DPDP Act 2023
India's data protection law, explained by people who have to implement it.
The Digital Personal Data Protection Act is short, which is why it is so often misread. It does not care about your turnover, it does not distinguish between ordinary and sensitive data, and it assumes you can prove what you did. This guide walks through the whole thing in the order it will matter to you — why it exists, who the players are, what the ten duties actually require, what it costs to get wrong, and the twelve steps we take clients through.
This is educational material written by practitioners who run security and compliance programmes, not by lawyers. It will make you a better-informed client of legal advice — it does not replace it.
- ₹250 cr
- Top penalty for weak security
- 72 hrs
- Board notification after a breach
- 22
- Languages a notice may be demanded in
- 18
- Under this age, parental consent
Part one · Why
How we got here, in five moments.
Nothing in this law arrived suddenly. Every clause is a response to something that had already gone wrong somewhere in the Indian digital economy.
- 2017
Privacy becomes a fundamental right
The Supreme Court's Puttaswamy judgment settled the constitutional question. A right on paper still needs machinery to enforce it in daily life, and that machinery took another six years to arrive.
- 2018–2022
Four drafts, several rewrites
Committee reports, a withdrawn bill, and a long public consultation. The final text is deliberately short — the detail was pushed into Rules so it could be updated without returning to Parliament.
- Aug 2023
The Act receives assent
India's first dedicated law for digital personal data. Twelve pages of obligations that apply to a two-person clinic and a listed bank in exactly the same words.
- Nov 2025
The Rules are notified
Notice formats, breach reporting, children's data verification and retention limits acquire dates. Commencement is staggered: a few duties bite at once, most substantive ones phase in later.
- Now
A digital-first regulator
The Data Protection Board takes complaints online and hears them online. There is no filing fee for the person complaining about you, and no need for them to hire anyone.
The cast
Six roles, and you are almost certainly the one carrying the liability.
Understand who is who and most of the Act reads itself. Get this wrong — usually by assuming your software vendor is responsible — and everything downstream is wrong too.
Data Principal
Your customer, patient, resident, student or employee. The data is about them, so under this Act the rights belong to them — not to whoever paid for the database.
Data Fiduciary
Anyone who decides why and how personal data gets processed. The word 'fiduciary' is chosen deliberately: you hold something that belongs to someone else and you answer for how you treat it.
Significant Data Fiduciary
Not a separate organisation — extra duties bolted onto a Data Fiduciary the government notifies, based on volume and sensitivity. Adds a India-based Data Protection Officer, independent audits and impact assessments.
Data Processor
The billing software, the cloud host, the call centre, the marketing agency. They act on your instructions — and when they leak your customers' data, the Board still comes to you first.
Consent Manager
A Board-registered platform where an individual can review and withdraw consents given across many organisations from one place. A regulatory status, not a product category.
Data Protection Board
Investigates, adjudicates and fines. It does not draft your policies or pre-approve your notice; it turns up after something has already gone wrong.
Part two · What the law asks
Ten duties. Read them as promises to the people whose data you hold.
Each one has a plain-English version and an operational version. The plain version is what you tell your team. The operational version is what a regulator will test.
Notice
Tell people what you take and why.
A standalone notice, before or at collection, naming the exact data, the specific purpose, how to withdraw, how to exercise rights, and how to complain — to you and to the Board. It must be available in English or any Eighth Schedule language, at the individual's choice. If a first-time reader cannot repeat back what you collect and why, the notice has failed regardless of what your lawyer thinks of it.
Consent
Ask properly, and let them change their mind.
Free, specific, informed, unconditional, unambiguous, and given by a clear affirmative act. Pre-ticked boxes are not consent. Bundling ten purposes behind one checkbox is not consent. Withdrawal must be as easy as granting was — if consent took one tap, withdrawal cannot take a written request on letterhead.
Legitimate uses
Some processing does not need consent.
Data an individual voluntarily gives for an obvious purpose, employment-related processing, medical emergencies, compliance with a court order or another law, and specified state functions. This is a short, closed list — it is not a general 'business interest' exemption, and treating it like one is the most common misreading of the Act.
Purpose limitation and accuracy
Use it for the reason you gave.
Data collected to deliver an order cannot quietly become a marketing list. Where the data drives a decision about the person or gets shared onward, you owe them accuracy and completeness — a wrong phone number is an inconvenience, a wrong credit flag is a lawsuit.
Retention and erasure
Delete it when the reason ends.
Once the purpose is served and no other law requires you to hold it, personal data must go — including from backups, exports, spreadsheets and the WhatsApp group. Write a retention schedule per data type, then actually run the deletion job. Undeleted data is pure liability: it can only ever leak.
Security safeguards
Protect it like it matters.
Reasonable technical and organisational measures — access control, encryption, logging, backups, and the ability to detect a breach in the first place. This is the clause carrying the ₹250 crore ceiling, and it is the one where 'we did not know it happened' is the worst possible answer.
Breach reporting
Tell the Board fast, tell the people too.
Notify the Data Protection Board within 72 hours of becoming aware, and affected individuals without undue delay, in plain language, describing what happened and what they should do. CERT-In's separate six-hour direction may also apply. Deciding who calls whom during an incident is a decision to make on a quiet Tuesday, not at 2 a.m.
Rights of individuals
Answer them, on a clock.
Access a summary of their data and who it went to, correction and completion, erasure, grievance redressal, and nomination of someone to act for them after death or incapacity. Publish a working channel — an email address nobody reads is a breach of this duty in slow motion.
Children's data
Under 18 changes everything.
Verifiable parental consent before processing, no behavioural tracking, no targeted advertising at children. Coaching classes, schools, playschools and ed-tech carry the strictest obligations in the entire Act, and they are frequently the least prepared for them.
Accountability
Be able to prove all of the above.
The Board will not ask whether you meant well. It asks for the notice version shown, the consent record, the access log, the retention rule, the vendor contract. Compliance you cannot evidence is, from the regulator's chair, indistinguishable from no compliance at all.
What people can demand
Four rights, and a clock attached to each.
Right to information
A summary of the personal data you hold about them and the identities of everyone you shared it with.
Right to correction and erasure
Fix what is wrong, complete what is missing, delete what is no longer needed.
Right to grievance redressal
A named, reachable route to complain to you — which must be exhausted before the Board is approached.
Right to nominate
Appoint another individual to exercise these rights on their behalf in the event of death or incapacity.
What it costs
Penalties are stated in crores, not percentages.
- Up to ₹250 crore
- Failure to take reasonable security safeguards to prevent a breach.
- Up to ₹200 crore
- Failure to notify the Board or affected individuals of a personal data breach.
- Up to ₹200 crore
- Breach of the additional obligations owed in relation to children's data.
- Up to ₹150 crore
- Breach of the extra duties placed on a Significant Data Fiduciary.
- Up to ₹50 crore
- Any other breach of the Act or the Rules made under it.
- Up to ₹10,000
- Levied on an individual who files a frivolous or false complaint.
Ceilings, not tariffs. The Board weighs the gravity of the breach, the data involved, whether it was repeated, and what you did the moment you found out.
Part three · What to do
Twelve steps, in the order that actually works.
Most programmes stall because they start with policy documents. Start with finding the data instead — everything else becomes obvious once you know where it lives.
Find the data
List every place personal data lives: billing software, CRM, spreadsheets, shared drives, email, WhatsApp groups, CCTV, ID photocopies, the old laptop in the cupboard. One page. This is the foundation of everything after it.
Write down why
Against each store, record the purpose in one sentence. Anything you cannot justify in a sentence is either an undeclared purpose or data you should not still hold.
Pick your lawful basis
Consent, or one of the listed legitimate uses. Choose deliberately per purpose, and write the choice down — you will be asked to defend it, not to invent it later.
Rewrite the notice
Standalone, specific, readable, and available in the languages your customers actually use. Version it, and keep every past version.
Fix how you capture consent
Unticked by default, one purpose per choice, timestamped, stored with the exact text shown. A consent you cannot reproduce is a consent you did not obtain.
Build the withdrawal path
As easy as granting. Then make withdrawal actually propagate to every downstream system and vendor that received the data.
Set retention rules
A period per data type, tied to law or purpose, with an automated deletion job and evidence that it ran.
Paper your vendors
A data processing agreement with every processor: scope, security, sub-processing, breach notice to you, deletion on exit, audit rights.
Harden the basics
Unique accounts, multi-factor authentication, least privilege, encryption at rest and in transit, tested backups, and logs that are retained and actually read.
Be able to see a breach
You cannot report in 72 hours what you never detected. Monitoring is not an optional extra to this clause; it is how the clause is satisfied.
Rehearse the incident
One tabletop exercise: who declares it, who drafts the Board notification, who calls affected people, who talks to the press. Two hours now, priceless later.
Review every quarter
New system, new vendor, new purpose — the register goes stale within weeks. Put the review in the calendar and treat it as maintenance, not a project.
Keep reading
