The Digital Personal Data Protection Act, 2023 — the DPDP Act — is India's general law on personal data. If you decide why and how personal data about people in India gets used, you need either the person's permission or one of nine specific allowances. You also owe her a plain account of what you are collecting and why.
That is the whole shape of it. The rest is detail, with the provision behind each claim so you can check it against the bare Act.
What the Act is
Parliament passed it as Act 22 of 2023 and the President assented on 11 August 2023. Its long title balances two things: the right of individuals to protect their personal data, and the need to process personal data for lawful purposes.
The Act did not commence on assent. Sec. 1(2) says it comes into force on such date as the Central Government notifies, and that different dates may be appointed for different provisions. That is why the law arrives in three pieces rather than one.
The operational detail came later. The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025, under Sec. 40. The Act states the duties; the Rules say what several of them mean in practice.
One note on pronouns: Sec. 2(y) provides that "she" includes an individual irrespective of gender. The Act is drafted that way, and so is this page.
The three roles, in plain words
Everything in the Act hangs off who is who. Three definitions in Sec. 2 carry most of the weight, with the Act's wording beside the plain version.
- Data Principal — the person the data is about. Sec. 2(j): "the individual to whom the personal data relates". Where she is a child it includes her parents or lawful guardian, and where she is a person with disability, her lawful guardian acting on her behalf.
- Data Fiduciary — you, if you decide why and how the data is processed. Sec. 2(i): "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data". This is the role that carries almost every duty in the Act.
- Data Processor — someone who handles the data for you, on your instructions. Sec. 2(k): "any person who processes personal data on behalf of a Data Fiduciary". Your payroll bureau and your cloud host are the usual examples.
Engaging a Data Processor does not move the duty. Sec. 8(1) keeps the Data Fiduciary responsible for processing done on its behalf, irrespective of any agreement to the contrary, and Sec. 8(2) requires a valid contract before you involve one at all.
Three more terms appear throughout, each defined in Sec. 2:
- Data Protection Board — the regulator. Sec. 2(c): the Data Protection Board of India, established by the Central Government under Sec. 18. It is the body a person complains to, and the body that imposes penalties.
- Consent Manager — a registered intermediary a person can use to manage consent in one place. Sec. 2(g): "a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform".
- Significant Data Fiduciary — a Data Fiduciary the government has singled out for extra duties. Sec. 2(z): any Data Fiduciary or class of Data Fiduciaries notified as such by the Central Government under Sec. 10.
Two definitions set the Act's reach. "Personal data" under Sec. 2(t) is "any data about an individual who is identifiable by or in relation to such data", and "digital personal data" under Sec. 2(n) is simply personal data in digital form. There is no special category for health, finance or biometrics — a diagnosis and a postal address sit under the same rules.
Who it applies to
Sec. 3 does the work. The Act applies to the processing of digital personal data within India, where the data was collected either in digital form, or on paper and digitised afterwards.
It also reaches outside India. Sec. 3(b) applies the Act to processing done abroad where that processing is connected with any activity related to offering goods or services to Data Principals within India. A company with no Indian office and Indian customers is covered.
Sec. 3(c) carves out two things, both narrower than they look. Personal data an individual processes for a personal or domestic purpose is outside the Act — your own contacts, not your employer's. So is personal data made publicly available by the Data Principal herself, or by someone under a legal obligation to publish it.
Neither is a business exemption. The Act's own illustration is a person blogging her views and publishing her personal data on social media herself.
Otherwise the test does not turn on your size or sector: if you determine the purpose and means, you are a Data Fiduciary. The sector detail is in does the DPDP Act apply to my organisation.
The two lawful grounds
Sec. 4(1) allows processing only in accordance with the Act and for a lawful purpose, on one of two grounds: consent, or certain legitimate uses — processing the Act allows without consent. Sec. 4(2) defines a lawful purpose as any purpose not expressly forbidden by law.
Consent, and the notice that has to precede it
Sec. 6(1) sets the standard. Consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action. It signifies agreement to processing for the specified purpose, and it is limited to the personal data necessary for that purpose.
A request for consent does not travel alone. Sec. 5(1) requires every request to be accompanied or preceded by a notice telling her the personal data and the purpose, how to exercise her rights under Sec. 6(4) and Sec. 13, and how to complain to the Board. Rule 3 adds that the notice must stand on its own and itemise the data.
Sec. 5(3) gives her the choice of language: she may access the notice in English or any language in the Eighth Schedule to the Constitution — the Constitution's list of scheduled languages, currently 22 of them. The choice is hers, not yours. What a DPDP consent notice must contain goes through Sec. 5 clause by clause.
Withdrawal is part of the same right. Sec. 6(4) lets her withdraw at any time, with the ease of doing so comparable to the ease with which consent was given. Sec. 6(6) then requires you, within a reasonable time, to cease processing and to cause your Data Processors to cease too.
