Jump to: Latest News ⚡ Live Intel 🔬 Research Labs 📡 All News →
🇮🇳 DPDP Act 2023

Digital Personal Data Protection Act 2023

Complete compliance reference — definitions, obligations, data principal rights, consent requirements, breach notification, cross-border transfers, penalties, and implementation checklist.

⚠️ Status: The DPDP Act received Presidential assent on 11 August 2023. Rules are being finalised by MeitY. The Act establishes the framework; rules will specify timelines, formats, and procedural requirements. Organisations should begin compliance preparation now.

What is the DPDP Act 2023?

The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law. It governs the processing of digital personal data of individuals (Data Principals) by organisations (Data Fiduciaries). The Act replaces the earlier IT Act provisions on data protection and brings India's framework closer to global standards like GDPR.

ItemDetail
Full nameThe Digital Personal Data Protection Act, 2023
Short titleDPDP Act 2023
Presidential assent11 August 2023
Gazette notification12 August 2023
Rules statusDPDP Rules being finalised by MeitY (2024–2025)
Regulatory authorityData Protection Board of India (DPBI) — to be established by Central Government
Chapters7 Chapters, 44 Sections
ScopeProcessing of digital personal data of Data Principals in India; also processing outside India if it involves offering goods/services in India
ExclusionsPersonal data processed for personal/domestic purposes; publicly made available by the Data Principal
ReplacesSection 43A and related IT Act provisions on sensitive personal data

Key Structural Changes from Previous Law

AspectPre-DPDP (IT Act / SPDI Rules 2011)DPDP Act 2023
ScopeOnly SPDI (sensitive personal data), paper data excludedAll digital personal data, regardless of sensitivity category
Lawful basisConsent only (with limited exceptions)Consent + Legitimate Uses (specified in Section 7)
Children's dataNo specific provisionsVerifiable parental consent mandatory; no tracking/behavioural monitoring of children
Data localisationRBI/SEBI sector mandates onlyAct itself does not mandate — but cross-border rules apply
RegulatorNo dedicated regulatorData Protection Board of India (adjudicatory body)
Penalties₹5 crore max under IT ActUp to ₹250 crore per violation
Data processor liabilityNot directly regulatedProcessors have direct obligations under the Act
Individual rightsLimited — only access and correction7 rights including erasure, grievance, and nomination

Key Definitions (Section 2)

Personal Data
Any data about an individual who is identifiable by or in relation to such data. Unlike GDPR, no distinction between personal and sensitive personal data categories in DPDP (children's data treated separately).
Section 2(t)
Data Principal
The individual to whom the personal data relates. In the case of a child (under 18), the parent or lawful guardian.
Section 2(j)
Data Fiduciary
Any person/entity that determines the purpose and means of processing personal data. Analogous to "Data Controller" under GDPR.
Section 2(i)
Significant Data Fiduciary (SDF)
Data Fiduciary notified by the Central Government based on volume and sensitivity of data, national security risk, or societal risk. Subject to additional obligations.
Section 10
Data Processor
Any person who processes personal data on behalf of a Data Fiduciary. Analogous to GDPR "Data Processor".
Section 2(k)
Consent Manager
An entity registered with DPBI through which a Data Principal can give, manage, review, and withdraw consent. A new intermediary model unique to DPDP.
Section 2(g)
Processing
Any operation on personal data including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transmission, erasure, or destruction.
Section 2(x)
Data Breach
Unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data.
Section 2(h)
Legitimate Uses
Processing without consent for specific purposes: state functions, medical emergencies, employment purposes, public interest. Exhaustive list in Section 7.
Section 7
Consent Manager
A registered entity through which Data Principals can give/withdraw consent. Must be registered with DPBI and maintain interoperability.
Section 6(7)
Child
A person under the age of 18 years. Verifiable parental consent required before processing any personal data of a child.
Section 2(d)
Data Protection Board of India
The adjudicatory body established to inquire into data breaches and complaints by Data Principals. Can impose penalties up to ₹250 crore.
Section 18
Nomination
A new right allowing Data Principals to nominate another person to exercise their rights in the event of death or incapacity.
Section 14
Deemed Consent
Certain processing activities are treated as having consent without an explicit consent request — e.g. voluntarily provided data for a specific purpose.
Section 8
Significant Data Fiduciary
Central Government notified entities subject to additional obligations: DPO appointment, DPIA, independent audits, algorithm assessment.
Section 10
Grievance Redressal
Data Fiduciaries must have a published mechanism to address Data Principal grievances. Complaints to DPBI only after fiduciary exhausts grievance process.
Section 13

