The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive law that governs how personal data is collected, processed, and protected.
Earlier, data protection and privacy in India was governed by the IT Act and some sectoral laws. The DPDP Act now requires every individual's personal data to be processed with their informed consent, gives individuals a set of rights over their data, and places obligations on the businesses that hold it.
The DPDP Act was notified in August 2023 but it began coming into force in phases after the DPDP Rules were notified in November 2025. The deadline for businesses to comply with the core obligations is 13 May 2027.
What are the DPDP Rules, 2025?
The DPDP Rules, 2025 were notified on 13 November 2025. The final Rules provide clear guidance on the operational aspects under the DPDP Act i.e. how to write a consent notice, secure personal data, report a breach, and register as a Consent Manager.
The Rules also mandate verifiable parental consent before processing a child's personal data, and set out how Significant Data Fiduciaries must run their annual audits and data protection impact assessments.
You can read about each obligation in detail in our blog on DPDP Rules.
Who does the DPDP Act apply to?
The DPDP Act applies to any entity processing personal data of persons in India.
What is personal data under the DPDP Act?
Under the DPDP Act, personal data is any data about an individual who is identifiable by or in relation to that data.
Some common examples of personal data are:
- Name
- Mobile number
- Bank account details
- Photograph
- Signature
- Aadhaar details
You can read more about what counts as personal data in our blog on personal data.
Which businesses does the DPDP Act apply to?
The DPDP Act applies to any business that processes the digital personal data of individuals in India - whether the business is based in India or abroad.
The location of the business does not matter. A company outside India is still covered if it processes the data of people in India to offer them goods or services.
Does the DPDP Act cover physical records?
The Act deals with digital personal data. This includes data collected in digital form, as well as physical data that is later digitised. Purely physical records that are never digitised are not covered.
What is excluded under the DPDP Act?
There are a few exclusions. The Act does not apply to:
- Personal data an individual processes for a personal or domestic purpose.
- Publicly available personal data i.e. data the individual has made public themselves, or that someone is required by law to make public.
Eg: If a person publishes their own views and personal details on a public blog or social media profile, the Act does not apply to that data.
Who are the main entities under the DPDP Act?
1. Data Fiduciary: A Data Fiduciary is any person or entity that decides the purpose and means of processing personal data.
2. Data Principal: A Data Principal is the individual to whom the personal data relates. Where the individual is a child, the Data Principal includes their parent or lawful guardian; where the individual is a person with disability, it includes their lawful guardian. Read in detail in our blog on Data Principal.
3. Data Processor: A Data Processor is a party that processes personal data on behalf of a Data Fiduciary. It can only act under a valid contract and on the Data Fiduciary's instructions. We have written a detailed blog explaining the roles and responsibilities of Data Processors.
4. Significant Data Fiduciary: A Significant Data Fiduciary (SDF) is a Data Fiduciary, or a class of Data Fiduciaries that the Central Government notifies that have some additional obligations under the Act.
SDF classification is based on factors like
- volume and sensitivity of data processed,
- risk to data principals, and
- impact on the sovereignty, security, or electoral democracy of India.
An SDF has these additional obligations:
- It must appoint a Data Protection Officer based in India,
- It must appoint an independent data auditor, and
- It must carry out periodic Data Protection Impact Assessments and audits.
Read more in our blog on Significant Data Fiduciary.
5. Consent Manager: A Consent Manager is an entity registered under Rule 4 of the DPDP Rules, 2025 that enables Data Principals to give, manage, review, and withdraw consent across multiple Data Fiduciaries through a single, interoperable platform. Learn more about how Consent Manager's work in our blog.
6. Data Protection Board: The Data Protection Board of India is the adjudicating body established by the Central Government to enforce the Act. It inquires into personal data breaches and imposes penalties under the Act. Read more in our blog on Data Protection Board.
What are the core obligations under the DPDP Act?
1. Collecting Consent : Under the DPDP Act, personal data can only be processed after collecting consent. As per Section 6 of the DPDP Act consent should be free, specific, informed, unconditional, unambiguous and given through a clear affirmative action. Consent must be limited to the personal data necessary for the specified purpose.
2. Notice: Under Section 5 of the Act, read with Rule 3 of the DPDP Rules, every consent request must be accompanied or preceded by a notice that contains:
- An itemised description of the personal data being collected.
- The specific purpose for which the data will be processed.
- The means to withdraw consent.
- How a customer can exercise their rights, and make a complaint to the Data Protection Board.
The Data Principal must be able to access the notice in English or any of the 22 languages listed in the Eighth Schedule to the Constitution.
See our blog on how to build a drop-off-free consent notice.
3. Purpose limitation: Personal data can be processed only for the purpose stated in the notice. Once that purpose is served the data must be erased, unless retention is required by law.
4. Reasonable security safeguards: Under Section 8(5) and Rule 6, a Data Fiduciary must protect personal data with reasonable security safeguards.
These include encryption, obfuscation or masking; access controls; logging and monitoring to detect unauthorised access; data backups for continuity; and a one-year retention of logs.
5. Breach reporting: Under Section 8(6) and Rule 7, a Data Fiduciary must intimate each affected Data Principal and the Data Protection Board of every personal data breach.
The affected individuals must be told without delay, and the Board must receive a detailed report within 72 hours of the Data Fiduciary becoming aware of the breach. Read our blog on Personal Data Breach for more details.
What to do with data collected before the DPDP Act?
For consent collected before the commencement of the DPDP Act, the Data Fiduciary must send the Data Principals a one-time notice describing the personal data being processed and the purpose of processing.
The Data Fiduciary may continue processing until the Data Principal withdraws consent — at which point processing must stop.
This is a significant obligation for data-heavy industries like BFSI, telemarketing, e-commerce, and healthcare. A notice must reach every existing customer, detailing:
- The personal data being processed
- The purpose of processing
- How to exercise their rights and raise a complaint
For guidance on retaining legacy data lawfully, see our Data Retention Guide.
What are the rights of Data Principals under the DPDP Act?
The Act gives every Data Principal a set of enforceable rights over their personal data:
- Right to access: a summary of their personal data and how it is being processed, along with the identities of others it has been shared with (Section 11).
- Right to correction: to correct, complete or update, or erase any inaccurate or incomplete personal data (Section 12).
- Right to grievance redressal: through a readily available mechanism provided by the Data Fiduciary or Consent Manager (Section 13).
- Right to nominate: another individual to exercise their rights in the event of death or incapacity (Section 14).
- Right to withdraw consent: a Data Principal should be able to withdraw consent at any time, and withdrawing must be as easy as giving consent (Section 6(4)).
- Right to erasure: unless the Data Fiduciary is required to retain it for the specified purpose or to comply with a law in force (Section 12(3)).
What are the duties of Data Principals under the DPDP Act?
Under Section 15 of the DPDP Act, a Data Principal must:
- Comply with all applicable laws while exercising their rights under the Act.
- Not impersonate another person while providing their personal data.
- Not suppress any material information while providing personal data for any document, unique identifier, proof of identity, or proof of address issued by the State.
- Not register a false or frivolous grievance or complaint with a Data Fiduciary or the Data Protection Board.
- Furnish only verifiably authentic information when exercising the right to correction or erasure.
What are the exemptions under the DPDP Act?
The DPDP Act is not absolute. It carves out situations where you can process personal data without consent, or continue to retain it even after a deletion request. There are three types of exemptions:
- Legitimate Uses (Section 7) — where you can process personal data without obtaining consent, such as voluntarily shared data, employment-related processing, legal obligations, and medical emergencies.
- Regulatory Retention (Sections 6(6) and 8(7)) — where you can retain data for a legal or regulatory purpose even after consent is withdrawn or a deletion request is raised.
- General Exemptions (Section 17) — where most DPDP obligations stop applying entirely, such as enforcing legal rights, investigating offences, BPO processing for foreign clients, and court-approved mergers.
These exemptions are real, but narrower than most compliance teams assume. We break each one down, with examples, in our blog on DPDP exemptions.
What are children's rights under the DPDP Act?
- Section 9(1) of the Act states that a child's personal data may be processed only after obtaining verifiable consent from their parent or lawful guardian. Rule 10 of the DPDP Rules sets out how verifiable parental consent is to be obtained.
