What Is the DPDP Act? A Practical Guide for Indian Businesses
Understand India's Digital Personal Data Protection Act 2023: scope, key concepts, obligations, and what compliance means for your business.
Executive Summary
India's Digital Personal Data Protection Act, 2023 (DPDP Act) is a comprehensive law governing how organizations collect, process, and protect personal data. Enacted on August 11, 2023, it began partial implementation on November 13, 2025, with full compliance required by May 13, 2027.
The Act establishes a consent-based framework, grants specific rights to individuals ("Data Principals"), and imposes obligations on organizations ("Data Fiduciaries") that process personal data within India.
What Is the DPDP Act?
The Digital Personal Data Protection Act is India's primary law regulating the processing of digital personal data. It applies to any organization that collects, uses, shares, or stores personal data of individuals in India—regardless of where the organization is located.
The Act was passed by Parliament and received Presidential assent on August 11, 2023. The government notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025, which operationalize the Act's provisions.
The Act replaces the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 as the primary framework for personal data protection in India.
Key Definitions You Need to Know
Data Principal
Any natural person to whom personal data relates. In other words, the individual whose data is being processed. The DPDP Act grants specific rights to Data Principals.
Data Fiduciary
The entity that determines the purpose and manner of personal data processing. The Data Fiduciary bears primary responsibility for DPDP compliance, including obtaining consent, providing notices, securing data, and responding to individual rights requests.
Data Processor
An entity that processes personal data on behalf of the Data Fiduciary, acting purely on the Fiduciary's instructions. Data Processors have limited direct obligations under the Act but must implement reasonable security measures. The Data Fiduciary remains responsible for the Processor's compliance.
Personal Data
Any data that relates to a natural person and can identify or could reasonably identify that person. This includes digital and non-digital information processed digitally. The definition is broad and includes names, email addresses, phone numbers, identification numbers, location data, and more.
Consent
Freely given, specific, informed, unambiguous, and clearly affirmative action signifying agreement to process personal data for a particular purpose. Under the DPDP Act, consent is typically the legal basis for processing personal data.
Scope and Application
The DPDP Act applies to:
- All personal data processing in India: Any organization collecting, using, or storing personal data of individuals in India, regardless of where the organization is located
- All types of personal data: Digital personal data processed by digital means
- Most sectors: Fintech, e-commerce, SaaS, BFSI, healthcare, consumer internet, and virtually all sectors that handle personal data
Implementation Timeline
The Act has a phased implementation:
Phase 1 (November 13, 2025)
Data Protection Board establishment and core governance provisions
Phase 2 (November 13, 2026)
Most operational obligations take effect for all Data Fiduciaries
Full Compliance (May 13, 2027)
Complete 18-month implementation period concludes
Core Obligations
1. Obtain and Prove Consent
Data Fiduciaries must obtain verifiable consent from Data Principals before processing personal data. The consent must be:
- Specific to the purpose of processing
- Informed (based on a clear notice)
- Free from coercion or undue pressure
- Unambiguous and clearly affirmative
Data Fiduciaries must be able to prove that consent was obtained in compliance with the Act's requirements.
2. Provide Clear Notices
Before requesting consent, Data Fiduciaries must provide Data Principals with a clear notice that includes:
- The personal data category and processing purpose
- How Data Principals can exercise their rights
- How to file complaints with the Data Protection Board
- Any other information prescribed in the rules
3. Implement Security
Data Fiduciaries must implement "reasonable security safeguards" appropriate to the nature and sensitivity of the personal data. This includes:
- Encryption and tokenization where appropriate
- Access controls and authentication
- Regular security assessments
- Breach response procedures
4. Report Breaches
In the event of a data breach involving personal data, Data Fiduciaries must:
- Notify the Data Protection Board "without undue delay"
- Provide a detailed report within 72 hours
- Notify affected Data Principals as soon as practicable
- Document the breach and response measures
5. Honor Data Principal Rights
Data Fiduciaries must respond to Data Principal requests for:
- Access: Know what personal data is being processed and why
- Correction: Correct inaccurate personal data
- Erasure: Delete personal data (subject to exceptions)
- Grievance Redressal: File complaints about violations
6. Establish Grievance Mechanisms
Data Fiduciaries must appoint a Grievance Officer and establish a process for Data Principals to file complaints about violations of their rights.
Data Principal Rights
The DPDP Act grants individuals four key rights:
1. Right to Know
Data Principals can request information about what personal data is being processed, why it's being processed, who has access, and for how long it will be retained.
