Asia-Pacific India

India DPDPA Guide: The Digital Personal Data Protection Act

India's DPDP Act 2023: who it covers, consent and legitimate uses, data fiduciary duties, INR 250 crore penalties, and the phased rollout under the 2025 rules.

Regulation

Digital Personal Data Protection Act, 2023 (enacted 11 August 2023; phased commencement via DPDP Rules)

Max Penalty

Up to INR 250 crore (approx. USD 30 million) per instance for failing security safeguards

Enforcing Authority

Data Protection Board of India

Official Source

www.meity.gov.in

Executive Summary

  • The DPDP Act 2023 is India's first comprehensive privacy statute, enacted 11 August 2023 after five years of drafts; operational rules were published in draft in January 2025 and commencement is phased.
  • It covers digital personal data processed in India and processing abroad connected to offering goods or services to individuals in India.
  • Lawful processing rests on two grounds only: consent (free, specific, informed, unconditional, unambiguous, with clear affirmative action) or defined 'legitimate uses' such as voluntary provision, state functions, emergencies, and employment.
  • Data fiduciaries carry the duties: notice, security safeguards, breach notification to the Board and affected individuals, erasure when purpose is served, and grievance mechanisms; Significant Data Fiduciaries add DPOs, audits, and DPIAs.
  • Penalties are per-schedule caps topping at INR 250 crore for security-safeguard failures, imposed by the new Data Protection Board of India.

India legislated privacy in one clean sweep after a decade of pressure: the Supreme Court’s 2017 Puttaswamy judgment declaring privacy a fundamental right, two failed bills, and finally the DPDP Act 2023, shorter and more consent-centric than GDPR, with its operational weight pushed into rules that arrived in draft form in January 2025. For anyone serving India’s roughly 900 million internet users, the act’s simplicity is deceptive: two lawful grounds, no sensitive-data tiers, and per-instance penalties reaching INR 250 crore.

RegulationDigital Personal Data Protection Act, 2023
Max penaltyINR 250 crore per instance (security failures)
Enforcing authorityData Protection Board of India
Official frameworkMeitY data protection framework / Act text (PDF)

The architecture

Actors. Data fiduciaries (controllers) determine purpose and means; data processors act on their behalf, with liability staying on the fiduciary. The government can designate Significant Data Fiduciaries by volume, sensitivity, and risk, adding enhanced obligations: an India-based DPO reporting to the board, independent audits, and periodic DPIAs.

Consent. The default ground, and demanding: free, specific, informed, unconditional, unambiguous, affirmative action, purpose-limited to what is necessary, and as easy to withdraw as to give. Notices must be available in English plus the 22 scheduled languages. Consent managers, a registered intermediary class unique to India, let individuals manage consents through interoperable platforms.

Duties. Security safeguards, breach notification to the Board and each affected individual (the draft rules set a 72-hour outer frame for detailed reports), erasure when purpose is served or consent withdrawn, accuracy for decisions affecting individuals, and grievance officers. Children under 18 require verifiable parental consent with tracking and targeted advertising prohibited.

Transfers. A negative-list model: personal data may flow to any country the government has not restricted, with sectoral rules (like the RBI’s payments localization) continuing to apply on top.

What to do before commencement

Sequence the build: map digital personal data flows and identify your fiduciary/processor roles; rebuild consent UX to the affirmative-action standard with multilingual notices; stand up grievance and erasure machinery; contract-paper your processors (the act makes you answerable for them); and monitor Significant Data Fiduciary designation criteria. The GDPR comparison maps where existing EU programs transfer over and where they do not. Test what your India-facing surfaces collect with a free scan.

Frequently Asked Questions

Is the DPDPA in force yet?

The act received presidential assent on 11 August 2023, but its operative provisions commence on government notification. Draft DPDP Rules were released for consultation in January 2025, defining notice formats, breach reporting, children's verification, and the Board's operations, with phased transition periods expected after finalization. Build now; the compliance clock starts with the rules.

What data does it cover?

Digital personal data: data in digital form, or digitized after collection, about an identifiable individual. There is no separate sensitive-data category, a deliberate simplification from earlier bills, and non-digital records outside automated processing fall outside scope. Publicly-made-available data by the individual is excluded.

What are 'legitimate uses'?

Section 7 grounds that substitute for consent: data voluntarily provided for a specified purpose, state subsidies and services, legal obligations and judgments, medical emergencies, disasters, and employment purposes. They are narrower than GDPR's legitimate interests, there is no general balancing-test ground, so most commercial processing runs on consent.

What rights do individuals (data principals) get?

Access to a summary of processed data and processing activities, correction and erasure, grievance redressal with escalation to the Board, and nomination of a person to exercise rights after death or incapacity, a distinctive DPDPA feature. Notably absent: portability and a general right to object.

How do penalties work?

The schedule caps by violation type: INR 250 crore for security-safeguard failures, INR 200 crore for breach-notification and children's-data violations, INR 150 crore for Significant Data Fiduciary obligations, down to INR 10,000 for data-principal duty breaches. The Board weighs gravity, repetitiveness, and mitigation; caps apply per instance.

Regulatory Crosswalk

GDPRDPDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.