DPDP Act 2023: Complete Guide to India’s Digital Personal Data Protection Law
India’s first comprehensive data privacy law — explained in plain language. Know your rights, understand business obligations, navigate penalties, and build a compliant future in the digital economy.
Quick Answer: What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first standalone, comprehensive data privacy law, enacted on 11 August 2023. It governs how personal data of Indian citizens is collected, stored, used, and transferred in digital form. It gives every individual four enforceable legal rights over their data, places clear obligations on every organisation that collects data, creates the Data Protection Board of India as the enforcement authority, and prescribes financial penalties up to ₹250 crore per violation.
- The DPDP Act is India’s first comprehensive, standalone data privacy law, enacted in August 2023, giving legal force to privacy as a fundamental right.
- Every organisation — company, startup, government body, hospital, school — that processes digital personal data of Indian citizens is a Data Fiduciary with binding obligations.
- Individuals have four enforceable rights: access, correction/erasure, grievance redressal, and the unique right to nominate a digital heir.
- Consent must be free, specific, informed, unconditional, and unambiguous. Pre-ticked boxes and blanket consents are invalid.
- Children under 18 receive the strongest protections — verifiable parental consent, no behavioral tracking, no targeted advertising.
- Significant Data Fiduciaries face additional duties: a Data Protection Officer, data audits, and Data Protection Impact Assessments.
- Penalties reach ₹250 crore per violation — making non-compliance economically devastating for any size of organisation.
- Cross-border data transfers are permitted by default unless the Government restricts specific countries — the opposite of GDPR’s approach.
- The Data Protection Board of India operates as a digital-first enforcement authority, handling complaints and imposing penalties.
- Compliance is a business opportunity, not just a legal burden — building user trust, enabling global partnerships, and reducing catastrophic liability.
1. Historical Background: The Road to India’s Data Privacy Law ↑ Contents
You opened an app this morning. It asked for your name, phone number, date of birth, and location. You clicked “I Agree” and moved on with your day. But do you know where that data went? Who has access to it? Can they share it? Sell it? And what happens if it leaks?
For decades, India had no comprehensive answer to those questions. That changed on 11 August 2023.
The IT Act 2000 and Section 43A
India’s first attempt at digital privacy came through the Information Technology Act, 2000, and its amendment in 2008. Section 43A of the IT Act introduced liability for body corporates that were negligent in maintaining “reasonable security practices” for sensitive personal data. But Section 43A had serious limitations — it was narrow, enforcement was weak, and it was reactive rather than preventive.
The Puttaswamy Judgment: Privacy as a Fundamental Right
On 24 August 2017, a nine-judge bench of the Supreme Court of India, in K.S. Puttaswamy (Retd.) v. Union of India [(2017) 10 SCC 1], unanimously held that privacy is a fundamental right under Article 21 of the Constitution of India.
Justice D.Y. Chandrachud observed: “Privacy is the constitutional core of human dignity. Privacy has both a normative and descriptive function. At a normative level, privacy sub-serves those eternal values upon which the guarantees of life, liberty and freedom are founded.”
This judgment made comprehensive data protection legislation not merely desirable — it made it constitutionally necessary.
Justice Srikrishna Committee (2018)
Following the Puttaswamy judgment, the Government constituted a Committee of Experts on Data Protection chaired by retired Supreme Court Judge Justice B.N. Srikrishna. The committee submitted its report and a draft Personal Data Protection Bill in July 2018, drawing heavily from the EU’s GDPR while accounting for India’s unique context.
The Legislative Journey (2019–2023)
| Year | Milestone |
|---|---|
| 2019 | Personal Data Protection Bill introduced in Parliament |
| 2021 | Referred to Joint Parliamentary Committee (JPC) |
| Dec 2021 | JPC submitted report with significant amendments |
| Aug 2022 | 2019 Bill withdrawn by the Government |
| Nov 2022 | Draft Digital Personal Data Protection Bill 2022 released for public consultation |
| 11 Aug 2023 | Digital Personal Data Protection Act, 2023 enacted — Presidential assent granted |
The six-year journey from the Puttaswamy judgment to the final legislation reflects the complexity of balancing individual privacy with India’s growing digital economy.
2. Why the DPDP Act Matters ↑ Contents
- Over 900 million internet users (TRAI, 2024)
- More than 700 million smartphone users
- Over 600 million active social media users
- A booming $1 trillion digital economy projected by 2030 (NASSCOM)
Before the DPDP Act, an organisation could legally collect far more data than it needed, store your data indefinitely, share it with third parties without meaningful consent, and suffer a data breach without any obligation to inform you. The DPDP Act changes all of this.
