The DPDP Act, in plain English
A practical guide to the Digital Personal Data Protection Act, 2023 for business owners, compliance teams and professionals. Always read alongside the official text of the Act and the DPDP Rules.
Reviewed: 14 July 2026
Phased enforcement timeline
Official sources: Act commencement notification and Digital Personal Data Protection Rules, 2025.
Who's who under the Act
- Data Principal — the individual the personal data is about. For a child, it includes their parent or lawful guardian.
- Data Fiduciary — any person or organisation that alone or with others determines the purpose and means of processing personal data. This is where most obligations sit.
- Data Processor — someone who processes personal data on behalf of a Data Fiduciary (e.g. your payroll vendor, cloud CRM). The fiduciary remains responsible for their compliance.
- Significant Data Fiduciary (SDF) — a fiduciary (or class of fiduciaries) notified by the Central Government based on factors like volume and sensitivity of data, with additional obligations.
- Consent Manager — a Board-registered platform through which individuals can give, manage, review and withdraw consent.
- Data Protection Board of India — the adjudicating body that inquires into breaches and imposes penalties.
Where the Act applies
The Act applies to digital personal data — personal data collected digitally, or collected offline and then digitised. It covers processing within India, and processing outside India if it is connected with offering goods or services to individuals in India.
It does not apply to personal data processed by an individual for personal or domestic purposes, or to data made publicly available by the data principal themselves or under a legal obligation.
The core rule: consent or "legitimate uses"
Personal data may be processed only for a lawful purpose, and only with the individual's consent or for certain legitimate uses defined in the Act (such as voluntary provision of data for a specified purpose, employment purposes, medical emergencies, or compliance with law).
What valid consent looks like
- Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — pre-ticked boxes and bundled consent don't qualify.
- Limited to the personal data necessary for the specified purpose.
- Preceded by a notice describing the personal data sought, the purpose, how to exercise rights, and how to complain to the Board — available in English or any of the 22 scheduled languages.
- Withdrawable with ease comparable to how it was given; on withdrawal, processing must stop and data must be erased unless retention is legally required.
Data Fiduciary obligations
- Ensure completeness, accuracy and consistency of data used to make decisions affecting the individual or shared with another fiduciary.
- Implement reasonable security safeguards to prevent personal data breaches — including for processing done by your processors.
- Notify every personal data breach to the Data Protection Board and to each affected data principal, in the form and manner prescribed by the Rules.
- Erase personal data when consent is withdrawn or as soon as the specified purpose is no longer being served, whichever is earlier (unless retention is required by law) — and ensure your processors erase it too.
- Publish contact details of a grievance officer / DPO and operate an effective grievance redressal mechanism.
Children's data
Before processing the personal data of a child (under 18) or a person with disability who has a lawful guardian, a fiduciary must obtain verifiable parental/guardian consent. Processing that is likely to cause detrimental effect on a child's well-being, and tracking, behavioural monitoring or targeted advertising directed at children, are prohibited (subject to exemptions prescribed for certain classes of fiduciaries and purposes).
Significant Data Fiduciaries
If notified as an SDF, an organisation must additionally appoint a Data Protection Officer based in India who reports to the board, appoint an independent data auditor, and conduct periodic Data Protection Impact Assessments and audits.
Your customers' rights (Data Principal rights)
- Access — a summary of their personal data being processed, the processing activities, and the identities of other fiduciaries/processors it was shared with.
- Correction and erasure — correction of inaccurate data, completion, updating, and erasure of data no longer needed for the specified purpose.
- Grievance redressal — a readily available means of grievance redressal, which must be used before escalating to the Board.
- Nomination — the right to nominate another individual to exercise these rights in case of death or incapacity.
Data principals also have duties — such as not impersonating others or filing false complaints — with a modest penalty for breach.
Penalties
The Data Protection Board can impose monetary penalties per instance of breach, after inquiry, based on the Schedule to the Act:
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failure to notify the Board / affected data principals of a personal data breach | ₹200 crore |
| Breach of obligations relating to children's data | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of any other provision of the Act or Rules | ₹50 crore |
| Breach of duties by a data principal | ₹10,000 |
A starting compliance checklist
- Map your personal data: what you collect, where it lives, who it's shared with, and why.
- Identify your lawful basis for each processing activity — consent or a legitimate use.
- Rewrite privacy notices to be itemised, purpose-specific and available in required languages.
- Build consent capture, records, and easy withdrawal into every collection point.
- Set retention periods per purpose and implement evidenced erasure when they expire.
- Review vendor/processor contracts for DPDP-aligned obligations.
- Implement reasonable security safeguards and document them.
- Prepare a breach response plan with Board and data-principal notification templates.
- Stand up processes for access, correction and erasure requests with timelines.
- Publish grievance officer contact details and train your team.
Frequently asked questions
We're a small business. Does the DPDP Act really apply to us?
Is there a difference between the DPDP Act and GDPR?
When do we actually have to comply?
What counts as a "personal data breach"?
Do we need a Data Protection Officer?
Can we keep data "just in case" after the purpose is over?
Does the Act apply to employee and recruitment records?
Are WhatsApp and ordinary business email records covered?
Do backups have to follow erasure requirements?
Is GDPR compliance enough?
What evidence should management retain?
When should legal or cybersecurity specialists be involved?
Want this checklist done for you?
Our gap assessment turns this page into a scored report and remediation plan specific to your organisation.
Get in touch