Data Fiduciary Obligations

All entities that determine the purpose and means of processing personal data must comply with these obligations, regardless of size or sector.

§ 5
Purpose Limitation
Personal data may only be used for the specific purpose for which consent was given or for which legitimate use applies. Processing for any other purpose is unlawful.
§ 6
Consent Notice
Before requesting consent, provide a clear and plain-language notice describing: what personal data will be collected, the purpose, how rights can be exercised, and how complaints can be filed.
§ 6
Consent Withdrawal
Must provide a mechanism for Data Principals to withdraw consent as easily as it was given. Processing after withdrawal must cease (unless legitimate use applies).
§ 8(3)
Data Quality
Reasonable efforts to ensure accuracy and completeness of personal data that may be used to make decisions affecting the Data Principal or that may be disclosed to others.
§ 8(7)
Storage Limitation
Retain personal data only for as long as necessary for the specified purpose. Erase data when the purpose is fulfilled or consent is withdrawn (unless retention is required by law).
§ 8(5)
Security Safeguards
Implement reasonable security safeguards to prevent data breaches — including technical measures appropriate to the volume and nature of the data processed.
§ 8(6)
Breach Notification
Notify the Data Protection Board and each affected Data Principal of a personal data breach in the prescribed manner and timeframe (Rules to specify — expected 72 hours).
§ 9
Children's Data Protection
Obtain verifiable parental consent before processing any personal data of a child (under 18). Prohibition on processing children's data that is likely to cause harm. No tracking, behavioural monitoring, or targeted advertising directed at children.
§ 10
SDF Additional Obligations
If notified as Significant Data Fiduciary: appoint a Data Protection Officer (Indian resident), conduct Data Protection Impact Assessments, commission independent data audits, ensure algorithmic accountability.
§ 11
Data Processor Contracts
Data processing must be conducted under a valid contract with Data Processors. Processors can only process data as instructed by the Fiduciary and must implement security safeguards.
§ 12
Grievance Mechanism
Publish a conspicuous and readily accessible mechanism to enable Data Principals to contact the Data Fiduciary with grievances. Address grievances within a reasonable time.
§ 16
Obligations on Data Principals
Data Principals must not impersonate another person when providing personal data, suppress material information, or file false/frivolous complaints.

Additional Obligations for Significant Data Fiduciaries (Section 10)

ObligationRequirementRationale
Data Protection OfficerAppoint a DPO who is a Key Managerial Personnel or a senior employee — must be resident in India. DPO is the contact point for DPBI.Accountability and single point of contact for regulatory enquiries.
Data Protection Impact AssessmentConduct DPIA for processing activities that are likely to create high risk for Data Principals.Proactive risk identification before deployment.
Periodic auditCommission independent audits of its compliance with the Act by a Data Auditor (registered with DPBI).Third-party verification of compliance posture.
Algorithmic accountabilityConduct assessment of risks from algorithmic profiling and automated decision-making that may harm Data Principals.Addresses AI/ML risks — relevant to fintech, insurtech, lendingtech.
No consent for children's data (certain categories)Central Government may exempt certain Data Fiduciaries from children's consent requirements based on specified safeguards being met.Age-appropriate design framework.

Data Principal Rights (Sections 11–14)

The DPDP Act grants individuals seven rights over their personal data. These can be exercised at any time, subject to the Data Fiduciary's grievance redressal process.

