Skip to main content
DPDP Act 2023 Explained: Rules, Obligations, Penalties — page loaded
DPDP 101

DPDP Act 2023 and DPDP Rules 2025 Explained in Plain Language

The DPDP Act, decoded.

Reading time
22 minutes
Last updated
04 May 2026
Authority
Gazette G.S.R. 846(E)
Audience
Legal · Security · Product · Boards
Section 01

Why the DPDP Act exists.

For most of India's digital era, personal data was governed by a single, ageing instrument: the Information Technology Act, 2000, supplemented by the SPDI Rules of 2011 — a regime designed before smartphones, social platforms, fintech apps and cloud computing made personal data the operating substrate of nearly every business.

The watershed moment was August 2017. A nine-judge constitutional bench of the Supreme Court, in Justice K.S. Puttaswamy (Retd.) v. Union of India, held unanimously that the right to privacy is a fundamental right protected by Article 21. That created a constitutional obligation on the State to enact a comprehensive data protection law.

What followed was a six-year journey. The Justice B.N. Srikrishna Committee delivered a draft Bill in 2018; iterations followed in 2019 and 2022. The current Act — pared down, simplified, and renamed — was introduced in Lok Sabha on 3 August 2023 and received Presidential assent on 11 August 2023. The final DPDP Rules, 2025 were notified by MeitY on 13 November 2025 via Gazette notification G.S.R. 846(E). With that, India finally has an operational data protection regime.

Long Title — DPDP Act, 2023
"An Act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes…"

The Act is unusual in two further respects. It is the first Act of the Indian Parliament to use the pronouns "she" and "her" by default, and it follows what MeitY calls the SARAL design — Simple, Accessible, Rational, and Actionable — using plain language throughout the statutory text.

Section 02

What the law covers — and what it doesn't.

The DPDP Act applies to the processing of digital personal data. That is a deliberately narrow phrase, and each word matters.

Personal data, defined broadly

Any data about an individual who is identifiable by or in relation to such data (Section 2(t)). Unlike GDPR, the Act creates no separate "sensitive personal data" category — all personal data is treated uniformly.

"Digital" is the key qualifier

Applies only to personal data in digital form, or non-digital data subsequently digitised (Section 3(a)). Paper records that remain on paper fall outside its scope.

Where it applies (and to whom)

Territorial and extraterritorial reach: processing within India, and outside India if connected to offering goods or services to data principals in India (Section 3(b)). A foreign SaaS with Indian users is in scope.

What sits outside the Act

Personal/domestic use; data made publicly available by the Principal or under legal obligation; and certain research, archiving and statistical processing (Section 3(c)).

Practical scope test
If your organisation collects or processes any digital personal data of any individual in India — whether you are based in Mumbai, Bengaluru, San Francisco or Singapore — the DPDP Act applies. There is no employee, revenue or data-volume threshold for baseline applicability.
Section 03

The seven SARAL principles.

Every operative provision of the Act and Rules traces back to seven foundational principles — the bedrock of MeitY's SARAL design. Respect these seven and the rest tends to follow.

01

Consent & Transparency

Personal data is processed lawfully, with the Data Principal informed clearly about what is collected and why.

02

Purpose Limitation

Data is collected and used only for the specific purpose for which consent was obtained or that the law permits.

03

Data Minimisation

Only personal data necessary for the specified purpose is collected — nothing more, no matter how useful it might be.

04

Accuracy

Reasonable steps are taken to ensure that personal data is accurate, complete, consistent and up to date.

05

Storage Limitation

Data is retained only as long as needed for the specified purpose; once that purpose is served, it must be erased.

06

Security Safeguards

Reasonable technical and organisational safeguards are deployed to prevent breaches and protect data integrity.

07

Accountability

Data Fiduciaries are answerable for their compliance — through documentation, audits, and where applicable, penalties.

These aren't merely aspirational — they map directly onto enforceable obligations: consent in Section 6, purpose limitation in Section 7, security safeguards in Section 8(5), and so on. Treat them as your compliance compass.

Section 04

Who's who: the key actors.

The framework introduces a vocabulary of roles you'll meet throughout the Act, the Rules and every operational document. Some borrow from the GDPR; others are uniquely Indian.

The IndividualSection 2(j)

Data Principal

The natural person to whom personal data relates. For minors, this includes their parent or lawful guardian; for persons with disabilities, their lawful guardian.

The ControllerSection 2(i)

Data Fiduciary

Any person who alone or jointly determines the purpose and means of processing personal data. Equivalent to the GDPR's "controller." Bears primary compliance liability.

