Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
Corporate Law

DPDP Act 2023: Simple Guide for Businesses in India

Advertisement

Summary: The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 establish a phased framework for regulating the processing of digital personal data in India. The Rules, notified on 13 November 2025, provide for staged implementation, with the main compliance obligations becoming effective from 13 May 2027, while provisions relating to the Data Protection Board took effect immediately and Consent Manager obligations commence on 13 November 2026. The framework applies to digital personal data processed in India and, in specified circumstances, outside India where goods or services are offered to Data Principals in India. It sets out requirements relating to notices, consent, legitimate uses, security safeguards, breach intimation, data retention and erasure, grievance redressal, processing of children’s and persons with disabilities’ data, Significant Data Fiduciary obligations, Data Principal rights and duties, cross-border data transfers, exemptions, and the constitution and functioning of the Data Protection Board of India. The framework also prescribes financial penalties, including up to ₹250 crore for failure to take reasonable security safeguards and up to ₹200 crore for specified breaches relating to breach notification and children’s data.

DECODING INDIA’S DATA PROTECTION LAW

A Practitioner’s Guide to the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025

On 11 August 2023, India enacted the Digital Personal Data Protection Act, 2023 (“the Act”) — its first standalone law on personal data protection. For over two years, the Act existed largely on paper, awaiting the procedural rules that would make it operable. That gap closed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 (“the Rules”), setting out a phased roadmap for compliance. This article walks through the framework the two documents together create — who it applies to, what it demands of organisations that handle personal data, and how it will be enforced.

1. Applicability: Who Does the Law Cover?

The Act’s territorial and subject-matter reach is defined in Section 3. Four elements determine whether a given instance of processing falls within scope:

  • It applies to the processing of digital personal data within India, whether that data was collected digitally or was originally collected offline and later digitised.
  • It also reaches processing outside India, if that processing is connected with offering goods or services to Data Principals located in India — a deliberate extraterritorial reach modelled on the EU’s GDPR.
  • It is confined to personal data in digital form; purely offline, non-digitised personal data falls outside it.
  • It does not apply to personal data processed by an individual for personal or domestic purposes, nor to personal data that a Data Principal (or someone legally obliged to do so) has made publicly available — for example, information a person voluntarily posts on social media.

Section 17 of the Act carves out further exemptions — for enforcing legal rights, for courts and regulators discharging judicial or supervisory functions, for crime prevention and investigation, for cross-border commercial contracts, for mergers and restructurings, and for assessing a defaulting borrower’s assets — and empowers the Central Government to exempt instrumentalities of the State and, for up to five years from commencement, any other class of Data Fiduciary, including startups.

2. A Phased Rollout

Rather than switching on the entire compliance regime at once, the Rules bring different obligations into force in three stages, giving Data Fiduciaries lead time to build the necessary systems.

Phase 13 November 2025 (on notification) 13 November 2026 (+1 year) 13 May 2027 (+18 months)
What comes into force Rules 1, 2 and 17 to 21 — definitions, and the Board’s constitution, appointment of Chairperson/Members, salaries, meeting procedure and digital-office functioning, and officer/employee terms Rule 4 — registration and obligations of Consent Managers Rules 3, 5 to 16, 22 and 23 — notice, security safeguards, breach intimation, erasure timelines, children’s/PwD consent, Significant Data Fiduciary duties, Data Principal rights, cross-border transfer, research exemption, appeals and government information calls

In practical terms, this means the bulk of the operative compliance burden — notices, consent mechanics, security safeguards, breach reporting, erasure timelines, children’s-data safeguards, and the rights of Data Principals — only takes effect from 13 May 2027, while the Consent Manager ecosystem is expected to be functional a year earlier, and the Data Protection Board’s own institutional machinery was set up immediately upon notification.

