For most of its digital history, India regulated personal data through a patchwork of contract terms and a handful of provisions buried in the Information Technology Act, 2000. The Digital Personal Data Protection Act, 2023 — usually shortened to the DPDP Act — changes that. It is India’s first standalone, comprehensive law for the protection of digital personal data, and it sets out clear duties for the organisations that handle data and clear rights for the people that data belongs to. This guide is the foundation of our DPDP Hub.
This guide is a plain-English orientation to the whole framework: what the Act is, who it applies to, the language it uses, how lawful processing works, the rights individuals gain, what businesses must actually do, and how the recently notified 2025 Rules turn the law into a working compliance regime. By the end you should understand not just the letter of the law but what it means for your organisation in practice — and how to approach dpdp compliance with confidence.
The DPDP Act in one minute
The DPDP Act establishes a consent-based framework for processing the digital personal data of individuals in India. Our primer on DPDP personal data explains exactly what the Act protects — and the narrow set of data it deliberately leaves out.
Two roles anchor the whole law. An organisation that decides why and how personal data is processed is called a data fiduciary, and it carries the bulk of the legal responsibility for protecting that data.
On the other side is the individual. The person whose data is processed is the data principal, and before processing on the basis of consent a fiduciary must give them a clear notice and obtain consent that is free, specific, informed and revocable.
In return, individuals gain enforceable rights — to access their data, to have it corrected or erased, to nominate someone to act for them, and to a grievance-redressal channel. A new regulator, the Data Protection Board of India, investigates complaints and breaches and can impose financial penalties that run as high as ₹250 crore. The law is principles-based and deliberately simpler than many of its global counterparts, but its reach is broad and its penalties are serious.
Why India needed a dedicated data protection law
India is one of the largest digital markets on earth, with hundreds of millions of people transacting, banking, learning and socialising online. That sheer scale is a large part of why DPDP matters — the volume of personal data in play makes strong protection a necessity rather than a nicety.
Until recently, protection was thin. The only meaningful statutory cover came from Section 43A of the IT Act and the 2011 SPDI Rules, and our comparison of DPDP vs IT Act shows just how much narrower that old regime was than the new law.
The road to the DPDP Act was a long one. The fuller DPDP Act background traces the journey from the Puttaswamy privacy judgment through years of draft bills and public consultation to the law that finally passed.
The constitutional turning point came in 2017, when the Supreme Court held in the Puttaswamy judgment that privacy is a fundamental right under the Indian Constitution. That ruling created a clear obligation on the State to protect informational privacy through law, and set in motion years of expert committee work, draft bills and public consultation that eventually produced the DPDP Act.
The result is a law designed for scale and clarity. It tries to balance two goals that are often in tension: the individual’s right to protect their personal data, and the legitimate need of businesses and the State to process that data for lawful purposes. Understanding that balance is the key to reading the Act sensibly.
When the law was passed — and when the Rules arrived
The DPDP Act received presidential assent on 11 August 2023. But like much Indian legislation, the Act is a framework: it states principles and obligations, while the operational detail — timelines, formats, thresholds and procedures — is left to subordinate rules. Until those rules were notified, the Act could not be meaningfully enforced.
That changed on 13 November 2025, when the Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 — the DPDP Rules 2025. The Rules flesh out how notices must be worded, how consent managers register and operate, what “reasonable security safeguards” look like in practice, how breaches must be reported, and how children’s data and significant data fiduciaries are treated.
Crucially, the Rules introduced a phased transition of roughly 18 months, mapped in our DPDP timeline. Some provisions — such as those establishing the Data Protection Board — apply almost immediately, while the substantive operational obligations have a compliance deadline around May 2027. In other words, organisations have a finite, fixed window to get ready, and that window is already running.
Who the DPDP Act applies to
The Act has both a territorial and a material scope. Territorially, it applies to the processing of digital personal data within India. It also applies to processing that happens outside India if that processing is connected to offering goods or services to people located in India. A company headquartered abroad with Indian customers can therefore fall squarely within scope, even without any physical presence in the country.
Materially, the Act covers personal data in digital form — data collected digitally, or collected on paper and later digitised. Purely personal or domestic processing by an individual is excluded, as is data that a person has voluntarily made publicly available, or that someone is required by law to make public.
The Act does not distinguish between large enterprises and small businesses in its core obligations: if you process the digital personal data of individuals in India, the duties around notice, consent, security and rights apply to you. Our guide on who does DPDP apply to works through the territorial and material scope tests in detail.
Smaller and younger companies do get some relief. Our guide to DPDP for startups explains the lighter treatment available to certain early-stage fiduciaries, and how to make the most of it without cutting corners.
That relief is defined by formal carve-outs. The notified DPDP exemptions set out which classes of fiduciary and which kinds of processing fall outside parts of the Act — but the baseline expectation for everyone else remains broad.
The key players: principals, fiduciaries and processors
Three roles sit at the centre of the Act. The data principal is the individual to whom the personal data relates — and, in the case of a child, includes the parent or lawful guardian. The full set of data principal rights is significant enough that we cover it in its own guide.
