What it is
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive law on the processing of digital personal data. It received Presidential assent on 11 August 2023 and is brought into force in stages by government notification. Implementing rules were later notified, and most substantive obligations are being phased in over a transition period, so the commencement status should be checked.
Who it applies to
The Act applies to the processing of digital personal data within India, whether collected in digital form or collected in non-digital form and later digitised. It also applies outside India where the processing relates to offering goods or services to individuals in India. It does not apply to personal data processed for personal or domestic purposes, or to data made publicly available by the individual or under a legal obligation. The person who decides the purpose and means of processing is the "Data Fiduciary", and the individual is the "Data Principal".
Core principles
Personal data may be processed only for a lawful purpose, with the Data Principal's consent or for one of the "certain legitimate uses" listed in the Act, such as compliance with law, responding to medical emergencies or providing a benefit or service from the State. Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and it must be as easy to withdraw as to give. Requests for consent must come with a notice describing the data, its purpose and how rights can be exercised.
Individual rights
Data Principals have the right to obtain a summary of the personal data processed and the identities of those with whom it has been shared, to request correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise their rights in the event of death or incapacity. The Act also sets out duties for Data Principals, such as not filing false or frivolous complaints and not impersonating another person. The Act contains no stand-alone right to data portability.
Key obligations
Data Fiduciaries must ensure accuracy where data is used for decisions or shared, take reasonable security safeguards, erase data when the purpose is served and consent is withdrawn (unless law requires retention), publish business contact details for questions, and set up a grievance redressal mechanism. They remain responsible for processing carried out by their Data Processors, which must be engaged under a valid contract. Data Principals may manage consent through registered Consent Managers. Children, defined as individuals under 18, require verifiable consent of a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited, subject to exemptions. "Significant Data Fiduciaries," designated by the government based on factors such as volume and sensitivity of data, must appoint a Data Protection Officer based in India, an independent data auditor, and carry out periodic data protection impact assessments.
Data breaches
In the event of a personal data breach, the Data Fiduciary must give intimation to the Data Protection Board of India and to each affected Data Principal, in the form and manner prescribed by the rules. The Act also requires reasonable security safeguards to prevent breaches in the first place.
International transfers
The Act takes a permissive approach: personal data may be transferred outside India except to countries or territories that the Central Government restricts by notification. Any other Indian law that imposes stricter localisation or transfer restrictions, for example in specific regulated sectors, continues to apply.
Enforcement and penalties
Enforcement is led by the Data Protection Board of India, a digital-first body that inquires into breaches, can direct remedial measures and imposes monetary penalties, with appeals to the Telecom Disputes Settlement and Appellate Tribunal. The Schedule sets maximum penalties by type of breach, up to INR 250 crore for failing to take reasonable security safeguards against a breach, INR 200 crore for failing to notify a breach or for breaching children's obligations, and INR 150 crore for breaching the additional obligations of Significant Data Fiduciaries. The Act does not provide for individual compensation claims before the Board.
The official text
The authoritative version is the Act as published in the Gazette of India (Extraordinary, Part II, Section 1) on 11 August 2023, linked here from the eGazette. English is the official language of the Act. Use that text and the current rules, not this summary, for anything that matters.
Below is the source we understand to be the official text (English, official (Gazette of India)). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →