Digital Personal Data Protection Act 2023
Complete compliance reference — definitions, obligations, data principal rights, consent requirements, breach notification, cross-border transfers, penalties, and implementation checklist.
What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law. It governs the processing of digital personal data of individuals (Data Principals) by organisations (Data Fiduciaries). The Act replaces the earlier IT Act provisions on data protection and brings India's framework closer to global standards like GDPR.
| Item | Detail |
|---|---|
| Full name | The Digital Personal Data Protection Act, 2023 |
| Short title | DPDP Act 2023 |
| Presidential assent | 11 August 2023 |
| Gazette notification | 12 August 2023 |
| Rules status | DPDP Rules being finalised by MeitY (2024–2025) |
| Regulatory authority | Data Protection Board of India (DPBI) — to be established by Central Government |
| Chapters | 7 Chapters, 44 Sections |
| Scope | Processing of digital personal data of Data Principals in India; also processing outside India if it involves offering goods/services in India |
| Exclusions | Personal data processed for personal/domestic purposes; publicly made available by the Data Principal |
| Replaces | Section 43A and related IT Act provisions on sensitive personal data |
Key Structural Changes from Previous Law
| Aspect | Pre-DPDP (IT Act / SPDI Rules 2011) | DPDP Act 2023 |
|---|---|---|
| Scope | Only SPDI (sensitive personal data), paper data excluded | All digital personal data, regardless of sensitivity category |
| Lawful basis | Consent only (with limited exceptions) | Consent + Legitimate Uses (specified in Section 7) |
| Children's data | No specific provisions | Verifiable parental consent mandatory; no tracking/behavioural monitoring of children |
| Data localisation | RBI/SEBI sector mandates only | Act itself does not mandate — but cross-border rules apply |
| Regulator | No dedicated regulator | Data Protection Board of India (adjudicatory body) |
| Penalties | ₹5 crore max under IT Act | Up to ₹250 crore per violation |
| Data processor liability | Not directly regulated | Processors have direct obligations under the Act |
| Individual rights | Limited — only access and correction | 7 rights including erasure, grievance, and nomination |
Key Definitions (Section 2)
Data Fiduciary Obligations
All entities that determine the purpose and means of processing personal data must comply with these obligations, regardless of size or sector.
Additional Obligations for Significant Data Fiduciaries (Section 10)
| Obligation | Requirement | Rationale |
|---|---|---|
| Data Protection Officer | Appoint a DPO who is a Key Managerial Personnel or a senior employee — must be resident in India. DPO is the contact point for DPBI. | Accountability and single point of contact for regulatory enquiries. |
| Data Protection Impact Assessment | Conduct DPIA for processing activities that are likely to create high risk for Data Principals. | Proactive risk identification before deployment. |
| Periodic audit | Commission independent audits of its compliance with the Act by a Data Auditor (registered with DPBI). | Third-party verification of compliance posture. |
| Algorithmic accountability | Conduct assessment of risks from algorithmic profiling and automated decision-making that may harm Data Principals. | Addresses AI/ML risks — relevant to fintech, insurtech, lendingtech. |
| No consent for children's data (certain categories) | Central Government may exempt certain Data Fiduciaries from children's consent requirements based on specified safeguards being met. | Age-appropriate design framework. |
Consent — Requirements and Management
Consent is the primary lawful basis under the DPDP Act. It must meet strict requirements to be valid.
Valid Consent Requirements (Section 6)
Consent Notice Requirements (Section 6(1))
Every consent request must be accompanied by a notice containing:
Notice Format Requirements
| Requirement | Detail |
|---|---|
| Language | Available in English and each of the 22 scheduled languages as specified in the Eighth Schedule of the Constitution. |
| Plain language | Must be clear and plain — no legal jargon. A notice that is not easily understandable to a Data Principal is invalid. |
| Layered approach | Recommended: short notice at point of collection + detailed privacy policy accessible on demand. |
| Pre-existing data | Where personal data was collected before the DPDP Act, the Data Fiduciary must provide the required notice at the time of first contact after the Rules are notified. |
| Children | Notice must be given to the parent or lawful guardian, not to the child directly. |
Legitimate Uses — Processing Without Consent (Section 7)
The following are exhaustive categories where personal data may be processed without consent. These are not a general "legitimate interests" ground — they are specific and narrowly defined.
