Global Privacy Law India

India DPDP Act and the Data Protection Board: How It Works

India's DPDP Act 2023 explained: consent-first processing, data fiduciary duties, the Data Protection Board, the 2025 draft rules, and penalties up to INR 250 crore.

Regulation

Digital Personal Data Protection Act, 2023 (DPDPA), enacted August 11, 2023; operational provisions await commencement notifications tied to the DPDP Rules (draft published January 2025, finalization in progress)

Max Penalty

Up to INR 250 crore (approximately USD $30 million) per instance for failure of reasonable security safeguards; INR 200 crore for breach-notification and children's-data failures; schedule-tiered below

Enforcing Authority

Data Protection Board of India (DPB), a central-government-appointed adjudicating body; appeals to the Telecom Disputes Settlement and Appellate Tribunal

Official Source

www.meity.gov.in

Executive Summary

  • The DPDPA is India's first comprehensive data protection law, governing digital personal data processed in India or in connection with offering goods or services to data principals in India.
  • Processing requires consent (free, specific, informed, unconditional, unambiguous, with affirmative action) or a listed 'legitimate use'; notices and consent requests must be available in English plus the 22 scheduled Indian languages.
  • Data fiduciaries owe security safeguards, breach notification to the Board and affected individuals, erasure at purpose-end, grievance redressal, and verifiable parental consent with a ban on tracking and behavioral advertising directed at children.
  • Significant data fiduciaries, designated by government, add DPO-in-India, independent audits, and periodic DPIAs; the Data Protection Board adjudicates breaches with penalties up to INR 250 crore per instance.
  • The Act awaits full commencement: draft DPDP Rules published January 2025 propose phased operation, making 2026-2027 the realistic compliance window.

India wrote the shortest major privacy law in the world, roughly a tenth the GDPR’s length, and spent its brevity budget on a distinctive set of bets: consent-first processing without a legitimate-interests escape, notices in 23 languages, an interoperable consent-manager infrastructure, a blacklist rather than whitelist transfer model, no-threshold breach notification, and an adjudicating Board rather than an independent regulator, with the operational details delegated to rules the government is still finalizing. For the billion-user market the Act governs, the strategy question is timing: the law is enacted but dormant, the rules are drafted but unfinished, and the phase-in will compress once notified. Companies serving Indian users who treat the 2025 draft rules as the blueprint, and start on the long-lead items now, multilingual consent, children’s flows, the breach pipeline, are buying their runway at par; those waiting for commencement will buy it at a premium, from the same vendors, at the same time, as everyone else.

EnactedAugust 11, 2023; commencement phased, pending final DPDP Rules (draft January 2025)
ModelConsent + enumerated legitimate uses; no legitimate-interests balancing
AdjudicatorData Protection Board of India; appeals to TDSAT
Top penaltiesINR 250 crore (security), 200 crore (breach notice, children), per instance
TransfersPermitted except to blacklisted countries; sectoral localization persists
Framework hubMeitY data protection framework

Going deeper

Work the full statute. The India DPDPA guide turns the Act and draft rules into a build list.

Scope the fiduciary role. Data fiduciary obligations details the duty set and SDF designation.

Solve children’s data first. DPDPA children’s data covers verifiable parental consent and the advertising ban.

Map the deltas. DPDPA vs GDPR and India data localization place the Act against global programs.

Consent UX starts at your web front door: see what your site collects today with a free scan.

Frequently Asked Questions

What does the DPDPA cover, and how does it reach foreign companies?

The Act covers digital personal data, personal data in digital form or digitized after non-digital collection, about an identifiable individual (the 'data principal'), processed by 'data fiduciaries' (who determine purpose and means, the controller analogue) and 'data processors' (who process on a fiduciary's behalf, regulated indirectly through the fiduciary's contracts and continued liability). Territorial scope: processing within India, and processing outside India in connection with any activity related to offering goods or services to data principals in India, an extraterritorial hook that captures foreign e-commerce, SaaS, and platforms serving Indian users without an Indian entity. Exclusions worth noting: non-digital data never digitized; personal or domestic processing; data made publicly available by the data principal or under legal obligation (a broad carve-out with sharp edges for scraping debates); and, controversially, the central government may exempt its instrumentalities on grounds including sovereignty and public order, plus notified exemptions for startups, research, and certain classes of fiduciaries. Two design choices distinguish India's model from the GDPR it otherwise echoes: there is no special-category regime, all digital personal data sits in one tier, with sensitivity handled through the significant-data-fiduciary mechanism and sectoral overlays (the RBI's payments localization, health regulations); and the Act imposes duties on data principals themselves (no impersonation, no false grievances), with modest penalties, a novelty among major regimes. Until commencement notifications issue, the operative Indian law remains the IT Act's SPDI Rules; companies building now are building for the DPDPA's phase-in against the 2025 draft rules' proposed timelines.

How do consent and 'legitimate uses' work as processing grounds?

The DPDPA is consent-first with a short second lane, not a six-basis menu. Consent: must be free, specific, informed, unconditional, and unambiguous with clear affirmative action, limited to personal data necessary for the specified purpose, requested with or after a notice describing the personal data, the purpose, the rights available, and the grievance mechanism, with the request and notice available in English or any of the 22 languages in the Eighth Schedule of the Constitution, an operational localization requirement with no GDPR analogue. Withdrawal must be as easy as giving consent, with processing ceasing (and processors instructed to cease) within a reasonable time, without affecting pre-withdrawal lawfulness. The Act creates 'consent managers,' registered platforms through which data principals can give, manage, review, and withdraw consent across fiduciaries, an interoperable consent infrastructure inspired by India's account-aggregator experience, unique among major regimes and elaborated in the draft rules. Legitimate uses (the second lane, exhaustively listed): voluntary provision by the data principal for a specified purpose without indicating non-consent; state functions, subsidies, benefits, services, licenses (with data minimization via existing government databases); legal obligations and judicial orders; medical emergencies, epidemics, disasters; and employment purposes, safeguarding the employer from loss or liability and provision of any service or benefit sought by an employee data principal, a compact employment ground doing the work GDPR programs spread across several bases. What is absent matters most: no legitimate-interests balancing test, no contract-necessity ground for ordinary commercial processing, so business models that lean on those bases in Europe (analytics, personalization, enrichment) must in India either fit a legitimate use, obtain genuine consent, or not process.