The ProcessorSection 2(k)

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary. Cannot be directly penalised by the DPBI — the Fiduciary remains liable for processor failures.

The Higher-Risk FiduciarySection 10 · Rule 13

Significant Data Fiduciary

A Fiduciary or class notified by the Central Government based on volume, sensitivity, risk to principals, sovereignty, electoral democracy or use of emerging tech.

The IntermediarySection 6(7) · Rule 4

Consent Manager

A registered entity that helps Data Principals give, manage, review and withdraw consent through a single interoperable platform. Must be incorporated in India.

The RegulatorSection 18-26

Data Protection Board of India

The adjudicatory body that enforces the Act. Functions as a fully digital institution with online complaint filing. Appeals lie to TDSAT within 60 days.

Section 05

The two ways data may be processed lawfully.

Unlike the GDPR with its six lawful bases, the DPDP Act recognises only two grounds: consent, or one of the closed-list legitimate uses in Section 7. There is no broad "legitimate interests" basis to fall back on.

Ground 1: Consent

Consent is the dominant pathway for commercial processing. Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, signified through clear affirmative action — and withdrawable at any time with the same ease it was given. Every request must be accompanied by a Section 5 notice describing the data, purpose, withdrawal and rights mechanics, and route to the DPBI — available in English and each of the 22 Eighth Schedule languages.

Ground 2: Certain Legitimate Uses

Section 7 sets out a closed list of legitimate uses where processing may proceed without consent. The most commonly invoked:

a

Voluntary provision by the Data Principal

Section 7(a)

Where the principal voluntarily provides her data and has not signalled disagreement to its use for the specified purpose.

b

State functions & benefit delivery

Section 7(b)

Provision by the State of subsidies, benefits, services, certificates, licences or permits.

c

Compliance with law or judicial order

Section 7(c)-(d)

Where processing is necessary to comply with any judgment, decree or law in force.

d

Medical emergencies & epidemics

Section 7(e)-(f)

For responding to medical emergencies, epidemics, outbreaks or threats to public health.

e

Employment-related processing

Section 7(i)

For ascertaining suitability for employment, providing services or benefits to employees, or safety at work.

What's deliberately absent
The GDPR's "legitimate interests" basis — widely used for analytics, fraud prevention and direct marketing — has no equivalent under the DPDP Act. If your processing doesn't fit a Section 7 use, you almost certainly need consent.
Section 06

Rights of the Data Principal.

Chapter III confers four substantive rights on every Data Principal, exercisable against any Fiduciary processing her data. The Rules require a response within ninety days of receipt.

Right to access information

A summary of personal data being processed, the processing activities, and the identities of any other Fiduciaries with whom it has been shared.

Right to correction & erasure

Correction of inaccurate or misleading data, completion of incomplete data, updating of out-of-date data, and erasure of data no longer needed.

Right of grievance redressal

To approach the Fiduciary's grievance officer first; to escalate to the DPBI only after exhausting that mechanism.

Right to nominate

To appoint another individual to exercise these rights on her behalf in case of death or incapacity.

The Act also imposes duties on Data Principals — not to file false or frivolous complaints, not to impersonate, not to suppress material information. Breach can attract a penalty of up to ₹10,000 (Section 15).

Section 07

Obligations of the Data Fiduciary.

Section 8, read with the operationalising Rules, sets out the core obligations every Fiduciary must observe — the obligations compliance programmes are built around.

Notice before processing

A clear, itemised notice in plain language at or before the time of collection — in English and the 22 scheduled languages.

Valid consent & lawful purpose

Process only on consent or under a Section 7 legitimate use; honour withdrawal as easily as consent was given.

Accuracy & completeness

Make reasonable efforts to ensure personal data used to make a decision affecting the Principal is accurate and complete.

Reasonable security safeguards

Implement appropriate technical and organisational measures to prevent breaches — including encryption, access control, monitoring and logs.

Breach notification

Intimate the DPBI without delay; furnish a detailed report within 72 hours; intimate affected Principals in plain language.

Storage limitation & erasure

Erase personal data when consent is withdrawn or the purpose is no longer served — with three-year defaults for ecommerce, social media and online gaming.

Children's data protections

Verifiable parental consent before processing data of anyone under 18; no tracking, behavioural monitoring or targeted advertising.

Grievance redressal mechanism

Publish business contact information and provide an effective grievance redressal mechanism, with response within 90 days.