Right to Access Information (§ 11)
Request a summary of: personal data being processed, processing activities, identities of all Data Fiduciaries and Processors with whom data has been shared, and any other information as prescribed.
→ How to exercise: Submit a written request to the Data Fiduciary's grievance officer or DPO. Response must be provided within a reasonable time (Rules will specify). Free of charge for the first request.
Right to Correction and Erasure (§ 12)
Request correction of inaccurate or misleading personal data. Request completion of incomplete data. Request erasure of personal data that is no longer necessary for the purpose it was collected.
→ How to exercise: Submit correction/erasure request to the Data Fiduciary. Fiduciary must act unless the data is legally required to be retained. Data Processors and other Fiduciaries who received the data must also be informed.
Right to Grievance Redressal (§ 13)
File a complaint with the Data Fiduciary's published grievance mechanism for any violation of their rights under the Act. If not resolved, escalate to the Data Protection Board.
→ Process: First to Fiduciary → then to Board (only after fiduciary grievance process is exhausted). Board can impose penalties if violation is established.
Right to Nominate (§ 14)
Nominate any individual to exercise the Data Principal's rights in the event of their death or incapacity to exercise rights. A right unique to the DPDP Act — not present in GDPR.
→ How to exercise: Submit nomination to the Data Fiduciary. Nominee has the same rights as the Data Principal once the nomination is activated.
Right to Withdraw Consent (§ 6(4))
Withdraw consent given for any processing activity at any time. Withdrawal must be as easy as giving consent. Upon withdrawal, processing must cease and data must be erased unless retention is legally required.
→ Note: Withdrawal does not affect the lawfulness of processing based on consent before withdrawal. Withdrawal from processing under legitimate use is not a right — only consent-based processing.
Right against Automated Decision-Making (Significant Data Fiduciaries)
For processing by Significant Data Fiduciaries that involves automated decision-making with significant effects, Data Principals have the right to information about and assessment of algorithmic processing.
→ Note: The specific rights against automated processing apply primarily to Significant Data Fiduciaries — not all Data Fiduciaries. Details in Rules.
Right to Seek Redressal from DPBI (§ 13(2))
After exhausting the Data Fiduciary's grievance mechanism, file a complaint with the Data Protection Board. The Board can summon, investigate, and impose penalties.
→ Process: File complaint with DPBI → Board appoints inquiry officer → parties heard → order passed → appeal to High Court (under CPC).

Personal Data Breach Notification (Section 8(6))

The DPDP Act mandates breach notification to both the Data Protection Board AND each affected Data Principal. Timelines and formats will be specified in DPDP Rules (expected to mirror CERT-In's 6-hour requirement or GDPR's 72-hour standard).

Who Must Be Notified

RecipientWhat to notifyTimeline
Data Protection Board of IndiaNature of the breach, categories and approximate number of Data Principals affected, categories and approximate number of personal data records affected, likely consequences, measures taken or proposed to address the breach.As per Rules — likely 72 hours from discovery (Rules pending)
Each affected Data PrincipalDescription of the personal data breach in clear and plain language. How the Data Principal can protect themselves (e.g. change passwords). Contact details for more information.As per Rules — promptly after Board notification
Relevant sector regulatorIn addition to DPBI — if the Data Fiduciary is also regulated by RBI, SEBI, IRDAI, TRAI: also notify sectoral regulator per their specific breach notification requirements.Per sectoral regulation: CERT-In 6h, RBI 2-6h, SEBI immediately

Definition of Personal Data Breach (Section 2(h))

Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises the confidentiality, integrity or availability of the data.

Note: Unlike GDPR, there is no "likely to result in harm" threshold for notification. Any breach that meets the definition must be reported — even low-risk breaches.

Breach Response Checklist (Internal)

1
Detect & Contain
Identify the nature and scope of the breach. Isolate affected systems. Stop ongoing exfiltration or unauthorised access.
2
Assess
Determine: categories of personal data affected, number of Data Principals affected, potential consequences, root cause.
3
Notify DPBI
Prepare and submit breach notification to Data Protection Board within prescribed timeframe. Include: nature, scope, impact, remediation.
4
Notify Data Principals
Send individual notifications to affected Data Principals in clear language. Include: what happened, what data was affected, steps to protect themselves, contact details.
5
Notify sectoral regulators
Submit additional notifications to RBI, SEBI, CERT-In, or other sectoral regulators as applicable per their timelines.
6
Remediate
Fix root cause, patch vulnerabilities, implement additional safeguards, update risk assessment.
7
Document
Maintain a full record of the breach, investigation findings, notification sent, and remediation actions for audit purposes.

