At a glanceThe Digital Personal Data Protection Act is India’s first law dedicated to what organisations may do with people’s personal data. It is built on a single relationship: a person hands over their data, and the organisation receiving it takes on duties. One chapter of the Act sets out those duties: notice, consent, security, deletion. The next gives the person matching rights. Most of it becomes binding on 13 May 2027.
Educational resource only. This is a plain-English account of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025. It explains what the law requires. It is not a compliance verdict on any organisation, and it is not formal legal advice.
Why did India need a data protection law?
India built one of the largest online populations in the world before it had a law governing what anyone could do with the data that population handed over.
Think about an ordinary week. You give a PAN copy to a broker, a phone number at a restaurant billing counter, an Aadhaar at a hotel check-in desk, a set of documents to a coaching class, a scan of a salary slip to a landlord. Each transfer feels small and unremarkable. Collectively they are an enormous, continuous movement of personal information from individuals into the hands of organisations, most of whom never had to say what they would do with it, how long they would keep it, or who else would see it.
It is not quite true that nothing governed this. The Information Technology Act, 2000 carried a provision on compensation for negligent handling of data, and the SPDI Rules of 2011 sat under it. But that framework was narrow: it applied only to a defined list of “sensitive personal data” like passwords, financial details and health records, leaving ordinary personal data (your name, your phone number, the documents you hand over every week) largely untouched. It leaned on contracts and reasonable security practices rather than on rights. And it was enforced rarely enough that most businesses never treated it as a real constraint. The difference between that regime and this one is not a matter of degree.
What changed the trajectory was a court judgment. In 2017, a nine-judge bench of the Supreme Court held in Justice K.S. Puttaswamy v. Union of India that the right to privacy is a fundamental right protected under Article 21 of the Constitution. Informational privacy, meaning control over your own data, was held to be part of it. The Court also observed that India needed a proper data protection framework and that this was work for the legislature.
That started a long drafting process. An expert committee produced a draft in 2018. A Personal Data Protection Bill was introduced in 2019, examined for three years, and withdrawn in 2022. A fresh, considerably shorter draft followed, and Parliament passed the Digital Personal Data Protection Act in August 2023.
Then the Act sat still. A law of this kind cannot function without Rules: the subordinate legislation that fills in the mechanics of how a notice reads, how a breach gets reported, how a parent proves they are a parent. Those Rules were notified on 13 November 2025, and only then did the law begin to come into force, in stages.
So the DPDP Act is not a sudden imposition. It is the end of a road that started with a constitutional judgment, and it exists because a country that moved its entire commercial and civic life online had no dedicated rules for the personal data that move made routine.
What does the DPDP Act actually govern?
The Act governs digital personal data, and it follows that data from the moment it is collected to the moment it is deleted.
Two words carry the weight. Personal data means data about an identifiable individual, meaning anything from which a living person can be identified. A name and phone number qualify. So do a customer ID, an uploaded document, or a set of records that identify someone when read together. There is no separate, higher category of “sensitive” data in this Act, which is a real departure from the old regime: your dietary preference and your medical report are both simply personal data, and both attract the same baseline duties.
Digital is the second limit. The Act covers personal data collected in digital form, and personal data collected on paper and subsequently digitised. That second half matters more than it first appears. A clinic that fills in paper forms and types them into a computer, or a society gate that photographs a visitor’s ID, is inside the Act. Purely paper records that never touch a system are outside it, though in practice very little stays purely on paper.
The Act applies to processing of digital personal data within India. It also reaches outside India, where processing abroad relates to offering goods or services to people in India. A foreign company with Indian users does not escape the Act by having no office here.
One structural choice is worth noticing early, because it surprises people who expect a privacy law to be organised by industry. The DPDP Act is horizontal: it has no sector chapters and no industry carve-outs. A hospital, a school, a recruitment firm, an insurance broker and a two-person design studio are all Data Fiduciaries under exactly the same provisions. What differs is not the obligation but the work it creates. A clinic holding medical histories and a shop holding phone numbers face the same duty to secure personal data and the same duty to delete it when its purpose ends, and those two duties look nothing alike in practice. Sectoral regulation then sits on top: banking, insurance, healthcare and telecom carry their own record-keeping, retention and security requirements from their own regulators, and where those are stricter they continue to apply alongside the Act rather than being displaced by it. How the same duties land in different industries is a question of application, not of a different rulebook.