| # | Legitimate Use | Example |
|---|---|---|
| 7(a) | State and its instrumentalities for providing benefits, services, certificates, licences, or permits | Aadhaar-linked DBT, PAN verification, government scheme enrolment |
| 7(b) | State functions related to maintaining national security, public order, or exercising legal authority | Law enforcement, intelligence agencies acting under lawful authority |
| 7(c) | Compliance with any judgment or order of a court or tribunal or quasi-judicial authority | Court-ordered disclosure, tax tribunal proceedings |
| 7(d) | Medical emergency threatening life or health of the Data Principal or other persons | Hospital emergency room, emergency medical services |
| 7(e) | Epidemic, disease outbreak, or public health emergency declared by the State | Contact tracing during pandemic |
| 7(f) | Employment — by employer of personal data of its employees for employment purposes | Payroll, HR management, statutory compliance (PF/ESI) |
| 7(g) | Legitimate business purpose where Data Principal has voluntarily provided data and has not indicated a desire that processing should not occur | Visiting card given at a conference, contact details submitted to access a form |
Consent Manager (Section 6(7)–(9))
A Consent Manager is a registered intermediary that enables Data Principals to manage all their consents in one place — across multiple Data Fiduciaries. This is a significant departure from the GDPR model.
Data Principal Rights (Sections 11–14)
The DPDP Act grants individuals seven rights over their personal data. These can be exercised at any time, subject to the Data Fiduciary's grievance redressal process.
Personal Data Breach Notification (Section 8(6))
Who Must Be Notified
| Recipient | What to notify | Timeline |
|---|---|---|
| Data Protection Board of India | Nature of the breach, categories and approximate number of Data Principals affected, categories and approximate number of personal data records affected, likely consequences, measures taken or proposed to address the breach. | As per Rules — likely 72 hours from discovery (Rules pending) |
| Each affected Data Principal | Description of the personal data breach in clear and plain language. How the Data Principal can protect themselves (e.g. change passwords). Contact details for more information. | As per Rules — promptly after Board notification |
| Relevant sector regulator | In addition to DPBI — if the Data Fiduciary is also regulated by RBI, SEBI, IRDAI, TRAI: also notify sectoral regulator per their specific breach notification requirements. | Per sectoral regulation: CERT-In 6h, RBI 2-6h, SEBI immediately |
Definition of Personal Data Breach (Section 2(h))
Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises the confidentiality, integrity or availability of the data.
Note: Unlike GDPR, there is no "likely to result in harm" threshold for notification. Any breach that meets the definition must be reported — even low-risk breaches.
Breach Response Checklist (Internal)
Identify the nature and scope of the breach. Isolate affected systems. Stop ongoing exfiltration or unauthorised access.
Determine: categories of personal data affected, number of Data Principals affected, potential consequences, root cause.
Prepare and submit breach notification to Data Protection Board within prescribed timeframe. Include: nature, scope, impact, remediation.
Send individual notifications to affected Data Principals in clear language. Include: what happened, what data was affected, steps to protect themselves, contact details.
Submit additional notifications to RBI, SEBI, CERT-In, or other sectoral regulators as applicable per their timelines.
Fix root cause, patch vulnerabilities, implement additional safeguards, update risk assessment.
Maintain a full record of the breach, investigation findings, notification sent, and remediation actions for audit purposes.
Interaction with CERT-In Directions 2022
| Obligation | CERT-In Directions 2022 | DPDP Act 2023 |
|---|---|---|
| Trigger | Any cyber security incident (broad) | Personal data breach specifically |
| Timeline | 6 hours from detection | As per Rules (expected 72h or similar) |
| Recipient | CERT-In only | Data Protection Board + affected individuals |
| Who must comply | All companies, intermediaries, government bodies | All Data Fiduciaries |
| Penalties | Up to ₹1 crore + directions | Up to ₹250 crore (DPBI) |
| Practical impact | Both obligations apply simultaneously for personal data breaches — comply with both | Must file separate notifications to CERT-In and DPBI |
Cross-Border Data Transfers (Section 16)
The DPDP Act permits transfer of personal data to other countries, except to countries that the Central Government specifically restricts or prohibits through a notification. This is a significant departure from the pre-existing patchwork of sectoral localisation mandates.