Interaction with CERT-In Directions 2022

ObligationCERT-In Directions 2022DPDP Act 2023
TriggerAny cyber security incident (broad)Personal data breach specifically
Timeline6 hours from detectionAs per Rules (expected 72h or similar)
RecipientCERT-In onlyData Protection Board + affected individuals
Who must complyAll companies, intermediaries, government bodiesAll Data Fiduciaries
PenaltiesUp to ₹1 crore + directionsUp to ₹250 crore (DPBI)
Practical impactBoth obligations apply simultaneously for personal data breaches — comply with bothMust file separate notifications to CERT-In and DPBI

Cross-Border Data Transfers (Section 16)

The DPDP Act permits transfer of personal data to other countries, except to countries that the Central Government specifically restricts or prohibits through a notification. This is a significant departure from the pre-existing patchwork of sectoral localisation mandates.

Transfer Framework

ModelHow it works
Whitelist approach (Central Government)Central Government may notify countries to which transfer is permitted — or conversely, countries to which transfer is restricted/prohibited. No list has been notified yet.
Default positionUntil a restriction is notified, transfers are permitted to any country — subject to other obligations (data must still be processed only for the consented purpose).
Contractual safeguardsNot explicitly required by the Act — but recommended as due diligence, especially when transferring to countries with weaker data protection laws.
Data localisationThe DPDP Act does not introduce a general data localisation mandate — unlike what was proposed in the PDPB 2019. Sector-specific mandates (RBI, IRDAI, SEBI) continue to apply independently.

Sectoral Data Localisation (Still Applicable)

RegulatorLocalisation requirementScope
RBIAll payment transaction data, full end-to-end transaction details must be stored only in India (RBI PA/PG Circular, 2018)Payment aggregators, payment gateways, banks, card networks
RBI (Banks)Customer data of Indian customers must be stored in India. For foreign banks — data on Indian customers cannot be mirrored abroad without RBI approval.All RBI-regulated entities
IRDAIInsurance data of Indian policyholders must be stored in IndiaInsurance companies regulated by IRDAI
SEBIMarket infrastructure data must be stored in India. Foreign exchanges operating in India: GIFT City specific provisions.Stock exchanges, depositories, clearing corporations
MeitY (Government cloud)Sensitive government data on government systems must use MeitY-empanelled cloud providers — no cross-border storage.Government entities and their cloud deployments
DPDP Act (future)Central Government may notify restricted countries for personal data transfers — not yet operationalised.All Data Fiduciaries (once notified)

Practical Implications for Cloud and SaaS Vendors

US-headquartered SaaS Processing Indian user data is subject to DPDP Act — must provide consent notice, honour data rights, notify breaches. Consider appoint ing a local DPO if SDF.
Multi-cloud / hybrid No general localisation under DPDP — but sectoral rules may require specific workloads to stay in India. Map data flows to identify regulated datasets.
Sub-processors Must have contractual protections — Fiduciary remains responsible for Processor's compliance. Processor cannot further sub-process without Fiduciary authorisation.
EU companies with India operations GDPR + DPDP both apply to the extent Indian users' data is involved. Requirements are similar but not identical — consent notice format, rights timelines may differ.

Penalty Structure (Schedule to Section 33)

The Data Protection Board can impose monetary penalties up to the amounts specified in the Schedule. Penalties are imposed after an inquiry — the Board has discretion to impose lower amounts based on circumstances.