What do data fiduciaries owe, and what extra duties hit significant data fiduciaries?

Every data fiduciary owes, regardless of consent or legitimate use: overall responsibility for compliance including by its processors (engaged only under valid contract); reasonable security safeguards to prevent personal data breaches, the duty carrying the Act's highest penalty (INR 250 crore per instance), with the draft rules enumerating minimums (encryption or obfuscation, access control, logs and monitoring with one-year retention, backups, contractual flow-down to processors); breach notification, to each affected data principal and to the Data Protection Board, with the draft rules proposing prompt intimation to affected individuals and to the Board without delay, followed by a detailed report within 72 hours to the Board, notably without a harm threshold, every personal data breach is notifiable, stricter on paper than the GDPR; completeness, accuracy, and consistency for data used in decisions affecting the principal or disclosed onward; erasure when consent is withdrawn or the specified purpose is no longer being served (with draft-rule retention backstops for large platforms, e.g., three years of user inactivity for notified classes), plus corresponding processor erasure; a published grievance-redressal mechanism with response timelines (the principal must exhaust it before approaching the Board); and contact information of a DPO or responsible person in every notice. Children (under 18, higher than most regimes): verifiable parental consent before processing, no processing likely to cause detrimental effect on a child's well-being, and a flat prohibition on tracking, behavioral monitoring, and targeted advertising directed at children, with narrow exemptions in the rules (health, education, safety contexts). Significant data fiduciaries, designated by the central government on factors including data volume and sensitivity, risk to electoral democracy, and national security: appoint a DPO based in India reporting to the board of directors, appoint an independent data auditor, conduct periodic DPIAs and audits with findings reportable to the Board, and, under the draft rules, additional measures potentially including restrictions on transferring specified data categories outside India, the vector through which localization can return fiduciary-by-fiduciary.

What is the Data Protection Board, and how do penalties work?

The Data Protection Board of India is the Act's adjudicator, a body appointed by the central government (chairperson and members with two-year renewable terms), functioning as a digital-office tribunal: it receives personal-data-breach intimations, inquires into breaches of the Act on complaint, reference, or its own intimation-triggered motion, issues interim and final orders, directs remediation and mitigation in breach situations, and imposes monetary penalties, with civil-court powers for summoning and evidence and appeals lying to the TDSAT and onward to the Supreme Court. It is deliberately not a GDPR-style regulator: no rulemaking power (that sits with the central government via the DPDP Rules), no standard-setting or guidance mandate, and its composition and service terms have drawn independence criticism relative to European supervisory authorities, structural facts that shape strategy, in India the government, not the Board, decides the law's operational details, and the Board's role is closer to an enforcement court. Penalties (Schedule to the Act), per instance, calibrated to nature, gravity, duration, mitigation, and proportionality: up to INR 250 crore for failing reasonable security safeguards; INR 200 crore for failing to notify breaches and for children's-data violations; INR 150 crore for significant-data-fiduciary failures; INR 50 crore for most other violations; INR 10,000 for data-principal duty breaches; and the Board may accept 'voluntary undertakings' (commitments with the Board's approval) that bar further proceedings on the undertaken matter, an early-settlement valve. A 2025 amendment discussion and the finalization of rules will determine phase-in; no penalties can flow until the relevant provisions commence, but the security-safeguards ceiling, roughly USD $30 million per instance, and instance-stacking language mean breach exposure arrives at full scale on day one of commencement.

How do cross-border transfers work, and how should companies sequence DPDPA readiness?

Transfers under the DPDPA invert the GDPR's architecture: personal data may be transferred to any country except those the central government restricts by notification, a blacklist model rather than adequacy whitelists or transfer mechanisms, with no SCC-equivalent paperwork required by the Act itself. Three overlays complicate the simplicity: the draft rules empower government to impose transfer conditions generally (including requirements around making data available to foreign states); significant data fiduciaries may face category-specific localization requirements; and sectoral mandates persist regardless, the RBI's 2018 directive keeping payment-system data storable only in India, insurance and telecom rules, and government-procurement conditions, so a transfer map must layer sector rules over the DPDPA's permissive default. Readiness sequencing against the phased commencement the draft rules propose (consent-manager and Board provisions first, substantive duties on an announced runway): first, inventory digital personal data flows and purposes, since purpose-tied consent and erasure both depend on it; second, rebuild consent UX, granular, multilingual (the 22-language obligation drives real product work), affirmative-action-only, withdrawal-symmetric, and integrate grievance redressal with tracked timelines; third, wire the no-threshold breach pipeline (detect, intimate principals and Board, 72-hour detailed report) into incident response, stricter than most global playbooks; fourth, solve children's flows, age assurance approaches, verifiable parental consent (the rules sketch digital-locker-based verification), and the advertising prohibition, which for consumer platforms is the heaviest lift; fifth, position for significant-data-fiduciary designation if scale suggests it (India-based DPO, auditor selection, DPIA cadence); and throughout, keep SPDI-Rules compliance current, since it remains the enforceable law until each DPDPA provision commences, and the gap between the two regimes is precisely the work plan.

Regulatory Crosswalk

GDPRIT Act 2000 / SPDI RulesRBI data localization directions

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.