Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
Corporate Law

DPDP Act 2023 & Rules 2025: India’s Data Protection Law

Summary: The Digital Personal Data Protection Act, 2023 (DPDP Act), together with the Digital Personal Data Protection Rules, 2025, establishes India’s comprehensive framework for protecting digital personal data and regulating how organisations collect, process, store and share such information. The framework applies to digital personal data processed in India and can also extend to processing outside India connected with offering goods or services to individuals in India. It places consent at the centre of data processing and requires consent to be free, specific, informed, unconditional and unambiguous, while imposing obligations on Data Fiduciaries relating to security safeguards, breach reporting, data accuracy, retention, grievance redressal and deletion of data after its purpose is fulfilled, subject to legal requirements. Data Principals receive rights concerning their personal data while also being subject to specified duties. Special protections apply to children and persons with disabilities having lawful guardians, while entities designated as Significant Data Fiduciaries face enhanced compliance requirements, including appointment of an India-based Data Protection Officer, independent audits and Data Protection Impact Assessments. The framework also establishes the Data Protection Board of India for enforcement and provides substantial monetary penalties, including penalties reaching ₹250 crore for specified contraventions. With implementation being phased, businesses need to progressively redesign consent mechanisms, privacy notices, data-retention practices, security systems, vendor arrangements and breach-response processes to prepare for full compliance.

Digital Personal Data Protection Act, 2023: India’s New Rulebook for Your Data

Advertisement


Introduction

Think about how many times each day you share a piece of your personal information with a digital platform. You enter your phone number into a food delivery app so the delivery partner can locate your address. You provide a hospital with your medical history before treatment. You allow a digital lending application to access your bank statements because it promises quick loan approval. Each of these everyday interactions creates a digital footprint containing personal information about you.

For many years, India lacked a single comprehensive law regulating how organisations could collect, use, store, and share such personal data. Although certain provisions of the Information Technology Act, 2000 and its associated rules provided limited protection, they were not designed to address the rapidly expanding digital economy or the increasing volume of personal data generated by individuals.

This changed with the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act), which received the assent of the President of India on 11 August 2023. However, like many modern regulatory statutes, the Act did not become fully operational immediately. Section 1(3) empowers the Central Government to bring different provisions into force on different dates through notifications in the Official Gazette.

A significant step towards implementation occurred when the Ministry of Electronics and Information Technology (MeitY) released the Draft Digital Personal Data Protection Rules, 2025 for public consultation in January 2025. After receiving thousands of comments from industry bodies, legal experts, civil society organisations, technology companies, and citizens, the Government notified the Digital Personal Data Protection Rules, 2025 in November 2025. Together, the Act and the Rules establish India’s first comprehensive legal framework dedicated exclusively to the protection of digital personal data. Their implementation is expected to fundamentally reshape how businesses, financial institutions, hospitals, educational institutions, online platforms, and government agencies process the personal information of more than one billion people.

The Long Road to a Data Protection Law

India’s journey with data protection legislation did not begin in 2023. For nearly two decades, the only real legal cover for personal data came from the Information Technology Act, 2000, and a set of rules under it called the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These rules were narrow. They applied mainly to “sensitive personal data” collected by body corporates, and they never really addressed the scale of a country that was rapidly getting online through cheap smartphones and cheaper mobile data.

The real turning point came from the courtroom rather than Parliament. In 2017, a nine-judge bench of the Supreme Court of India, in the landmark case of Justice K.S. Puttaswamy (Retd.) v. Union of India, held that the right to privacy is a fundamental right protected under Article 21 of the Constitution, which guarantees the right to life and personal liberty. That judgment did not create a data protection law by itself, but it created a constitutional obligation for the state to build one. A committee led by Justice B.N. Srikrishna was set up soon after, and it produced a draft data protection bill in 2018. What followed was a long and winding legislative journey: a 2019 bill, a Joint Parliamentary Committee report in 2021, the eventual withdrawal of that bill in 2022, and then a fresh, simplified version released for public consultation later that year. The version that finally passed both Houses of Parliament in August 2023 was considerably shorter and more direct than its predecessors.

