Digital Personal Data Protection Act, 2023 & Rules, 2025: A Practical Compliance Guide for Indian Businesses
Summary: The Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 establish India’s dedicated framework for processing and protecting digital personal data. The framework affects employers, businesses, HR teams, technology functions, vendors and other organisations processing employee, customer and other personal data. It regulates consent, notices, Data Fiduciary and Data Processor responsibilities, security safeguards, breach management, children’s data, Significant Data Fiduciaries, Data Principal rights, Consent Managers and the Data Protection Board of India. The law also creates substantial financial exposure, with maximum penalties reaching ₹250 crore for failure to take reasonable security safeguards and ₹200 crore for specified breach-notification failures. Importantly, implementation is phased rather than simultaneous. Certain institutional provisions commenced on 13 November 2025, Rule 4 becomes effective after one year, while major operational provisions are scheduled for the eighteen-month phase. Businesses should therefore use the implementation period to map personal data, identify lawful processing grounds, review notices and consent mechanisms, strengthen processor and vendor governance, establish retention and deletion frameworks, prepare breach-response procedures and operationalise Data Principal rights. DPDP compliance is consequently not merely an IT or privacy-policy exercise but a broader governance, HR, legal, cybersecurity, procurement and enterprise-risk programme.
- Introduction
- 1. What is the DPDP Act, 2023?
- 2. The Basic Architecture of the DPDP Framework
- Data Principal
- Data Fiduciary
- Data Processor
- 3. The Nine Chapters of the DPDP Act
- 4. What Constitutes Personal Data?
- 5. Processing Must Have a Lawful Basis
- Consent
- Certain Legitimate Uses
- 6. Notice: The First Major Compliance Requirement
- 7. Consent Must Be Capable of Being Withdrawn
- 8. Obligations of Data Fiduciaries
- 9. Data Processors Cannot Be Ignored
- 10. Reasonable Security Safeguards
- 11. Personal Data Breach Management
- 12. Special Protection for Children
- 13. Significant Data Fiduciaries
- 14. Data Protection Officer
- 15. Rights of Data Principals
- Access information
- Correction and erasure
- Grievance redressal
- Nomination
- 16. Duties of Data Principals
- 17. Consent Managers
- 18. Data Protection Board of India
- 19. Penalties: The Compliance Risk Has Become Financially Significant
- 20. What Do the DPDP Rules, 2025 Add?
- 21. A Crucial Point: The DPDP Framework Has Phased Commencement
- Already commenced
- One-year phase
- Eighteen-month phase
- 22. DPDP Compliance Is Particularly Relevant to HR
- Recruitment
- Joining
- Employment
- Benefits
- Exit
- 23. What HR Leaders Should Start Doing
- 24. The Biggest Mistake Businesses Can Make
- 25. DPDP and Existing Compliance Frameworks
- 26. DPDP Is Also a Vendor-Management Issue
- 27. DPDP and Employee Experience
- 28. DPDP Should Be Viewed as a Governance Transformation
- 29. What Should Organisations Do Now?
- Phase 1 – Understand
- Phase 2 – Map
- Phase 3 – Assess
- Phase 4 – Govern
- Phase 5 – Remediate
- Phase 6 – Implement
- Phase 7 – Test
- Phase 8 – Audit
- Conclusion
Introduction
Personal data has become one of the most valuable assets of a modern organisation.
Every organisation collects and processes personal data—whether it is employee information, customer details, vendor records, job applications, CCTV footage, payroll information, health or insurance records, contact details, website data or information generated through digital platforms.
For years, India’s data protection framework was largely dependent upon provisions under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, along with contractual and sector-specific requirements.
The Digital Personal Data Protection Act, 2023 (DPDP Act) represents a fundamental shift.
The Act establishes a dedicated framework governing the processing of digital personal data, balancing two objectives:
- recognising an individual’s right to protect personal data; and
- permitting lawful processing of personal data for legitimate purposes.
The Act received Presidential assent on 11 August 2023.
The framework has now moved substantially beyond legislation on paper. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, providing the operational framework required for implementation.
For employers and businesses, therefore, DPDP should no longer be viewed merely as an IT or cybersecurity issue.
It is a business governance, HR, legal, compliance, technology and risk-management issue.
1. What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 is India’s principal legislation governing the processing of digital personal data.
The Act applies to the processing of digital personal data within India where the personal data is:
- collected in digital form; or
- collected in non-digital form and subsequently digitised.
It can also apply to processing outside India where such processing is in connection with offering goods or services to Data Principals in India, subject to the framework prescribed by the Act.
The legislation is therefore relevant not only to Indian companies but potentially also to organisations outside India that offer goods or services to individuals in India.
2. The Basic Architecture of the DPDP Framework
The DPDP framework revolves around three principal stakeholders:
Data Principal
The individual to whom the personal data relates.
For example:
- employee;
- customer;
- job applicant;
- contractor;
- student;
- patient;
- website user.
Data Fiduciary
The person or organisation that determines the purpose and means of processing personal data.
In a corporate environment, the employer will ordinarily be a Data Fiduciary for employee personal data.
Data Processor
A person or organisation that processes personal data on behalf of a Data Fiduciary.
Examples include:
- payroll processors;
- HR technology providers;
- cloud service providers;
- background verification agencies;
- recruitment platforms;
- benefits administrators;
- customer support vendors.
This distinction is important because an organisation may outsource processing, but outsourcing does not automatically eliminate its responsibility as Data Fiduciary.
3. The Nine Chapters of the DPDP Act
The Act is structured into nine Chapters, dealing with the following broad areas.
| Chapter | Broad Subject |
|---|---|
| Chapter I | Preliminary |
| Chapter II | Obligations of Data Fiduciary |
| Chapter III | Rights and Duties of Data Principal |
| Chapter IV | Special Provisions |
| Chapter V | Data Protection Board of India |
| Chapter VI | Powers, Functions and Procedure of Board |
| Chapter VII | Appeals and Alternative Dispute Resolution |
| Chapter VIII | Penalties and Adjudication |
| Chapter IX | Miscellaneous |
This structure is important because the Act does not merely prescribe privacy rights. It creates an entire governance and enforcement architecture.
4. What Constitutes Personal Data?
The Act defines personal data broadly as:
“any data about an individual who is identifiable by or in relation to such data.”
The important point is that the DPDP framework focuses on digital personal data.
This could include, depending on the context:
- name;
- address;
- telephone number;
- email address;
- employee ID;
- Aadhaar-related information;
- PAN;
- bank account details;
- salary information;
- performance information;
- photographs;
- biometric information;
- medical or insurance information;
- recruitment records;
- IP address and digital identifiers;
- customer transaction information.
For HR departments, the implications are particularly significant because the employee lifecycle involves extensive processing of personal data.
5. Processing Must Have a Lawful Basis
One of the central principles under the DPDP Act is that a Data Fiduciary cannot process personal data arbitrarily.
Processing is generally based on:
Consent
Consent must be:
- free;
- specific;
- informed;
- unconditional;
- unambiguous; and
- given through clear affirmative action.
Consent must also be capable of being withdrawn.
Certain Legitimate Uses
The Act also recognises specified circumstances where personal data may be processed without relying upon consent, subject to the statutory conditions.
This is particularly relevant to employers because not every processing activity should necessarily be forced into a consent-based model.
For example, organisations may process personal data for certain employment-related, legal, regulatory or statutory purposes where the Act recognises such processing.
A critical compliance lesson:
Organisations should not simply introduce one blanket “employee consent form” and assume that DPDP compliance is complete.
The organisation needs to identify what data is being processed, why it is being processed, under which legal basis, who receives it and how long it is retained.
6. Notice: The First Major Compliance Requirement
The DPDP Rules, 2025 provide significant operational detail concerning notices.
The notice must be:
- standalone;
- understandable;
- written in clear and plain language;
- sufficiently specific;
- capable of enabling informed consent.
The notice must include, among other things:
- an itemised description of the personal data being processed;
- the specific purpose or purposes of processing;
- information about the goods, services or uses enabled by the processing; and
- information enabling the Data Principal to access mechanisms for withdrawal of consent, exercising rights and making complaints.
This has a direct implication for existing privacy notices.
Copy-pasting a generic global privacy policy may not necessarily satisfy the Indian DPDP notice framework.
Organisations should review:
- website privacy notices;
- employee privacy notices;
- recruitment notices;
- customer forms;
- mobile applications;
- vendor onboarding forms;
- CCTV notices;
- HR technology interfaces.
7. Consent Must Be Capable of Being Withdrawn
The Act gives the Data Principal the right to withdraw consent.
The Rules further emphasise that withdrawal should be as easy as giving consent.
This means that businesses should think beyond the initial consent screen.
A mature privacy programme should answer:
How does an individual withdraw consent?
Who receives the request?
What systems are updated?
Which downstream processors are informed?
What processing can continue because it has another lawful basis?
This requires integration between legal, HR, IT and business processes.
8. Obligations of Data Fiduciaries
The Data Fiduciary is at the centre of the DPDP compliance framework.
Broadly, organisations are expected to:
- comply with the Act and Rules;
- ensure lawful processing;
- provide appropriate notices;
- implement reasonable security safeguards;
- respond to personal data breaches;
- establish mechanisms for Data Principal rights;
- ensure appropriate arrangements with Data Processors;
- delete personal data when retention is no longer necessary, subject to applicable requirements;
- maintain appropriate governance and accountability.
The Rules add operational requirements around security safeguards, breach management, rights mechanisms, consent management and other aspects.
9. Data Processors Cannot Be Ignored
Many organisations make a common mistake:
“The data is with our vendor, so the vendor is responsible.”
That is not an adequate compliance approach.
Consider a typical employee ecosystem:
Employee → Employer → HRMS → Payroll Provider → Insurance Provider → Background Verification Agency → Cloud Infrastructure
Personal data may travel through multiple systems.
The organisation therefore needs visibility over:
- who processes the data;
- why they process it;
- what categories of data they receive;
- where the data is stored;
- how long they retain it;
- what security safeguards they maintain;
- what happens after termination of the contract;
- how a breach is reported.
DPDP implementation therefore requires a Data Processor Governance Framework.
10. Reasonable Security Safeguards
Security is one of the most important components of the DPDP framework.
The Rules prescribe security safeguards that require organisations to adopt appropriate technical and organisational measures.
These include measures relating to:
- encryption, masking or tokenisation where appropriate;
- access controls;
- logging and monitoring;
- backups;
- detection and remediation of unauthorised access;
- continuity and resilience;
- appropriate contractual safeguards with processors;
- measures to prevent and mitigate personal data breaches.
The underlying principle is simple:
Personal data protection cannot be achieved through a privacy policy alone.
It has to be supported by actual controls.
11. Personal Data Breach Management
A personal data breach can have serious consequences under DPDP.
Organisations need a defined incident-response mechanism covering:
1. detection;
2. containment;
3. assessment;
4. internal escalation;
5. regulatory notification;
6. communication with affected Data Principals where applicable;
7. remediation;
8. documentation;
9. post-incident review.
The Act specifically provides significant penalties for failure to take reasonable security safeguards and for breach notification obligations.
The maximum penalty for failure to take reasonable security safeguards can extend to ₹250 crore, while failure relating to breach notification can attract a penalty of up to ₹200 crore.
Therefore:
Cybersecurity incident response and privacy compliance can no longer operate as two completely separate functions.
12. Special Protection for Children
The DPDP framework gives special protection to children.
The Act defines a child as an individual who has not completed 18 years of age.
Additional obligations apply to processing children’s personal data.
Among other things, the framework regulates:
- verifiable parental consent;
- processing of children’s data;
- behavioural monitoring;
- targeted advertising directed at children.
The Rules prescribe mechanisms relating to verifiable consent in specified circumstances.
Organisations dealing with:
- schools;
- education technology;
- gaming;
- social platforms;
- children’s products;
- healthcare;
- family-oriented digital services
will need particularly careful processes.
13. Significant Data Fiduciaries
The Government may notify an organisation as a Significant Data Fiduciary (SDF) based on factors such as:
- volume and sensitivity of personal data processed;
- risk to the rights of Data Principals;
- potential impact on India’s sovereignty and integrity;
- risk to electoral democracy;
- security of the State;
- public order;
- other relevant factors.
Significant Data Fiduciaries have enhanced obligations.
These include requirements relating to:
- appointment of a Data Protection Officer;
- appointment of an independent data auditor;
- periodic impact assessment;
- audits;
- other compliance requirements prescribed under the Rules.
The maximum penalty for non-compliance with the additional obligations of a Significant Data Fiduciary can extend to ₹150 crore.
14. Data Protection Officer
For organisations covered by the SDF framework, the Data Protection Officer assumes particular importance.