For businesses, the DPDP Act is not just a compliance burden — it is a business opportunity. Organisations that demonstrate strong data governance earn customer trust and competitive advantage. Privacy-compliant businesses attract global investment, win enterprise clients, and access international markets that demand privacy standards.
3. Who Does the DPDP Act Apply To? ↑ Contents
Territorial Applicability
The DPDP Act applies to:
- Processing of digital personal data within India — whether collected in digital form, or collected in non-digital form and subsequently digitised.
- Processing of digital personal data outside India — if such processing is in connection with offering goods or services to individuals within India.
The DPDP Act’s extraterritorial scope means global platforms — including those based in the United States, Europe, or Singapore — that serve Indian users are subject to Indian data protection law regardless of where their servers are located.
Key Roles Defined
| Role | Who They Are | Examples |
|---|---|---|
| Data Principal | The individual whose data is processed. For children, the parent/guardian acts as Data Principal. | You — when an app collects your data |
| Data Fiduciary | Entity that determines the purpose and means of processing personal data. Bears primary legal obligations. | Hospitals, banks, e-commerce platforms, schools, apps, government departments |
| Data Processor | Processes personal data on behalf of a Data Fiduciary, following its instructions. | Cloud providers, analytics firms, payment gateways |
| Consent Manager | Registered intermediary through which Data Principals manage all their consents in one place. | Future platforms enabling unified consent management across apps |
What Qualifies as Personal Data?
The DPDP Act defines personal data broadly as: “any data about an individual who is identifiable by or in relation to such data.”
This includes names, phone numbers, email addresses, Aadhaar numbers, PAN, financial information, health records, location data, biometric data, device identifiers, IP addresses, photographs, and behavioural and preference data.
4. Key Definitions You Must Know ↑ Contents
| Term | Plain-Language Meaning |
|---|---|
| Digital Personal Data | Personal data in digital form |
| Processing | Collection, storage, use, sharing, transfer, or deletion of data |
| Significant Data Fiduciary | Large or high-risk Fiduciary notified by the Central Government |
| Personal Data Breach | Unauthorised access, disclosure, alteration, or destruction of data |
| Purpose Limitation | Data can only be used for the purpose it was collected for |
| Data Minimisation | Only collect what is strictly necessary |
| Consent | Free, specific, informed, unconditional, unambiguous agreement |
| Data Protection Board | India’s independent data protection enforcement authority |
5. Core Principles of the DPDP Act ↑ Contents
The DPDP Act is built on seven foundational principles drawn from global best practices.
| # | Principle | What It Means in Practice |
|---|---|---|
| 1 | Lawful Processing | Data can only be processed for a purpose not prohibited by law |
| 2 | Purpose Limitation | Data collected for one purpose cannot be repurposed without fresh consent |
| 3 | Data Minimisation | Collect only what is adequate, relevant, and necessary |
| 4 | Data Accuracy | Reasonable steps must be taken to keep data accurate and updated |
| 5 | Storage Limitation | Delete data once the purpose is fulfilled and retention is not legally required |
| 6 | Security Safeguards | Implement appropriate technical and organisational measures to prevent breaches |
| 7 | Accountability | The Data Fiduciary is responsible for compliance and cannot outsource accountability |
6. Consent Under the DPDP Act ↑ Contents
Consent is the cornerstone of the DPDP Act. Before processing personal data, a Data Fiduciary must obtain consent that is free, specific, informed, unconditional, and unambiguous.
- A 47-page terms and conditions document in 8-point font
- A pre-ticked checkbox buried in settings
- “By using our service, you agree to data collection”
- Blanket consent for all purposes in a single click
- A clear, plain-language notice explaining exactly what data is collected and why
- An affirmative action by the user — a specific, clearly worded consent request
- Notice available in any of the 22 languages in the Eighth Schedule of the Constitution, on request
- Granular consent — separate consent for each purpose, not a bundled all-or-nothing
Deemed Consent — When Consent Is Not Required
The DPDP Act recognises that consent is not always practical. “Deemed consent” (processing without explicit consent) is permitted in specific situations:
- Voluntary provision for evident purpose — e.g., giving your address to a courier for delivery
- State functions — government processing for welfare schemes, legal functions, subsidies
- Legal proceedings — processing required for legal proceedings or asserting legal rights
- Medical emergency — to protect life or health of the principal or another person
- Employment — lawful employment-related processing
- Public interest — research, archiving, or statistical purposes
Withdrawal of Consent
A Data Principal can withdraw consent at any time. The withdrawal process must be as easy as giving consent. The Data Fiduciary must stop processing within a reasonable time after withdrawal. Withdrawal does not affect the lawfulness of processing done before withdrawal.
Consent Managers
The DPDP Act introduces Consent Managers — registered intermediaries that provide individuals a single platform to grant, track, modify, and withdraw consent across multiple Data Fiduciaries. This is a globally novel concept designed to empower individuals in India’s complex digital ecosystem.
7. Rights of the Data Principal (Individual) ↑ Contents
The DPDP Act gives every Indian citizen four legally enforceable rights over their personal data.
Right to Access Information
Know what data is held about you, a summary of processing, and the identity of Data Processors it was shared with. (Section 11)
Right to Correction & Erasure
Demand correction of inaccurate data, completion of incomplete data, and erasure of data once the purpose is fulfilled. (Section 12)
Right to Grievance Redressal
Have your grievances addressed by the Data Fiduciary. Escalate to the Data Protection Board if unsatisfied. (Section 13)
Right to Nominate a Digital Heir
Nominate another individual to exercise your data rights after your death or incapacity. A globally unique right. (Section 14)
Duties of the Data Principal
The DPDP Act also imposes duties on individuals — a unique feature among global data privacy laws:
- Do not impersonate another person while providing consent
- Do not suppress material information when providing data
- Do not file false or frivolous complaints with the Data Protection Board
8. Obligations of the Data Fiduciary (Organisations) ↑ Contents
-
Give a Clear Notice Before Processing
Provide a plain-language notice explaining what data is collected, the purpose, how to exercise rights, and grievance officer contact details.
-
Obtain Valid Consent
Secure consent that is free, specific, informed, unconditional, and unambiguous. No pre-ticked boxes. No bundled consent.
-
Process Data Only for Specified Purpose
Use data only for the purpose stated in the notice. Do not repurpose data without fresh consent.
-
Maintain Data Quality
Ensure data processed is accurate, complete, and up-to-date, especially where inaccuracy could cause significant harm.
-
Delete Data When No Longer Needed
Erase personal data when the purpose is fulfilled or consent is withdrawn, unless legally required to retain it.
-
Implement Security Safeguards
Deploy encryption, access controls, audit logs, and incident response plans proportionate to the nature of data and risk.
-
Report Data Breaches Promptly
Notify both the Data Protection Board and affected Data Principals in the event of a personal data breach, in the prescribed form and timeframe.
-
Establish a Grievance Redressal Mechanism
Designate a named grievance officer, publish contact details prominently, and resolve complaints within prescribed timelines.
-
Conduct Due Diligence on Data Processors
Ensure third-party processors meet adequate data protection standards through contractual obligations.
-
Comply with Data Principal Requests
Respond to access, correction, and erasure requests accurately and within prescribed timelines.
9. Significant Data Fiduciaries: Special Rules for Big Players ↑ Contents
The Central Government may notify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to individuals, and threats to national security or electoral democracy.
Additional Obligations for SDFs
| Obligation | Details |
|---|---|
| Data Protection Officer (DPO) | Must be appointed and based in India, reporting to the Board of Directors, responsible for overall DPDP Act compliance |
| Independent Data Auditor | Periodic compliance audits and data management practice reviews by an independent auditor |
| Data Protection Impact Assessments (DPIA) | Mandatory for high-risk processing activities — assessing impact on individual rights |
| No Behavioral Tracking of Children | Categorical prohibition on algorithmic tracking, monitoring, or profiling of children |
| No Targeted Advertising to Children | Direct prohibition on serving targeted advertisements to children |
| Processing Records | Detailed records of all data processing activities must be maintained |
While the Government has not yet officially notified SDFs, industry analysts expect this list to include major social media platforms, large e-commerce companies, fintech platforms, digital healthcare platforms, telecom operators, and large government data aggregators serving Indian users.
10. Data Protection Board of India ↑ Contents
The Data Protection Board of India is India’s independent data protection enforcement authority created by the DPDP Act. It operates as a digital-first body — complaints can be filed, hearings conducted, and orders issued entirely online.
Powers of the Data Protection Board
- Inquire into complaints from Data Principals
- Summon Data Fiduciaries and examine records
- Impose financial penalties up to prescribed limits
- Issue directions to Data Fiduciaries
- Block or restrict data processing activities in extreme cases
- Refer matters to appropriate authorities
How to File a Complaint
You must first exhaust the Data Fiduciary’s internal grievance mechanism before escalating to the Board. The Board’s process is designed to be fully digital, affordable, and accessible in multiple Indian languages.