SDF additional obligations

For notified SDFs: appoint a DPO based in India, engage an independent data auditor, and conduct annual DPIA + audit.

Section 08

Penalties at a glance.

The DPDP Act establishes a purely civil penalty regime — no criminal sanctions. Section 33, read with the Schedule, empowers the DPBI to impose penalties up to specified caps, per contravention.

Failure to implement reasonable security safeguards
₹250 Cr
Failure to notify the DPBI & affected Principals of a breach
₹200 Cr
Breach of additional obligations relating to children's data
₹200 Cr
Breach of additional obligations of Significant Data Fiduciaries
₹150 Cr
Breach of any other provision of the Act or the Rules
₹50 Cr
Breach of duties by a Data Principal (frivolous complaints, impersonation)
₹10K
Cumulation matters
Three distinct findings — say, inadequate security and delayed breach notification and children's-data violations — could theoretically expose a Fiduciary to up to ₹650 Cr in a single proceeding. The DPBI's power is discretionary; Section 33(2) requires it to weigh nature, gravity, duration, repetition, gains and remediation.

Orders of the DPBI are appealable to the TDSAT within 60 days, with further appeals to the Supreme Court. Importantly, data processors cannot be directly penalised — the Fiduciary remains liable for processor failures, which makes vendor governance a critical compliance domain.

Section 09

The phased implementation timeline.

Although the Act passed in 2023 and the Rules were notified in November 2025, substantive obligations switch on in three phases. Knowing which phase you're in is essential for both legal exposure and programme planning.

11 August 2023Passed

DPDP Act receives Presidential assent

Parliament passes the DPDP Bill, 2023; the President gives assent. The Act exists on the books but has no operational force without Rules.

3 January 2025Consulted

Draft DPDP Rules released for public consultation

MeitY publishes draft Rules and invites stakeholder input. 6,915 submissions are received from startups, enterprises, civil society and citizens.

13 November 2025Notified

DPDP Rules, 2025 notified · Phase 1 in force

Final Rules notified via G.S.R. 846(E). Phase 1 brings into force the procedural provisions: definitions, establishment of the DPBI, and the bar on civil court jurisdiction.

~14 November 2026Phase 2

Consent Manager provisions in force

Registration of Consent Managers with the DPBI, their obligations, and the Board's powers to inquire into and penalise breaches of registration conditions become effective.

~13 May 2027Phase 3

Substantive obligations in full force

All remaining provisions activate: notice and consent, processing grounds, security safeguards, breach notification, children's data, SDF obligations, cross-border transfer, Data Principal rights, and exemptions.

The 9-month runway from notification to full enforcement is what makes now the critical preparation window. Organisations that wait until May 2027 will find 9 months barely enough — particularly for data discovery, consent re-engineering, vendor renegotiation and notice translation.

Section 10

How DPDP differs from GDPR & the SPDI Rules.

For organisations already aligned to the GDPR or the SPDI Rules, DPDP is partly familiar and partly novel. This comparison surfaces the differences that matter operationally.

CriterionDPDP Act & RulesEU GDPR
ScopeDigital personal data onlyAll personal data, digital or otherwise (incl. structured paper)
Sensitive data categoryNo separate "sensitive" category — all personal data treated uniformlySpecial categories with heightened obligations (health, biometric, etc.)
Lawful basesTwo: consent or one of the closed-list legitimate uses (Section 7)Six: consent, contract, legal obligation, vital interests, public task, legitimate interests
Cross-border transferDefault-permitted; restricted only for countries blacklisted by GovernmentAdequacy decisions, SCCs, BCRs and other prescribed mechanisms
Breach notificationWithout delay; detailed report within 72 hours; all breaches reportableWithin 72 hours unless unlikely to result in risk to rights and freedoms
Maximum penalty₹250 Cr per contravention (~USD 30M); cumulative across violations€20M or 4% of global annual turnover, whichever is higher
EnforcementCivil penalties only; no criminal sanctionsCivil penalties; some Member States retain criminal provisions
Right to data portabilityNot granted in the current ActGranted under Article 20
Right to object to automated decisionsNot granted in the current ActGranted under Article 22

For Indian businesses transitioning from the SPDI Rules, the most disruptive shifts are: (a) the move from "sensitive personal data" to uniform treatment, (b) the loss of permissive lawful bases (no more "legitimate interests"), and (c) the dramatic escalation of penalty exposure — from indemnification of actual damages to statutory caps in hundreds of crores.

Continue your journey

You've understood the law. Now put it into practice.