Failure to safeguard children's personal data or process data of children in violation of Section 9
₹250 crore
Most serious offence — child data protection
Failure to implement reasonable security safeguards resulting in a personal data breach (Section 8(5))
₹200 crore
Security breach due to inadequate safeguards
Failure to notify the Board and affected Data Principals of a personal data breach (Section 8(6))
₹200 crore
Breach notification failure
Non-compliance with additional obligations applicable to Significant Data Fiduciaries (Section 10)
₹150 crore
SDF-specific violations
Data Principal providing false particulars, suppressing material information, impersonating another person (Section 16)
₹10,000
Obligations on individuals

Penalty Determination Factors

The Board must consider the following when determining the penalty quantum:

Nature, gravity, and duration of non-compliance
Type of personal data affected
Repetitive nature of the non-compliance
Whether the violation was deliberate or negligent
Action taken to mitigate the damage or distress to the Data Principal
Whether the Data Fiduciary gave timely notice of the breach
Revenue and financial capacity of the Data Fiduciary
Whether the Data Fiduciary cooperated with the Board during the inquiry

Comparison with Other Regimes

RegimeMaximum penaltyBasis
DPDP Act 2023 (India)₹250 crore (~$30M)Per violation
GDPR (EU)€20 million or 4% of global annual turnover (whichever higher)Per violation — % of turnover is typically much larger
CERT-In Directions 2022 (India)₹1 crore + directionsPer violation
IT Act 2000, S.43A (old)Compensation determined by court — no fixed capCivil remedy
RBI (Data breach)Monetary penalty + licence conditions + directionsPer violation
PDPB 2019 (never enacted)₹15 crore or 4% of global turnoverWas higher % than DPDP Act

DPDP Act Compliance Checklist

Progress saves automatically in your browser.

Data Mapping & Inventory
Consent Management
Data Principal Rights Implementation
Security Safeguards
Breach Notification Readiness
Third-Party & Processor Management
Significant Data Fiduciary (if applicable)
Governance & Documentation

Sector-Specific Applicability

SectorKey Data TypesAdditional RegulatorsDPDP Priority Actions
Banking & NBFC Customer KYC, transaction history, credit data, Aadhaar-linked data RBI Consent for marketing vs account management (separate purposes); children's savings accounts (parental consent); breach notification to both DPBI and RBI
Insurance Policyholder health data, nominee details, claim records IRDAI Health data processing (sensitive but not separately classified under DPDP); data localisation compliance; consent for third-party data sharing
Fintech / Payments UPI transaction data, payment history, device fingerprints RBI, NPCI Payment data localisation (RBI mandate); consent for credit scoring; children's data (minor accounts)
Healthcare Patient health records, diagnostic data, treatment history, biometrics NMC, CDSCO (sector-specific) No separate "sensitive data" category — all personal data covered; consent critical; breach notification for EHR systems
EdTech Student data, learning history, assessments, parental data UGC (sector guidance) Children's data — majority of users under 18; verifiable parental consent mandatory; no behavioural profiling of minors
E-Commerce & Retail Purchase history, address, payment data, browsing behaviour CCI (competition concerns) Purpose limitation for recommendations; right to erasure for inactive accounts; consent for marketing profiling
HR & Recruitment Candidate data, employee records, biometric attendance, salary data Labour law compliance Legitimate use for employment (Section 7(f)); consent for third-party background checks; data erasure after recruitment rejection
Government & PSUs Citizen data, Aadhaar-linked records, welfare scheme data MeitY, UIDAI Government processing under Legitimate Use (Section 7(a)); UIDAI Aadhaar regulations apply separately; DPDP exemptions for state functions

Exemptions Under the DPDP Act (Section 17)

ExemptionScope
Personal / domestic useProcessing by an individual for personal or domestic purposes — e.g. personal WhatsApp, personal diary app. Not applicable to businesses.
Publicly available dataPersonal data that the Data Principal has made publicly available (e.g. public social media posts). Does not extend to aggregation or profiling.
Research and archivingProcessing for research, archiving, or statistical purposes in the public interest — subject to not identifying individuals and not being used for harmful purposes.
National security / defenceCentral Government may exempt any instrumentality of the State from any provisions of the Act in the interest of sovereignty, security, friendly relations, public order, or prevention of offences.
Law enforcementCourts and judicial proceedings; legal obligations; prevention, detection, investigation, prosecution, and punishment of offences.
Startups (expected)Central Government is expected to provide exemptions or relaxations for startups and small businesses in the Rules — details pending.