11. Penalties Under the DPDP Act ↑ Contents
The Penalty Schedule (Schedule 1 of the Act)
Failure to implement reasonable security safeguards leading to a personal data breach
Failure to notify the Data Protection Board and affected individuals of a data breach
Processing children’s data in violation of Section 9 (without verifiable parental consent)
Non-fulfilment of additional obligations as a Significant Data Fiduciary
Non-fulfilment of general Data Fiduciary obligations under the Act
Breach of any other provision of the Act or Rules
Each separate violation can attract a separate penalty. A single breach event involving inadequate security and failure to notify and affecting children’s data could theoretically attract multiple penalties — cumulatively running into hundreds of crores.
Illustrative Scenarios
| Scenario | Violations | Potential Penalty Exposure |
|---|---|---|
| A healthcare startup suffers a breach exposing 50,000 patient records and fails to report it for 15 days | Inadequate security + Failure to notify | Up to ₹450 Cr |
| A children’s educational platform collects data without verifiable parental consent and serves targeted ads | Children’s data violation (Section 9) | Up to ₹200 Cr |
| An e-commerce company ignores a Data Principal’s erasure request for six months after account closure | Non-fulfilment of obligations | Up to ₹50 Cr |
The DPDP Act does not provide for imprisonment of company officers — penalties are civil/financial in nature. The Act also does not provide a direct right for individuals to claim compensation from Data Fiduciaries. Penalties are paid to the Government, not the affected individual. These gaps have been identified by legal scholars and privacy advocates as areas requiring future legislative attention.
12. Exemptions Under the DPDP Act ↑ Contents
| Exemption Category | Scope |
|---|---|
| State Instrumentalities & National Security | Central Government can exempt State instrumentalities in the interest of sovereignty, security, or public order — a broad exemption that has attracted scrutiny from privacy advocates |
| Research and Archiving | Processing for research, archiving, or statistical purposes is permissible, provided it is not used to take decisions about specific individuals |
| Prevention of Offences | Processing for prevention, detection, investigation, or prosecution of offences or contraventions of law is exempt |
| Enforcement of Rights or Claims | Processing necessary to enforce any right or claim in law is exempt |
| Courts | Processing necessary for judicial or quasi-judicial functions is exempt |
| Startups and Small Businesses | The Central Government may exempt certain classes of Data Fiduciaries (including startups) from specified provisions — these exemptions have not yet been notified |
13. Cross-Border Data Transfers ↑ Contents
Personal data may be transferred to any country or territory outside India except those that the Central Government specifically restricts. This is a blacklist approach — transfers are permitted by default unless restricted — the opposite of GDPR’s adequacy-first approach.
While the DPDP Act does not mandate blanket data localisation, the Government retains power to require Significant Data Fiduciaries to store certain categories of sensitive data within India’s borders. RBI and SEBI have already established data localisation requirements for financial data, which continue to apply.
14. Children’s Data: The Strongest Protections ↑ Contents
Under the DPDP Act, a “child” means an individual below 18 years of age. Children’s personal data receives the most comprehensive protection in the Act.
Requirements Before Processing Children’s Data
- Obtain verifiable parental consent — not just a checkbox declaring age
- Ensure processing is not detrimental to the well-being of the child
Categorically Prohibited Activities
- Behavioural tracking or monitoring of children using algorithms or AI
- Targeted advertising directed at children
- Geolocation data collection of children
- Algorithmic profiling of children based on personal data
India has over 500 million internet users below 18 years of age. A gaming app that tracks a 14-year-old’s gameplay behaviour to serve targeted in-app purchase recommendations — without verifiable parental consent — is now in clear violation of the DPDP Act and faces penalties up to ₹200 crore.