The counterpart is the data fiduciary: any person or organisation that, alone or with others, determines the purpose and means of processing personal data. Because it carries the bulk of the legal responsibility, it is worth reading the full list of data fiduciary obligations before you build anything.
A data processor under DPDP processes personal data on behalf of a fiduciary — a cloud host, a payroll vendor or an analytics provider, for example. Processors act only under a valid contract with the fiduciary, and the fiduciary remains accountable to the data principal for what its processors do.
The Act also creates a special class called the significant data fiduciary (SDF). The government can designate an organisation as an SDF based on the volume and sensitivity of the data it handles, the risk to data principals, and factors such as impact on sovereignty or public order.
SDFs carry heavier obligations than ordinary fiduciaries. Chief among them is appointing a DPDP data protection officer based in India, who serves as the accountable point of contact for compliance and for the Data Protection Board.
They must also submit to deeper scrutiny. SDFs are required to commission DPDP DPIA and audit work — periodic impact assessments and independent audits that demonstrate their processing genuinely meets the Act’s standards.
One further role rounds out the cast. A consent manager under DPDP is a registered intermediary through which individuals can give, manage and withdraw consent across multiple fiduciaries from a single interface.
How lawful processing works: notice, consent and legitimate uses
Under the DPDP Act, the default lawful basis for processing personal data is DPDP consent. That consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the data necessary for the stated purpose. Withdrawing it must be as easy as giving it, and the request must be available in English or any language listed in the Eighth Schedule of the Constitution.
Getting the mechanics of capture right is where many teams struggle. Our DPDP consent form guide shows what compliant consent capture looks like in practice — itemised, in plain language, and easy to revoke.
Consent cannot be obtained in a vacuum. It must be preceded by a DPDP privacy notice that tells the person, in clear and plain language, what personal data will be collected, the purpose of processing, how they can exercise their rights, and how they can complain to the Data Protection Board. The 2025 Rules require this notice to be itemised and standalone, so people can actually understand what they are agreeing to.
The Act recognises that consent is not always practical, so it permits processing for certain DPDP legitimate uses without fresh consent. These include situations where a person voluntarily provides data for a service they have requested, processing for specified State functions and subsidies, compliance with legal obligations, responding to medical emergencies, and ensuring safety during disasters. These are narrow, defined gateways — not a general-purpose escape from consent.
The rights the law gives individuals
The DPDP Act gives data principals a compact but meaningful set of rights. The right to access lets a person obtain a summary of the personal data being processed and the identities of other fiduciaries and processors with whom it has been shared. The right to correction and erasure lets them fix inaccurate data and have data deleted once the purpose for which it was collected is over.
There is also a right to DPDP grievance redressal: every fiduciary must provide an accessible mechanism for complaints and respond within a defined period, and only after exhausting that channel can a person escalate to the Data Protection Board. A distinctive feature of the Indian law is the right to nominate — a data principal can nominate another individual to exercise their rights in the event of death or incapacity.
Younger users get extra protection. The Act treats DPDP children's data with particular care, requiring verifiable parental consent and prohibiting tracking, behavioural monitoring, or targeted advertising directed at children.
Rights come with responsibilities. The Act also places duties on data principals: not to file false or frivolous complaints, not to impersonate others, and to provide authentic information when exercising rights. This two-way framing is one of the ways the DPDP Act differs in tone from purely individual-centric regimes.
What businesses must actually do
Translated into operational terms, the Act asks every data fiduciary to do a recognisable set of things, summarised in our DPDP compliance requirements guide. You must map the personal data you hold and tie each processing activity to a lawful basis. You must rewrite notices and consent flows so they are clear, itemised and easy to withdraw, and build a process to honour access, correction, erasure and grievance requests within the timelines the Rules set.
On the security side, the Act requires DPDP security safeguards to prevent breaches. The 2025 Rules give this teeth, pointing to measures such as encryption or masking of personal data, strong access controls and multi-factor authentication, and the retention of logs for at least a year to support investigation.
You cannot keep data forever, either. DPDP data retention rules require you to delete personal data once the purpose it was collected for has been served, which means building deletion into your systems rather than treating it as an afterthought.
Your processors must be contractually bound too. Engaging any processor requires a proper DPDP data processing agreement that passes your obligations down the chain and makes clear who is accountable for what.
Where data physically lives is also in scope. The evolving rules on DPDP data localization affect which categories of data may need to stay within India, a question that matters a great deal for cloud architecture.
And moving data abroad has its own regime. DPDP cross-border data transfer follows a negative-list model — data may flow to any country except those the government specifically restricts — which you must track as that list evolves.
If a breach does occur, DPDP data breach notification to both the Data Protection Board and affected individuals is mandatory. The Rules set a two-tier, time-bound duty: an immediate notification describing the nature, scope and likely impact, followed by a fuller report within 72 hours covering the circumstances, the remedial measures taken and the findings on cause.