2. Right to Correct
Data Principals can request correction of inaccurate or incomplete personal data. This right applies where consent was given or data was voluntarily provided.
3. Right to Erasure
Data Principals can request deletion of their personal data, subject to exceptions for legal obligations, public interest, or where a legitimate use exception applies.
4. Right to Grievance
Data Principals can file complaints with the Data Fiduciary's Grievance Officer and, if unresolved, escalate to the Data Protection Board.
Special Categories of Data
Children's Data
Special protections apply to processing data of children (individuals under 18):
- Parental/guardian consent is required with verification of identity
- The guardian must be verified to be an adult and authorized
- Additional safeguards apply; different from adult data processing
Sensitive Personal Data
Certain categories receive additional protection, including:
- Medical/health data
- Biometric data
- Genetic data
- Sex life information
- Religious/caste/tribe affiliation
- Political affiliation
- Union membership
- Criminal/prosecution records
Significant Data Fiduciaries
The government can designate certain Data Fiduciaries as "Significant Data Fiduciaries" (SDFs) based on:
- Volume and sensitivity of personal data processed
- Risk to Data Principals' rights
- Impact on sovereignty or public order
SDFs face additional obligations, including:
- Appointment of India-based Data Protection Officer
- Maintenance of detailed data audit trail
- Impact assessments on data processing
- Enhanced security measures
- Quarterly compliance certifications
Enforcement and Penalties
The Data Protection Board of India (DPBI) enforces the Act. Penalties are substantial:
| Violation Type | Maximum Penalty |
|---|---|
| Failure to implement reasonable security | ₹250 crore |
| Failure to notify breach | ₹200 crore |
| Failure to provide notice to Data Principal | ₹200 crore |
| Unauthorized disclosure | ₹250 crore |
| Failure to honor rights requests | ₹150 crore |
Important: Penalties are assessed per violation, not per incident. A single breach affecting multiple individuals could result in multiple penalties.
Practical Implications
For Early-Stage Companies
If your company collects personal data of individuals in India, you must:
- Begin DPDP compliance planning now
- Audit your current data collection and usage
- Document the purposes for which you process data
- Implement consent mechanisms
- Establish data security practices
- Prepare breach notification procedures
- Implement systems to honor rights requests
For Established Companies
Established companies must:
- Urgently audit existing personal data processing
- Assess whether existing consents comply with the Act
- Update privacy notices
- Implement consent management systems
- Ensure downstream systems respect consent decisions
- Train staff on DPDP obligations
- Consider appointing a Chief Privacy Officer or Data Protection Officer
For Data Processors
If your company provides infrastructure (hosting, CRM, analytics, etc.) and customers process personal data on your platform:
- Understand your role as a Data Processor
- Establish Data Processing Agreements with customers
- Implement security features
- Document compliance capabilities for customers
- Consider privacy by design in your product
Key Takeaways
1. Consent Is Central: The DPDP Act is a consent-based framework. Obtaining, proving, and managing consent is the foundation of compliance.
2. Businesses Must Act Now: Phase 2 begins November 2026. Organizations should begin compliance planning immediately.
3. Compliance Is Broad: The Act applies to all businesses processing personal data of individuals in India, regardless of company size or sector.
4. Penalties Are Substantial: Non-compliance can result in penalties up to ₹250 crore per violation.
5. It's Operational: The DPDP Act isn't just legal—it requires operational changes to how businesses handle data, respond to individuals, and manage their technology systems.
What Next?
Now that you understand the DPDP Act's basics:
- Read our article on "What Is Consent Under the DPDP Act?"
- Use our DPDP Compliance Checklist to assess your current state
- Explore our Product Overview to learn how ConsentLog helps operationalize compliance
Sources & Further Reading
Digital Personal Data Protection Act, 2023
Parliament of India — Full Text
https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sectionsDigital Personal Data Protection Act, 2023
Ministry of Electronics and Information Technology — Official Document
https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfDigital Personal Data Protection Rules, 2025
Ministry of Electronics and Information Technology — Implementation Rules
https://www.meity.gov.in/Related Articles
DPDP Act Compliance Checklist for Indian Businesses
A practical checklist covering data inventory, consent, notices, rights handling, security, and everything your business needs to operationalize DPDP compliance.
What Is Consent Under the DPDP Act?
A deep dive into consent under India's DPDP Act: requirements, notice, informed decision-making, withdrawal, and how to implement consent properly.
Data Principal Rights Under the DPDP Act
The rights Data Principals have under the DPDP Act: access, correction, erasure, and grievance. What businesses must do to honor these rights.
Building your DPDP compliance infrastructure?
ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.