Sec. 6(10) decides who proves what. Where consent is the basis and a question arises in a proceeding, the Data Fiduciary must prove that notice was given and consent obtained. The record is the defence.
The legitimate uses, including the one that surprises people
Sec. 7 lists nine uses — clauses (a) to (i) — for which a Data Fiduciary may process personal data without consent. They are specific rather than general, and most are narrow.
Clause (a) covers data she voluntarily provided for a purpose, where she has not objected. Clauses (b) to (d) concern the State. Clauses (f) to (h) cover a medical emergency, a public-health measure, and a disaster or breakdown of public order.
Clause (e) is not a State ground, though it sits among them. It covers compliance with a judgment, decree or order — including a foreign one on a contractual or civil claim — and a private Data Fiduciary can rely on it.
Clause (i) is the one that surprises people. Sec. 7(i) makes employment a legitimate use, covering processing for the purposes of employment and processing related to safeguarding the employer from loss or liability — the Act names corporate espionage, trade secrets, intellectual property and classified information.
So the Act permits payroll, attendance and access control without consent. The Sec. 5 notice duty attaches to a request for consent, so it is not triggered by processing under Sec. 7(i). Sec. 8 applies regardless: safeguards under Sec. 8(5), breach reporting under Sec. 8(6), erasure under Sec. 8(7) and a grievance mechanism under Sec. 8(10) are all owed whatever the ground.
What she can ask you for
Chapter III gives the Data Principal four rights, and they commence together.
Access, Sec. 11. On request, she can obtain a summary of the personal data being processed and of the processing activities undertaken. She can also obtain the identities of every other Data Fiduciary and Data Processor it was shared with, and a description of what was shared. Clause (c) adds anything else the Rules prescribe.
Sec. 11(2) withholds clauses (b) and (c) in one case: sharing with another Data Fiduciary authorised by law, on a written request, for the prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
Correction and erasure, Sec. 12. She may have her data corrected, completed, updated or erased. On a correction request you must correct what is inaccurate or misleading, complete what is incomplete, and update what is stale. On an erasure request you must erase, unless retention is necessary for the specified purpose or for compliance with law.
Grievance redressal, Sec. 13. She is entitled to readily available means of complaining to a Data Fiduciary or Consent Manager about how it has performed its obligations. Rule 14(3) fixes the outer limit of a response at a reasonable period not exceeding ninety days. Sec. 13(3) requires her to exhaust this route before approaching the Board.
Nomination, Sec. 14. Sec. 14(1) lets her nominate any other individual to exercise her rights if she dies or becomes incapable, and rule 14(4) puts it as one or more individuals. Sec. 14(2) defines incapacity as inability arising from unsoundness of mind or infirmity of body.
One limit is easy to miss. Sec. 11(1) and Sec. 12(1) both run against a Data Fiduciary to whom she has previously given consent, including consent referred to in Sec. 7(a). Neither reaches processing that rests on Sec. 7(i) alone. Sec. 13 and Sec. 14 carry no such limit.
What she owes in return
The Act is not one-directional. Sec. 15 places five duties on the Data Principal:
- comply with applicable law when exercising her rights;
- do not impersonate another person when providing personal data;
- do not suppress material information when providing data for a State-issued document, identifier, or proof of identity or address;
- do not register a false or frivolous grievance or complaint;
- furnish only verifiably authentic information when seeking correction or erasure.
The scale of the consequence is worth noting. Entry 5 of the Schedule caps a breach of Sec. 15 at ten thousand rupees, against ceilings in the crores for your own failures.
When there is a breach
Sec. 2(u) defines a personal data breach broadly: any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data. A lost laptop qualifies; so does an internal misuse.
Sec. 8(6) requires intimation to the Board and to each affected Data Principal. Rule 7 then sets out two clocks, and conflating them is the usual mistake.
To each affected person, under rule 7(1): without delay, in concise and plain language, through her user account or a channel she registered. It covers the breach's nature, extent and timing, the consequences for her, the mitigation under way, what she can do to protect herself, and a contact who can answer her.
To the Board, under rule 7(2): without delay, a description covering nature, extent, timing, location and likely impact. Then, within seventy-two hours of becoming aware — or longer if the Board allows it in writing — a detailed follow-up, including who caused it, the remedial measures, and a report on what affected people were told.
The seventy-two hours governs that second report only. Both first intimations are due without delay, so an incident process built around a single deadline will be late on one of them.
Children, and the Fiduciaries singled out for more
A child under the Act is anyone who has not completed eighteen years, per Sec. 2(f). Sec. 9(1) requires verifiable consent from a parent or lawful guardian before you process a child's personal data, and the same applies to a person with disability who has a lawful guardian.
Two further prohibitions sit alongside it. Sec. 9(2) forbids processing likely to cause a detrimental effect on a child's well-being, and Sec. 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children. Rule 12 and the Fourth Schedule exempt some classes and purposes, schools and clinical establishments among them.
