Connect with us

blogs What Is the DPDP Act? Explained Everything About It
dpdp-act

What Is the DPDP Act? Explained Everything About It

Author : NYS Surya Kiran

The Digital Personal Data Protection (DPDP) Act, 2023 is India's comprehensive data privacy law that governs how organizations collect, process, store, and protect the digital personal data of individuals. It applies across industries and establishes the rights of individuals alongside the responsibilities of organizations that handle personal data.

Ask five people in an Indian office what the DPDP Act actually requires and you'll probably get five different answers. Some think it's just about cookie banners. Some think it only applies to tech companies. A few think it's basically GDPR with a different name. None of that is quite right, and the gap between what people assume and what the law actually says is exactly where compliance mistakes happen.

The Digital Personal Data Protection Act, 2023 is India's first comprehensive, cross-sectoral data privacy law. It applies to almost every organization that touches personal data connected to India, government departments, banks, hospitals, SaaS platforms, e-commerce companies, and yes, foreign companies serving Indian users too. This piece walks through what the Act actually says, who it applies to, what it demands, and what happens if you get it wrong.

What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023, commonly shortened to the DPDP Act or DPDPA, is a comprehensive data privacy law enacted by the Parliament of India. It establishes a legal framework for processing digital personal data, built around balancing an individual's right to privacy with an organization's need to process data for lawful, legitimate purposes.

One detail that stands out once you actually read the Act: it uses what's called the SARAL approach, Simple, Accessible, Rational, and Actionable drafting, which means the law leans on plain language and illustrations rather than dense legalese. It's also notable for using "she/her" pronouns universally throughout the text, regardless of the individual's actual gender, which is the first Indian legislation to do that.

The full text of the Act is publicly available on the Ministry of Electronics and Information Technology's official portal, and it's worth actually reading the primary source rather than relying only on secondary summaries, since a lot of nuance sits in the specific illustrations the drafters included.

Why India Needed the DPDP Act

Before this law, India relied on Section 43A of the Information Technology Act, 2000, along with the associated 2011 rules covering sensitive personal data. Both were narrow, dated, and never designed for a digital economy of India's current scale. Sector regulators like the RBI had their own patchwork rules for specific industries, but there was no single, unified framework governing personal data across the board.

The push for something more comprehensive really accelerated after 2017, when the Supreme Court's landmark Puttaswamy judgment recognized privacy as a fundamental right under the Constitution. That ruling more or less forced the government's hand. A dedicated privacy law wasn't optional anymore, it was a constitutional expectation waiting to be legislated.

Timeline: From the Puttaswamy Judgment to the 2025 Rules

The road here was long, and it's worth knowing the timeline because it explains why compliance deadlines are staggered the way they are.

The Justice B.N. Srikrishna Committee published its foundational report in 2018, which fed into the Personal Data Protection Bill, 2019. That bill went through parliamentary review, got withdrawn, and was replaced by a substantially revised draft in November 2022. The current Act, built largely on that 2022 draft, received Presidential assent on August 11, 2023, making India the 19th G20 nation with a comprehensive data protection law.

But the Act itself was designed as a framework law, meaning it needed delegated legislation, rules, to actually operate day to day. That gap sat open for over two years until the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025, following public consultations that drew nearly 7,000 stakeholder submissions. You can read the official notification directly through the Press Information Bureau's release on the draft Rules process.

Implementation is phased across roughly 18 months. The Data Protection Board's governance provisions took effect immediately in November 2025. Consent Manager provisions activate in November 2026. The bulk of substantive obligations, consent mechanics, breach notification, Data Principal rights, become fully enforceable by May 13, 2027, which is also when the Act formally supersedes the old IT Act rules it's replacing.

Key Players: Data Fiduciary, Data Principal, and Data Processor

Almost everything in the Act hinges on three roles, and getting them straight makes the rest of the law much easier to follow.

A Data Fiduciary is any person, company, or government entity that determines the purpose and means of processing personal data. If your organization decides what data to collect and why, you're a Data Fiduciary, full stop. A Data Principal is the individual whose personal data is being processed, essentially the person the whole law exists to protect. A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary, typically under a contract, think of a cloud vendor or outsourced support team handling data for someone else's business.

The Act applies to digital personal data processed within India, and also to processing outside India when it involves offering goods or services to individuals inside the country. That extraterritorial reach is why foreign SaaS companies selling into India can't treat this as someone else's problem.

Data Principal Rights Under the DPDP Act

The rights side of the Act is where individuals actually gain leverage over how their data gets used. A Data Principal can request a summary of what personal data a Fiduciary holds and how it's being processed, along with the identities of other Fiduciaries or Processors that data has been shared with. There's a right to correction and erasure, meaning individuals can ask for inaccurate data to be fixed or for data to be deleted once its purpose has been served. There's a grievance redressal right, requiring Fiduciaries to provide accessible complaint mechanisms before an individual can escalate to the Data Protection Board.

