The DPDP Act, in plain English

A practical guide to the Digital Personal Data Protection Act, 2023 for business owners, compliance teams and professionals. Always read alongside the official text of the Act and the DPDP Rules.

Reviewed: 14 July 2026

Status as at 14 July 2026: The final DPDP Rules, 2025 and the Act are being commenced in phases under notifications published on 13 November 2025. Most operational duties are scheduled to commence eighteen months after publication. Always verify later notifications before relying on this timeline.

Phased enforcement timeline

13 November 2025Institutional and enabling provisions commenced, including establishment and functioning of the Data Protection Board.
13 November 2026Consent Manager registration-related provisions in section 6(9) and section 27(1)(d) are scheduled to commence one year after publication.
13 May 2027Most substantive processing obligations, rights, security, breach, children’s-data and penalty provisions are scheduled to commence eighteen months after publication.

Official sources: Act commencement notification and Digital Personal Data Protection Rules, 2025.

Who's who under the Act

  • Data Principal — the individual the personal data is about. For a child, it includes their parent or lawful guardian.
  • Data Fiduciary — any person or organisation that alone or with others determines the purpose and means of processing personal data. This is where most obligations sit.
  • Data Processor — someone who processes personal data on behalf of a Data Fiduciary (e.g. your payroll vendor, cloud CRM). The fiduciary remains responsible for their compliance.
  • Significant Data Fiduciary (SDF) — a fiduciary (or class of fiduciaries) notified by the Central Government based on factors like volume and sensitivity of data, with additional obligations.
  • Consent Manager — a Board-registered platform through which individuals can give, manage, review and withdraw consent.
  • Data Protection Board of India — the adjudicating body that inquires into breaches and imposes penalties.

Where the Act applies

The Act applies to digital personal data — personal data collected digitally, or collected offline and then digitised. It covers processing within India, and processing outside India if it is connected with offering goods or services to individuals in India.

It does not apply to personal data processed by an individual for personal or domestic purposes, or to data made publicly available by the data principal themselves or under a legal obligation.

The core rule: consent or "legitimate uses"

Personal data may be processed only for a lawful purpose, and only with the individual's consent or for certain legitimate uses defined in the Act (such as voluntary provision of data for a specified purpose, employment purposes, medical emergencies, or compliance with law).

What valid consent looks like

  • Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — pre-ticked boxes and bundled consent don't qualify.
  • Limited to the personal data necessary for the specified purpose.
  • Preceded by a notice describing the personal data sought, the purpose, how to exercise rights, and how to complain to the Board — available in English or any of the 22 scheduled languages.
  • Withdrawable with ease comparable to how it was given; on withdrawal, processing must stop and data must be erased unless retention is legally required.

Data Fiduciary obligations

  • Ensure completeness, accuracy and consistency of data used to make decisions affecting the individual or shared with another fiduciary.
  • Implement reasonable security safeguards to prevent personal data breaches — including for processing done by your processors.
  • Notify every personal data breach to the Data Protection Board and to each affected data principal, in the form and manner prescribed by the Rules.
  • Erase personal data when consent is withdrawn or as soon as the specified purpose is no longer being served, whichever is earlier (unless retention is required by law) — and ensure your processors erase it too.
  • Publish contact details of a grievance officer / DPO and operate an effective grievance redressal mechanism.

Children's data

Before processing the personal data of a child (under 18) or a person with disability who has a lawful guardian, a fiduciary must obtain verifiable parental/guardian consent. Processing that is likely to cause detrimental effect on a child's well-being, and tracking, behavioural monitoring or targeted advertising directed at children, are prohibited (subject to exemptions prescribed for certain classes of fiduciaries and purposes).

Significant Data Fiduciaries

If notified as an SDF, an organisation must additionally appoint a Data Protection Officer based in India who reports to the board, appoint an independent data auditor, and conduct periodic Data Protection Impact Assessments and audits.

Your customers' rights (Data Principal rights)

  • Access — a summary of their personal data being processed, the processing activities, and the identities of other fiduciaries/processors it was shared with.
  • Correction and erasure — correction of inaccurate data, completion, updating, and erasure of data no longer needed for the specified purpose.
  • Grievance redressal — a readily available means of grievance redressal, which must be used before escalating to the Board.
  • Nomination — the right to nominate another individual to exercise these rights in case of death or incapacity.

Data principals also have duties — such as not impersonating others or filing false complaints — with a modest penalty for breach.