15. DPDP Act vs GDPR: Key Differences ↑ Contents
| Feature | DPDP Act 2023 (India) | GDPR 2018 (EU) |
|---|---|---|
| Scope | Digital personal data only | Digital and non-digital data |
| Lawful bases | Consent + deemed consent categories | 6 lawful bases including legitimate interest |
| Right to data portability | Not explicitly included | Included |
| DPO requirement | Only for Significant Data Fiduciaries | Required for certain organisations |
| Cross-border transfers | Blacklist (permitted unless restricted) | Adequacy decision or safeguards required |
| Individual compensation | Not directly provided | Individuals can claim compensation |
| Maximum penalty | ₹250 crore (~€28 million) | €20 million or 4% of global annual turnover |
| Enforcement authority | Data Protection Board (digital-first) | Each EU member state has its own DPA |
| Children’s age threshold | Below 18 | Below 16 (varies by member state, min 13) |
| Sensitive data categories | Not separately defined (Government can notify) | Explicitly defined special categories |
| Complaint mechanism | First exhaust Fiduciary’s mechanism, then DPB | File directly with supervisory authority (DPA) |
16. DPDP Act and Existing Indian Laws ↑ Contents
| Law | Interaction with DPDP Act |
|---|---|
| IT Act 2000 / SPDI Rules 2011 | DPDP Act supersedes Section 43A and the SPDI Rules for matters it covers. Other IT Act provisions remain in force. |
| Aadhaar Act 2016 | The Aadhaar Act’s data protection provisions continue alongside the DPDP Act. For conflicts, the more specific statute may prevail. |
| RBI Regulations | RBI data localisation requirements, KYC data retention rules, and customer data protection guidelines continue to apply to banks and financial institutions. |
| Consumer Protection Act 2019 | Consumer protection provisions on unfair trade practices and misleading representations interact with DPDP notice and consent obligations. |
| SEBI Regulations | SEBI’s data protection framework for capital markets participants continues alongside the DPDP Act. |
17. DPDP Act Compliance Roadmap for Businesses ↑ Contents
Many organisations are waiting for the DPDP Rules to be notified before acting. This is a costly mistake. The Act is law now. Rules will fill in procedural details, but the obligations and rights exist today. Build your compliance infrastructure immediately.
Phase 1: Data Discovery and Mapping (Months 1–2)
- Conduct a Data Audit — Map every category of personal data: what, from whom, for what purpose, where stored, who has access, how long retained, and with whom shared.
- Map Data Flows — Document how data moves from collection through storage, use, sharing, and deletion.
- Classify Data by Risk — Financial, health, and children’s data require higher levels of protection.
Phase 2: Consent and Notice Framework (Months 2–3)
- Audit Existing Consent Mechanisms — Review all consent forms, privacy policies, and cookie banners for DPDP Act compliance.
- Redesign Notice and Consent Architecture — Create plain-language, granular consent mechanisms with easy withdrawal options.
- Update Privacy Policy — Write in plain language, available in multiple Indian languages, easily accessible, regularly updated.
Phase 3: Rights Fulfilment Infrastructure (Months 3–4)
- Set Up Data Principal Request Management — Build or purchase a system to receive, track, and respond to access, correction, and erasure requests.
- Designate a Grievance Officer — Appoint a named individual and publish contact details prominently on your website and app.
Phase 4: Security and Breach Response (Months 4–5)
- Implement Technical Security Measures — Encryption at rest and in transit, multi-factor authentication, role-based access controls, regular penetration testing, audit logs.
- Develop a Data Breach Response Plan — Include internal escalation procedures, assessment criteria, notification templates for the Data Protection Board and affected individuals, and clear timelines.
Phase 5: Third-Party Management (Month 5)
- Audit Data Processors — Review all third-party cloud providers, analytics tools, CRMs, and marketing platforms that process personal data on your behalf.
- Update Data Processing Agreements — Include scope of processing, security obligations, breach notification duties, deletion obligations at contract end, and audit rights.
Phase 6: Training and Culture (Ongoing)
- Train Your Team — Every employee handling personal data must understand DPDP Act requirements, breach identification, and escalation procedures.
- Build a Privacy-First Culture — Periodic data audits, privacy impact assessments for new products, regular policy reviews, and board-level accountability.
18. DPDP Act for Startups and Small Businesses ↑ Contents
Many startup founders are asking: “We are a 10-person team. Does this law really apply to us?” The honest answer is: yes, but with nuance.
The DPDP Act explicitly empowers the Central Government to exempt certain classes of startups from specific provisions. However, these exemptions have not yet been notified. Until they are, all Data Fiduciaries — regardless of size — are technically subject to the full Act.
- Know your data — Understand exactly what personal data you collect and why
- Get consent right — Clean up your consent mechanisms — it is not expensive
- Write a proper privacy policy — A clear, accurate policy builds user trust and reduces legal risk
- Designate a point of contact — Someone must own data privacy, even without a formal DPO requirement
- Plan for breaches — A basic incident response plan costs nothing and saves everything if a breach occurs
The Business Case for Startup Compliance
- Earn user trust — critical in an era of growing privacy awareness
- Attract investment — global investors increasingly scrutinise data governance
- Enable international expansion — GDPR-adjacent compliance makes entering EU/US markets easier
- Avoid catastrophic penalties — a ₹250 crore penalty can destroy a startup overnight
- Win enterprise clients — B2B clients increasingly demand vendor DPDP compliance
19. DPDP Act for NRIs ↑ Contents
Non-Resident Indians whose personal data is processed by Indian entities — a bank, an investment platform, a healthcare provider, or a family property management service — are Data Principals entitled to all rights under the DPDP Act.