A Significant Data Fiduciary is one the Central Government has notified under Sec. 10(1). The factors include the volume and sensitivity of the data, the risk to Data Principals' rights, electoral democracy and security of the State.
Notification brings more duties: a Data Protection Officer based in India, an independent data auditor, and periodic impact assessments and audits under Sec. 10(2). Rule 13 sets a twelve-month cycle and a report of significant observations to the Board. Until you are notified, none of it applies to you.
Sending personal data abroad
Sec. 16(1) does not ban transfers. It lets the Central Government restrict transfer to a country or territory it notifies, which makes the restricted list the thing to watch rather than the transfer itself.
Rule 15 adds a second condition: a transfer must meet such requirements as the Central Government specifies, by general or special order, about making the data available to a foreign State, or to any person or entity under the control of such a State or any agency of it. Sec. 16(2) preserves any other Indian law that restricts transfers more tightly — sectoral rules still bite. Rule 15 commences on 13 May 2027 with the rest.
One restriction is narrower and harder. Rule 13(4) applies only to a Significant Data Fiduciary, and it is not a condition but a prohibition: personal data the Central Government specifies, on the recommendation of a committee it constitutes, must not leave India at all — neither the data nor the traffic data describing its flow. So a firm notified under Sec. 10 has a second cross-border question to answer, and it is the one with no mechanism for satisfying it abroad.
What the Board can impose, and how
Penalties are not automatic and they are not fines you calculate yourself. Sec. 33(1) lets the Board impose a monetary penalty only if it determines, on conclusion of an inquiry, that a breach is significant — and only after giving the person an opportunity of being heard.
Sec. 33(2) then lists seven things the Board must weigh, among them the gravity and duration of the breach, whether it was repetitive, what mitigation was taken and how promptly, and the penalty's likely impact on the person.
The Schedule to Sec. 33(1) sets seven entries. Six read "may extend to" — a maximum, not a tariff — and entry 6, for breaking a voluntary undertaking, is measured against the breach the undertaking settled:
- Up to 250 crore rupees — failing to take reasonable security safeguards to prevent a personal data breach, under Sec. 8(5). The largest figure in the Act attaches to security, not to consent banners.
- Up to 200 crore rupees — failing to give the Board or an affected Data Principal notice of a breach, under Sec. 8(6).
- Up to 200 crore rupees — breaching the additional obligations in relation to children, under Sec. 9.
- Up to 150 crore rupees — breaching the additional obligations of a Significant Data Fiduciary, under Sec. 10.
- Up to 10,000 rupees — breaching the Data Principal's own duties under Sec. 15.
- Up to the amount applicable to the underlying breach — breaching a term of a voluntary undertaking the Board accepted under Sec. 32.
- Up to 50 crore rupees — breaching any other provision of the Act or the Rules.
Sec. 34 sends everything realised to the Consolidated Fund of India. The compliance map lists each provision against the control that answers it.
When all of this starts
Three dates, set by rule 1 of the DPDP Rules, 2025 rather than by the Act.
Rule 1(2) brought rules 1, 2 and 17 to 21 into force on publication, 13 November 2025 — the Board, the definitions, and the procedure for staffing it. Rule 1(3) brings rule 4 into force a year later, on 13 November 2026, when Consent Manager registration opens.
Rule 1(4) is the one to plan against. It brings rules 3, 5 to 16, 22 and 23 into force eighteen months after publication, on 13 May 2027 — notice, consent, rights, safeguards, breach reporting and retention, all at once.
As this page was last updated, the first date had passed and the next was 13 November 2026.
Your existing consents survive the transition. Sec. 5(2) requires a Data Fiduciary that obtained consent before commencement to give her a notice as soon as it is reasonably practicable, and permits processing to continue until she withdraws. The base does not go dark on 13 May 2027, but every person in it has to be noticed.
DPDP Rules 2025: what commences when covers the staging in more detail, including the state of the Board's appointments.
The order the work happens in
The duties commence together, but they cannot be built together. The dependencies run in one direction, and the first is the one most often skipped.
Purpose-scoped consent under Sec. 6(1) is impossible to express without first knowing the purposes, so the data inventory precedes the notice, and the notice precedes consent capture. Withdrawal under Sec. 6(6) has to reach your Data Processors, which is engineering rather than interface work. Rights requests under Sec. 11 to 14 need somewhere to read from. And Sec. 6(10) means the evidence is a deliverable in its own right.
The DPDP compliance checklist sets out twelve items in that order, each against the provision requiring it, with the evidence to retain.
Where to go from here
The guides linked above go deeper on applicability, on the notice, and on the dates. One more covers a role this page only mentions: Consent Manager registration, on the First Schedule's conditions for the intermediary business the Act licenses.
For the work itself, the compliance map ties every provision to a control, and our own surfaces follow the order above: the processing register for the inventory, consent management for notice and consent per purpose, and rights and grievance for Sec. 11 to 14.