What is the India DPDP Act 2023?
The Digital Personal Data Protection Act 2023 (DPDP Act) received Presidential assent on 11 August 2023, making India one of the world's largest economies to enact a comprehensive data protection law. The Act was passed by both houses of Parliament in August 2023 and marks a significant milestone in India's digital governance — replacing the patchwork of the IT Act 2000's Section 43A and the SPDI Rules 2011 with a modern, standalone data protection framework.
As of mid-2026, the Central Government has issued implementation Rules under the DPDP Act (through the Ministry of Electronics and Information Technology — MeitY), specifying timeframes for compliance, registration processes for Consent Managers, Data Protection Board procedures, and other operational requirements. Organisations processing personal data of Indian individuals should be implementing compliance programmes now, as the Data Protection Board of India (DPBI) is active and can levy penalties up to ₹250 crore per violation.
Scope and applicability
The DPDP Act applies to the processing of digital personal data of individuals (called data principals) within India, and to processing outside India if the personal data is processed in connection with offering goods or services to individuals within India. This extraterritorial scope mirrors GDPR's territorial reach and means that foreign SaaS companies, e-commerce platforms, and app developers serving Indian users are subject to the Act.
The Act does not apply to personal data processed by individuals for personal or domestic purposes, publicly available personal data, and personal data processed for certain specified government purposes. The Central Government may also exempt certain classes of Data Fiduciaries from all or some provisions.
Core consent architecture
The DPDP Act's consent framework (Section 6) requires that consent for processing personal data must be free, specific, informed, unconditional, and unambiguous — given through a clear affirmative action. This rules out pre-ticked boxes, bundled consent, and consent obtained through dark patterns.
Before seeking consent, the Data Fiduciary must provide the data principal with a consent notice (Section 5) that itemises: the personal data to be collected, the purpose of processing, the rights of the data principal, and how to withdraw consent and file a complaint. The notice must be available in English and, upon request, in any of the 22 languages listed in the Eighth Schedule of the Constitution — a multilingual accessibility requirement unique to India.
Deemed consent (legitimate use): Section 7 provides for processing without consent in specified legitimate use cases: (a) the individual has voluntarily provided personal data and it is obvious that they consent to its use for that purpose; (b) the State requires the data for subsidies, benefits, licenses, or other governmental functions; (c) processing is for compliance with a legal obligation; (d) medical emergency or epidemic; (e) employment purposes; (f) public order and national security. Each legitimate use basis must be documented and cannot be used as a general workaround for consent.
Data principal rights
The DPDP Act grants data principals four core rights:
- Right to information (Section 11): Upon request, the data principal is entitled to receive a summary of personal data processed about them and information about the processing activities undertaken.
- Right to correction and erasure (Section 12): Data principals can request correction of inaccurate or incomplete data, and erasure of personal data where the purpose is no longer being served or consent has been withdrawn — unless the Data Fiduciary is required by law to retain the data.
- Right to grievance redressal (Section 13): Data principals have the right to have complaints addressed within 48 hours of receipt — a notably tight timeline compared to most other jurisdictions (GDPR gives one month). The grievance officer's name and contact details must be published.
- Right to nominate (Section 14): Data principals may nominate another individual to exercise their rights in the event of the data principal's death or incapacity — a provision unique to the DPDP Act that reflects Indian family and succession law context.
Data principals can also approach the Data Protection Board directly if a complaint is not resolved by the Data Fiduciary.
Significant Data Fiduciary (SDF) designation
Section 10 creates an enhanced obligation tier for Significant Data Fiduciaries (SDFs) — designated by the Central Government based on: (a) volume and sensitivity of personal data processed; (b) risk to the rights of data principals; (c) potential impact on sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; (f) public order. The designation is made by notification and can apply to entire classes of organisations or specific entities.
SDFs face four additional obligations beyond baseline Data Fiduciary requirements:
- Data Protection Officer (DPO): Must appoint a DPO who is a resident of India and who represents the SDF before the Data Protection Board. The Board of Directors (or equivalent) is accountable for the DPO's decisions. This is a more demanding standard than GDPR's DPO requirement — the India DPO must be a resident, and board accountability is explicit.
- Independent data auditor: SDFs must have their compliance with the DPDP Act audited by an independent data auditor at intervals specified by the Central Government. The auditor verifies that the SDF is complying with the Act's provisions.