This means NRIs can request access to their personal data held by Indian entities, demand correction of incorrect information, request erasure of data no longer needed, and file complaints with the Data Protection Board if their rights are violated.
For NRIs who own or operate businesses in India, the Indian entity is a Data Fiduciary subject to the full DPDP Act. If your business has global operations that process Indian citizens’ data, extraterritorial provisions may also apply.
For professional guidance on NRI data rights or DPDP compliance for NRI-owned Indian businesses, consult the Midhati team.
20. Myths vs Facts About the DPDP Act ↑ Contents
“The DPDP Act is not yet in force — we can wait.”
The Act received Presidential assent on 11 August 2023. It is law. Rules are being phased in, but the core obligations exist now.
“We are GDPR compliant, so we are DPDP compliant.”
GDPR and DPDP Act differ in important ways — consent framework, cross-border transfers, sensitive data categories, individual compensation, and more. A separate DPDP review is necessary.
“We are a small startup — the DPDP Act does not apply to us.”
The Act applies to all Data Fiduciaries. Startup exemptions, when notified, will be partial and conditional — not blanket immunity.
“Our servers are in Singapore — Indian law does not apply.”
The DPDP Act has extraterritorial reach. If you offer goods or services to Indian users, you are subject to the Act regardless of server location.
“A data breach just means a fine — not existential risk.”
A single breach can attract penalties of ₹450 crore or more across multiple violations. For most companies, this is an existential event.
“Children need separate protection only for social media, not all apps.”
The DPDP Act’s children’s data protections apply to ALL Data Fiduciaries — not just social media. Any app, website, or platform accessible to children under 18 is covered.
21. Common Mistakes to Avoid ↑ Contents
- Treating the DPDP Act as a future problem. The Act is law now. Rules add procedural detail, not new obligations.
- Copying a GDPR policy and calling it done. GDPR and DPDP Act differ on consent framework, rights, and data transfer rules. A DPDP-specific review is mandatory.
- Using vague or bundled consent. Blanket “I Agree to everything” consent is invalid. Consent must be specific and granular.
- Neglecting the erasure obligation. Storing user data indefinitely “just in case” is a violation. Build data retention schedules and automated deletion workflows.
- Ignoring children’s data obligations. If your platform is accessible to users under 18, you need verifiable parental consent mechanisms immediately.
- No data breach response plan. Discovering a breach months after it occurred and failing to notify within the required timeframe creates a second, separate major violation.
- Inadequate vendor contracts. Using cloud storage, analytics tools, or CRMs without DPDP-compliant data processing agreements exposes you to liability when your processor causes a breach.
- Making consent withdrawal difficult. If withdrawing consent requires multiple steps or is buried in settings, this directly violates the Act.
- Not informing users of the nomination right. Failing to inform Data Principals of their right to nominate a digital heir is a gap in notice obligations.
- No grievance officer appointed. Every Data Fiduciary must have a named grievance officer with published contact details.
22. Expert Tips for DPDP Compliance ↑ Contents
- Privacy by Design, not Privacy by Compliance. Build data protection into your products from the beginning. Evaluate every new feature against: “Do we actually need this data?”
- Invest in plain language. Clear, understandable notices build trust. Users who understand what they’re agreeing to are more comfortable, more loyal, and less likely to file complaints.
- Appoint a Privacy Champion. Even without a formal DPO requirement, designate someone internally who “owns” data privacy with direct access to senior leadership.
- Conduct annual privacy audits. Data landscapes change. Products evolve. New vendors are added. An annual comprehensive privacy audit catches compliance gaps before they become penalties.
- Document everything. Keep records of consent obtained, data processing activities, vendor contracts, breach incidents and responses, and training conducted.
- Monitor MeitY notifications actively. The DPDP Act’s full implementation depends on subsidiary rules and government notifications. Subscribe to MeitY’s official updates.
- Prepare for algorithmic accountability. Even for non-SDFs, the direction is clear — understand and be able to explain your algorithms, especially those that make decisions about individuals.
- Consult a data privacy lawyer. The DPDP Act has nuances that general legal counsel may miss. Engage a specialist for a DPDP readiness assessment and compliance architecture review.
