The Digital Personal Data Protection Act, 2023 is India's general law for digital personal data. It uses its own vocabulary: the individual is a Data Principal, the organisation deciding purposes and means is a Data Fiduciary, and a Data Processor processes on the Fiduciary's behalf.
The Act applies to digital personal data processed within India, and to processing outside India where it relates to offering goods or services to Data Principals in India. Personal data made publicly available by the individual themselves, or under a legal obligation, is carved out.
Its lawful-processing model is narrower than the GDPR's. Processing generally rests on consent, or on a defined set of legitimate uses set out in the Act. There is no open-ended legitimate-interests balancing test.
Operational detail — including timelines, thresholds for Significant Data Fiduciaries and the mechanics of consent managers — sits in rules made under the Act, so implementation planning should track the notified rules rather than the statute alone.
Who and what it applies to
- Material scope
- Digital personal data — personal data in digital form, and non-digital personal data that is subsequently digitised.
- Territorial scope
- Processing within India, and processing outside India connected with offering goods or services to Data Principals in India.
- Exclusions
- Personal data that the individual has made publicly available themselves, or that is made public under a legal obligation, and certain processing for personal or domestic purposes.
Core principles
- Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action for a stated purpose.
- Notice must accompany or precede the consent request and describe the personal data, the purpose and how to exercise rights and complain.
- Purpose limitation — process only for the purpose for which consent was given or the legitimate use relied on.
- Data minimisation — collect only personal data necessary for the specified purpose.
- Accuracy — take reasonable steps to ensure completeness, accuracy and consistency where data is used for decisions or shared.
- Erasure — delete personal data when consent is withdrawn or the purpose is no longer served, unless retention is legally required.
- Security safeguards — reasonable measures to prevent personal data breaches, including where a Processor is engaged.
Individual rights
Access
A summary of personal data being processed and of processing activities, and the identities of other Fiduciaries with whom data has been shared.
Correction and erasure
Correction, completion, updating and erasure of personal data.
Grievance redressal
A readily available means of raising grievances with the Data Fiduciary, before approaching the Board.
Nomination
Nominate another individual to exercise rights in the event of death or incapacity.
Withdraw consent
Withdraw consent as easily as it was given, with processing ceasing within a reasonable time.
Organisational obligations
Notice and consent
Provide an itemised notice and obtain valid consent, with the notice available in English and the languages listed in the Constitution's Eighth Schedule.
Accountability for processors
A Data Fiduciary remains responsible for compliance even where processing is carried out by a Processor under contract.
Breach intimation
Inform the Board and each affected Data Principal of a personal data breach in the manner prescribed by the rules.
Children's data
Obtain verifiable consent from a parent or lawful guardian for children, and do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Significant Data Fiduciaries
Entities notified as significant must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits.
Grievance mechanism
Publish contact details of a DPO or a person able to answer questions about processing, and operate a grievance route.
Cross-border considerations
- The Act permits transfer of personal data outside India except to territories restricted by notification by the Central Government.
- This is a restriction-by-exception model rather than an adequacy model, so the practical control is monitoring notified restrictions.
- Sector regulators — notably in banking, insurance and payments — impose their own localisation requirements that continue to apply alongside the Act.
Enforcement overview
- The Data Protection Board of India inquires into breaches of the Act and may impose monetary penalties following an inquiry.
- The Act sets out a schedule of penalties tied to specific failures, including a substantially higher band for failure to take reasonable security safeguards to prevent a personal data breach.
- Penalties are administrative; the Act does not create a general right to compensation for individuals.
- Appeals from Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal.
Implementation checklist
- 1Map which processing depends on consent and which fits a defined legitimate use.
- 2Rebuild consent notices as itemised, purpose-specific requests with multilingual availability.
- 3Implement withdrawal of consent that is as easy as giving it, and propagate withdrawal downstream.
- 4Establish a grievance route with named contacts and defined response handling.
- 5Identify children's data flows and put verifiable parental consent in place.
- 6Prepare for Significant Data Fiduciary duties if scale or sensitivity makes designation likely.
- 7Track notified rules and restricted-territory notifications rather than relying on the statute alone.
Frequently asked questions
Does the DPDP Act have a legitimate-interests basis like the GDPR?
No. Processing rests on consent or on the specific legitimate uses listed in the Act. There is no open-ended balancing test.
Does the DPDP Act require data localisation?
The Act itself allows transfers except to territories restricted by government notification. Separate sector regulations may still require localisation.
Official sources
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.