Data Privacy Law Digital Rights Business Compliance Central Legislation

DPDP Act 2023: Complete Guide to India’s Digital Personal Data Protection Law

India’s first comprehensive data privacy law — explained in plain language. Know your rights, understand business obligations, navigate penalties, and build a compliant future in the digital economy.

By Updated Reading time 35 min

Quick Answer: What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first standalone, comprehensive data privacy law, enacted on 11 August 2023. It governs how personal data of Indian citizens is collected, stored, used, and transferred in digital form. It gives every individual four enforceable legal rights over their data, places clear obligations on every organisation that collects data, creates the Data Protection Board of India as the enforcement authority, and prescribes financial penalties up to ₹250 crore per violation.

1. Historical Background: The Road to India’s Data Privacy Law ↑ Contents

You opened an app this morning. It asked for your name, phone number, date of birth, and location. You clicked “I Agree” and moved on with your day. But do you know where that data went? Who has access to it? Can they share it? Sell it? And what happens if it leaks?

For decades, India had no comprehensive answer to those questions. That changed on 11 August 2023.

The IT Act 2000 and Section 43A

India’s first attempt at digital privacy came through the Information Technology Act, 2000, and its amendment in 2008. Section 43A of the IT Act introduced liability for body corporates that were negligent in maintaining “reasonable security practices” for sensitive personal data. But Section 43A had serious limitations — it was narrow, enforcement was weak, and it was reactive rather than preventive.

The Puttaswamy Judgment: Privacy as a Fundamental Right

Landmark Judgment

On 24 August 2017, a nine-judge bench of the Supreme Court of India, in K.S. Puttaswamy (Retd.) v. Union of India [(2017) 10 SCC 1], unanimously held that privacy is a fundamental right under Article 21 of the Constitution of India.

Justice D.Y. Chandrachud observed: “Privacy is the constitutional core of human dignity. Privacy has both a normative and descriptive function. At a normative level, privacy sub-serves those eternal values upon which the guarantees of life, liberty and freedom are founded.”

This judgment made comprehensive data protection legislation not merely desirable — it made it constitutionally necessary.

Justice Srikrishna Committee (2018)

Following the Puttaswamy judgment, the Government constituted a Committee of Experts on Data Protection chaired by retired Supreme Court Judge Justice B.N. Srikrishna. The committee submitted its report and a draft Personal Data Protection Bill in July 2018, drawing heavily from the EU’s GDPR while accounting for India’s unique context.

The Legislative Journey (2019–2023)

YearMilestone
2019Personal Data Protection Bill introduced in Parliament
2021Referred to Joint Parliamentary Committee (JPC)
Dec 2021JPC submitted report with significant amendments
Aug 20222019 Bill withdrawn by the Government
Nov 2022Draft Digital Personal Data Protection Bill 2022 released for public consultation
11 Aug 2023Digital Personal Data Protection Act, 2023 enacted — Presidential assent granted

The six-year journey from the Puttaswamy judgment to the final legislation reflects the complexity of balancing individual privacy with India’s growing digital economy.

2. Why the DPDP Act Matters ↑ Contents

📊 India’s Data Landscape
  • Over 900 million internet users (TRAI, 2024)
  • More than 700 million smartphone users
  • Over 600 million active social media users
  • A booming $1 trillion digital economy projected by 2030 (NASSCOM)

Before the DPDP Act, an organisation could legally collect far more data than it needed, store your data indefinitely, share it with third parties without meaningful consent, and suffer a data breach without any obligation to inform you. The DPDP Act changes all of this.

For businesses, the DPDP Act is not just a compliance burden — it is a business opportunity. Organisations that demonstrate strong data governance earn customer trust and competitive advantage. Privacy-compliant businesses attract global investment, win enterprise clients, and access international markets that demand privacy standards.

3. Who Does the DPDP Act Apply To? ↑ Contents

Territorial Applicability

The DPDP Act applies to:

  1. Processing of digital personal data within India — whether collected in digital form, or collected in non-digital form and subsequently digitised.
  2. Processing of digital personal data outside India — if such processing is in connection with offering goods or services to individuals within India.
⚠️ Important — Extraterritorial Reach

The DPDP Act’s extraterritorial scope means global platforms — including those based in the United States, Europe, or Singapore — that serve Indian users are subject to Indian data protection law regardless of where their servers are located.