Find your sector
- Chartered Accountants
- Healthcare
- Real Estate
- Recruitment & HR
- Fintech
- EdTech
- E-Commerce
- MSMEs
- Freelancers
- Tutors & Coaching
- Micro-SaaS
- Law Firms
- Immigration
- Insurance
- Schools & Universities
- Financial Advisors
- Company Secretaries
- Tax Practitioners
- Marketing Agencies
- Hotels
- Gyms & Fitness
- NGOs
- Events & Photography
- Salons & Spas
A few things fall outside. Personal data processed by an individual for a purely personal or domestic purpose is not covered. Neither is personal data that the individual concerned has themselves made publicly available, or that someone is required by law to make public.
Who does the DPDP Act apply to?
The whole Act is written around a single relationship between two parties, and almost everyone in India is on both sides of it.
The organisation that decides why and how personal data gets processed is the Data Fiduciary. The word is deliberate: a fiduciary holds something on behalf of somebody else and owes duties in respect of it. The individual whose data it is, is the Data Principal. Between them sits a third, lesser role: the Data Processor, who processes data on a Data Fiduciary’s instructions and under contract. Your payroll vendor, your cloud CRM, your accountant’s document tool are typically processors. The fiduciary stays accountable for what its processors do. These three terms, and the rest of the Act’s vocabulary, are defined in plain language in the glossary.
The important thing about these roles is that they attach to a situation, not to a type of person. A two-person consultancy is a Data Fiduciary in respect of its clients’ documents and a Data Principal in respect of its founder’s data sitting with a bank. A hospital is a fiduciary over patient records and a principal when its own vendor holds its staff details. Most organisations are both, several times over, and the useful question is never “which one am I” but “which am I in this particular transaction”.
This is also why the law does not divide into a business half and a consumer half. Its two central chapters describe one set of facts from two ends. One sets out what the Data Fiduciary must do. The next sets out what the Data Principal may demand. The duty to delete data when its purpose is over and the right to have your data deleted are not two rules. They are one rule, written twice, from opposite sides of the same table. Read either chapter alone and you have half the picture.
When can an organisation use your data at all?
Personal data may be processed on exactly two bases: your consent, or one of a closed list of legitimate uses. There is no general-purpose third option.
This is the gateway question, and the Act answers it narrowly. An organisation either has consent, or it is relying on a specific legitimate use that the Act itself names. If neither applies, the processing is not lawful, however reasonable, commercially sensible, or well-intentioned it might be.
That closed list is the design choice worth noticing. Some other data protection regimes include a broad “legitimate interests” basis that lets an organisation weigh its own interests against yours and proceed. India’s law does not. The legitimate uses are enumerated:
- Voluntary provision - where you gave the data for a purpose yourself and have not objected to its use for that purpose.
- State benefits - for the State to provide a subsidy, benefit, certificate, licence or service.
- Legal obligation - for compliance with a law in force or an order of a court.
- Medical emergency - where there is a threat to life or an immediate risk to health.
- Disaster and public order - during a breakdown of public order or a disaster.
One entry on that list does more day-to-day work than the rest. Processing for employment purposes is a legitimate use, which means recruitment, payroll, attendance and the ordinary administration of an employment relationship do not need separate consent from an employee. This is genuinely load-bearing for anyone running an HR function, and it is also frequently over-read: it covers the employment relationship, not everything an employer might like to do with employee data. Using employee contact details to market an unrelated product is not employment administration, and needs consent like anything else. What an employer can and cannot rely on turns on exactly that boundary.
It is worth being clear about what falls away here. The old idea of “deemed consent”, inferring agreement from conduct or from a term buried in a contract, does not survive as a general basis. The distinction between consent, deemed consent and legitimate use is one of the more common places businesses go wrong.
What must happen at the moment data is collected?
Two things must happen before data is taken, not afterwards: a plain notice, and a real, specific yes.
The notice comes first. Before or at the point of asking for consent, the Data Fiduciary must tell the person what personal data it wants, the purpose it will be used for, how they can exercise their rights, and how they can complain to the Data Protection Board. It must be a standalone communication in clear, plain language, not a clause folded into terms and conditions, and not something the person could reasonably be expected to find later in a privacy policy. It must be available in English or any of the twenty-two languages listed in the Eighth Schedule to the Constitution, at the person’s option. What a notice must actually contain is more specific than most published ones manage.
Then the consent itself. The Act sets five conditions, and all of them have to hold at once:
- Free - a real choice, not extracted by making an unrelated service conditional on it.
- Specific - tied to a stated purpose, not a general permission.
- Informed - given after the notice, not before it.
