At a glanceIndia’s new data privacy law is the Digital Personal Data Protection Act — a dedicated law that controls how any organisation collects, uses and stores your personal data. It gives you rights over your own information (to see it, correct it, and have it deleted), and it makes the businesses handling your data legally responsible for protecting it. It applies to almost any company that takes your details digitally, from an app to a local clinic.
Educational resource only. This explains, in plain English, what India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is and what it means for you; it is not formal legal advice.
What is the law, exactly?
For the first time, India has a single law dedicated only to protecting your personal data.
Until recently, India had no standalone privacy law. Scattered rules under the Information Technology Act (IT Act) covered some “sensitive” data, but there was no comprehensive protection for the everyday information you hand over dozens of times a week — your name, phone number, email, Aadhaar, PAN, or a photo of your ID.
The Digital Personal Data Protection Act, 2023 — usually shortened to the DPDP Act — changes that. It is a dedicated law that sets clear rules for how organisations are allowed to handle your personal data, and it backs those rules with a regulator and real financial penalties. Think of it as a rulebook that finally says, in law, what a company can and can’t do with the information you give it.
“Personal data” here means any information that can identify you. That is deliberately broad: it isn’t only bank details or Aadhaar numbers, but also your name, contact details, and photographs.
Whose data does it protect?
It protects you — every individual in India whose data is being collected — and puts the legal burden on the organisation, not on you.
The law uses two plain roles. You, the person the data is about, are the Data Principal. The organisation that decides why and how your data gets used — the shop, the app, the hospital, the housing society — is the Data Fiduciary. The word “fiduciary” is doing real work: it signals that the organisation holds your data in a position of trust and carries the responsibility to protect it.
That framing matters. The obligation to handle your data properly sits with the organisation, not with you. You don’t have to become an expert or read the fine print to be protected — the duty to get consent, explain the purpose, keep the data safe, and delete it when it’s no longer needed is theirs by law.
What does it actually let you do?
It gives you a set of rights you can use against any company holding your data.
In practical terms, the DPDP Act gives you the ability to:
- Know what’s being collected and why — before you hand over your data, the organisation must give you a clear notice explaining what it’s taking and the purpose.
- See what a company holds about you — you can ask an organisation for a summary of the personal data it has on you.
- Get errors fixed — if their records about you are wrong or out of date, you can ask for a correction.
- Have your data deleted — once the purpose is over, or you withdraw consent, you can ask for your data to be erased.
- Withdraw consent — you can take back permission you earlier gave, and it should be as easy to withdraw as it was to give.
- Complain and be heard — every organisation must offer a way to raise a grievance, and you can escalate to the Data Protection Board of India if it isn’t resolved.
These aren’t favours a company grants — they are obligations the law places on it.
Are these protections in force yet?
The Act is being phased in, with full compliance due by 13 May 2027 — but the direction is set and organisations are already on the clock.
The Act passed in 2023 and its detailed rules were notified in November 2025, with businesses required to be fully compliant by 13 May 2027. That doesn’t mean your rights are imaginary until then — organisations are in the window where they’re expected to build the compliant consent, deletion and rights-handling the law demands. So if a company today can’t tell you what data it holds or won’t delete it, that’s a gap they’re now on a clock to close.
For how the phase-in works and how it’s enforced — the regulator, the penalties, the deadline — see What the government is doing to protect your personal data.
FAQ
What is the new data privacy law in India called?
The Digital Personal Data Protection Act, 2023, usually shortened to the DPDP Act. It is India’s first dedicated law for protecting personal data.
Does it protect my Aadhaar and PAN specifically?
Yes — but not only those. The Act protects all personal data that can identify you, including your name, phone number, email and photographs, alongside documents like Aadhaar and PAN.
Does the law apply to small businesses and apps, or only big companies?
It applies to almost any organisation that decides how and why to use your personal data, regardless of size — a local clinic, a coaching class or a small app are all covered.
Do I have to do anything to be protected?
No. The legal responsibility to handle your data correctly sits with the organisation collecting it. Your rights exist automatically; you simply exercise them when you want to.