Key Roles Defined

RoleWho They AreExamples
Data Principal The individual whose data is processed. For children, the parent/guardian acts as Data Principal. You — when an app collects your data
Data Fiduciary Entity that determines the purpose and means of processing personal data. Bears primary legal obligations. Hospitals, banks, e-commerce platforms, schools, apps, government departments
Data Processor Processes personal data on behalf of a Data Fiduciary, following its instructions. Cloud providers, analytics firms, payment gateways
Consent Manager Registered intermediary through which Data Principals manage all their consents in one place. Future platforms enabling unified consent management across apps

What Qualifies as Personal Data?

The DPDP Act defines personal data broadly as: “any data about an individual who is identifiable by or in relation to such data.”

This includes names, phone numbers, email addresses, Aadhaar numbers, PAN, financial information, health records, location data, biometric data, device identifiers, IP addresses, photographs, and behavioural and preference data.

4. Key Definitions You Must Know ↑ Contents

TermPlain-Language Meaning
Digital Personal DataPersonal data in digital form
ProcessingCollection, storage, use, sharing, transfer, or deletion of data
Significant Data FiduciaryLarge or high-risk Fiduciary notified by the Central Government
Personal Data BreachUnauthorised access, disclosure, alteration, or destruction of data
Purpose LimitationData can only be used for the purpose it was collected for
Data MinimisationOnly collect what is strictly necessary
ConsentFree, specific, informed, unconditional, unambiguous agreement
Data Protection BoardIndia’s independent data protection enforcement authority

5. Core Principles of the DPDP Act ↑ Contents

The DPDP Act is built on seven foundational principles drawn from global best practices.

#PrincipleWhat It Means in Practice
1Lawful ProcessingData can only be processed for a purpose not prohibited by law
2Purpose LimitationData collected for one purpose cannot be repurposed without fresh consent
3Data MinimisationCollect only what is adequate, relevant, and necessary
4Data AccuracyReasonable steps must be taken to keep data accurate and updated
5Storage LimitationDelete data once the purpose is fulfilled and retention is not legally required
6Security SafeguardsImplement appropriate technical and organisational measures to prevent breaches
7AccountabilityThe Data Fiduciary is responsible for compliance and cannot outsource accountability

7. Rights of the Data Principal (Individual) ↑ Contents

The DPDP Act gives every Indian citizen four legally enforceable rights over their personal data.

01

Right to Access Information

Know what data is held about you, a summary of processing, and the identity of Data Processors it was shared with. (Section 11)

02

Right to Correction & Erasure

Demand correction of inaccurate data, completion of incomplete data, and erasure of data once the purpose is fulfilled. (Section 12)

03

Right to Grievance Redressal

Have your grievances addressed by the Data Fiduciary. Escalate to the Data Protection Board if unsatisfied. (Section 13)

04

Right to Nominate a Digital Heir

Nominate another individual to exercise your data rights after your death or incapacity. A globally unique right. (Section 14)

Duties of the Data Principal

ℹ️ Note — DPDP Act Creates Mutual Obligations

The DPDP Act also imposes duties on individuals — a unique feature among global data privacy laws:

  • Do not impersonate another person while providing consent
  • Do not suppress material information when providing data
  • Do not file false or frivolous complaints with the Data Protection Board

8. Obligations of the Data Fiduciary (Organisations) ↑ Contents

  • Give a Clear Notice Before Processing

    Provide a plain-language notice explaining what data is collected, the purpose, how to exercise rights, and grievance officer contact details.

  • Obtain Valid Consent

    Secure consent that is free, specific, informed, unconditional, and unambiguous. No pre-ticked boxes. No bundled consent.

  • Process Data Only for Specified Purpose

    Use data only for the purpose stated in the notice. Do not repurpose data without fresh consent.

  • Maintain Data Quality

    Ensure data processed is accurate, complete, and up-to-date, especially where inaccuracy could cause significant harm.

