Compliance

DPDP Act Explained: India's Data Protection Law

Understand the DPDP Act, India's landmark data protection law. Learn compliance obligations, exact legal citations, penalties up to ₹250 crore, and next steps.

Editorial Team ·
12 min read intermediate

Introduction

On 11 August 2023, India enacted Act No. 22 of 2023 — the Digital Personal Data Protection Act. For the first time, India has a dedicated law governing how organizations must handle citizens’ digital personal information, with financial penalties reaching ₹250 crore (approximately USD 30 million) for a single category of violation. That is not a theoretical risk. India has the world’s second-largest internet user base, processing personal data at a scale that now has explicit legal obligations attached to it.

The DPDP Act is not a bureaucratic checkbox exercise. Organizations that ignore it face penalties adjudicated by the Data Protection Board of India — a statutory body with the power to impose fines immediately upon determining a violation. Unlike GDPR’s graduated enforcement history, the DPDP Act’s Board is empowered to act swiftly. The Rules notified in 2025 set timelines and technical requirements that businesses must meet before the Board becomes fully operational.

This article dissects the Act section by section, maps the exact compliance obligations to technical and operational controls, and gives you a structured checklist your legal and engineering teams can work from together.

What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) governs the processing of digital personal data in India. It establishes a rights-based framework with two primary parties:

  • Data Principal (Section 2(j)): The individual whose personal data is being processed. For a child, the parent or legal guardian acts as the Data Principal.
  • Data Fiduciary (Section 2(i)): Any person who alone or in conjunction with others determines the purpose and means of processing personal data. Equivalent to GDPR’s “data controller.”
  • Data Processor (Section 2(k)): Any person who processes personal data on behalf of a Data Fiduciary. Must operate under a written contract with the Fiduciary.

Scope (Section 3): The Act applies to processing of digital personal data within India, and to processing outside India if it is in connection with offering goods or services to Data Principals in India. Paper records are explicitly excluded from scope.

Significant Data Fiduciaries (Section 10): The Central Government may designate certain Data Fiduciaries as “Significant” based on volume, sensitivity, national security risk, or systemic impact. Significant Data Fiduciaries face additional obligations including mandatory Data Protection Impact Assessments and periodic audits.

How the DPDP Act Works

The Act establishes a lifecycle of obligations from data collection through deletion.

1. Notice (Section 5): Before or at the time of seeking consent, a Data Fiduciary must provide a notice in English or any language listed in the Eighth Schedule to the Constitution. The notice must clearly state what personal data is being collected, the purpose of processing, and how the Data Principal can exercise their rights. Pre-ticked boxes and bundled consent are prohibited.

2. Consent (Section 6): Processing must be based on free, specific, informed, unconditional, and unambiguous consent — given through a clear affirmative action. Consent must be granular: separate consent for each distinct purpose. The Data Principal may withdraw consent at any time. Upon withdrawal, the Data Fiduciary must cease processing and delete the data unless retention is required by law.

3. Purpose Limitation (Section 6(4)): Data collected for one purpose cannot be processed for a different purpose without fresh consent. A delivery address collected for shipping cannot be used for marketing without separate consent.

4. Data Minimisation (Section 6(4)): Only personal data necessary for the stated purpose may be collected. Data Fiduciaries cannot collect data “just in case.”

5. Security Safeguards (Section 8(5)): Data Fiduciaries must implement “reasonable security safeguards to prevent personal data breach.” The DPDP Rules 2025 specify technical standards including encryption of personal data at rest and in transit.

6. Breach Notification (Section 8(6)): Upon becoming aware of a personal data breach, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal. The notification must be made in the prescribed form and within the time specified by the Board.

7. Data Retention (Section 8(7)): Personal data must be erased once the purpose for which it was collected is served and retention is no longer necessary for legal purposes. The Rules specify retention periods for different categories.

8. Children’s Data (Section 9): Processing of personal data of children (under 18) requires verifiable parental consent. Tracking, behavioral monitoring, and targeted advertising to children are prohibited without exception.

This explainer breaks down the specific rules and technical requirements mandated by the DPDP Act. Pay particular attention to the sections on consent mechanisms and security safeguards — these map directly to the compliance checklist below.

DPDP Act Compliance Checklist

Use this checklist to structure your compliance program. Each item cites the relevant section of Act No. 22 of 2023 or the DPDP Rules 2025.

Consent and Notice Infrastructure (Sections 5–6)

  1. Consent management platform implemented — capable of recording granular, purpose-specific consent with timestamp and version
  2. Privacy notice available in English and at least one language from the Eighth Schedule (Hindi minimum for India-facing products)
  3. No pre-ticked boxes or bundled consent in sign-up, checkout, or onboarding flows
  4. Consent withdrawal mechanism — user can withdraw any individual consent, triggering automated halt of processing for that purpose
  5. Audit trail: every consent collected stored with: timestamp, version of notice shown, IP address, Data Principal ID
  6. Children’s data: age verification mechanism in place before collecting any data from users who may be under 18 (Section 9)
  7. Parental consent workflow for users confirmed under 18 — verifiable, documented, auditable

Purpose Limitation and Data Minimisation (Section 6(4))

  1. Data map maintained: every field collected, the purpose stated to the user, and the system it lands in
  2. No secondary use without fresh consent: marketing, analytics, third-party sharing — each requires separate consent
  3. Data minimisation review: confirm each collected field is necessary for the stated purpose; remove fields that are not

Security Safeguards (Section 8(5) and DPDP Rules 2025)

  1. Personal data encrypted at rest with AES-256 (or equivalent per DPDP Rules technical standards)
  2. Personal data encrypted in transit with TLS 1.2 minimum across all endpoints, internal and external
  3. Access controls: least-privilege access to personal data by employees and systems
  4. Multi-factor authentication enforced for all systems with access to personal data
  5. Vulnerability assessment and penetration testing schedule documented and executed at least annually
  6. Data processor contracts: written agreement with every processor (Section 8(2)) specifying security obligations
  7. Employee training: documented data protection training for all staff with access to personal data

Breach Notification (Section 8(6) and DPDP Rules 2025)

  1. Breach detection capability: SIEM, anomaly detection, or equivalent — tested annually
  2. Breach response procedure: documented runbook for who assesses, who notifies, and what timeline
  3. Data Protection Board notification: form and timeline for Board notification (prescribed by Rules)
  4. Data Principal notification: template for notifying affected individuals, translated into required languages
  5. Breach log: all incidents and near-misses documented (even if below notification threshold)

Data Retention and Erasure (Section 8(7))

  1. Retention schedule documented for each category of personal data
  2. Automated or procedural deletion triggered when retention period expires
  3. Right to erasure workflow: Data Principal erasure request received, acknowledged, executed, and confirmed within required timeframe
  4. Deletion confirmed across all systems including backups, analytics, and third-party processors

Data Principal Rights (Sections 11–14)

  1. Access request workflow: Data Principal can request what data is held — response mechanism documented
  2. Correction request workflow: Data Principal can request correction of inaccurate data
  3. Grievance redressal mechanism: contact person designated, response SLA defined (Section 13)
  4. Nomination mechanism: Data Principals can nominate a representative (Section 14)

Significant Data Fiduciary (Section 10 — if applicable)

  1. Check whether designation thresholds apply (volume, sensitivity, systemic risk)
  2. If designated: Data Protection Impact Assessment conducted and documented
  3. If designated: periodic audit by independent auditor engaged
  4. If designated: Data Protection Officer appointed (cannot be an outsourced role)

DPDP Act vs GDPR

FeatureDPDP Act (India, 2023)GDPR (European Union, 2016)
Legal basisConsent or specific legitimate usesSix lawful bases including legitimate interest
Data categoriesAll personal data treated uniformlyStricter rules for “special categories”
Paper recordsExcluded from scope (Section 3)Included in scope
Cross-border transferPermitted unless restricted by government notificationRequires adequacy decision or safeguards
Highest penalty₹250 crore (~USD 30M) per Schedule I€20M or 4% of global annual turnover
Enforcement bodyData Protection Board of IndiaNational supervisory authorities (54 DPAs)
Children’s age thresholdUnder 18 (Section 9)Under 16 (Member State discretion to lower to 13)
Legitimate interest basisNot recognizedRecognized with balancing test

The most operationally significant difference is the absence of “legitimate interest” as a lawful basis. GDPR allows organizations to process personal data without consent if they have a legitimate interest that is not overridden by the Data Principal’s rights — a basis widely used for fraud prevention, security monitoring, and analytics. Under the DPDP Act, all such uses require either consent or must fall within the narrow “certain legitimate uses” carved out in Section 7 (employment, medical emergency, public health).

Real-World Use Cases

E-commerce platforms: A shopping platform collecting Indian users’ names, addresses, and payment data must obtain separate consent for: (1) order fulfillment, (2) product recommendations, and (3) marketing emails. One bundled consent checkbox at checkout violates Section 6. The platform must implement a consent management system that records granular consent per purpose and allows per-purpose withdrawal.

Fintech companies: A loan application app processing income data, PAN numbers, and bank statements must provide its consent notice in the user’s preferred language (Section 5). If a user in Tamil Nadu prefers Tamil, the notice must be available in Tamil. The technical architecture must support multi-language notice delivery and confirm the language in which consent was obtained.

Multinational SaaS providers: A US-headquartered SaaS company with Indian customers falls under Section 3(b)‘s extraterritorial scope. The company must appoint a Data Protection Officer (if designated as a Significant Data Fiduciary), sign Data Processor Agreements with its own sub-processors for Indian data, and maintain breach notification capability aligned with the Board’s prescribed timelines.

Common Mistakes and Penalties

Treating consent as a one-time event. Section 6(3) explicitly provides the right to withdraw consent at any time. If your system cannot process a consent withdrawal and halt the associated data processing within a reasonable timeframe, you are in continuous violation. The technical requirement is not aspirational — it requires engineering work to implement per-purpose data pipelines that can be switched off without disrupting unrelated functionality.

Failing to notify a breach. Section 8(6) requires notification to the Board and affected Data Principals upon becoming aware of a breach. Covering up a database leak or delaying notification is specifically penalized under Schedule I Item 4 at up to ₹200 crore. The 2024 amendments to many global data protection laws have made timely breach notification a top enforcement priority — India’s Board is expected to follow the same enforcement pattern.

Ignoring children’s data obligations. Section 9’s prohibition on tracking and targeting children applies regardless of whether your service is designed for minors. If a minor registers and you process their data with behavioral targeting, you are in violation. The penalty under Schedule I for this category is among the highest. Age verification mechanisms and separate parental consent workflows are non-optional for services likely to attract users under 18.

Penalties Reference (Schedule I, Act No. 22 of 2023):

  • Failure to implement adequate security safeguards resulting in a data breach: up to ₹250 crore
  • Failure to notify the Data Protection Board of a breach: up to ₹200 crore
  • Failure to comply with additional obligations applicable to Significant Data Fiduciaries: up to ₹150 crore
  • Breach of obligations regarding children’s data (Section 9): up to ₹200 crore
  • Failure to comply with directions of the Data Protection Board: up to ₹50 crore

Getting Started

Your first compliance step is a data discovery audit. You cannot protect what you cannot see. Catalog every system that processes Indian users’ personal data — applications, databases, analytics platforms, marketing tools, and CRM systems. For each system, record what data is held, for what purpose, and whether consent was properly obtained.

Audit your consent flows next. Run through your sign-up and onboarding flows and map every data field collected to a stated purpose in the privacy notice. Identify any data collected without explicit consent or collected for one purpose but used for another. These are your highest-priority remediations.

Implement security safeguards aligned with the DPDP Rules 2025 technical standards: AES-256 encryption at rest for all databases containing personal data, TLS 1.2+ in transit across all endpoints, and MFA for all staff access to personal data systems. Document these controls — the Board may request evidence of safeguards in any enforcement proceeding.

Establish a breach response procedure with clear ownership, a notification timeline, and templates for both Board notification and Data Principal communication in required languages.

To understand the technical security controls that underpin DPDP compliance, read what is data security: definition, types, and risks. For the cross-regulatory comparison between Indian and European law, see data security vs data privacy: key differences.

FAQ

Common questions — answered in plain English.

What is the DPDP Act in India?
The Digital Personal Data Protection (DPDP) Act 2023 is India's comprehensive privacy law governing how businesses collect and process digital personal information. It establishes rights for individuals (Data Principals) and strict obligations for organizations (Data Fiduciaries) handling their data, with penalties up to ₹250 crore per violation under Schedule I.
Who does the DPDP Act apply to?
The DPDP Act applies to any organization processing digital personal data within India under Section 3(b). It also applies extraterritorially to companies outside India if they process data in connection with offering goods or services to Data Principals located in India — the same territorial reach model as GDPR.
What is the penalty for violating the DPDP Act?
Penalties are set out in Schedule I of the Act. The highest tier — failure to take reasonable security safeguards resulting in a personal data breach — carries a penalty of up to ₹250 crore (approximately USD 30 million). Failing to notify the Data Protection Board of a breach carries up to ₹200 crore. Multiple violations are aggregated per Schedule I.
How is the DPDP Act different from GDPR?
The DPDP Act is narrower in scope than GDPR: it covers only digital personal data (not paper records), does not recognize 'sensitive personal data' as a distinct category requiring stricter rules, lacks 'legitimate interest' as a lawful basis for processing, and relies almost entirely on explicit consent. GDPR's penalty ceiling (4% of global turnover) is higher for large multinationals, but DPDP's fixed ₹250 crore ceiling is severe for India-centric companies.
What are the rights of individuals under the DPDP Act?
Section 11 grants the right to access information about personal data processed. Section 12 provides the right to correction and erasure. Section 13 gives the right to grievance redressal directly with the Data Fiduciary. Section 14 provides the right to nominate a representative to exercise rights in case of death or incapacity. All rights must be exercisable through a contact mechanism the Data Fiduciary must maintain.
When will the DPDP Act be fully enforced?
The Act received Presidential assent on 11 August 2023 and was published in the Official Gazette under Act No. 22 of 2023. The DPDP Rules 2025 were notified in early 2025, starting a transition period. Full compliance enforcement — including the Data Protection Board adjudication machinery — is expected to be operational by 2026–2027 per MeitY's implementation timeline.

References

  1. [1]
    The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023)Ministry of Electronics and Information Technology (MeitY), 2023
  2. [2]
    Digital Personal Data Protection Rules, 2025Ministry of Electronics and Information Technology (MeitY), 2025
  3. [3]
  4. [4]
  5. [5]