- Unconditional - not bundled with terms that have nothing to do with it.
- Unambiguous - given by a clear affirmative action: a box the person ticks themselves, a signature, a deliberate step.
Silence is not consent. A pre-ticked box is not consent. Consent, in full, is where most intake processes in India currently fail.
Two consequences follow that are easy to miss. First, consent is per purpose. One combined agreement covering service delivery, marketing, analytics and sharing with partners is not four consents; it is an invalid one. Granular consent, meaning separate, unticked opt-ins each naming one purpose, is the pattern that actually works. Second, a person may withdraw consent at any time, and withdrawing must be as easy as giving it was. When they do, processing on that basis must stop, and the data must be erased unless some other lawful ground genuinely requires keeping it.
How a consent flow is designed, worded and recorded is covered across consent mechanics, and the wider question of how to run an intake that satisfies all of it sits in collecting data compliantly.
Underneath all of this sits a burden of proof that catches organisations out. If a consent is ever questioned, it is the Data Fiduciary who must be able to demonstrate that valid notice was given and valid consent obtained. Consent is not something you take and forget. It is something you must be able to prove later, with a record of who agreed, to what, and when.
Tools & walkthroughsBoth halves of this are things you can pick up ready-made. Templates and tools has a fill-in notice, a per-purpose consent form, and a consent register for the proof record.
What does an organisation owe you after that?
Collecting data lawfully is the start of the obligation, not the end of it. The Act attaches a set of continuing duties to whoever holds it.
The general obligations run roughly as follows. A Data Fiduciary must:
- Remain accountable for compliance, including for anything done by a processor it engages.
- Keep the data accurate and complete, particularly where it drives a decision about the person or gets shared onward.
- Protect it with reasonable security safeguards. The standard is prevention, not apology after the fact.
- Publish a contact for a Data Protection Officer or responsible person, and run a grievance route people can actually use.
If a personal data breach occurs, the fiduciary must inform both the Data Protection Board and every affected person. There is no harm threshold that lets a small breach go unreported.
It must erase personal data once the person withdraws consent, or as soon as it is reasonable to assume the purpose has been served, whichever comes first, unless a law requires it to be kept. Retention and erasure is the duty most organisations have no process for at all, because keeping everything forever has always been the path of least resistance.
Two categories of fiduciary carry more. Where children are involved, meaning anyone under eighteen, processing requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. The children’s data regime is one of the strictest parts of the Act. And an organisation notified by the Central Government as a Significant Data Fiduciary, based on data volume, sensitivity, and risk to rights or to the sovereignty and integrity of India, picks up additional duties: appointing a Data Protection Officer based in India, commissioning independent audits, and conducting Data Protection Impact Assessments.
Taken together these duties are less a checklist than an operating posture, and turning them into working practice inside a business is a separate discipline from understanding them.
Tools & walkthroughsIt is easier to see these duties than to describe them. DPDP in practice tears down real intake forms and flows line by line, marking what meets each obligation and what quietly fails it.
What rights do you have over your own data?
Every obligation above has a matching right, and this is the part of the Act that people are most surprised to learn exists. What you can ask for, and how, is the individual’s side of everything above.
You have the right to access information about your personal data: a summary of what a Data Fiduciary holds about you, what it is doing with it, and who else it has been shared with. How to ask, and what you should get back, is a straightforward process most people have never used.
You have the right to correction, completion, updating and erasure. If a company’s records about you are wrong, you can require them to be fixed; errors in records that drive decisions about you are not something you have to live with. And you can require your data to be deleted, and a company generally must honour that request unless retention is legally required.
You have the right to grievance redressal: a route to complain to the Data Fiduciary itself and get a response, which you must ordinarily use before escalating.
And you have the right to nominate another person to exercise your rights if you die or become incapable of acting for yourself. Digital accounts and records after death is a genuinely novel provision, and one with very little awareness behind it.
That last right raises a question the Act answers in more than one place: who may exercise these rights when the person cannot? Nomination covers death and incapacity. For a child, meaning anyone under eighteen, the rights belong to the child, but it is the parent or lawful guardian who exercises them, which is the same person whose verifiable consent was required before the data could be collected at all. The Act applies the same principle where a person with disability has a lawful guardian, though the verification is stricter there. A guardian must be shown to have been appointed by a court or a designated authority, not merely to claim the role. So the consent obligation and the rights machinery meet in the same place: whoever was entitled to agree on someone’s behalf is also the person entitled to ask, correct and withdraw on their behalf. What this means for parents in practice is one of the least understood corners of the law, and one of the few where the individual holding the right and the person exercising it are routinely different people.