One provision that doesn't show up in most comparable global laws is the right to nominate. A Data Principal can designate another individual to exercise their data rights on their behalf in the event of death or incapacity, which is a genuinely distinctive addition compared to something like GDPR.

Interestingly, the Act also imposes duties on Data Principals themselves, something GDPR doesn't really do. Users are legally barred from filing false or frivolous complaints, impersonating someone else, or suppressing material information when providing their data, and violating these duties can trigger a penalty of up to ₹10,000 against the individual.

Obligations of Data Fiduciaries

This is the section that actually keeps compliance teams up at night. Every Data Fiduciary must provide a clear, itemized notice before or at the point of collecting personal data, explaining exactly what's being collected and why, in plain language available across all 22 scheduled languages under the Eighth Schedule of the Constitution.

Consent has to be free, specific, informed, and unambiguous, and it must be just as easy to withdraw as it was to give. Data must only be used for the purpose it was originally collected for, and once that purpose is fulfilled, the Fiduciary is required to erase it, subject to specific retention schedules that vary by sector. Fiduciaries must implement what the Act calls "reasonable security safeguards" to prevent breaches, and if a breach happens anyway, they're required to notify the Data Protection Board and every affected individual, generally within a tight window rather than at their own leisure.

Where this framework touches messaging and internal communication tools specifically is worth calling out, since it's easy to assume "data protection" only means customer-facing databases. It doesn't. A collaboration platform carrying employee records, internal case files, or citizen correspondence is processing personal data too, and needs the same underlying safeguards, which is part of why examining how encryption keys actually protect business communication is relevant even for teams that think of themselves as "just using a chat app."

Special Provisions for Children and Persons with Disabilities

The Act treats anyone under 18 as a child, and the obligations here are notably strict. Before processing a child's data, a Fiduciary must obtain verifiable parental or guardian consent, with the 2025 Rules specifying approved verification methods including integration with DigiLocker to confirm the parent-child relationship.

Beyond consent, Fiduciaries are flatly prohibited from tracking, monitoring, or behaviorally profiling children, and from serving them targeted advertising. The Rules do carve out some exemptions from parental consent, healthcare providers handling emergency treatment, schools managing routine student administration, and government bodies delivering welfare services, but outside those narrow lanes, the bar is high and deliberately so.

Cross-Border Data Transfers Under the Act

This is one area where the DPDP Act genuinely diverges from GDPR's model. GDPR uses a "whitelist" approach, data can only move to countries the EU deems adequately protective. The DPDP Act flips that. It uses a blocklist model under Section 16, meaning personal data can generally be transferred outside India to any jurisdiction unless the Central Government has specifically restricted that country by notification.

That's a meaningfully lighter-touch approach on paper, but there's a wrinkle worth knowing. Significant Data Fiduciaries, organizations the government designates based on data volume, sensitivity, and risk, face additional restrictions and may be barred from transferring certain categories of personal data and traffic data outside India altogether, based on recommendations from a government-appointed committee.

The Data Protection Board of India

Enforcement runs through a single dedicated body: the Data Protection Board of India, established under Chapter V of the Act as an independent, digital-first adjudicatory authority. It's designed to operate as a fully paperless office, which is itself a first among Indian regulatory institutions.

The Board can receive and investigate breach complaints, issue binding directions to Fiduciaries, and impose monetary penalties. It's structured to function more like an adjudicator resolving disputes than a proactive watchdog patrolling the market, so most of its work begins reactively, once a complaint or breach notification lands on its desk. There's no cure period built into the process either. Organizations don't get a grace window to quietly fix a violation before penalties kick in, though the Board is required to give the accused party a hearing before any penalty is finalized. Decisions can be appealed to the Telecom Disputes Settlement and Appellate Tribunal within 60 days, and beyond that, to the Supreme Court.

Penalties for Non-Compliance

The numbers here are large enough to get a CFO's attention immediately. The single highest penalty, up to ₹250 crore, applies specifically to a Fiduciary's failure to implement reasonable security safeguards where that failure results in an actual breach. Failing to notify the Board or affected individuals of a breach can independently draw penalties up to ₹200 crore, and violations of the Act's special obligations toward children's data carry the same ceiling. Failures specific to Significant Data Fiduciary obligations top out around ₹150 crore, and general violations not covered elsewhere can still reach ₹50 crore.

When calculating the actual amount within these ceilings, the Board weighs factors like the severity of the breach, how many individuals were affected, the sensitivity of the data involved, and the organization's prior compliance track record. It's not a flat fine, it's a judgment call shaped by how badly things went wrong.

How the DPDP Act Affects Communication and Collaboration Tools

It's tempting to think of the DPDP Act as something that only matters to a legal or compliance department, but the reality touches IT infrastructure decisions directly. Any platform that stores conversations, files, or employee records containing personal data is, functionally, processing personal data under this law, whether that's an HR system, a CRM, or an internal messaging tool.