Even after receiving presidential assent, the Act sat dormant for a long stretch because Section 1(3) of the law allows the government to bring different provisions into force on different dates. A draft of the Rules was released for public comment in January 2025, and after receiving nearly 7,000 inputs from startups, industry bodies, civil society groups, and ordinary citizens through consultations held across several cities, the final DPDP Rules, 2025 were notified in November 2025.

Legislative & Implementation Timeline

What the Law Covers — and What It Doesn’t

The DPDP Act is deliberately narrow in scope, and that narrowness is one of its defining features. It applies only to personal data that is in digital form, or non-digital personal data that is later digitised. A paper diary kept at home, or a handwritten register maintained by a small shopkeeper, does not fall within the Act unless that information is converted into a digital format.

The Act also has extraterritorial reach, a feature clearly inspired by the European Union’s General Data Protection Regulation (GDPR). It applies to processing of digital personal data within India, but it also reaches processing that happens outside India if that processing is connected with offering goods or services to individuals located in India.

Two Terms to Know

  • Data Principal: the individual to whom the personal data relates — essentially, you, the person whose name, phone number, health record, or shopping history is being collected. Where the data belongs to a child, the parent or lawful guardian stands in for consent purposes.
  • Data Fiduciary: the entity — a company, an individual, an organisation, or a government body — that decides why and how personal data is processed. This is the party that carries almost all the legal responsibility under the Act.
  • Data Processor: an entity that processes personal data on behalf of a Data Fiduciary, such as a cloud storage vendor or a third-party support agency.

Unlike the GDPR, the DPDP Act does not create a separate, heavier category for “sensitive personal data” such as health records or biometric information — The Act does not create a separate statutory category of sensitive personal data.

The Philosophy Behind the Law: SARAL

The government has repeatedly described its approach using the acronym SARAL — Simple, Accessible, Rational, and Actionable. The idea was to move away from dense, jargon-heavy legalese and instead write a law that an ordinary business owner, and even an ordinary citizen, could read and largely understand. The Act contains illustrative examples woven directly into its sections, a style borrowed loosely from the Indian Contract Act and the Indian Penal Code.

For example, the Act illustrates the idea of consent bundling using a simple scenario: a person named X buys an insurance policy through an app run by an insurer, Y. X gives consent for two things — first, that Y can process her personal data to issue the policy, and second, that she waives her right to ever file a complaint with the Data Protection Board. The Act makes clear that the second part of that consent is invalid, because certain statutory protections cannot be contracted away.

The Act rests on seven guiding principles that echo internationally recognised privacy norms: consent and transparency, purpose limitation, data minimisation, accuracy of data, storage limitation, reasonable security safeguards, and accountability.

Consent is the primary lawful basis for processing personal data, and the law is fairly demanding about what counts as valid consent. It must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action — not pre-ticked boxes, not silence, and not consent buried inside forty pages of legal English.

Before asking for consent, a Data Fiduciary must give the Data Principal a notice explaining exactly what personal data is being collected, why, how the person can exercise their rights, and how they can complain to the Data Protection Board. This notice must be available not only in English but in any of the twenty-two languages listed in the Eighth Schedule of the Constitution — Hindi, Tamil, Bengali, Marathi, Telugu, and more.

Consider a practical example: a fintech lending app wants to check a user’s bank statements to decide whether to approve a personal loan. Under the Act, the app must clearly disclose what data it is pulling and why, and if it later wants to use that same data to sell targeted insurance products, that would very likely breach the purpose limitation principle, since consent given for one purpose cannot simply be stretched to cover an unrelated one.

