Skip to main content
DPDP Act 2023 Full Text, Rules and Schedules | Annotated — page loaded
The Law

DPDP Act 2023 Full Text: Sections, Rules and Schedules

The bare Act, Rules and Schedules, navigable.

44 Sections22 Rules7 Schedules
Act · Ch I Preliminary
Section 2

Definitions

Defines the core vocabulary — personal data (2(t)), Data Principal (2(j)), Data Fiduciary (2(i)), Data Processor (2(k)), consent, and processing. All personal data is treated uniformly; there is no separate "sensitive" category.

Read the full text
Act · Ch I Preliminary
Section 3

Application of the Act

Applies to digital personal data within India and to processing outside India connected to offering goods/services to people in India. Excludes personal/domestic use and data made publicly available by the Principal or under legal obligation.

Read the full text
Act · Ch II Obligations
Section 5 · Rule 3

Notice

A clear, itemised notice in plain language at or before collection — the data, the purposes, how to withdraw consent, how to exercise rights and how to complain to the Board. English plus the 22 Eighth Schedule languages.

Read the full text
Act · Ch II Obligations
Section 6 · Rule 4

Consent

Consent must be free, specific, informed, unconditional and unambiguous, by clear affirmative action — and withdrawable as easily as it was given. Introduces the Consent Manager ecosystem.

Read the full text
Act · Ch II Obligations
Section 7

Certain legitimate uses

A closed list of uses where processing may proceed without consent: voluntary provision, State functions, legal compliance, medical emergencies, disasters, and employment. No broad "legitimate interests" basis exists.

Read the full text
Act · Ch II Obligations
Section 8 · Rule 6-8

General obligations of a Data Fiduciary

Accuracy, reasonable security safeguards, breach notification, storage limitation and erasure, and a grievance mechanism. Section 8(2) makes the Fiduciary liable for its processors.

Read the full text
Act · Ch II Obligations
Section 9 · Rule 10

Processing of children's data

Verifiable parental consent before processing data of anyone under 18; absolute prohibition on tracking, behavioural monitoring and targeted advertising of children.

Read the full text
Act · Ch II Obligations
Section 10 · Rule 13

Significant Data Fiduciaries

The Government may designate SDFs by volume, sensitivity, risk and sovereignty factors. SDFs must appoint an India-resident DPO, run annual DPIAs and independent audits.

Read the full text
Act · Ch III Rights & Duties
Section 11

Right to access information

A summary of personal data being processed, the processing activities, and the identities of other Fiduciaries with whom it has been shared.

Read the full text
Act · Ch III Rights & Duties
Section 12

Right to correction and erasure

Correction of inaccurate or misleading data, completion of incomplete data, and erasure of data no longer needed for the stated purpose.

Read the full text
Act · Ch III Rights & Duties
Section 13

Right of grievance redressal

Approach the Fiduciary's grievance officer first; escalate to the DPBI only after exhausting that mechanism. 90-day response SLA.

Read the full text
Act · Ch III Rights & Duties
Section 14

Right to nominate

Appoint another individual to exercise these rights on your behalf in the event of death or incapacity.

Read the full text
Act · Ch III Rights & Duties
Section 15

Duties of a Data Principal

No false or frivolous complaints, no impersonation, no suppression of material information. Breach can attract a penalty of up to ₹10,000.

Read the full text
Act · Ch IV Special provisions
Section 16

Transfer outside India

Default-permitted: the Government may restrict transfer to specified countries by notification. As of May 2026, no country has been blacklisted.

Read the full text
Act · Ch IV Special provisions
Section 17

Exemptions

Conditional, notified exemptions for certain State and research processing — not a blanket carve-out; safeguards still apply.

Read the full text
Act · Ch V Data Protection Board
Section 18-26

The Data Protection Board of India

A digital-first adjudicatory body that inquires into breaches, directs remedial measures and imposes penalties. Constitution, composition and procedure run through Rules 16-22.

Read the full text
Act · Ch VI Appeal & ADR
Section 29

Appeal to TDSAT

Appeals from DPBI orders lie to the Telecom Disputes Settlement and Appellate Tribunal within 60 days; further appeal to the Supreme Court on questions of law.

Read the full text
Act · Ch VII Penalties
Section 33 · Schedule

Penalties and the Schedule

Civil-only penalties, per contravention: ₹250 Cr (security), ₹200 Cr (breach notice / children), ₹150 Cr (SDF), ₹50 Cr (any other), ₹10K (Data Principal duties). The Board weighs nature, gravity, duration, repetition, gains and remediation.

Read the full text
DPDP Rules, 2025
Rule 3

Notice given by a Data Fiduciary

Prescribes the itemised content and form of the notice required under Section 5.

Read the full text
DPDP Rules, 2025
Rule 4

Registration & obligations of Consent Managers

How Consent Managers register with the DPBI and the standards they must meet. Expected to commence in Phase 2 (~Nov 2026).

Read the full text
DPDP Rules, 2025
Rule 6

Reasonable security safeguards

The seven safeguard categories: encryption, access control, backups, 1-year log retention, detection, processor contracts and technical/organisational measures.

Read the full text
DPDP Rules, 2025
Rule 7

Intimation of a personal data breach

Two-track intimation — to the Board "without delay" with prescribed contents, and to affected Data Principals as soon as feasible.

Read the full text
DPDP Rules, 2025
Rule 8

Retention & erasure (Third Schedule)

Retention defaults for high-volume e-commerce, gaming and social-media entities: three years from last activity, with 48-hour pre-erasure intimation.

Read the full text
DPDP Rules, 2025
Rule 10

Verifiable consent for children

Requires identity-verified parental consent before processing children's data; self-declared age gates do not suffice.

Read the full text
DPDP Rules, 2025
Rule 13

Additional obligations of SDFs

DPIA, annual independent audit, India-resident DPO reporting to the Board, and periodic risk assessment.

Read the full text
DPDP Rules, 2025
Rule 14

Rights of Data Principals

Operationalises the rights process and the 90-day response SLA.

Read the full text
Schedules
Schedule

The Schedule of Penalties

Maps each contravention to its monetary ceiling under Section 33.

Read the full text
Schedules
Third Schedule

Retention thresholds

User-count thresholds that trigger the Rule 8 retention defaults for e-commerce, gaming and social-media intermediaries.

Read the full text
This explorer gives the structure and the practitioner reading of each provision. For the full plain-English walkthrough with examples, see the DPDP 101 guide; for the official gazetted text, refer to G.S.R. 846(E) on the Gazette of India.
Read the full walkthrough

The full text, provision by provision

Every section of the Act and every rule of the Rules, each on its own page, as published in the Gazette of India.

DPDP Act, 2023 — Chapter IV: SPECIAL PROVISIONS
DPDP Act, 2023 — Chapter VI: POWERS, FUNCTIONS AND PROCEDURE TO BE FOLLOWED BY BOARD
DPDP Rules, 2025

Know the law. Now check your readiness.