3. Key Definitions

A handful of defined terms recur throughout the Act and Rules, and getting them right is the starting point for any compliance exercise (Section 2 of the Act):

  • Personal data — any data about an individual who is identifiable by or in relation to that data.
  • Data Principal — the individual to whom the personal data relates; for a child this includes the parent or lawful guardian, and for a person with disability, her lawful guardian.
  • Data Fiduciary — any person who, alone or with others, determines the purpose and means of processing personal data. This can be an individual, a company, an LLP, a government body or an NGO.
  • Data Processor — any person who processes personal data on behalf of a Data Fiduciary, and strictly under its instructions.
  • Consent Manager — a person registered with the Data Protection Board of India who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, interoperable platform.
  • Significant Data Fiduciary (SDF) — a Data Fiduciary or class of Data Fiduciaries that the Central Government notifies as such, having regard to factors such as the volume and sensitivity of data processed, risk to Data Principals’ rights, and potential impact on India’s sovereignty, integrity, electoral democracy, security or public order.
  • Data Protection Officer (DPO) — an individual an SDF must appoint, based in India, answerable to its board or equivalent governing body, and serving as the point of contact for grievance redressal.
  • Person — defined broadly to include individuals, Hindu Undivided Families, companies, firms, associations of persons, the State, and any other artificial juristic person.

4. Grounds for Processing: Consent or Legitimate Use

Section 4 of the Act permits processing of personal data only for a lawful purpose, and only on one of two grounds: the Data Principal’s consent, or one of the “certain legitimate uses” listed in Section 7.

4.1 Notice (Section 5 of the Act; Rule 3)

Every consent request must be accompanied or preceded by a notice. Rule 3 requires that notice to be capable of being understood independently of any other material the Data Fiduciary provides, and to give — in clear and plain language — a fair account sufficient for informed consent, including at minimum an itemised description of the personal data and the specific purpose(s) and goods, services or uses the processing enables. The notice must also specify the communication link for reaching the Data Fiduciary’s website or app, and describe how the Data Principal may withdraw consent (as easily as she gave it), exercise her other rights, and complain to the Data Protection Board. Where consent was obtained before the Act’s commencement, the Data Fiduciary must still issue an equivalent notice as soon as reasonably practicable. Under Section 5(3), the Data Principal must have the option to view this notice in English or in any of the 22 languages listed in the Eighth Schedule to the Constitution.

4.2 Consent (Section 6 of the Act)

Valid consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose — any part of a consent that infringes the Act is invalid only to that extent, not in its entirety. The request for consent must itself be in clear and plain language, offered in English or a Schedule Eight language, and must carry the contact details of the DPO or another person who can respond to the Data Principal’s queries. Consent may be withdrawn at any time with the same ease as it was given, though withdrawal does not undo the legality of processing that already took place, and the Data Principal bears the consequences of withdrawing (for instance, losing access to a service). A Data Principal may also route her consent through a registered Consent Manager, who acts in a fiduciary capacity toward her (Rules 4 and First Schedule, Part B).

Consent Managers themselves need Board registration, meeting conditions such as being an Indian-incorporated company with net worth of at least ₹2 crore and sound financials (First Schedule, Part A), and are bound to obligations including maintaining consent records for at least seven years, avoiding conflicts of interest with the Data Fiduciaries on their platform, and never sub-contracting their core obligations (First Schedule, Part B).

4.3 Certain Legitimate Uses (Section 7 of the Act)

Even without consent, a Data Fiduciary may process personal data for a defined set of legitimate uses, including:

  • data the Data Principal voluntarily provided for a specified purpose without indicating she withholds consent;
  • the State providing a notified subsidy, benefit, service, certificate, licence or permit;
  • the State performing a statutory function or acting in the interest of India’s sovereignty, integrity or security; compliance with a legal obligation to disclose information to the State;
  • compliance with a court judgment, decree or order; responding to a medical emergency; providing medical treatment during an epidemic or public-health threat;
  • ensuring safety during a disaster or breakdown of public order;
  • and employment-related purposes, including protecting an employer from loss such as breaches of confidentiality or corporate espionage.

Rule 5 and the Second Schedule prescribe the standards the State must follow when relying on the subsidy/benefit ground, including limiting processing to what is necessary, taking reasonable security safeguards, and giving the Data Principal an intimation with contact details for queries.

5. General Obligations of a Data Fiduciary (Section 8 of the Act; Rules 6–9)

Section 8 fixes responsibility squarely on the Data Fiduciary — irrespective of any contrary agreement or of a Data Principal’s own lapses — for every processing activity it undertakes itself or through a Data Processor, and any engagement of a processor must rest on a valid contract. Where processed data will be used to make a decision affecting the Data Principal, or will be disclosed to another Data Fiduciary, the Data Fiduciary must ensure its completeness, accuracy and consistency.

5.1 Security safeguards (Rule 6)

At a minimum, a Data Fiduciary must adopt security measures such as encryption, obfuscation, masking or tokenisation of personal data; controls over access to computer resources; logging, monitoring and review sufficient to detect and investigate unauthorised access; measures for continued processing if confidentiality, integrity or availability is compromised (for instance, data backups); retention of logs and personal data for at least one year to support such detection and investigation; appropriate contractual safeguards with Data Processors; and organisational measures to make all of this effective.

5.2 Breach intimation (Rule 7)

On becoming aware of a personal data breach, a Data Fiduciary must, without delay and in clear language, inform each affected Data Principal — through her registered user account or communication channel — of the nature, extent and timing of the breach, its likely consequences, the mitigation measures taken, steps she can take to protect herself, and contact details for queries. It must also inform the Board without delay of the breach’s nature, extent, timing, location and likely impact, and follow up within 72 hours (or a longer period the Board permits) with a detailed account covering the causes and circumstances, mitigation measures, any findings on who caused the breach, remedial steps to prevent recurrence, and a report on the intimations sent to affected individuals.

5.3 Retention and erasure (Section 8(7)–(8); Rule 8 and Third Schedule)

Unless retention is required by law, a Data Fiduciary must erase personal data once the Data Principal withdraws consent or once the specified purpose can reasonably be considered no longer served — whichever comes first — and must ensure its Data Processors do the same. A purpose is deemed no longer served once the Data Principal neither approaches the Data Fiduciary for its performance nor exercises her rights for a prescribed period. The Third Schedule sets that period at three years (from the Data Principal’s last contact, or from the Rules’ commencement, whichever is later) for large e-commerce entities (2 crore+ registered users), online gaming intermediaries (50 lakh+ users) and social media intermediaries (2 crore+ users) — though this erasure duty does not extend to data needed for the Data Principal to keep accessing her own account or stored virtual tokens. Rule 8(2) requires a further intimation at least 48 hours before such data is actually erased. Separately, Rule 8(3) requires retention of personal data, traffic data and processing logs for a minimum of one year for law-enforcement-related purposes listed in the Seventh Schedule.

5.4 Grievance redressal and contact information (Rule 9 and Rule 14)

Every Data Fiduciary must prominently publish the business contact information of its DPO (or another responsible person) on its website or app, and repeat this in every response to a Data Principal seeking to exercise her rights. It must also publish, within a reasonable period not exceeding ninety days, details of its grievance redressal system, and implement adequate technical and organisational measures to make that system effective.

6. Processing the Personal Data of Children and Persons with Disabilities

Section 9 of the Act prohibits processing a child’s personal data (a “child” being anyone under 18) without verifiable parental consent, bars any processing likely to harm a child’s well-being, and bans tracking, behavioural monitoring or targeted advertising directed at children. Rule 10 requires a Data Fiduciary to adopt technical and organisational measures to obtain verifiable parental consent and to exercise due diligence in confirming that the person identifying as parent is a verifiable adult — either from reliable identity/age details already held, or from details (or a mapped virtual token, such as one issued through a Digital Locker service) voluntarily furnished by the individual or an authorised entity. Section 11 extends an equivalent verifiable-consent obligation where a person with disability has a lawful guardian, requiring due diligence to confirm the guardian was validly appointed by a court, a designated authority under the Rights of Persons with Disabilities Act, 2016, or a local-level committee under the National Trust Act, 1999.