Consent can be withdrawn at any time, and withdrawing it must be just as easy as giving it — a rule aimed squarely at “dark patterns,” where signing up takes ten seconds but cancelling requires navigating five confusing menus. The Act also allows for Consent Managers — independent, registered platforms through which a person can view and manage consent across multiple companies from a single dashboard. Under the DPDP Rules, a Consent Manager must be an Indian company with a minimum net worth of at least two crore rupees, and must retain audit trails for at least seven years.

Obligations of the Data Fiduciary

Chapter 2 of the Act lays out what a Data Fiduciary must actually do once it starts collecting personal data.

Non-delegable Responsibility

Section 8(1) makes clear that a Data Fiduciary remains fully responsible for compliance regardless of any contract that tries to shift blame elsewhere. If a vendor mishandles data processed on the company’s behalf, the company cannot escape liability.

Reasonable Security Safeguards

Every Data Fiduciary and Data Processor must implement appropriate technical and organisational measures to prevent personal data breaches — encryption, access controls, and routine security audits. Failing to do this carries the single heaviest penalty in the entire Act.

Breach Notification

If a personal data breach occurs, the Data Fiduciary must notify the Data Protection Board and the affected Data Principals without delay. Under Rule 7 of the DPDP Rules, 2025, the Data Fiduciary must also submit a detailed follow-up report to the Board within 72 hours of becoming aware of the breach (or within such extended period as the Board may permit).

Data Accuracy and Retention Limits

Fiduciaries must keep personal data accurate and erase it once its purpose is fulfilled, unless retention is required by law. The DPDP Rules prescribe sector-specific retention periods for certain categories of Data Fiduciaries. For example, specified e-commerce entities, online gaming intermediaries, and social media intermediaries above the prescribed user thresholds must erase the personal data of inactive users after three years of inactivity, subject to the exceptions provided in the Rules and after giving the required prior notice.

Grievance Redressal

Every Data Fiduciary must appoint a contact person — a grievance officer, or for larger entities, a Data Protection Officer — and publish clear timelines for resolving complaints.

The Rights and Duties of the Data Principal

The Act gives ordinary citizens a defined set of rights, though notably fewer and less granular than under the GDPR.

Rights of the Data Principal Under the DPDP Act, 2023

According to the DPDP Rules, Data Fiduciaries must specify a reasonable timeframe for responding to Data Principal requests and grievances under their grievance redressal mechanism, with the response period not exceeding ninety days. Interestingly, the Act also imposes duties on the Data Principal under Section 15—including not impersonating another person, not suppressing material information, and not filing false or frivolous complaints. Breach of these duties can attract a penalty of up to ten thousand rupees, a modest figure compared to the penalties applicable to Data Fiduciaries, but a clear signal that the law expects good faith from both sides of the data relationship.

Special Protection for Children and Persons with Disabilities

Section 9 deals with the processing of personal data belonging to children — defined as anyone under eighteen — and persons with disabilities who have a lawful guardian. Before processing a child’s personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian. The DPDP Rules allow integration with Digi Locker, India’s government-backed digital identity wallet, to confirm both the parent’s identity and the parent-child relationship.

The Act draws a hard line: Data Fiduciaries are prohibited from any processing likely to cause a detrimental effect on a child’s well-being, and are barred from tracking, behavioural monitoring, or targeted advertising directed at children — a direct response to concerns about how apps profile young users to maximise engagement.

There are sensible carve-outs too. The DPDP Rules exempt certain low-risk or protective purposes from the strict parental-consent requirement — for example, child-protection platforms, school-issued email accounts used strictly for education, or processing necessary to deliver a government subsidy to the child.

Significant Data Fiduciaries

Not every company handling personal data poses the same level of risk. The Act allows the government to designate certain entities as Significant Data Fiduciaries (SDFs) based on factors such as the volume and sensitivity of data processed, risk to Data Principals’ rights, and potential impact on sovereignty, security, and public order.

Once designated, an SDF must appoint an India-based Data Protection Officer who reports to the company’s board, appoint an independent data auditor, conduct periodic Data Protection Impact Assessments, and undertake regular compliance audits — a tiered approach meant to concentrate the heaviest compliance burden on organisations whose failures would cause the widest damage.

Cross-Border Data Transfers

Unlike the GDPR’s elaborate “adequacy” system, the DPDP Act takes a simpler, negative-list approach. Under Section 16, a Data Fiduciary may transfer personal data outside India to any country or territory except those specifically restricted by the Central Government through notification. The default position is permissive — transfer is allowed unless a country is expressly blacklisted — a notably lighter-touch approach than earlier draft bills, which had proposed strict data localisation requirements.

The Data Protection Board of India

Enforcement rests with a newly created body, the Data Protection Board of India (DPBI), established under the DPDP Rules as a fully digital, paperless institution consisting of Chairperson and Members appointed by the Central Government. Rather than functioning like a traditional courtroom, the Board operates through an online portal and mobile application, letting citizens file complaints, track their status, and receive resolutions digitally.

The Board can inquire into breaches and complaints, direct urgent remedial measures, and impose financial penalties after giving the concerned party a reasonable opportunity to be heard. It can also accept voluntary undertakings from a Data Fiduciary seeking to proactively fix a compliance failure. Appeals against the Board’s orders go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and from there to the Supreme Court of India. The Act bars civil courts from entertaining matters that the Board or Tribunal is empowered to decide.

Penalties: How Steep Is the Fine?

The financial penalties are set out in a Schedule referenced by Section 33(1), and they are, by Indian legislative standards, quite severe.

Maximum Penalty Ceillings

When deciding the actual amount within these ceilings, the Board weighs factors including the nature, gravity, and duration of the breach; the type of personal data affected; whether it was repeated; any gains made or losses avoided by the Data Fiduciary; mitigation steps taken; and the likely impact on affected Data Principals. These fines are paid to the government, not as compensation to affected individuals — the Act does not create an explicit private right to monetary compensation for a breach victim, a point often raised by consumer rights groups.

To put this in perspective: imagine a large digital lending platform suffers a breach exposing the Aadhaar numbers, bank details, and loan histories of two million users, and it is later found the company had failed to encrypt this data or restrict internal access properly. Under the Schedule, to implement reasonable security safeguards alone could expose the company to a fine of up to ₹250 crore, per instance of non-compliance quite apart from any separate penalty for delayed breach notification.

The Phased Rollout: A Long Runway

Phase Effective Date What Comes Into Force
Phase 1 Nov 2025 (on notification of Rules) Core institutional framework: establishment of the Data Protection Board of India, definitions operationalized, central government powers activated, administrative machinery setup, and restriction on jurisdiction of civil courts (Board becomes primary adjudicatory body).
Phase 2 Nov 2026 (estimated transition period) Consent Manager ecosystem becomes operational (registration, duties, accountability), Board enforcement powers expand in practice, breach handling workflows stabilise, compliance onboarding for intermediaries begins
Phase 3 May 2027 (full compliance enforcement window) Full substantive obligations become enforceable: notice & consent requirements, lawful processing conditions, children’s data protections, breach notification duties, Significant Data Fiduciary (SDF) obligations, and complete Data Principal rights framework.

In effect, businesses operating in India have roughly eighteen months from notification of the Rules to update privacy notices, redesign consent flows, train staff, appoint Data Protection Officers where required, and build breach-response systems — before the core obligations and matching penalties become fully enforceable. Until Phase 3 takes full effect, the older IT Act framework continues to apply in parallel.

How This Compares to the GDPR

Comparisons with the European Union’s GDPR are inevitable, as the DPDP Act adopts several concepts inspired by the European framework. For example, the Act’s concept of the “Data Fiduciary” broadly resembles the GDPR’s “controller,” while its extraterritorial application reflects a similar regulatory philosophy.

DPDP Act, 2023 vs GDPR- Selected Structural Differences

The GDPR provides enhanced protection for “special categories of personal data,” including health, biometric, religious, and genetic data, whereas the DPDP Act generally applies a uniform regulatory framework to all personal data and does not create a separate statutory category of sensitive personal data.

The GDPR requires the appointment of a Data Protection Officer in specified circumstances, such as large-scale monitoring or processing of sensitive data, whereas the DPDP Act requires one only for Significant Data Fiduciaries notified by the Central Government. Whereas the GDPR permits administrative fines of up to 4% of a company’s worldwide annual turnover (or €20 million, whichever is higher), the DPDP Act prescribes fixed monetary ceilings for different categories of contraventions, with the highest penalty currently capped at ₹250 crore.

Criticism and Open Questions

No law of this scale arrives without debate. The DPDP Act has drawn criticism from privacy researchers, journalists, and civil liberties groups on several fronts:

  • Broad government exemptions: Section 17 allows the Central Government to exempt its own agencies from many obligations on grounds such as national security and public order — exemptions critics say are wide enough to shield significant state surveillance from scrutiny.
  • Weakened regulator independence: the Central Government retains considerable control over appointment, tenure, and terms of the Data Protection Board’s members, raising questions about independence when the government itself is a major data processor.
  • No distinct treatment for sensitive data: treating shopping preferences the same as health or caste data, without heightened safeguards, strikes many advocates as a significant gap.
  • Dilution of the RTI Act: the DPDP Act amended Section 8(1)(j) of the RTI Act in a way critics say makes it easier for authorities to deny disclosure involving personal data, potentially at the cost of governance transparency.
  • Ambiguity in breach thresholds: the absence of a harm-based reporting threshold could mean minor incidents receive the same treatment as catastrophic ones.

What This Means in Practice — A Few Everyday Scenarios

  • A hospital chain collecting patient records digitally must give a clear notice in a language patients understand, obtain valid consent for non-emergency processing, secure the data against breaches, and be ready to correct or erase records once treatment and legal retention obligations are complete.
  • A ride-hailing app that wants to use a rider’s location history for targeted advertising to third parties needs explicit, specific consent for that purpose — location data collected to complete a ride cannot silently be repurposed.
  • A school running a parent-teacher app for young children needs verifiable parental consent before creating student profiles, and must avoid behavioural tracking or advertising aimed at children.
  • A bank designated an SDF needs an India-based Data Protection Officer, periodic impact assessments before new digital products launch, and regular third-party audits — well beyond what a small business collecting a handful of phone numbers would need.

Conclusion

The Digital Personal Data Protection Act, 2023, closes a long-standing gap in India’s legal landscape. For the first time, the country has a dedicated statute that spells out, with reasonable clarity, what companies and government bodies must do before collecting, using, and storing the digital footprints of their citizens, and what recourse those citizens have when things go wrong. Its SARAL philosophy — simple, accessible, rational, actionable — reflects a genuine attempt to make privacy law usable by the very small businesses and ordinary citizens it affects, not just corporate lawyers.

At the same time, the Act is a product of compromise. Its broad government exemptions, its uniform treatment of sensitive and non-sensitive data, and its relatively centralised control over the regulatory Board leave real questions about how much protection it will deliver in practice, especially against the state’s own data practices. The long, phased implementation timeline — stretching to May 2027 for full enforcement — means the real test of this law is still ahead. How the Data Protection Board interprets its powers, how strictly it enforces the penalty ceilings, and how courts eventually treat challenges to the government exemption clauses will determine whether the DPDP Act becomes a genuine shield for personal privacy or remains a law with strong words and softer enforcement. Either way, for the first time, Indians now have a named law to point to when they ask a company the simple but important question: what are you doing with my data?

Relevant TaxGuru reference: Digital Personal Data Protection Act, 2023 – Comprehensive Summary

Relevant TaxGuru reference: Data Fiduciary Obligations under Digital Personal Data Protection Rules, 2025

Advertisement

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *