive additional protection, including:

  • Medical/health data
  • Biometric data
  • Genetic data
  • Sex life information
  • Religious/caste/tribe affiliation
  • Political affiliation
  • Union membership
  • Criminal/prosecution records

Significant Data Fiduciaries

The government can designate certain Data Fiduciaries as "Significant Data Fiduciaries" (SDFs) based on:

  • Volume and sensitivity of personal data processed
  • Risk to Data Principals' rights
  • Impact on sovereignty or public order

SDFs face additional obligations, including:

  • Appointment of India-based Data Protection Officer
  • Maintenance of detailed data audit trail
  • Impact assessments on data processing
  • Enhanced security measures
  • Quarterly compliance certifications

Enforcement and Penalties

The Data Protection Board of India (DPBI) enforces the Act. Penalties are substantial:

Violation TypeMaximum Penalty
Failure to implement reasonable security₹250 crore
Failure to notify breach₹200 crore
Failure to provide notice to Data Principal₹200 crore
Unauthorized disclosure₹250 crore
Failure to honor rights requests₹150 crore

Important: Penalties are assessed per violation, not per incident. A single breach affecting multiple individuals could result in multiple penalties.

Practical Implications

For Early-Stage Companies

If your company collects personal data of individuals in India, you must:

  • Begin DPDP compliance planning now
  • Audit your current data collection and usage
  • Document the purposes for which you process data
  • Implement consent mechanisms
  • Establish data security practices
  • Prepare breach notification procedures
  • Implement systems to honor rights requests

For Established Companies

Established companies must:

  • Urgently audit existing personal data processing
  • Assess whether existing consents comply with the Act
  • Update privacy notices
  • Implement consent management systems
  • Ensure downstream systems respect consent decisions
  • Train staff on DPDP obligations
  • Consider appointing a Chief Privacy Officer or Data Protection Officer

For Data Processors

If your company provides infrastructure (hosting, CRM, analytics, etc.) and customers process personal data on your platform:

  • Understand your role as a Data Processor
  • Establish Data Processing Agreements with customers
  • Implement security features
  • Document compliance capabilities for customers
  • Consider privacy by design in your product

Key Takeaways

1. Consent Is Central: The DPDP Act is a consent-based framework. Obtaining, proving, and managing consent is the foundation of compliance.

2. Businesses Must Act Now: Phase 2 begins November 2026. Organizations should begin compliance planning immediately.

3. Compliance Is Broad: The Act applies to all businesses processing personal data of individuals in India, regardless of company size or sector.

4. Penalties Are Substantial: Non-compliance can result in penalties up to ₹250 crore per violation.

5. It's Operational: The DPDP Act isn't just legal—it requires operational changes to how businesses handle data, respond to individuals, and manage their technology systems.

What Next?

Now that you understand the DPDP Act's basics:

Sources & Further Reading

Digital Personal Data Protection Act, 2023

Parliament of India — Full Text

https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sections

Digital Personal Data Protection Act, 2023

Ministry of Electronics and Information Technology — Official Document

https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

Digital Personal Data Protection Rules, 2025

Ministry of Electronics and Information Technology — Implementation Rules

https://www.meity.gov.in/

Building your DPDP compliance infrastructure?

ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.