Recognising that a blanket rule would be unworkable for certain functions, Section 12 and Rule 12 (with the Fourth Schedule) carve out exemptions from the parental-consent and no-tracking obligations. Part A exempts specified classes — clinical establishments, mental health establishments and healthcare professionals (for health services), educational institutions (for educational activities and student safety), and crèche/childcare or child-transport providers (for safety-related tracking). Part B exempts specific purposes regardless of who is processing — exercising a statutory power or duty in a child’s interest, providing a State benefit under Section 7(b), creating an email account, determining a child’s real-time location for her safety, ensuring harmful content or advertising does not reach her, and confirming (for age-gating purposes) that a Data Principal is not in fact a child.

7. Significant Data Fiduciaries (Section 10 of the Act; Rule 13)

The Central Government may notify any Data Fiduciary, or class of them, as a Significant Data Fiduciary based on factors such as the volume and sensitivity of data handled, risk to Data Principals’ rights, and potential impact on sovereignty, integrity, electoral democracy, security of the State or public order. An SDF must appoint an India-based DPO answerable to its governing body, engage an independent data auditor, and — per Rule 13 — undertake a Data Protection Impact Assessment and audit once every twelve months, submit a report of significant observations to the Board, exercise due diligence that its algorithmic tools do not pose risks to Data Principals’ rights, and, where the Central Government specifies (on a committee’s recommendation), ensure that certain categories of personal data and associated traffic data are not transferred outside India.

8. Rights and Duties of Data Principals (Sections 11–15 of the Act; Rule 14)

  • The Act gives every Data Principal the right to obtain a summary of the personal data a Data Fiduciary is processing about her and the identities of other fiduciaries/processors it has been shared with (Section 11);
  • the right to correction, completion, updating and erasure of her data (Section 12);
  • the right to accessible grievance redressal, to be exhausted before approaching the Board (Section 13);
  • and the right to nominate another individual to exercise her rights in the event of her death or incapacity (Section 14).
  • Rule 14 requires Data Fiduciaries and Consent Managers to prominently publish the means for exercising these rights and any identifiers needed to authenticate a request, and to resolve grievances within ninety days.
  • In turn, Section 15 casts duties on the Data Principal herself — to comply with applicable law while exercising her rights, not to impersonate another person, not to suppress material information when obtaining official documents, not to file false or frivolous complaints, and to furnish only verifiably authentic information when seeking correction or erasure.

9. Cross-Border Data Transfer (Section 16 of the Act; Rule 15)

Rather than a country-by-country whitelist, the Act takes a restriction-based approach: personal data may generally be transferred outside India, except to any country or territory that the Central Government specifically notifies as restricted. Rule 15 adds that such transfers remain subject to any requirements the Central Government may specify, by general or special order, in respect of making personal data available to a foreign State or to persons or agencies under its control — leaving room for future government orders to condition or limit specific transfers.

10. Exemption for Research, Archiving and Statistical Purposes (Section 17(2)(b); Rule 16)

The Act does not apply to processing necessary for research, archiving or statistical purposes, provided such processing is not used to make any decision specific to a Data Principal and follows the standards in the Second Schedule — lawful processing limited to what is necessary, reasonable efforts toward data accuracy, retention no longer than needed, and appropriate security safeguards.

