DPDP Act
Digital Personal Data Protection Act 2023 (India)
India's comprehensive privacy law, consent-centered, with duties for significant data fiduciaries.
The law in brief
India's Digital Personal Data Protection Act 2023 is the country's first comprehensive privacy law. It is built around consent: organizations (data fiduciaries) must give clear notice and obtain consent for most processing, with a limited list of other legitimate uses. It adds heavy duties for significant data fiduciaries designated by the government and strict rules for children's data.
The Digital Personal Data Protection Rules were notified on 13 November 2025, and the law is coming into force in phases. The core duties apply from 13 May 2027.
Who it applies to
- Processing of digital personal data within India, whether collected digitally or digitized later.
- Processing outside India in connection with offering goods or services to individuals in India.
- Data fiduciaries, which decide the purpose and means of processing, and data processors acting for them.
- It does not apply to personal data an individual makes publicly available, or to purely personal or domestic use.
What it requires
Notice and consent
Process personal data only for a lawful purpose with the data principal's consent, given after an itemized notice, or for a legitimate use listed in the Act.
Security safeguards and breach intimation
Take reasonable security safeguards to prevent breaches, and notify the Board and each affected data principal of a breach in the form and manner the Rules prescribe.
Erase when the purpose ends
Erase personal data when the data principal withdraws consent or the purpose is no longer being served, unless retention is required by law.
Children's data
Obtain verifiable consent from a parent or guardian before processing a child's data, and do not track, monitor behavior or target advertising at children.
Significant data fiduciaries
Fiduciaries designated as significant appoint a data protection officer based in India, an independent data auditor, and carry out periodic impact assessments and audits.
People's rights
Individuals (data principals) can get a summary of their data and processing, correct, complete, update and erase it, have grievances addressed, and nominate someone to exercise their rights on death or incapacity. They can withdraw consent as easily as they gave it.
Enforcement and penalties
The Data Protection Board of India can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, with lower maximums for other failures such as breach notification, children's data and significant data fiduciary duties (Schedule). There is no private right to compensation under the Act.
What's changing
Phased commencement. The Data Protection Board provisions took effect on 13 November 2025. Rules on consent managers take effect on 13 November 2026. Notice, consent, security, breach notification, rights, children's data and significant data fiduciary duties take effect on 13 May 2027.
What to do first
- Map digital personal data of individuals in India and each purpose.
- Rewrite notices as standalone, itemized notices in clear language.
- Rebuild consent so it is free, specific, informed and as easy to withdraw as to give.
- Plan breach intimation to the Board and to each affected individual.
- Prepare verifiable parental consent for children under 18 and stop tracking or targeted ads to them.
- Set retention and erasure when purposes end, and a grievance channel.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Digital Personal Data Protection Act, 2023 Ministry of Electronics and Information Technology · Official text or regulator