The DPDP Act 2023 Explained: What Every Indian Organisation Must Know

India's Digital Personal Data Protection Act, 2023 (DPDP Act) is the country's first comprehensive law governing how organisations collect, use and protect the personal data of individuals. If your organisation handles digital personal data of people in India — customers, employees, students, citizens — this law applies to you. Here is what you need to know, in plain language.

Who does the Act apply to?

The Act applies to any organisation processing digital personal data within India — and to processing outside India if it relates to offering goods or services to individuals in India. The organisation that decides why and how data is processed is called the Data Fiduciary. The individual the data belongs to is the Data Principal. There is no turnover threshold and no small-business carve-out from the core obligations: a two-person consultancy and a national bank are both data fiduciaries.

The government may notify certain organisations as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data they process. SDFs carry extra obligations: appointing a Data Protection Officer based in India who reports to the board, independent data audits, and periodic Data Protection Impact Assessments.

Key definitions you need to get right

TermWhat it means
Personal dataAny data about an individual who is identifiable by or in relation to such data. Note the breadth: an employee ID, a device identifier or a customer number can all be personal data.
ProcessingAny wholly or partly automated operation on digital personal data — collection, storage, use, sharing, alteration, erasure. Simply holding data is processing.
Data FiduciaryThe person or organisation that determines the purpose and means of processing.
Data ProcessorAnyone who processes data on behalf of a fiduciary — payroll vendors, cloud hosts, SMS gateways.
Data PrincipalThe individual the data relates to. For a child, it includes their parent or lawful guardian.

The core obligations

1. Consent must be genuine

Personal data may generally be processed only with the data principal's consent, or for certain legitimate uses defined in the Act. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, for a specified purpose. Pre-ticked boxes, bundled consent and "agree to everything" walls do not qualify. Every consent request must be accompanied by a notice, in plain language, describing what data is collected and why — with the option to read it in English or any of the 22 languages in the Eighth Schedule of the Constitution.

2. Purpose limitation and data minimisation

Collect only the data you need for the stated purpose, use it only for that purpose, and delete it once the purpose is served unless retention is required by law. Purpose creep — collecting for delivery, then using for marketing — is one of the most common violations in Indian organisations.

3. Accuracy

Where personal data is used to make a decision affecting the data principal, or is disclosed to another fiduciary, you must make reasonable efforts to ensure it is complete, accurate and consistent.

4. Security safeguards

Every fiduciary must take reasonable security safeguards to prevent personal data breaches. The Rules set a practical floor: encryption or equivalent protection, access control, logging and monitoring to detect unauthorised access, backups, and log retention sufficient to investigate an incident. This is the single largest penalty in the Act — up to ₹250 crore.

5. Breach notification

In the event of a personal data breach, the fiduciary must notify both the Data Protection Board of India and each affected data principal — with no risk threshold. A detailed report to the Board is due within 72 hours. See our step-by-step breach playbook.

6. Children's data

For data principals under 18, fiduciaries must obtain verifiable parental consent before processing, and must not undertake tracking, behavioural monitoring or targeted advertising directed at children. Violations sit in the ₹200-crore penalty tier.

7. Processor governance

You may engage processors only under a valid contract — and liability for their processing stays with you. Vendor registers and contractual protections are compliance obligations, not procurement niceties.

Rights of the data principal

  • Right to access — a summary of what data is processed and the identities of everyone it has been shared with.
  • Right to correction and erasure — have inaccurate data corrected, incomplete data completed, and data no longer needed erased.
  • Right to grievance redressal — an accessible channel to complain, which the fiduciary must answer before the principal can escalate to the Board.
  • Right to nominate — designate someone to exercise these rights in case of death or incapacity.

The Act also imposes duties on data principals — not to impersonate others, not to suppress material information, not to file false or frivolous complaints — with a penalty up to ₹10,000.

What the Act does not cover

  • Personal or domestic use. An individual processing data for purely personal purposes is out of scope. This does not extend to a sole proprietor's customer list.
  • Publicly available data made public by the data principal themselves, or by someone under a legal obligation to publish. A person's own public profile is outside the Act; a scraped database compiled from many sources is not automatically cleansed by this exclusion.
  • Non-digital data never digitised, and certain government processing notified as exempt for research, archiving or statistical purposes subject to prescribed standards.

Start-ups should note that the government may exempt certain classes of fiduciaries from specified provisions by notification. Until such a notification names you, assume the full obligations apply.

Penalties

ViolationMaximum penalty
Failure to take reasonable security safeguards₹250 crore
Failure to notify a personal data breach₹200 crore
Breach of obligations relating to children₹200 crore
Breach of SDF obligations₹150 crore
Other breaches of the Act₹50 crore

These are ceilings. The Board sets the actual amount considering gravity, duration, repetitiveness, gains realised, mitigating action taken and its timeliness, and the likely impact of the penalty. Read that as a scoring rubric: every factor rewards organisations that documented safeguards, detected quickly and remediated visibly. See our full penalties breakdown.

Cross-border transfers

The Act takes a permissive default: transfers outside India are allowed except to countries specifically restricted by central government notification. That is more relaxed than GDPR's adequacy regime — but sectoral rules still bind you. RBI's payment-data localisation, and insurance and telecom requirements, operate independently of the DPDP Act.

The timeline

The DPDP Rules were notified in November 2025, beginning a phased rollout: the Data Protection Board is operational, Consent Manager registration follows in November 2026, and full enforcement arrives in May 2027. That sounds distant — but building a data inventory, redesigning consent journeys, and standing up rights and breach processes routinely takes organisations nine to fifteen months. See the complete timeline breakdown.

Where organisations should start

The first move is never drafting a policy. It is finding your data. Every subsequent obligation — valid consent, honest access responses, real erasure, credible breach scoping — presupposes an accurate answer to "what personal data do we hold, where, and why?" Most Indian organisations cannot answer that today, which is why automated data discovery is the practical entry point to DPDP compliance rather than its final step.

Frequently asked questions

Who does the DPDP Act 2023 apply to?
Any organisation processing digital personal data within India, and organisations outside India processing data in connection with offering goods or services to individuals in India. There is no turnover threshold — every Data Fiduciary, from a two-person firm to a national bank, carries the baseline obligations.
What is the difference between a Data Fiduciary and a Data Principal?
The Data Fiduciary is the organisation that determines the purpose and means of processing personal data. The Data Principal is the individual the data relates to — including, for a child, their parent or lawful guardian.
What data is excluded from the DPDP Act?
Personal data processed by an individual for purely personal or domestic purposes; data the individual has themselves made publicly available, or which is published under a legal obligation; non-digital data that has never been digitised; and certain government processing notified as exempt for research, archiving or statistical purposes.
When does the DPDP Act come into force?
The Rules were notified in November 2025 and the Data Protection Board is operational. Consent Manager registration opens in November 2026 and full enforcement of substantive obligations arrives in May 2027.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →

Ready to become DPDP compliant?

Get a personalised compliance assessment — free, no obligation.

Book a Free Assessment →