Look at those four against the previous section and the symmetry is exact. The duty to keep data accurate is the right to correction. The duty to erase is the right to erasure. The duty to run a grievance mechanism is the right to redressal. The Act is not describing two systems; it is describing one, and it writes it out twice because obligations and rights need different words even when they name the same fact.
There is one part of this chapter that is not a mirror, and it is regularly left out of summaries: the Act also places duties on the Data Principal. You must not impersonate someone else when providing your data, must not suppress material information, must not register false or frivolous grievances, and must furnish only authentic information when exercising a right to correction. These are enforceable, with a penalty of up to ten thousand rupees. The number is small next to the penalties on organisations, but its presence tells you something about how the Act was designed: it is a framework of mutual obligation, not a one-way instrument.
What do the DPDP Rules add?
The Act states the duties. The Rules specify how they are actually performed, and the specifics are where compliance is won or lost.
An Act of Parliament sets obligations at the level of principle: give notice, report a breach, obtain verifiable parental consent. It does not say what a notice must look like on a signup page, how many hours you have, or what counts as verifying a parent. That is the work of the Digital Personal Data Protection Rules, 2025, and it is why the Act sat dormant from 2023 until the Rules arrived in November 2025.
Some of what they add:
Notice content and form. A notice must be capable of being understood independently of anything else the organisation has made available. It cannot lean on a privacy policy or a set of terms to make sense. In clear and plain language it must give an itemised description of the personal data being collected, the specified purpose together with a specific description of the goods or services involved, and the communication link through which the person can withdraw consent as easily as they gave it, exercise their rights, and complain to the Board.
Breach reporting, in two stages. On becoming aware of a personal data breach, the Data Fiduciary must inform the Board and each affected person without delay, describing the nature and extent of the breach and its likely consequences in plain language. It must then provide the Board with a detailed report within 72 hours, covering the circumstances, the remedial steps taken, and its findings on who was responsible. The widely repeated shorthand that you have “72 hours to report a breach” gets this wrong in a way that matters: the 72 hours is the deadline for the full report, not a grace period before you act. And a cyber incident can simultaneously trigger CERT-In’s separate six-hour obligation under the IT Act.
How rights requests must be handled. The Rules require a Data Fiduciary to publish the means by which a person makes a request, and the identifiers they should furnish so their record can be found. The grievance redressal route carries an outer limit of a response within a reasonable period not exceeding ninety days, and a published timeframe shorter than that is what a complainant will hold the organisation to.
Erasure, with a warning first. For specified classes of Data Fiduciary the Rules set retention periods in the Third Schedule, after which personal data must be erased unless a law requires keeping it. Before that point arrives the person must be told: at least forty-eight hours before the erasure deadline, the Data Fiduciary has to inform them that the data is about to be deleted, so they have a chance to act. Separately, personal data, associated traffic data and processing logs must be retained for a minimum of one year.
Verifiable parental consent. The Rules describe how a fiduciary must satisfy itself that the person consenting is genuinely an adult parent or guardian, with carve-outs for essential services such as healthcare, education and child safety. What actually counts as verification is more demanding than a tick-box declaring adulthood.
Consent Managers. The Rules set the conditions for Consent Managers, the Board-registered platforms through which a person can give, review and withdraw consents across many services from one place. They must be companies incorporated in India and meet financial and technical thresholds. This part of the framework carries its own twelve-month clock.
Tools & walkthroughsMost of what the Rules ask for is a process rather than a document. Build-your-own guides walks through assembling each one yourself: a rights-request pipeline, a retention schedule, a breach-response plan, a record of processing.
What happens if an organisation breaks the law?
Enforcement runs through a dedicated regulator, and the penalties are large enough to be a board-level concern.
The Data Protection Board of India is the body that receives complaints, decides whether to inquire, and imposes penalties. It functions as an adjudicating body rather than a broad rule-making regulator. A person who believes their data has been mishandled ordinarily raises it with the Data Fiduciary’s grievance mechanism first, and escalates to the Board if that fails. What the Board does with a complaint is a defined process, and its orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal.
The financial exposure is tiered by what went wrong:
- Security failure - not taking reasonable safeguards, up to ₹250 crore.
- Unreported breach - failing to tell the Board and the people affected, up to ₹200 crore.
- Children’s data - breaching the obligations around under-18s, up to ₹200 crore.
- Significant Data Fiduciary - failing the additional duties, up to ₹150 crore.
- Anything else - any other contravention of the Act or its Rules, up to ₹50 crore.
- Data Principal duties - impersonation or a false complaint, up to ₹10,000. The penalty structure rewards reading closely: the largest single number attaches to security failure, which is the obligation most often treated as an IT housekeeping matter.
One honest limitation is worth stating plainly, because it is frequently misunderstood. Penalties under this Act are payable to the government, not to the affected individuals. The DPDP Act does not create a route for a person to claim compensation for harm suffered. If you are looking for damages, this is not the instrument that provides them.
What does the DPDP Act not cover?
A number of situations are carved out, and knowing them prevents both false alarm and false comfort.
The Act sets out exemptions covering, among others:
- Legal claims - processing necessary to enforce a legal right or claim.
- Courts and regulators - processing by courts and tribunals, and by bodies performing judicial, quasi-judicial or regulatory functions.
- Law enforcement - processing to prevent, detect, investigate or prosecute an offence.
- Non-resident data - processing under a contract with a person outside India.
- Corporate restructuring - certain mergers or arrangements approved by a court or regulator.
- Loan defaulters - ascertaining the financial information, assets and liabilities of someone who has defaulted. Processing for research, archiving or statistical purposes is exempt where it is not used to make a decision specific to a particular person. The Central Government may also exempt State instrumentalities in the interests of sovereignty, security, public order and similar grounds, and may exempt certain classes of Data Fiduciary, including startups, from some provisions.
Cross-border transfer works differently from what many expect. The Act does not require personal data to stay in India by default. Instead, the Central Government may restrict transfer to particular countries or territories by notification. That is a negative-list model rather than a whitelist. Sectoral regulators can and do impose stricter localisation requirements of their own, and where another law is more protective, that stricter law prevails. Cross-border transfer is therefore governed by the Act plus whatever your sector requires on top.
And as covered earlier, purely personal or domestic processing, and personal data the individual has themselves made public, sit outside the Act altogether.
What is in force now, and what is coming?
The law arrived in stages, and the date most organisations need to plan around is 13 May 2027.
The Rules were notified on 13 November 2025 and use a staggered commencement. The institutional machinery (the Data Protection Board, the definitions, the framework of penalties) came into force immediately, which means the regulator exists and can act. The Consent Manager framework carries a twelve-month clock, landing on 13 November 2026. And the substantive obligations that most organisations actually have to implement, from notice and consent through to security safeguards, breach reporting, retention and erasure, rights fulfilment, the children’s data regime and Significant Data Fiduciary duties, become binding eighteen months after notification, on 13 May 2027.
That date deserves to be read as a build deadline rather than a start date. None of these obligations is a switch to be flipped. Capturing consent correctly at every point of intake, being able to produce a record of who agreed to what, standing up a breach response that works at three in the morning, and being able to find every copy of one person’s data when they ask for it: these are systems and habits, and they take months to establish. The full commencement timeline sets out precisely what lands when, and anything that moves after that is logged as it happens.
Beside the law, rather than inside it. Two things this article deliberately leaves out are habits rather than obligations. The DPDP Act does not prescribe how a document should travel from one person to another, or what an individual ought to do to look after their own records. But in practice those habits decide whether the duties above can be met at all.
Safe document handling covers how personal documents should be collected, sent, stored and disposed of: the operational layer beneath consent and security.
Protecting your personal data is the same question from the individual’s side: what you can do on your own account, without waiting for anyone else to comply.
FAQ
Is the DPDP Act in force right now?
Partly. The Data Protection Board, the definitions and the penalty framework have been in force since the Rules were notified on 13 November 2025. The substantive obligations most organisations must meet become binding on 13 May 2027.
Does the DPDP Act apply to small businesses?
Yes. The Act contains no general small-business exemption. Any organisation that decides why and how personal data is processed is a Data Fiduciary, whatever its size, though the Government may exempt certain classes including startups from some provisions.
Is there a separate category of sensitive personal data?
No. Unlike the earlier SPDI Rules, the DPDP Act does not create a separate sensitive category. All personal data attracts the same baseline duties, though children’s data and Significant Data Fiduciaries carry additional obligations.
Can I claim compensation if my data is misused?
Not under this Act. Penalties imposed by the Data Protection Board are payable to the government. The DPDP Act does not provide a route for individuals to recover damages.
Does personal data have to be stored in India?
Not as a default rule under this Act. The Central Government may restrict transfers to specified countries by notification, and sectoral regulators may impose stricter localisation requirements that continue to apply.