  • Delete Data When No Longer Needed

    Erase personal data when the purpose is fulfilled or consent is withdrawn, unless legally required to retain it.

  • Implement Security Safeguards

    Deploy encryption, access controls, audit logs, and incident response plans proportionate to the nature of data and risk.

  • Report Data Breaches Promptly

    Notify both the Data Protection Board and affected Data Principals in the event of a personal data breach, in the prescribed form and timeframe.

  • Establish a Grievance Redressal Mechanism

    Designate a named grievance officer, publish contact details prominently, and resolve complaints within prescribed timelines.

  • Conduct Due Diligence on Data Processors

    Ensure third-party processors meet adequate data protection standards through contractual obligations.

  • Comply with Data Principal Requests

    Respond to access, correction, and erasure requests accurately and within prescribed timelines.

9. Significant Data Fiduciaries: Special Rules for Big Players ↑ Contents

The Central Government may notify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to individuals, and threats to national security or electoral democracy.

Additional Obligations for SDFs

ObligationDetails
Data Protection Officer (DPO)Must be appointed and based in India, reporting to the Board of Directors, responsible for overall DPDP Act compliance
Independent Data AuditorPeriodic compliance audits and data management practice reviews by an independent auditor
Data Protection Impact Assessments (DPIA)Mandatory for high-risk processing activities — assessing impact on individual rights
No Behavioral Tracking of ChildrenCategorical prohibition on algorithmic tracking, monitoring, or profiling of children
No Targeted Advertising to ChildrenDirect prohibition on serving targeted advertisements to children
Processing RecordsDetailed records of all data processing activities must be maintained
ℹ️ Who Is Likely to Be an SDF?

While the Government has not yet officially notified SDFs, industry analysts expect this list to include major social media platforms, large e-commerce companies, fintech platforms, digital healthcare platforms, telecom operators, and large government data aggregators serving Indian users.

10. Data Protection Board of India ↑ Contents

The Data Protection Board of India is India’s independent data protection enforcement authority created by the DPDP Act. It operates as a digital-first body — complaints can be filed, hearings conducted, and orders issued entirely online.

Powers of the Data Protection Board

  • Inquire into complaints from Data Principals
  • Summon Data Fiduciaries and examine records
  • Impose financial penalties up to prescribed limits
  • Issue directions to Data Fiduciaries
  • Block or restrict data processing activities in extreme cases
  • Refer matters to appropriate authorities

How to File a Complaint

You must first exhaust the Data Fiduciary’s internal grievance mechanism before escalating to the Board. The Board’s process is designed to be fully digital, affordable, and accessible in multiple Indian languages.

11. Penalties Under the DPDP Act ↑ Contents

The Penalty Schedule (Schedule 1 of the Act)

₹250 Cr

Failure to implement reasonable security safeguards leading to a personal data breach

₹200 Cr

Failure to notify the Data Protection Board and affected individuals of a data breach

₹200 Cr

Processing children’s data in violation of Section 9 (without verifiable parental consent)

₹150 Cr

Non-fulfilment of additional obligations as a Significant Data Fiduciary

₹50 Cr

Non-fulfilment of general Data Fiduciary obligations under the Act

₹50 Cr

Breach of any other provision of the Act or Rules

⚠️ Penalties Are Per Instance

Each separate violation can attract a separate penalty. A single breach event involving inadequate security and failure to notify and affecting children’s data could theoretically attract multiple penalties — cumulatively running into hundreds of crores.

Illustrative Scenarios

ScenarioViolationsPotential Penalty Exposure
A healthcare startup suffers a breach exposing 50,000 patient records and fails to report it for 15 days Inadequate security + Failure to notify Up to ₹450 Cr
A children’s educational platform collects data without verifiable parental consent and serves targeted ads Children’s data violation (Section 9) Up to ₹200 Cr
An e-commerce company ignores a Data Principal’s erasure request for six months after account closure Non-fulfilment of obligations Up to ₹50 Cr
ℹ️ Note — No Criminal Liability or Individual Compensation

The DPDP Act does not provide for imprisonment of company officers — penalties are civil/financial in nature. The Act also does not provide a direct right for individuals to claim compensation from Data Fiduciaries. Penalties are paid to the Government, not the affected individual. These gaps have been identified by legal scholars and privacy advocates as areas requiring future legislative attention.

12. Exemptions Under the DPDP Act ↑ Contents

Exemption CategoryScope
State Instrumentalities & National SecurityCentral Government can exempt State instrumentalities in the interest of sovereignty, security, or public order — a broad exemption that has attracted scrutiny from privacy advocates
Research and ArchivingProcessing for research, archiving, or statistical purposes is permissible, provided it is not used to take decisions about specific individuals
Prevention of OffencesProcessing for prevention, detection, investigation, or prosecution of offences or contraventions of law is exempt
Enforcement of Rights or ClaimsProcessing necessary to enforce any right or claim in law is exempt
CourtsProcessing necessary for judicial or quasi-judicial functions is exempt
Startups and Small BusinessesThe Central Government may exempt certain classes of Data Fiduciaries (including startups) from specified provisions — these exemptions have not yet been notified

13. Cross-Border Data Transfers ↑ Contents

Personal data may be transferred to any country or territory outside India except those that the Central Government specifically restricts. This is a blacklist approach — transfers are permitted by default unless restricted — the opposite of GDPR’s adequacy-first approach.

ℹ️ Data Localisation

While the DPDP Act does not mandate blanket data localisation, the Government retains power to require Significant Data Fiduciaries to store certain categories of sensitive data within India’s borders. RBI and SEBI have already established data localisation requirements for financial data, which continue to apply.

14. Children’s Data: The Strongest Protections ↑ Contents

Under the DPDP Act, a “child” means an individual below 18 years of age. Children’s personal data receives the most comprehensive protection in the Act.

Requirements Before Processing Children’s Data

  1. Obtain verifiable parental consent — not just a checkbox declaring age
  2. Ensure processing is not detrimental to the well-being of the child

Categorically Prohibited Activities

🚫 Prohibited — No Exceptions for Children’s Data
  • Behavioural tracking or monitoring of children using algorithms or AI
  • Targeted advertising directed at children
  • Geolocation data collection of children
  • Algorithmic profiling of children based on personal data

India has over 500 million internet users below 18 years of age. A gaming app that tracks a 14-year-old’s gameplay behaviour to serve targeted in-app purchase recommendations — without verifiable parental consent — is now in clear violation of the DPDP Act and faces penalties up to ₹200 crore.

15. DPDP Act vs GDPR: Key Differences ↑ Contents

FeatureDPDP Act 2023 (India)GDPR 2018 (EU)
ScopeDigital personal data onlyDigital and non-digital data
Lawful basesConsent + deemed consent categories6 lawful bases including legitimate interest
Right to data portabilityNot explicitly includedIncluded
DPO requirementOnly for Significant Data FiduciariesRequired for certain organisations
Cross-border transfersBlacklist (permitted unless restricted)Adequacy decision or safeguards required
Individual compensationNot directly providedIndividuals can claim compensation
Maximum penalty₹250 crore (~€28 million)€20 million or 4% of global annual turnover
Enforcement authorityData Protection Board (digital-first)Each EU member state has its own DPA
Children’s age thresholdBelow 18Below 16 (varies by member state, min 13)
Sensitive data categoriesNot separately defined (Government can notify)Explicitly defined special categories
Complaint mechanismFirst exhaust Fiduciary’s mechanism, then DPBFile directly with supervisory authority (DPA)

16. DPDP Act and Existing Indian Laws ↑ Contents

LawInteraction with DPDP Act
IT Act 2000 / SPDI Rules 2011DPDP Act supersedes Section 43A and the SPDI Rules for matters it covers. Other IT Act provisions remain in force.
Aadhaar Act 2016The Aadhaar Act’s data protection provisions continue alongside the DPDP Act. For conflicts, the more specific statute may prevail.
RBI RegulationsRBI data localisation requirements, KYC data retention rules, and customer data protection guidelines continue to apply to banks and financial institutions.
Consumer Protection Act 2019Consumer protection provisions on unfair trade practices and misleading representations interact with DPDP notice and consent obligations.
SEBI RegulationsSEBI’s data protection framework for capital markets participants continues alongside the DPDP Act.

17. DPDP Act Compliance Roadmap for Businesses ↑ Contents

⚠️ Do Not Wait for Rules

Many organisations are waiting for the DPDP Rules to be notified before acting. This is a costly mistake. The Act is law now. Rules will fill in procedural details, but the obligations and rights exist today. Build your compliance infrastructure immediately.

Phase 1: Data Discovery and Mapping (Months 1–2)

  1. Conduct a Data Audit — Map every category of personal data: what, from whom, for what purpose, where stored, who has access, how long retained, and with whom shared.
  2. Map Data Flows — Document how data moves from collection through storage, use, sharing, and deletion.
  3. Classify Data by Risk — Financial, health, and children’s data require higher levels of protection.

Phase 2: Consent and Notice Framework (Months 2–3)

  1. Audit Existing Consent Mechanisms — Review all consent forms, privacy policies, and cookie banners for DPDP Act compliance.
  2. Redesign Notice and Consent Architecture — Create plain-language, granular consent mechanisms with easy withdrawal options.
  3. Update Privacy Policy — Write in plain language, available in multiple Indian languages, easily accessible, regularly updated.

Phase 3: Rights Fulfilment Infrastructure (Months 3–4)

  1. Set Up Data Principal Request Management — Build or purchase a system to receive, track, and respond to access, correction, and erasure requests.
  2. Designate a Grievance Officer — Appoint a named individual and publish contact details prominently on your website and app.

Phase 4: Security and Breach Response (Months 4–5)

  1. Implement Technical Security Measures — Encryption at rest and in transit, multi-factor authentication, role-based access controls, regular penetration testing, audit logs.
  2. Develop a Data Breach Response Plan — Include internal escalation procedures, assessment criteria, notification templates for the Data Protection Board and affected individuals, and clear timelines.

Phase 5: Third-Party Management (Month 5)

  1. Audit Data Processors — Review all third-party cloud providers, analytics tools, CRMs, and marketing platforms that process personal data on your behalf.
  2. Update Data Processing Agreements — Include scope of processing, security obligations, breach notification duties, deletion obligations at contract end, and audit rights.

Phase 6: Training and Culture (Ongoing)

  1. Train Your Team — Every employee handling personal data must understand DPDP Act requirements, breach identification, and escalation procedures.
  2. Build a Privacy-First Culture — Periodic data audits, privacy impact assessments for new products, regular policy reviews, and board-level accountability.

18. DPDP Act for Startups and Small Businesses ↑ Contents

Many startup founders are asking: “We are a 10-person team. Does this law really apply to us?” The honest answer is: yes, but with nuance.

The DPDP Act explicitly empowers the Central Government to exempt certain classes of startups from specific provisions. However, these exemptions have not yet been notified. Until they are, all Data Fiduciaries — regardless of size — are technically subject to the full Act.

✅ What Startups Should Do Right Now
  • Know your data — Understand exactly what personal data you collect and why
  • Get consent right — Clean up your consent mechanisms — it is not expensive
  • Write a proper privacy policy — A clear, accurate policy builds user trust and reduces legal risk
  • Designate a point of contact — Someone must own data privacy, even without a formal DPO requirement
  • Plan for breaches — A basic incident response plan costs nothing and saves everything if a breach occurs

The Business Case for Startup Compliance

  • Earn user trust — critical in an era of growing privacy awareness
  • Attract investment — global investors increasingly scrutinise data governance
  • Enable international expansion — GDPR-adjacent compliance makes entering EU/US markets easier
  • Avoid catastrophic penalties — a ₹250 crore penalty can destroy a startup overnight
  • Win enterprise clients — B2B clients increasingly demand vendor DPDP compliance

19. DPDP Act for NRIs ↑ Contents

Non-Resident Indians whose personal data is processed by Indian entities — a bank, an investment platform, a healthcare provider, or a family property management service — are Data Principals entitled to all rights under the DPDP Act.

This means NRIs can request access to their personal data held by Indian entities, demand correction of incorrect information, request erasure of data no longer needed, and file complaints with the Data Protection Board if their rights are violated.

For NRIs who own or operate businesses in India, the Indian entity is a Data Fiduciary subject to the full DPDP Act. If your business has global operations that process Indian citizens’ data, extraterritorial provisions may also apply.

For professional guidance on NRI data rights or DPDP compliance for NRI-owned Indian businesses, consult the Midhati team.

20. Myths vs Facts About the DPDP Act ↑ Contents

✗ Myth

“The DPDP Act is not yet in force — we can wait.”

✓ Fact

The Act received Presidential assent on 11 August 2023. It is law. Rules are being phased in, but the core obligations exist now.

✗ Myth

“We are GDPR compliant, so we are DPDP compliant.”

✓ Fact

GDPR and DPDP Act differ in important ways — consent framework, cross-border transfers, sensitive data categories, individual compensation, and more. A separate DPDP review is necessary.

✗ Myth

“We are a small startup — the DPDP Act does not apply to us.”

✓ Fact

The Act applies to all Data Fiduciaries. Startup exemptions, when notified, will be partial and conditional — not blanket immunity.

✗ Myth

“Our servers are in Singapore — Indian law does not apply.”

✓ Fact

The DPDP Act has extraterritorial reach. If you offer goods or services to Indian users, you are subject to the Act regardless of server location.

✗ Myth

“A data breach just means a fine — not existential risk.”

✓ Fact

A single breach can attract penalties of ₹450 crore or more across multiple violations. For most companies, this is an existential event.

✗ Myth

“Children need separate protection only for social media, not all apps.”

✓ Fact

The DPDP Act’s children’s data protections apply to ALL Data Fiduciaries — not just social media. Any app, website, or platform accessible to children under 18 is covered.

21. Common Mistakes to Avoid ↑ Contents

⚠️ Critical Compliance Errors
  • Treating the DPDP Act as a future problem. The Act is law now. Rules add procedural detail, not new obligations.
  • Copying a GDPR policy and calling it done. GDPR and DPDP Act differ on consent framework, rights, and data transfer rules. A DPDP-specific review is mandatory.
  • Using vague or bundled consent. Blanket “I Agree to everything” consent is invalid. Consent must be specific and granular.
  • Neglecting the erasure obligation. Storing user data indefinitely “just in case” is a violation. Build data retention schedules and automated deletion workflows.
  • Ignoring children’s data obligations. If your platform is accessible to users under 18, you need verifiable parental consent mechanisms immediately.
  • No data breach response plan. Discovering a breach months after it occurred and failing to notify within the required timeframe creates a second, separate major violation.
  • Inadequate vendor contracts. Using cloud storage, analytics tools, or CRMs without DPDP-compliant data processing agreements exposes you to liability when your processor causes a breach.
  • Making consent withdrawal difficult. If withdrawing consent requires multiple steps or is buried in settings, this directly violates the Act.
  • Not informing users of the nomination right. Failing to inform Data Principals of their right to nominate a digital heir is a gap in notice obligations.
  • No grievance officer appointed. Every Data Fiduciary must have a named grievance officer with published contact details.

22. Expert Tips for DPDP Compliance ↑ Contents

💡 Expert Guidance
  • Privacy by Design, not Privacy by Compliance. Build data protection into your products from the beginning. Evaluate every new feature against: “Do we actually need this data?”
  • Invest in plain language. Clear, understandable notices build trust. Users who understand what they’re agreeing to are more comfortable, more loyal, and less likely to file complaints.
  • Appoint a Privacy Champion. Even without a formal DPO requirement, designate someone internally who “owns” data privacy with direct access to senior leadership.
  • Conduct annual privacy audits. Data landscapes change. Products evolve. New vendors are added. An annual comprehensive privacy audit catches compliance gaps before they become penalties.
  • Document everything. Keep records of consent obtained, data processing activities, vendor contracts, breach incidents and responses, and training conducted.
  • Monitor MeitY notifications actively. The DPDP Act’s full implementation depends on subsidiary rules and government notifications. Subscribe to MeitY’s official updates.
  • Prepare for algorithmic accountability. Even for non-SDFs, the direction is clear — understand and be able to explain your algorithms, especially those that make decisions about individuals.
  • Consult a data privacy lawyer. The DPDP Act has nuances that general legal counsel may miss. Engage a specialist for a DPDP readiness assessment and compliance architecture review.

Frequently Asked Questions ↑ Contents

The Act & Its Fundamentals

The full name is the Digital Personal Data Protection Act, 2023. It is India’s first standalone, comprehensive data privacy legislation. It gives legal enforcement to the Supreme Court’s 2017 declaration that privacy is a fundamental right under Article 21 of the Constitution, and it transforms the legal relationship between Indian citizens and every organisation that processes their personal data.

The Act received Presidential assent on 11 August 2023. Its substantive provisions are being brought into force in phases through Central Government notifications issued by the Ministry of Electronics and Information Technology (MeitY). Businesses should monitor MeitY’s official notifications actively for current implementation timelines.

Personal data means “any data about an individual who is identifiable by or in relation to such data.” This is deliberately broad and includes names, phone numbers, email addresses, Aadhaar numbers, PAN, financial information, health records, location data, biometric data, device identifiers, IP addresses, photographs, and behavioural and preference data.

The IT Act 2000 addressed cybercrime and electronic commerce broadly, with limited data protection provisions under Section 43A. The DPDP Act is specifically focused on personal data protection, providing a comprehensive rights framework for individuals and binding obligations for organisations. The DPDP Act supersedes Section 43A of the IT Act for matters it covers.

The Act covers digital personal data. Non-digital data that is subsequently digitised also falls within scope. Purely offline data that is never digitised is outside the Act’s scope.

Rights of Individuals

You have four legally enforceable rights: (1) Right to access information — know what data is held and who it was shared with; (2) Right to correction and erasure — correct inaccurate data and request deletion once the purpose is served; (3) Right to grievance redressal — complain to the Data Fiduciary and escalate to the Data Protection Board; and (4) Right to nominate a digital heir — appoint someone to exercise your data rights after death or incapacity.

Yes. Under Section 12 of the DPDP Act, you can request erasure of your personal data once the purpose for which it was collected is fulfilled, or when you withdraw consent. The company may retain data if required to do so under another law — for example, banks must retain KYC data for a minimum period under RBI regulations.

Section 14 of the DPDP Act gives you the right to nominate another individual — your digital heir — who can exercise your data rights, including requesting erasure of accounts and data, after your death or incapacity. This is a globally unique right that addresses a growing real-world problem as India’s digital economy matures.

Data Principals must: (1) not impersonate another person when providing consent or data; (2) not suppress material information when providing personal data; and (3) not file false or frivolous complaints with the Data Protection Board. The DPDP Act’s mutual obligations framework is unique among global data privacy laws.

Consent and Compliance

Valid consent must be free (no coercion), specific (not bundled), informed (the person understands), unconditional (not tied to unrelated services), and unambiguous (a clear affirmative action — no pre-ticked boxes). The notice must be in plain language and available in any Eighth Schedule language on request.

Deemed consent means processing is lawful without explicit consent in specific situations — such as voluntary provision of data for an evident purpose (giving your address to a courier), state functions, medical emergencies, lawful employment-related processing, and public interest research. Deemed consent is an exception, not the rule.

No. Under the DPDP Act, personal data can only be used for the specific purpose for which consent was given (purpose limitation principle). Selling or sharing data for a different purpose requires separate consent. Processing without valid consent is a violation subject to penalties up to ₹50 crore for general violations, and up to ₹250 crore if it leads to a breach.

A Consent Manager is a registered intermediary that provides individuals a single platform to grant, track, modify, and withdraw consent across multiple Data Fiduciaries. It is a novel concept unique to India’s DPDP Act, designed to give individuals meaningful control over their digital data footprint across the dozens of apps and platforms they interact with daily.

Business Obligations and Penalties

The maximum penalty is ₹250 crore for failure to implement reasonable security safeguards leading to a data breach. Failure to notify a breach attracts up to ₹200 crore. Violations involving children’s data attract up to ₹200 crore. Non-fulfilment of SDF obligations attracts up to ₹150 crore. General obligation violations attract up to ₹50 crore.

Yes. If a foreign company processes personal data of Indian citizens in connection with offering goods or services to individuals in India, it is subject to the DPDP Act’s extraterritorial provisions. This applies regardless of where the company’s servers are located. Google, Meta, and other global platforms serving Indian users are covered.

The company must notify both the Data Protection Board of India and every affected Data Principal. Failure to notify is itself a separate violation attracting penalties up to ₹200 crore, independent of any penalty for the breach itself. Organisations should have a documented incident response plan well before any breach occurs.

A Significant Data Fiduciary (SDF) is a Data Fiduciary notified by the Central Government based on: volume and sensitivity of data processed, risk to individuals’ rights, potential impact on national security or sovereignty, and risk to electoral democracy. Industry analysts expect major social media platforms, large e-commerce companies, fintech platforms, digital healthcare platforms, and telecom operators to be designated as SDFs.

Not automatically. The Act empowers the Government to exempt certain classes of entities, including startups, from specified provisions through notifications. Until such notifications are issued, all Data Fiduciaries — regardless of size — are subject to the full Act. Begin building compliance infrastructure now rather than waiting for exemptions that may be conditional or partial.

Data Protection Board and Enforcement

You must first file a grievance with the Data Fiduciary’s designated grievance officer. If your grievance is not resolved satisfactorily, you can then escalate to the Data Protection Board of India. The Board operates as a digital-first authority — complaints are filed, hearings conducted, and orders issued entirely online. Further appeals go to the Appellate Tribunal, and on questions of law, to the Supreme Court.

Yes, government bodies are Data Fiduciaries if they process personal data. However, the Central Government can exempt state instrumentalities from specific provisions in the interest of sovereignty, security, or public order. This broad government exemption has attracted criticism from privacy advocates who argue it could be used to justify extensive state surveillance.

The DPDP Act uses a blacklist approach — personal data may be transferred to any country or territory outside India unless the Central Government specifically restricts that country. This is the opposite of GDPR’s adequacy-first approach. Cross-border transfers are permitted by default; restrictions, when imposed, are exceptions.

Children (individuals below 18) receive the strongest protections in the Act. Processing their data requires verifiable parental consent. The Act categorically prohibits behavioural tracking, targeted advertising, algorithmic profiling, and geolocation data collection for children. Violations attract penalties up to ₹200 crore.

The 2019 Bill was more detailed, included explicit data portability rights, defined specific categories of sensitive personal data, had different penalty structures, and included a Data Protection Authority with different powers. The 2019 Bill was withdrawn in August 2022. The DPDP Act 2023 is leaner, more principle-based, and grants the Central Government broader delegated power to issue rules and make determinations — a design choice intended to allow regulatory flexibility as technology evolves.

Yes. Social media platforms, messaging apps, and all digital services that process personal data of Indian citizens are Data Fiduciaries subject to the DPDP Act. Given their scale, these platforms are strong candidates for Significant Data Fiduciary designation, which would impose additional obligations including DPO appointment, data audits, and DPIAs.

NRIs whose personal data is processed by Indian entities are Data Principals with full rights under the DPDP Act. They can request access, demand correction or erasure, file complaints with the Data Protection Board, and nominate digital heirs. NRIs who own Indian businesses are subject to the Act as Data Fiduciaries. For personalised guidance, consult the Midhati team.

Midhati Legal Aid Foundation

Legal Research & Content Team

The Midhati Legal Aid Foundation is a trusted legal services platform serving individuals, businesses, startups, NRIs, and professionals across India. Our team of advocates and legal researchers provides practical, accessible legal guidance on data privacy, corporate compliance, consumer rights, and more. All legal content is reviewed for accuracy and compliance with current Indian law.

Disclaimer: This article is intended for general legal awareness and educational purposes only. It does not constitute legal advice and does not create an advocate-client relationship. The Digital Personal Data Protection Act, 2023 is being implemented in phases; rules, notifications, and regulatory guidance are evolving. Always verify the current position of the law, applicable rules, and official notifications before taking any legal or compliance decision. Consult a qualified advocate or legal professional before acting on any information in this article. Midhati Legal Aid Foundation accepts no liability for actions taken solely on the basis of this article. For specific legal guidance, contact us.

Scroll to Top