What does the DPDPA cover, and how does it reach foreign companies?
The Act covers digital personal data, personal data in digital form or digitized after non-digital collection, about an identifiable individual (the 'data principal'), processed by 'data fiduciaries' (who determine purpose and means, the controller analogue) and 'data processors' (who process on a fiduciary's behalf, regulated indirectly through the fiduciary's contracts and continued liability). Territorial scope: processing within India, and processing outside India in connection with any activity related to offering goods or services to data principals in India, an extraterritorial hook that captures foreign e-commerce, SaaS, and platforms serving Indian users without an Indian entity. Exclusions worth noting: non-digital data never digitized; personal or domestic processing; data made publicly available by the data principal or under legal obligation (a broad carve-out with sharp edges for scraping debates); and, controversially, the central government may exempt its instrumentalities on grounds including sovereignty and public order, plus notified exemptions for startups, research, and certain classes of fiduciaries. Two design choices distinguish India's model from the GDPR it otherwise echoes: there is no special-category regime, all digital personal data sits in one tier, with sensitivity handled through the significant-data-fiduciary mechanism and sectoral overlays (the RBI's payments localization, health regulations); and the Act imposes duties on data principals themselves (no impersonation, no false grievances), with modest penalties, a novelty among major regimes. Until commencement notifications issue, the operative Indian law remains the IT Act's SPDI Rules; companies building now are building for the DPDPA's phase-in against the 2025 draft rules' proposed timelines.
How do consent and 'legitimate uses' work as processing grounds?
The DPDPA is consent-first with a short second lane, not a six-basis menu. Consent: must be free, specific, informed, unconditional, and unambiguous with clear affirmative action, limited to personal data necessary for the specified purpose, requested with or after a notice describing the personal data, the purpose, the rights available, and the grievance mechanism, with the request and notice available in English or any of the 22 languages in the Eighth Schedule of the Constitution, an operational localization requirement with no GDPR analogue. Withdrawal must be as easy as giving consent, with processing ceasing (and processors instructed to cease) within a reasonable time, without affecting pre-withdrawal lawfulness. The Act creates 'consent managers,' registered platforms through which data principals can give, manage, review, and withdraw consent across fiduciaries, an interoperable consent infrastructure inspired by India's account-aggregator experience, unique among major regimes and elaborated in the draft rules. Legitimate uses (the second lane, exhaustively listed): voluntary provision by the data principal for a specified purpose without indicating non-consent; state functions, subsidies, benefits, services, licenses (with data minimization via existing government databases); legal obligations and judicial orders; medical emergencies, epidemics, disasters; and employment purposes, safeguarding the employer from loss or liability and provision of any service or benefit sought by an employee data principal, a compact employment ground doing the work GDPR programs spread across several bases. What is absent matters most: no legitimate-interests balancing test, no contract-necessity ground for ordinary commercial processing, so business models that lean on those bases in Europe (analytics, personalization, enrichment) must in India either fit a legitimate use, obtain genuine consent, or not process.
What do data fiduciaries owe, and what extra duties hit significant data fiduciaries?
Every data fiduciary owes, regardless of consent or legitimate use: overall responsibility for compliance including by its processors (engaged only under valid contract); reasonable security safeguards to prevent personal data breaches, the duty carrying the Act's highest penalty (INR 250 crore per instance), with the draft rules enumerating minimums (encryption or obfuscation, access control, logs and monitoring with one-year retention, backups, contractual flow-down to processors); breach notification, to each affected data principal and to the Data Protection Board, with the draft rules proposing prompt intimation to affected individuals and to the Board without delay, followed by a detailed report within 72 hours to the Board, notably without a harm threshold, every personal data breach is notifiable, stricter on paper than the GDPR; completeness, accuracy, and consistency for data used in decisions affecting the principal or disclosed onward; erasure when consent is withdrawn or the specified purpose is no longer being served (with draft-rule retention backstops for large platforms, e.g., three years of user inactivity for notified classes), plus corresponding processor erasure; a published grievance-redressal mechanism with response timelines (the principal must exhaust it before approaching the Board); and contact information of a DPO or responsible person in every notice. Children (under 18, higher than most regimes): verifiable parental consent before processing, no processing likely to cause detrimental effect on a child's well-being, and a flat prohibition on tracking, behavioral monitoring, and targeted advertising directed at children, with narrow exemptions in the rules (health, education, safety contexts). Significant data fiduciaries, designated by the central government on factors including data volume and sensitivity, risk to electoral democracy, and national security: appoint a DPO based in India reporting to the board of directors, appoint an independent data auditor, conduct periodic DPIAs and audits with findings reportable to the Board, and, under the draft rules, additional measures potentially including restrictions on transferring specified data categories outside India, the vector through which localization can return fiduciary-by-fiduciary.
What is the Data Protection Board, and how do penalties work?
The Data Protection Board of India is the Act's adjudicator, a body appointed by the central government (chairperson and members with two-year renewable terms), functioning as a digital-office tribunal: it receives personal-data-breach intimations, inquires into breaches of the Act on complaint, reference, or its own intimation-triggered motion, issues interim and final orders, directs remediation and mitigation in breach situations, and imposes monetary penalties, with civil-court powers for summoning and evidence and appeals lying to the TDSAT and onward to the Supreme Court. It is deliberately not a GDPR-style regulator: no rulemaking power (that sits with the central government via the DPDP Rules), no standard-setting or guidance mandate, and its composition and service terms have drawn independence criticism relative to European supervisory authorities, structural facts that shape strategy, in India the government, not the Board, decides the law's operational details, and the Board's role is closer to an enforcement court. Penalties (Schedule to the Act), per instance, calibrated to nature, gravity, duration, mitigation, and proportionality: up to INR 250 crore for failing reasonable security safeguards; INR 200 crore for failing to notify breaches and for children's-data violations; INR 150 crore for significant-data-fiduciary failures; INR 50 crore for most other violations; INR 10,000 for data-principal duty breaches; and the Board may accept 'voluntary undertakings' (commitments with the Board's approval) that bar further proceedings on the undertaken matter, an early-settlement valve. A 2025 amendment discussion and the finalization of rules will determine phase-in; no penalties can flow until the relevant provisions commence, but the security-safeguards ceiling, roughly USD $30 million per instance, and instance-stacking language mean breach exposure arrives at full scale on day one of commencement.
How do cross-border transfers work, and how should companies sequence DPDPA readiness?
Transfers under the DPDPA invert the GDPR's architecture: personal data may be transferred to any country except those the central government restricts by notification, a blacklist model rather than adequacy whitelists or transfer mechanisms, with no SCC-equivalent paperwork required by the Act itself. Three overlays complicate the simplicity: the draft rules empower government to impose transfer conditions generally (including requirements around making data available to foreign states); significant data fiduciaries may face category-specific localization requirements; and sectoral mandates persist regardless, the RBI's 2018 directive keeping payment-system data storable only in India, insurance and telecom rules, and government-procurement conditions, so a transfer map must layer sector rules over the DPDPA's permissive default. Readiness sequencing against the phased commencement the draft rules propose (consent-manager and Board provisions first, substantive duties on an announced runway): first, inventory digital personal data flows and purposes, since purpose-tied consent and erasure both depend on it; second, rebuild consent UX, granular, multilingual (the 22-language obligation drives real product work), affirmative-action-only, withdrawal-symmetric, and integrate grievance redressal with tracked timelines; third, wire the no-threshold breach pipeline (detect, intimate principals and Board, 72-hour detailed report) into incident response, stricter than most global playbooks; fourth, solve children's flows, age assurance approaches, verifiable parental consent (the rules sketch digital-locker-based verification), and the advertising prohibition, which for consumer platforms is the heaviest lift; fifth, position for significant-data-fiduciary designation if scale suggests it (India-based DPO, auditor selection, DPIA cadence); and throughout, keep SPDI-Rules compliance current, since it remains the enforceable law until each DPDPA provision commences, and the gap between the two regimes is precisely the work plan.