Penalties

The Data Protection Board can impose monetary penalties per instance of breach, after inquiry, based on the Schedule to the Act:

BreachMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board / affected data principals of a personal data breach₹200 crore
Breach of obligations relating to children's data₹200 crore
Breach of additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of duties by a data principal₹10,000

A starting compliance checklist

  • Map your personal data: what you collect, where it lives, who it's shared with, and why.
  • Identify your lawful basis for each processing activity — consent or a legitimate use.
  • Rewrite privacy notices to be itemised, purpose-specific and available in required languages.
  • Build consent capture, records, and easy withdrawal into every collection point.
  • Set retention periods per purpose and implement evidenced erasure when they expire.
  • Review vendor/processor contracts for DPDP-aligned obligations.
  • Implement reasonable security safeguards and document them.
  • Prepare a breach response plan with Board and data-principal notification templates.
  • Stand up processes for access, correction and erasure requests with timelines.
  • Publish grievance officer contact details and train your team.

Frequently asked questions

We're a small business. Does the DPDP Act really apply to us?
Almost certainly yes, if you handle any personal data digitally — customer lists, employee records, CCTV linked to identity, WhatsApp business chats. The Act has no general small-business exemption, though the government can exempt notified classes of fiduciaries (including startups) from some provisions. The safest assumption is that the core obligations apply to you.
Is there a difference between the DPDP Act and GDPR?
They share DNA (consent, purpose limitation, individual rights) but differ meaningfully: the DPDP Act covers only digital personal data, has no special "sensitive data" categories, sets 18 as the age of consent for children's data, and uses fixed penalty ceilings rather than turnover percentages. GDPR compliance gives you a head start, not automatic DPDP compliance.
When do we actually have to comply?
As at 14 July 2026, most operational obligations are scheduled to become enforceable on 13 May 2027, eighteen months after publication of the commencement notification and final Rules. Some provisions commenced in November 2025 and another group is scheduled for November 2026. Verify later government notifications before relying on these dates.
What counts as a "personal data breach"?
Any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Note that every breach must be reported — the Act does not have a materiality threshold for notification.
Do we need a Data Protection Officer?
A DPO is mandatory only for Significant Data Fiduciaries. Every fiduciary, however, must publish the contact details of a person able to answer data principals' questions and operate a grievance mechanism — a role someone in your organisation must own either way.
Can we keep data "just in case" after the purpose is over?
No. Once the specified purpose is served (or consent withdrawn), the data must be erased unless a law requires you to retain it — for example, tax or company-law record-keeping. "It might be useful later" is not a lawful basis, and unevidenced deletion is hard to defend. Retention schedules plus auditable erasure are the answer.
Does the Act apply to employee and recruitment records?
Yes, digital personal data in recruitment and employment is within scope, subject to the Act’s provisions including specified legitimate uses. Employers should still document purposes, restrict access, maintain accuracy where decisions are made, define retention, govern processors and prepare for incidents.
Are WhatsApp and ordinary business email records covered?
They can be. If messages identify an individual and are processed digitally for business purposes, they may contain personal data. Map official and informal channels, control exports and backups, and avoid indefinite retention without a defined purpose or legal requirement.
Do backups have to follow erasure requirements?
Backup architecture must be considered in the erasure design. Immediate selective deletion may not always be technically feasible, but access, expiry cycles, restoration controls and prevention of restored data returning to active use should be documented and tested.
Is GDPR compliance enough?
No. GDPR controls provide useful foundations, but the DPDP Act has its own scope, terminology, legitimate uses, children’s-data rules, consent-manager framework, notices and phased commencement. Perform a specific mapping rather than assuming equivalence.
What evidence should management retain?
Useful evidence includes approved data maps, notices, consent records, request registers, processor reviews, retention schedules, erasure records, access reviews, training records, incident exercises, breach decisions, remediation tracking and periodic management review.
When should legal or cybersecurity specialists be involved?
Use legal counsel for legal opinions, complex statutory interpretation, disputes and representation. Use qualified cybersecurity specialists for architecture, penetration testing, forensic investigation and technical remediation. Compliance implementation should coordinate these disciplines rather than replace them.
Disclaimer: This guide summarises the law in general terms and may not reflect the latest amendments, rules or notifications. It is not legal advice. Obtain professional advice on your specific circumstances before acting.

Want this checklist done for you?

Our gap assessment turns this page into a scored report and remediation plan specific to your organisation.

Get in touch