Frequently Asked Questions ↑ Contents
The Act & Its Fundamentals
The full name is the Digital Personal Data Protection Act, 2023. It is India’s first standalone, comprehensive data privacy legislation. It gives legal enforcement to the Supreme Court’s 2017 declaration that privacy is a fundamental right under Article 21 of the Constitution, and it transforms the legal relationship between Indian citizens and every organisation that processes their personal data.
The Act received Presidential assent on 11 August 2023. Its substantive provisions are being brought into force in phases through Central Government notifications issued by the Ministry of Electronics and Information Technology (MeitY). Businesses should monitor MeitY’s official notifications actively for current implementation timelines.
Personal data means “any data about an individual who is identifiable by or in relation to such data.” This is deliberately broad and includes names, phone numbers, email addresses, Aadhaar numbers, PAN, financial information, health records, location data, biometric data, device identifiers, IP addresses, photographs, and behavioural and preference data.
The IT Act 2000 addressed cybercrime and electronic commerce broadly, with limited data protection provisions under Section 43A. The DPDP Act is specifically focused on personal data protection, providing a comprehensive rights framework for individuals and binding obligations for organisations. The DPDP Act supersedes Section 43A of the IT Act for matters it covers.
The Act covers digital personal data. Non-digital data that is subsequently digitised also falls within scope. Purely offline data that is never digitised is outside the Act’s scope.
Rights of Individuals
You have four legally enforceable rights: (1) Right to access information — know what data is held and who it was shared with; (2) Right to correction and erasure — correct inaccurate data and request deletion once the purpose is served; (3) Right to grievance redressal — complain to the Data Fiduciary and escalate to the Data Protection Board; and (4) Right to nominate a digital heir — appoint someone to exercise your data rights after death or incapacity.
Yes. Under Section 12 of the DPDP Act, you can request erasure of your personal data once the purpose for which it was collected is fulfilled, or when you withdraw consent. The company may retain data if required to do so under another law — for example, banks must retain KYC data for a minimum period under RBI regulations.
Section 14 of the DPDP Act gives you the right to nominate another individual — your digital heir — who can exercise your data rights, including requesting erasure of accounts and data, after your death or incapacity. This is a globally unique right that addresses a growing real-world problem as India’s digital economy matures.
Data Principals must: (1) not impersonate another person when providing consent or data; (2) not suppress material information when providing personal data; and (3) not file false or frivolous complaints with the Data Protection Board. The DPDP Act’s mutual obligations framework is unique among global data privacy laws.
Consent and Compliance
Valid consent must be free (no coercion), specific (not bundled), informed (the person understands), unconditional (not tied to unrelated services), and unambiguous (a clear affirmative action — no pre-ticked boxes). The notice must be in plain language and available in any Eighth Schedule language on request.
Deemed consent means processing is lawful without explicit consent in specific situations — such as voluntary provision of data for an evident purpose (giving your address to a courier), state functions, medical emergencies, lawful employment-related processing, and public interest research. Deemed consent is an exception, not the rule.
No. Under the DPDP Act, personal data can only be used for the specific purpose for which consent was given (purpose limitation principle). Selling or sharing data for a different purpose requires separate consent. Processing without valid consent is a violation subject to penalties up to ₹50 crore for general violations, and up to ₹250 crore if it leads to a breach.
A Consent Manager is a registered intermediary that provides individuals a single platform to grant, track, modify, and withdraw consent across multiple Data Fiduciaries. It is a novel concept unique to India’s DPDP Act, designed to give individuals meaningful control over their digital data footprint across the dozens of apps and platforms they interact with daily.
Business Obligations and Penalties
The maximum penalty is ₹250 crore for failure to implement reasonable security safeguards leading to a data breach. Failure to notify a breach attracts up to ₹200 crore. Violations involving children’s data attract up to ₹200 crore. Non-fulfilment of SDF obligations attracts up to ₹150 crore. General obligation violations attract up to ₹50 crore.
Yes. If a foreign company processes personal data of Indian citizens in connection with offering goods or services to individuals in India, it is subject to the DPDP Act’s extraterritorial provisions. This applies regardless of where the company’s servers are located. Google, Meta, and other global platforms serving Indian users are covered.
The company must notify both the Data Protection Board of India and every affected Data Principal. Failure to notify is itself a separate violation attracting penalties up to ₹200 crore, independent of any penalty for the breach itself. Organisations should have a documented incident response plan well before any breach occurs.