Transfer Framework
| Model | How it works |
|---|---|
| Whitelist approach (Central Government) | Central Government may notify countries to which transfer is permitted — or conversely, countries to which transfer is restricted/prohibited. No list has been notified yet. |
| Default position | Until a restriction is notified, transfers are permitted to any country — subject to other obligations (data must still be processed only for the consented purpose). |
| Contractual safeguards | Not explicitly required by the Act — but recommended as due diligence, especially when transferring to countries with weaker data protection laws. |
| Data localisation | The DPDP Act does not introduce a general data localisation mandate — unlike what was proposed in the PDPB 2019. Sector-specific mandates (RBI, IRDAI, SEBI) continue to apply independently. |
Sectoral Data Localisation (Still Applicable)
| Regulator | Localisation requirement | Scope |
|---|---|---|
| RBI | All payment transaction data, full end-to-end transaction details must be stored only in India (RBI PA/PG Circular, 2018) | Payment aggregators, payment gateways, banks, card networks |
| RBI (Banks) | Customer data of Indian customers must be stored in India. For foreign banks — data on Indian customers cannot be mirrored abroad without RBI approval. | All RBI-regulated entities |
| IRDAI | Insurance data of Indian policyholders must be stored in India | Insurance companies regulated by IRDAI |
| SEBI | Market infrastructure data must be stored in India. Foreign exchanges operating in India: GIFT City specific provisions. | Stock exchanges, depositories, clearing corporations |
| MeitY (Government cloud) | Sensitive government data on government systems must use MeitY-empanelled cloud providers — no cross-border storage. | Government entities and their cloud deployments |
| DPDP Act (future) | Central Government may notify restricted countries for personal data transfers — not yet operationalised. | All Data Fiduciaries (once notified) |
Practical Implications for Cloud and SaaS Vendors
Penalty Structure (Schedule to Section 33)
The Data Protection Board can impose monetary penalties up to the amounts specified in the Schedule. Penalties are imposed after an inquiry — the Board has discretion to impose lower amounts based on circumstances.
Penalty Determination Factors
The Board must consider the following when determining the penalty quantum:
Comparison with Other Regimes
| Regime | Maximum penalty | Basis |
|---|---|---|
| DPDP Act 2023 (India) | ₹250 crore (~$30M) | Per violation |
| GDPR (EU) | €20 million or 4% of global annual turnover (whichever higher) | Per violation — % of turnover is typically much larger |
| CERT-In Directions 2022 (India) | ₹1 crore + directions | Per violation |
| IT Act 2000, S.43A (old) | Compensation determined by court — no fixed cap | Civil remedy |
| RBI (Data breach) | Monetary penalty + licence conditions + directions | Per violation |
| PDPB 2019 (never enacted) | ₹15 crore or 4% of global turnover | Was higher % than DPDP Act |
DPDP Act Compliance Checklist
Progress saves automatically in your browser.
Sector-Specific Applicability
| Sector | Key Data Types | Additional Regulators | DPDP Priority Actions |
|---|---|---|---|
| Banking & NBFC | Customer KYC, transaction history, credit data, Aadhaar-linked data | RBI | Consent for marketing vs account management (separate purposes); children's savings accounts (parental consent); breach notification to both DPBI and RBI |
| Insurance | Policyholder health data, nominee details, claim records | IRDAI | Health data processing (sensitive but not separately classified under DPDP); data localisation compliance; consent for third-party data sharing |
| Fintech / Payments | UPI transaction data, payment history, device fingerprints | RBI, NPCI | Payment data localisation (RBI mandate); consent for credit scoring; children's data (minor accounts) |
| Healthcare | Patient health records, diagnostic data, treatment history, biometrics | NMC, CDSCO (sector-specific) | No separate "sensitive data" category — all personal data covered; consent critical; breach notification for EHR systems |
| EdTech | Student data, learning history, assessments, parental data | UGC (sector guidance) | Children's data — majority of users under 18; verifiable parental consent mandatory; no behavioural profiling of minors |
| E-Commerce & Retail | Purchase history, address, payment data, browsing behaviour | CCI (competition concerns) | Purpose limitation for recommendations; right to erasure for inactive accounts; consent for marketing profiling |
| HR & Recruitment | Candidate data, employee records, biometric attendance, salary data | Labour law compliance | Legitimate use for employment (Section 7(f)); consent for third-party background checks; data erasure after recruitment rejection |
| Government & PSUs | Citizen data, Aadhaar-linked records, welfare scheme data | MeitY, UIDAI | Government processing under Legitimate Use (Section 7(a)); UIDAI Aadhaar regulations apply separately; DPDP exemptions for state functions |
Exemptions Under the DPDP Act (Section 17)
| Exemption | Scope |
|---|---|
| Personal / domestic use | Processing by an individual for personal or domestic purposes — e.g. personal WhatsApp, personal diary app. Not applicable to businesses. |
| Publicly available data | Personal data that the Data Principal has made publicly available (e.g. public social media posts). Does not extend to aggregation or profiling. |
| Research and archiving | Processing for research, archiving, or statistical purposes in the public interest — subject to not identifying individuals and not being used for harmful purposes. |
| National security / defence | Central Government may exempt any instrumentality of the State from any provisions of the Act in the interest of sovereignty, security, friendly relations, public order, or prevention of offences. |
| Law enforcement | Courts and judicial proceedings; legal obligations; prevention, detection, investigation, prosecution, and punishment of offences. |
| Startups (expected) | Central Government is expected to provide exemptions or relaxations for startups and small businesses in the Rules — details pending. |