Free resource
The Ultimate Guide to the DPDP Act
A practical, plain-English handbook to the DPDP Act & 2025 Rules — scope, roles, consent, safeguards and a readiness path.
Penalties and the Data Protection Board
Enforcement under the DPDP Act runs through the Data Protection Board of India, a digital-first regulator that receives complaints, investigates breaches and imposes monetary penalties. The Board is designed to function largely online, and its decisions can be appealed to the Telecom Disputes Settlement and Appellate Tribunal.
The penalty schedule is tiered by the nature of the failure rather than the size of the company. The highest exposure — up to ₹250 crore — attaches to failing to take reasonable security safeguards that results in a personal data breach. Failing to notify a breach, or failing to meet the additional obligations around children’s data, can attract penalties up to ₹200 crore. Other breaches of the Act’s obligations carry their own ceilings, and the Board weighs factors such as the gravity and duration of the breach, whether it was repetitive, and the steps taken to mitigate it.
The practical takeaway is that DPDP penalties are large enough to matter to even the biggest organisations, and they are tied closely to security and breach-response failures rather than minor paperwork slips.
It helps to understand how those penalties are actually applied. Knowing how DPDP enforcement works — the Board’s digital-first process and the factors it weighs — makes the unglamorous work of safeguards, logging and incident readiness the single highest-leverage area of compliance.
DPDP vs GDPR — a quick orientation
Anyone who has worked with Europe’s General Data Protection Regulation will find the DPDP Act familiar in spirit: both are consent-centric, both give individuals strong rights, and both impose accountability on the organisations that control data. But there are real differences that matter when you design a single global programme.
The DPDP Act is deliberately leaner. It does not create a separate category of “sensitive personal data” with extra rules, where the GDPR does. It uses a negative-list model for cross-border transfers — data may flow to any country except those the government specifically restricts — rather than the GDPR’s adequacy-and-safeguards approach. It centralises enforcement in a single Data Protection Board rather than a network of supervisory authorities, and it lacks some GDPR rights such as data portability and a general right to object.
For multinationals, the good news is that a mature GDPR programme provides a strong foundation. Our side-by-side DPDP vs GDPR comparison maps exactly where the two align and where India’s law diverges, so you can adapt rather than rebuild.
An existing security certification helps just as much. If you already run an ISMS, DPDP and ISO 27001 shows how much of that control work carries straight over — leaving mainly notice and consent language, the India-specific roles, and breach-reporting timelines to adjust.
What to do next — prepare before the deadline
Because the 2025 Rules set a fixed, roughly 18-month runway, the smartest posture is to treat DPDP readiness as a programme rather than a last-minute scramble. Start by building a defensible record of what personal data you hold, where it lives, why you process it and who you share it with. That data map is the foundation everything else rests on.
From there, prioritise the highest-penalty areas first: security safeguards, logging and a tested breach-response plan that can meet the 72-hour reporting duty. In parallel, redesign notices and consent capture, stand up your rights-and-grievance workflow, paper your processor relationships with proper contracts, and decide whether you are likely to be designated a significant data fiduciary and therefore need a DPO, audits and impact assessments.
The clearest place to start is a sequenced plan. Our step-by-step guide on how to comply with DPDP lays out the journey from first data map to an operating, defensible programme.
To keep that work concrete, use a list you can tick off. The DPDP compliance checklist breaks the Act and Rules into actionable tasks so progress is visible and nothing is missed.
Much of DPDP is documentation, and you needn’t start from scratch. Ready-made DPDP policy templates give you notices, consent artefacts and internal policies you can adapt to your organisation in hours rather than weeks.
The right tooling keeps the programme sustainable. DPDP compliance software centralises your records, consents and evidence so compliance lives in a system rather than a pile of spreadsheets.
Repetitive work is best handed to machines. DPDP automation takes over routine tasks like consent tracking and evidence collection, which is exactly the work that tends to lapse under pressure.
Guidance is also tailored by sector. If you build software, DPDP for SaaS covers the processor and data-residency questions specific to multi-tenant products.
Financial services face sharper scrutiny. DPDP for fintech addresses consent, retention and cross-border questions in a sector that already sits under heavy regulation.
Online retailers have their own patterns. DPDP for ecommerce looks at customer data, marketing consent, and the third-party integrations typical of a storefront.
Health data demands the most care. DPDP for healthcare covers the heightened expectations around sensitive medical information and the consent it requires.
Employee data is easy to overlook. DPDP for HR deals with the personal data organisations hold about their own staff, which is squarely within scope.
And marketing teams need clear rules. DPDP for marketing explains how consent, tracking and outreach must change so that growth activity stays on the right side of the Act.
None of this needs to be done alone. A specialist compliance partner can compress the timeline considerably — running a gap assessment against the Act and Rules, helping remediate the technical safeguards, and putting the documentation and governance in place so that when the deadline arrives, DPDP compliance is something you can demonstrate rather than something you are still chasing.
Free consultation
Need help getting DPDP-ready?
Talk to our compliance team — we’ll map your gaps against the Act and the 2025 Rules.