A Significant Data Fiduciary (SDF) is a Data Fiduciary notified by the Central Government based on: volume and sensitivity of data processed, risk to individuals’ rights, potential impact on national security or sovereignty, and risk to electoral democracy. Industry analysts expect major social media platforms, large e-commerce companies, fintech platforms, digital healthcare platforms, and telecom operators to be designated as SDFs.
Not automatically. The Act empowers the Government to exempt certain classes of entities, including startups, from specified provisions through notifications. Until such notifications are issued, all Data Fiduciaries — regardless of size — are subject to the full Act. Begin building compliance infrastructure now rather than waiting for exemptions that may be conditional or partial.
Data Protection Board and Enforcement
You must first file a grievance with the Data Fiduciary’s designated grievance officer. If your grievance is not resolved satisfactorily, you can then escalate to the Data Protection Board of India. The Board operates as a digital-first authority — complaints are filed, hearings conducted, and orders issued entirely online. Further appeals go to the Appellate Tribunal, and on questions of law, to the Supreme Court.
Yes, government bodies are Data Fiduciaries if they process personal data. However, the Central Government can exempt state instrumentalities from specific provisions in the interest of sovereignty, security, or public order. This broad government exemption has attracted criticism from privacy advocates who argue it could be used to justify extensive state surveillance.
The DPDP Act uses a blacklist approach — personal data may be transferred to any country or territory outside India unless the Central Government specifically restricts that country. This is the opposite of GDPR’s adequacy-first approach. Cross-border transfers are permitted by default; restrictions, when imposed, are exceptions.
Children (individuals below 18) receive the strongest protections in the Act. Processing their data requires verifiable parental consent. The Act categorically prohibits behavioural tracking, targeted advertising, algorithmic profiling, and geolocation data collection for children. Violations attract penalties up to ₹200 crore.
The 2019 Bill was more detailed, included explicit data portability rights, defined specific categories of sensitive personal data, had different penalty structures, and included a Data Protection Authority with different powers. The 2019 Bill was withdrawn in August 2022. The DPDP Act 2023 is leaner, more principle-based, and grants the Central Government broader delegated power to issue rules and make determinations — a design choice intended to allow regulatory flexibility as technology evolves.
Yes. Social media platforms, messaging apps, and all digital services that process personal data of Indian citizens are Data Fiduciaries subject to the DPDP Act. Given their scale, these platforms are strong candidates for Significant Data Fiduciary designation, which would impose additional obligations including DPO appointment, data audits, and DPIAs.
NRIs whose personal data is processed by Indian entities are Data Principals with full rights under the DPDP Act. They can request access, demand correction or erasure, file complaints with the Data Protection Board, and nominate digital heirs. NRIs who own Indian businesses are subject to the Act as Data Fiduciaries. For personalised guidance, consult the Midhati team.
Need DPDP Compliance Help?
Whether you need a compliance audit, a legally sound privacy policy, data breach response guidance, or expert advice on becoming DPDP-ready — the Midhati team is here. We work with individuals, startups, businesses, and professionals across India.
Statutory References
Primary Legislation
- Digital Personal Data Protection Act, 2023 — the primary statute discussed in this article
- Information Technology Act, 2000 (with 2008 amendments) — predecessor legislation and cybercrime framework
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — superseded by the DPDP Act for covered matters
- Constitution of India, Article 21 — fundamental right to life and personal liberty, interpreted to include the right to privacy (K.S. Puttaswamy v. Union of India, 2017)
- Constitution of India, Eighth Schedule — 22 recognised languages in which privacy notices may be provided
- Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
Key Case Laws
- K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 — nine-judge bench unanimously recognised privacy as a fundamental right under Article 21
Official Government Sources
- Digital Personal Data Protection Act, 2023 — Official Gazette, Government of India
- Ministry of Electronics and Information Technology (MeitY) — Regulatory Authority
- Supreme Court of India — Puttaswamy Judgment and Case Records
- Reserve Bank of India — Data Localisation and Financial Data Protection Circulars
- Telecom Regulatory Authority of India (TRAI) — Internet Subscriber Data
- NASSCOM — India’s Digital Economy Data and Technology Reports
Related Reading on Midhati
Disclaimer: This article is intended for general legal awareness and educational purposes only. It does not constitute legal advice and does not create an advocate-client relationship. The Digital Personal Data Protection Act, 2023 is being implemented in phases; rules, notifications, and regulatory guidance are evolving. Always verify the current position of the law, applicable rules, and official notifications before taking any legal or compliance decision. Consult a qualified advocate or legal professional before acting on any information in this article. Midhati Legal Aid Foundation accepts no liability for actions taken solely on the basis of this article. For specific legal guidance, contact us.