India's Digital Personal Data Protection Act, 2023 (DPDP Act) is the country's first comprehensive law governing how organisations collect, use and protect the personal data of individuals. If your organisation handles digital personal data of people in India — customers, employees, students, citizens — this law applies to you. Here is what you need to know, in plain language.
The Act applies to any organisation processing digital personal data within India — and to processing outside India if it relates to offering goods or services to individuals in India. The organisation that decides why and how data is processed is called the Data Fiduciary. The individual the data belongs to is the Data Principal. There is no turnover threshold and no small-business carve-out from the core obligations: a two-person consultancy and a national bank are both data fiduciaries.
The government may notify certain organisations as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data they process. SDFs carry extra obligations: appointing a Data Protection Officer based in India who reports to the board, independent data audits, and periodic Data Protection Impact Assessments.
| Term | What it means |
|---|---|
| Personal data | Any data about an individual who is identifiable by or in relation to such data. Note the breadth: an employee ID, a device identifier or a customer number can all be personal data. |
| Processing | Any wholly or partly automated operation on digital personal data — collection, storage, use, sharing, alteration, erasure. Simply holding data is processing. |
| Data Fiduciary | The person or organisation that determines the purpose and means of processing. |
| Data Processor | Anyone who processes data on behalf of a fiduciary — payroll vendors, cloud hosts, SMS gateways. |
| Data Principal | The individual the data relates to. For a child, it includes their parent or lawful guardian. |
Personal data may generally be processed only with the data principal's consent, or for certain legitimate uses defined in the Act. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, for a specified purpose. Pre-ticked boxes, bundled consent and "agree to everything" walls do not qualify. Every consent request must be accompanied by a notice, in plain language, describing what data is collected and why — with the option to read it in English or any of the 22 languages in the Eighth Schedule of the Constitution.
Collect only the data you need for the stated purpose, use it only for that purpose, and delete it once the purpose is served unless retention is required by law. Purpose creep — collecting for delivery, then using for marketing — is one of the most common violations in Indian organisations.
Where personal data is used to make a decision affecting the data principal, or is disclosed to another fiduciary, you must make reasonable efforts to ensure it is complete, accurate and consistent.
Every fiduciary must take reasonable security safeguards to prevent personal data breaches. The Rules set a practical floor: encryption or equivalent protection, access control, logging and monitoring to detect unauthorised access, backups, and log retention sufficient to investigate an incident. This is the single largest penalty in the Act — up to ₹250 crore.
In the event of a personal data breach, the fiduciary must notify both the Data Protection Board of India and each affected data principal — with no risk threshold. A detailed report to the Board is due within 72 hours. See our step-by-step breach playbook.
For data principals under 18, fiduciaries must obtain verifiable parental consent before processing, and must not undertake tracking, behavioural monitoring or targeted advertising directed at children. Violations sit in the ₹200-crore penalty tier.
You may engage processors only under a valid contract — and liability for their processing stays with you. Vendor registers and contractual protections are compliance obligations, not procurement niceties.
The Act also imposes duties on data principals — not to impersonate others, not to suppress material information, not to file false or frivolous complaints — with a penalty up to ₹10,000.
Start-ups should note that the government may exempt certain classes of fiduciaries from specified provisions by notification. Until such a notification names you, assume the full obligations apply.
| Violation | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a personal data breach | ₹200 crore |
| Breach of obligations relating to children | ₹200 crore |
| Breach of SDF obligations | ₹150 crore |
| Other breaches of the Act | ₹50 crore |
These are ceilings. The Board sets the actual amount considering gravity, duration, repetitiveness, gains realised, mitigating action taken and its timeliness, and the likely impact of the penalty. Read that as a scoring rubric: every factor rewards organisations that documented safeguards, detected quickly and remediated visibly. See our full penalties breakdown.
The Act takes a permissive default: transfers outside India are allowed except to countries specifically restricted by central government notification. That is more relaxed than GDPR's adequacy regime — but sectoral rules still bind you. RBI's payment-data localisation, and insurance and telecom requirements, operate independently of the DPDP Act.
The DPDP Rules were notified in November 2025, beginning a phased rollout: the Data Protection Board is operational, Consent Manager registration follows in November 2026, and full enforcement arrives in May 2027. That sounds distant — but building a data inventory, redesigning consent journeys, and standing up rights and breach processes routinely takes organisations nine to fifteen months. See the complete timeline breakdown.
The first move is never drafting a policy. It is finding your data. Every subsequent obligation — valid consent, honest access responses, real erasure, credible breach scoping — presupposes an accurate answer to "what personal data do we hold, where, and why?" Most Indian organisations cannot answer that today, which is why automated data discovery is the practical entry point to DPDP compliance rather than its final step.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →
Get a personalised compliance assessment — free, no obligation.
Book a Free Assessment →