This is where infrastructure choices start to matter for compliance rather than just performance or cost. Organizations that keep sensitive communication on infrastructure they fully control tend to have a much easier time demonstrating compliance during an audit, since there's no third-party vendor's data-handling practices to verify or explain. The reasoning behind this is laid out well in the overview of on-premise servers and enterprise data control, which covers why regulated sectors increasingly default to self-hosted deployment rather than assuming a cloud vendor's compliance posture matches their own.

As compliance expectations continue to evolve, Data Localisation India enterprise strategies are becoming a key consideration for organizations handling sensitive personal data. Keeping regulated workloads and communication infrastructure within India can simplify governance, support sector-specific regulatory requirements, and strengthen overall data protection practices under the DPDP framework.

The same logic shows up in regulated industries outside India too, which is a useful comparison point. The approach clinics and healthcare providers take toward building a HIPAA-compliant tech stack mirrors a lot of what DPDP-regulated Indian organizations now need to think through, minimum necessary access, audit logging, and platforms that don't leak sensitive data through unapproved shadow tools.

If your organization is specifically navigating government procurement rather than general compliance, it's worth reading the companion piece on data localization requirements under the DPDP Act, which goes deeper into the procurement-specific angle of where data physically sits, separate from the broader obligations covered here.

Steps Organizations Should Take to Prepare

Waiting until May 2027 to start is a mistake, since building compliant systems takes real time. A sensible starting sequence looks like this: map every place personal data enters, moves through, and exits your systems, since you can't protect what you haven't located. Build a consent management mechanism that captures itemized, plain-language notices and makes withdrawal just as easy as opt-in. Establish a breach response protocol with clear internal ownership, since notification timelines under the Rules are tight. Review vendor contracts for any third party that touches personal data on your behalf, since Data Processors extend your compliance exposure rather than removing it. And appoint a Data Protection Officer if your data volume or sensitivity is likely to trigger Significant Data Fiduciary status, since that designation brings a heavier compliance load.

Organizations that treat this as a checkbox exercise tend to build systems that technically comply on day one and quietly drift out of compliance within a year. Privacy-by-design, baking these protections into system architecture rather than bolting them on afterward, holds up much better over time.

Conclusion

The DPDP Act represents India's first serious, comprehensive attempt at data privacy regulation, and it's arriving with real teeth, ₹250 crore penalties aren't symbolic. What makes it distinct from something like GDPR is worth sitting with. It's more permissive on cross-border transfers, it imposes duties on individuals as well as organizations, and its state exemptions under Section 17 remain genuinely contested among privacy advocates, a debate the Carnegie Endowment's policy analysis covers in more depth than most compliance guides bother to.

For organizations processing personal data connected to India, in whatever form that takes, this isn't a distant regulatory concern anymore. The Board is operational, the Rules are notified, and the clock toward full enforcement in May 2027 is already running.

Frequently Asked Questions

Q1. What is the DPDP Act in simple terms?

The DPDP Act is India's comprehensive data privacy law, passed in 2023 and operationalized through the 2025 Rules. It governs how organizations, called Data Fiduciaries, collect, use, and protect the personal data of individuals connected to India. It gives individuals defined rights over their data and imposes financial penalties on organizations that mishandle it or fail to secure it properly.

Q2. Does the DPDP Act apply to foreign companies?

Yes. The Act applies to processing outside India whenever it involves offering goods or services to individuals within India, or profiling individuals located in India. A foreign SaaS company or e-commerce platform serving Indian customers is treated as a Data Fiduciary under the law, regardless of where its servers or headquarters are actually based.

Q3. What's the maximum penalty under the DPDP Act?

The highest single penalty is ₹250 crore, applied when a Data Fiduciary fails to implement reasonable security safeguards and a breach results. Other violations carry separate ceilings, ₹200 crore for breach notification failures or violations involving children's data, ₹150 crore for Significant Data Fiduciary obligations, and up to ₹50 crore for other general violations.

Q4. When does the DPDP Act become fully enforceable?

Implementation is phased. The Data Protection Board became operational in November 2025 when the Rules were notified. Consent Manager provisions activate in November 2026. The core compliance obligations, consent, breach notification, and Data Principal rights, become fully enforceable by May 13, 2027, giving organizations an 18-month runway from notification.

Q5. Who is considered a Data Fiduciary under the Act?

A Data Fiduciary is any individual, company, or government entity that determines the purpose and means of processing personal data. If your organization decides what personal data to collect and why, you're a Data Fiduciary. This covers everything from e-commerce platforms and hospitals to government departments and SaaS providers operating in India.

Recent blogs
To create a Company Messenger
get started
download mobile app
download pc app
close Quick Intro
close
troop messenger demo
Schedule a Free Personalized Demo
Enter
loading
Header
loading