- Data Protection Impact Assessment (DPIA): SDFs must conduct periodic DPIAs for processing activities that may pose a risk to the rights of data principals. DPIAs must be documented and may need to be submitted to the Board.
- Other measures as notified: The Central Government can prescribe additional obligations for SDFs through Rules — giving flexibility to add requirements as the landscape evolves.
Children's data: the strictest rules
The DPDP Act has particularly strict rules for processing personal data of children (under 18 years of age). Verifiable parental consent must be obtained before processing any personal data of a child. SDFs and certain platforms must implement age-gating mechanisms to verify that consent is obtained from a parent or guardian, not the child directly.
Section 9 also prohibits Data Fiduciaries from processing personal data that causes detrimental effects on the wellbeing of a child and from undertaking targeted advertising directed at children. For SDFs operating consumer platforms (social media, gaming, e-commerce), this means no behavioural profiling or targeted advertising to under-18 users, regardless of parental consent. The Central Government may exempt classes of Data Fiduciaries from the verifiable consent requirement where processing does not create risk to the child's wellbeing.
Cross-border data transfers: the whitelist approach
Section 16 of the DPDP Act takes a "whitelist" approach to cross-border transfers — personal data may only be transferred to countries or territories notified by the Central Government as permitted for transfer. This is different from GDPR's adequacy decision mechanism (where the EU assesses whether a third country provides adequate protection); under the DPDP Act, India's Central Government determines which countries are permitted, based on considerations including whether the country poses any risk to national security or public order.
The Central Government may also specify categories of personal data that must be processed only in India (data localisation requirements). While the original DPDP Bill drafts proposed extensive localisation, the enacted Act is more flexible — localisation is applied category-by-category through notification rather than as a blanket requirement.
Organisations must map all cross-border personal data flows and verify that destination countries are on the permitted list before initiating any new international transfers. Data processor contracts must also ensure that overseas processors are bound by DPDP-equivalent obligations.
Personal data breach notification
Under Section 8(6), Data Fiduciaries must notify the Data Protection Board and affected data principals of any personal data breach in such form and manner as may be prescribed by Rules. The specific notification timeframe is expected to be approximately 72 hours (based on international comparators and draft Rules), but organisations should monitor final Rules for confirmed timelines.
Unlike GDPR, which has a risk-based threshold for individual notification (notify individuals when a breach is "likely to result in a high risk" to rights and freedoms), the DPDP Act's initial framework appears to require notification of both the Board and affected data principals for all breaches, subject to Rules-based exceptions. Breach response procedures must be implemented and tested before a breach occurs.
Penalties: up to ₹250 crore per violation
The DPDP Act (Schedule) sets out financial penalties for non-compliance. Key penalty amounts include:
- Failure to implement reasonable security safeguards resulting in a personal data breach: up to ₹250 crore
- Failure to notify the Board and data principals of a breach: up to ₹200 crore
- Non-compliance with special provisions for children's data: up to ₹200 crore
- Non-compliance with SDF additional obligations: up to ₹150 crore
- Non-compliance with other provisions of the Act: up to ₹50 crore
- Non-compliance with Rules or Board directions: up to ₹10,000 per violation
The Data Protection Board of India determines penalties after giving the Data Fiduciary an opportunity to be heard. The Board can also issue directions for compliance and order Data Fiduciaries to take corrective action.
Assess your India DPDP Act compliance
The India DPDP Act Compliance Checklist covers 42 key obligations across six categories: lawful processing and consent (consent validity, notice requirements, deemed consent bases, withdrawal, records), data principal rights (information, correction, erasure, grievance redressal, nominate, grievance officer publication), Data Fiduciary obligations (purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, breach notification, processor contracts), Significant Data Fiduciary obligations (SDF monitoring, DPO, DPIA, algorithmic accountability, children's age-gating, no targeted advertising to children, independent audit), cross-border transfers (permitted country whitelist, data localisation, overseas processor contracts), and governance and Data Protection Board compliance. Mark each item as compliant, partial, gap, or not applicable, and generate an AI-drafted DPDP Act compliance report with a 90-day remediation roadmap tailored to your SDF classification status.
Related tools
See also: Singapore PDPA Compliance Checker, GDPR Compliance Audit, Privacy Policy Generator, DSAR Policy, DPIA Generator.