- Under Section 9, a Data Fiduciary must obtain verifiable parental consent before processing the personal data of a child (anyone under 18).
- Under Sections 9(2) and 9(3), a Data Fiduciary must not process children's data in a way likely to cause a detrimental effect on their well-being, and it must not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
Read more about the DPDP law on children's data in our blog on DPDP compliance.
How is the data of persons with disabilities processed under the DPDP Act?
For a person with disability who has a lawful guardian, a Data Fiduciary must obtain the verifiable consent of that guardian before processing their personal data under Section 9 of the DPDP Act.
Under Rule 11, the Data Fiduciary must exercise due diligence to verify that the guardian has been appointed by a court, a designated authority, or a local-level committee under the applicable guardianship law.
What are the restrictions on cross-border data transfers under the DPDP Act?
Under the DPDP Act, there is a black list approach to cross-border data transfers. As per Section 16, personal data can be transferred to any country or territory outside India — unless the Central Government specifically restricts transfers to a notified jurisdiction.
Separately, a Significant Data Fiduciary may be required to keep certain categories of personal data within India. You can read in detail about these restrictions on our blog on Cross Border Data Transfer under DPDP Act.
What are the penalties for violating the DPDP Act?
Penalties under the DPDP Act can extend up to ₹250 crore per instance of non-compliance, imposed by the Data Protection Board following an inquiry. The Schedule to the Act sets out the maximum penalty for each category of breach.
For a full breakdown, see our blog on penalties under the DPDP Act.
How does the inquiry process work?
The Data Protection Board first determines whether there are sufficient grounds to proceed. If there are, it conducts an inquiry and after giving the person an opportunity to be heard, the Board may impose a monetary penalty. A person aggrieved by the Board's order can appeal to the Appellate Tribunal within 60 days. Read more in our blog on Data Protection Board.
What is the difference between the DPDP Act and GDPR?
The European Union's General Data Protection Regulation (GDPR) and India's DPDP Act are both landmark data protection laws, but they differ in important ways.
Read more in our comparison of DPDP vs GDPR.
Are there other data protection regulations to follow alongside the DPDP Act?
Yes. The DPDP Act is in addition to, not in derogation of, other laws in force. Where a conflict arises, the DPDP Act prevails to the extent of the conflict.
For regulated sectors, DPDP compliance must sit alongside existing obligations:
- BFSI: Banks and regulated financial entities must align DPDP compliance with RBI, SEBI, and IRDAI requirements. Read more in our blog on DPDP for BFSI.
Banks and NBFCs are also required to follow the Responsible Business Conduct Directions. Read more in our blog on Responsible Business Conduct Directions.
- Lending and fintech: Digital lenders must reconcile DPDP consent obligations with the RBI's KYC Master Directions and Digital Lending Guidelines. Read more in our blog on DPDP for Lenders.
- E-commerce: Large e-commerce entities face specific data-retention timelines under the DPDP Rules. Read more in our blog on DPDP for e-commerce.
- Healthcare: Health data processing carries heightened sensitivity and sector-specific obligations.
Frequently Asked Questions
When does the DPDP Act come into force? The Act was notified in August 2023 and is coming into force in phases. The core obligations for businesses take effect on 13 May 2027, following the notification of the DPDP Rules in November 2025.
Does the DPDP Act apply to companies outside India? Yes. A company based outside India is covered if it processes the personal data of individuals in India to offer them goods or services.
Is consent always required to process personal data? No. Consent is the default, but the Act allows processing without consent in specific "legitimate uses" and provides broader general exemptions. See our blog on DPDP exemptions.
What is the maximum penalty under the DPDP Act? Up to ₹250 crore per instance of non-compliance, imposed by the Data Protection Board of India.
What is a Consent Manager under the DPDP Act? A Consent Manager is a company registered with the Data Protection Board under Rule 4 of the DPDP Rules that lets individuals give, manage, review, and withdraw consent across multiple businesses through a single platform.
Note: This article is for informational purposes only and does not constitute legal advice. Consult your legal counsel for advice specific to your situation.
.avif)


.png)