11. The Data Protection Board of India

Chapters V to VII of the Act establish the Data Protection Board — a body corporate empowered to inquire into breaches (on its own action following a breach intimation, on a Data Principal’s complaint, or on a government reference), issue directions, and impose penalties. Rules 17 to 21 flesh out its institutional design: Search-cum-Selection Committees recommend the Chairperson and other Members, who serve two-year, renewable terms; the Chairperson and Members draw a consolidated monthly salary (₹4.5 lakh and ₹4 lakh respectively, without housing or car benefits, and without pension or gratuity, per the Fifth Schedule); Board meetings require a quorum of one-third of its membership, with decisions by majority and the Chairperson holding a casting vote; and the Board is designed to function as a “digital office,” able to conduct proceedings without requiring anyone’s physical presence, using techno-legal measures, while retaining its power to summon persons and examine them on oath. An inquiry must ordinarily be completed within six months of receiving a complaint or reference, extendable by up to three months at a time for recorded reasons. Orders of the Board may be appealed to the Appellate Tribunal (the Telecom Disputes Settlement and Appellate Tribunal) under Section 29 of the Act and Rule 22, which similarly functions as a digital office and is not bound by the Code of Civil Procedure, being guided instead by natural justice.

Rule 23 and the Seventh Schedule also empower the Central Government, acting through designated authorised persons, to call for information from a Data Fiduciary or intermediary for defined purposes — safeguarding India’s sovereignty and security, enabling performance of or compliance with other laws, and assessing whether a fiduciary should be notified as an SDF — and to direct that certain disclosures not be revealed to the affected Data Principal where doing so would prejudice sovereignty, integrity or security.

12. Penalties

The Schedule to the Act prescribes the financial consequences of non-compliance, determined by the Board after hearing the person concerned and having regard to factors such as the nature, gravity, duration and repetitive character of the breach, any gain made or loss avoided, and the proportionality and likely deterrent effect of the penalty (Section 33).

Nature of breach Maximum penalty
Failure to take reasonable security safeguards (Section 8(5)) ₹250 crore
Failure to notify the Board / affected Data Principals of a breach (Section 8(6)) ₹200 crore
Breach of obligations relating to children’s data (Section 9) ₹200 crore
Breach of additional obligations of a Significant Data Fiduciary (Section 10) ₹150 crore
Breach of duties of a Data Principal (Section 15) ₹10,000
Breach of a voluntary undertaking accepted by the Board Up to the penalty for the underlying breach
Any other breach of the Act or Rules ₹50 crore

All penalties collected are credited to the Consolidated Fund of India (Section 34), underscoring that the regime, unlike some data protection laws elsewhere, does not channel penalty proceeds toward affected individuals or a dedicated fund.

Concluding Thoughts

The DPDP Act and its 2025 Rules together move India from a fragmented, largely contractual approach to data privacy toward a codified, rights-based framework built around consent, purpose limitation, security safeguards and accountable grievance redressal — enforced by a dedicated regulator with real financial teeth. For organisations that collect or process personal data of individuals in India — a category that, given the Act’s extraterritorial reach, includes many entities with no physical presence in the country — the eighteen-month runway to 13 May 2027 is not a reason to wait. Notices need to be rewritten, consent flows re-engineered, data retention schedules mapped against the Third and Seventh Schedules, breach-response playbooks built around the 72-hour Board-intimation clock, and children’s-data processes checked against the Fourth Schedule’s narrow exemptions. Entities that meet the thresholds for Significant Data Fiduciary status should, in particular, start planning for annual Data Protection Impact Assessments and audits well before that classification is formally notified. The law rewards early, structured preparation — and penalises, sometimes heavily, organisations caught unprepared when its remaining provisions come into force.

******

This article is based on the Digital Personal Data Protection Act, 2023 (No. 22 of 2023) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), dated 13 November 2025), and is intended for general understanding only; it is not legal advice.

Advertisement

Author Info

Itisha Sahu
Name: Itisha Sahu
Qualification: CS
Location: Indore, Madhya Pradesh
Articles Published: 4

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *