DPDP Act Explained: India's Data Protection Law
Understand the DPDP Act, India's landmark data protection law. Learn compliance obligations, exact legal citations, penalties up to ₹250 crore, and next steps.
Introduction
On 11 August 2023, India enacted Act No. 22 of 2023 — the Digital Personal Data Protection Act. For the first time, India has a dedicated law governing how organizations must handle citizens’ digital personal information, with financial penalties reaching ₹250 crore (approximately USD 30 million) for a single category of violation. That is not a theoretical risk. India has the world’s second-largest internet user base, processing personal data at a scale that now has explicit legal obligations attached to it.
The DPDP Act is not a bureaucratic checkbox exercise. Organizations that ignore it face penalties adjudicated by the Data Protection Board of India — a statutory body with the power to impose fines immediately upon determining a violation. Unlike GDPR’s graduated enforcement history, the DPDP Act’s Board is empowered to act swiftly. The Rules notified in 2025 set timelines and technical requirements that businesses must meet before the Board becomes fully operational.
This article dissects the Act section by section, maps the exact compliance obligations to technical and operational controls, and gives you a structured checklist your legal and engineering teams can work from together.
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) governs the processing of digital personal data in India. It establishes a rights-based framework with two primary parties:
- Data Principal (Section 2(j)): The individual whose personal data is being processed. For a child, the parent or legal guardian acts as the Data Principal.
- Data Fiduciary (Section 2(i)): Any person who alone or in conjunction with others determines the purpose and means of processing personal data. Equivalent to GDPR’s “data controller.”
- Data Processor (Section 2(k)): Any person who processes personal data on behalf of a Data Fiduciary. Must operate under a written contract with the Fiduciary.
Scope (Section 3): The Act applies to processing of digital personal data within India, and to processing outside India if it is in connection with offering goods or services to Data Principals in India. Paper records are explicitly excluded from scope.
Significant Data Fiduciaries (Section 10): The Central Government may designate certain Data Fiduciaries as “Significant” based on volume, sensitivity, national security risk, or systemic impact. Significant Data Fiduciaries face additional obligations including mandatory Data Protection Impact Assessments and periodic audits.
How the DPDP Act Works
The Act establishes a lifecycle of obligations from data collection through deletion.
1. Notice (Section 5): Before or at the time of seeking consent, a Data Fiduciary must provide a notice in English or any language listed in the Eighth Schedule to the Constitution. The notice must clearly state what personal data is being collected, the purpose of processing, and how the Data Principal can exercise their rights. Pre-ticked boxes and bundled consent are prohibited.
2. Consent (Section 6): Processing must be based on free, specific, informed, unconditional, and unambiguous consent — given through a clear affirmative action. Consent must be granular: separate consent for each distinct purpose. The Data Principal may withdraw consent at any time. Upon withdrawal, the Data Fiduciary must cease processing and delete the data unless retention is required by law.
3. Purpose Limitation (Section 6(4)): Data collected for one purpose cannot be processed for a different purpose without fresh consent. A delivery address collected for shipping cannot be used for marketing without separate consent.
4. Data Minimisation (Section 6(4)): Only personal data necessary for the stated purpose may be collected. Data Fiduciaries cannot collect data “just in case.”
5. Security Safeguards (Section 8(5)): Data Fiduciaries must implement “reasonable security safeguards to prevent personal data breach.” The DPDP Rules 2025 specify technical standards including encryption of personal data at rest and in transit.
6. Breach Notification (Section 8(6)): Upon becoming aware of a personal data breach, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal. The notification must be made in the prescribed form and within the time specified by the Board.
7. Data Retention (Section 8(7)): Personal data must be erased once the purpose for which it was collected is served and retention is no longer necessary for legal purposes. The Rules specify retention periods for different categories.
8. Children’s Data (Section 9): Processing of personal data of children (under 18) requires verifiable parental consent. Tracking, behavioral monitoring, and targeted advertising to children are prohibited without exception.
DPDP Act Compliance Checklist
Use this checklist to structure your compliance program. Each item cites the relevant section of Act No. 22 of 2023 or the DPDP Rules 2025.
Consent and Notice Infrastructure (Sections 5–6)
- Consent management platform implemented — capable of recording granular, purpose-specific consent with timestamp and version
- Privacy notice available in English and at least one language from the Eighth Schedule (Hindi minimum for India-facing products)
- No pre-ticked boxes or bundled consent in sign-up, checkout, or onboarding flows
- Consent withdrawal mechanism — user can withdraw any individual consent, triggering automated halt of processing for that purpose
- Audit trail: every consent collected stored with: timestamp, version of notice shown, IP address, Data Principal ID
- Children’s data: age verification mechanism in place before collecting any data from users who may be under 18 (Section 9)
- Parental consent workflow for users confirmed under 18 — verifiable, documented, auditable
Purpose Limitation and Data Minimisation (Section 6(4))
- Data map maintained: every field collected, the purpose stated to the user, and the system it lands in
- No secondary use without fresh consent: marketing, analytics, third-party sharing — each requires separate consent
- Data minimisation review: confirm each collected field is necessary for the stated purpose; remove fields that are not
Security Safeguards (Section 8(5) and DPDP Rules 2025)
- Personal data encrypted at rest with AES-256 (or equivalent per DPDP Rules technical standards)
- Personal data encrypted in transit with TLS 1.2 minimum across all endpoints, internal and external
- Access controls: least-privilege access to personal data by employees and systems
- Multi-factor authentication enforced for all systems with access to personal data
- Vulnerability assessment and penetration testing schedule documented and executed at least annually
- Data processor contracts: written agreement with every processor (Section 8(2)) specifying security obligations
- Employee training: documented data protection training for all staff with access to personal data
Breach Notification (Section 8(6) and DPDP Rules 2025)
- Breach detection capability: SIEM, anomaly detection, or equivalent — tested annually
- Breach response procedure: documented runbook for who assesses, who notifies, and what timeline
- Data Protection Board notification: form and timeline for Board notification (prescribed by Rules)
- Data Principal notification: template for notifying affected individuals, translated into required languages
- Breach log: all incidents and near-misses documented (even if below notification threshold)
Data Retention and Erasure (Section 8(7))
- Retention schedule documented for each category of personal data
- Automated or procedural deletion triggered when retention period expires
- Right to erasure workflow: Data Principal erasure request received, acknowledged, executed, and confirmed within required timeframe
- Deletion confirmed across all systems including backups, analytics, and third-party processors
Data Principal Rights (Sections 11–14)
- Access request workflow: Data Principal can request what data is held — response mechanism documented
- Correction request workflow: Data Principal can request correction of inaccurate data
- Grievance redressal mechanism: contact person designated, response SLA defined (Section 13)
- Nomination mechanism: Data Principals can nominate a representative (Section 14)
Significant Data Fiduciary (Section 10 — if applicable)
- Check whether designation thresholds apply (volume, sensitivity, systemic risk)
- If designated: Data Protection Impact Assessment conducted and documented
- If designated: periodic audit by independent auditor engaged
- If designated: Data Protection Officer appointed (cannot be an outsourced role)
DPDP Act vs GDPR
| Feature | DPDP Act (India, 2023) | GDPR (European Union, 2016) |
|---|---|---|
| Legal basis | Consent or specific legitimate uses | Six lawful bases including legitimate interest |
| Data categories | All personal data treated uniformly | Stricter rules for “special categories” |
| Paper records | Excluded from scope (Section 3) | Included in scope |
| Cross-border transfer | Permitted unless restricted by government notification | Requires adequacy decision or safeguards |
| Highest penalty | ₹250 crore (~USD 30M) per Schedule I | €20M or 4% of global annual turnover |
| Enforcement body | Data Protection Board of India | National supervisory authorities (54 DPAs) |
| Children’s age threshold | Under 18 (Section 9) | Under 16 (Member State discretion to lower to 13) |
| Legitimate interest basis | Not recognized | Recognized with balancing test |
The most operationally significant difference is the absence of “legitimate interest” as a lawful basis. GDPR allows organizations to process personal data without consent if they have a legitimate interest that is not overridden by the Data Principal’s rights — a basis widely used for fraud prevention, security monitoring, and analytics. Under the DPDP Act, all such uses require either consent or must fall within the narrow “certain legitimate uses” carved out in Section 7 (employment, medical emergency, public health).
Real-World Use Cases
E-commerce platforms: A shopping platform collecting Indian users’ names, addresses, and payment data must obtain separate consent for: (1) order fulfillment, (2) product recommendations, and (3) marketing emails. One bundled consent checkbox at checkout violates Section 6. The platform must implement a consent management system that records granular consent per purpose and allows per-purpose withdrawal.
Fintech companies: A loan application app processing income data, PAN numbers, and bank statements must provide its consent notice in the user’s preferred language (Section 5). If a user in Tamil Nadu prefers Tamil, the notice must be available in Tamil. The technical architecture must support multi-language notice delivery and confirm the language in which consent was obtained.
Multinational SaaS providers: A US-headquartered SaaS company with Indian customers falls under Section 3(b)‘s extraterritorial scope. The company must appoint a Data Protection Officer (if designated as a Significant Data Fiduciary), sign Data Processor Agreements with its own sub-processors for Indian data, and maintain breach notification capability aligned with the Board’s prescribed timelines.
Common Mistakes and Penalties
Treating consent as a one-time event. Section 6(3) explicitly provides the right to withdraw consent at any time. If your system cannot process a consent withdrawal and halt the associated data processing within a reasonable timeframe, you are in continuous violation. The technical requirement is not aspirational — it requires engineering work to implement per-purpose data pipelines that can be switched off without disrupting unrelated functionality.
Failing to notify a breach. Section 8(6) requires notification to the Board and affected Data Principals upon becoming aware of a breach. Covering up a database leak or delaying notification is specifically penalized under Schedule I Item 4 at up to ₹200 crore. The 2024 amendments to many global data protection laws have made timely breach notification a top enforcement priority — India’s Board is expected to follow the same enforcement pattern.
Ignoring children’s data obligations. Section 9’s prohibition on tracking and targeting children applies regardless of whether your service is designed for minors. If a minor registers and you process their data with behavioral targeting, you are in violation. The penalty under Schedule I for this category is among the highest. Age verification mechanisms and separate parental consent workflows are non-optional for services likely to attract users under 18.
Penalties Reference (Schedule I, Act No. 22 of 2023):
- Failure to implement adequate security safeguards resulting in a data breach: up to ₹250 crore
- Failure to notify the Data Protection Board of a breach: up to ₹200 crore
- Failure to comply with additional obligations applicable to Significant Data Fiduciaries: up to ₹150 crore
- Breach of obligations regarding children’s data (Section 9): up to ₹200 crore
- Failure to comply with directions of the Data Protection Board: up to ₹50 crore
Getting Started
Your first compliance step is a data discovery audit. You cannot protect what you cannot see. Catalog every system that processes Indian users’ personal data — applications, databases, analytics platforms, marketing tools, and CRM systems. For each system, record what data is held, for what purpose, and whether consent was properly obtained.
Audit your consent flows next. Run through your sign-up and onboarding flows and map every data field collected to a stated purpose in the privacy notice. Identify any data collected without explicit consent or collected for one purpose but used for another. These are your highest-priority remediations.
Implement security safeguards aligned with the DPDP Rules 2025 technical standards: AES-256 encryption at rest for all databases containing personal data, TLS 1.2+ in transit across all endpoints, and MFA for all staff access to personal data systems. Document these controls — the Board may request evidence of safeguards in any enforcement proceeding.
Establish a breach response procedure with clear ownership, a notification timeline, and templates for both Board notification and Data Principal communication in required languages.
To understand the technical security controls that underpin DPDP compliance, read what is data security: definition, types, and risks. For the cross-regulatory comparison between Indian and European law, see data security vs data privacy: key differences.
FAQ
Common questions — answered in plain English.
What is the DPDP Act in India?
Who does the DPDP Act apply to?
What is the penalty for violating the DPDP Act?
How is the DPDP Act different from GDPR?
What are the rights of individuals under the DPDP Act?
When will the DPDP Act be fully enforced?
References
- [1]The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023)Ministry of Electronics and Information Technology (MeitY), 2023
- [2]Digital Personal Data Protection Rules, 2025Ministry of Electronics and Information Technology (MeitY), 2025
- [3]
- [4]
- [5]OWASP Top Ten — A02: Cryptographic FailuresOWASP, 2021