The DPO serves as an important interface between:
- the organisation;
- Data Principals;
- the Data Protection Board;
- internal management;
- compliance and technology functions.
However, even organisations that are not SDFs should consider identifying a clear internal privacy/data protection owner.
The practical question should not merely be:
“Who is our DPO?”
It should be:
“Who owns personal-data governance within the organisation?”
15. Rights of Data Principals
The DPDP Act recognises several important rights.
These include the right to:
Access information
A Data Principal can seek information about personal data being processed and related matters, subject to the Act.
Correction and erasure
Individuals can request correction of inaccurate or incomplete personal data and erasure where applicable.
Grievance redressal
Organisations must provide mechanisms for Data Principals to raise grievances.
Nomination
A Data Principal can nominate another individual to exercise rights in specified circumstances, particularly in the event of death or incapacity.
These rights require operational readiness.
A privacy right without a mechanism to respond to it is effectively an incomplete compliance framework.
16. Duties of Data Principals
The Act also recognises that individuals have responsibilities.
Data Principals are expected, among other things, to:
- comply with applicable law;
- provide authentic information while exercising specified rights;
- not impersonate another person;
- not suppress material information while providing information;
- furnish information that is authentic while exercising rights;
- respect applicable legal requirements.
This is an important feature of the Indian framework.
DPDP is not designed as a one-way compliance obligation on businesses; it creates responsibilities for both sides.
17. Consent Managers
The DPDP framework introduces the concept of a Consent Manager.
A Consent Manager is intended to provide a technology-enabled mechanism through which Data Principals can:
- give consent;
- manage consent;
- review consent;
- withdraw consent.
The Rules prescribe eligibility and operational requirements for Consent Managers, including incorporation in India, financial and operational capability, a minimum net worth requirement and interoperable technology infrastructure.
The concept is particularly relevant as India’s digital ecosystem increasingly involves multiple consent-based interactions.
18. Data Protection Board of India
The Act establishes the Data Protection Board of India as the principal regulatory and adjudicatory body under the framework.
The Government established the Board through notification dated 13 November 2025. Its head office is in the National Capital Region.
The Board has been notified to consist of four members.
Its role includes dealing with matters such as:
- non-compliance;
- personal data breach-related obligations;
- complaints and grievances within its jurisdiction;
- directions;
- penalties;
- voluntary undertakings and other statutory functions.
The establishment of the Board marks an important transition:
Data protection compliance now has a dedicated institutional enforcement architecture.
19. Penalties: The Compliance Risk Has Become Financially Significant
The DPDP Act provides for substantial financial penalties.
| Non-compliance | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure relating to personal data breach notification | ₹200 crore |
| Non-compliance relating to children | ₹200 crore |
| Non-compliance by Significant Data Fiduciary | ₹150 crore |
| Breach of duties of Data Principal | ₹10,000 |
| Other breaches of Act/Rules | ₹50 crore |
The Schedule to the Act prescribes these maximum amounts.
It is important to understand that these are maximum statutory penalties, not automatic penalties for every instance of non-compliance.
Nevertheless, the financial exposure is substantial enough to make DPDP a board-level risk-management issue.
20. What Do the DPDP Rules, 2025 Add?
The Act establishes the principles.
The Rules provide much of the operational detail.
The DPDP Rules, 2025 contain 23 Rules, dealing with matters including:
- notices;
- Consent Managers;
- registration and obligations;
- security safeguards;
- personal data breach notifications;
- retention and erasure;
- children’s data;
- Significant Data Fiduciaries;
- rights of Data Principals;
- grievance mechanisms;
- cross-border processing-related matters;
- information and directions;
- Board procedures;
- other implementation mechanisms.
The Rules were notified on 13 November 2025.
21. A Crucial Point: The DPDP Framework Has Phased Commencement
One of the most important aspects for businesses is that not every provision became operational on the same day.
The Government’s commencement notification dated 13 November 2025 adopts a phased approach.
Already commenced
Certain provisions, including the institutional provisions concerning the Board, came into force upon publication of the notification.
One-year phase
Specified provisions come into force one year after publication, i.e. 13 November 2026.
Eighteen-month phase
The major operational provisions of the Act come into force 18 months after publication, i.e. 13 May 2027.
The Rules follow a similar phased structure.
Rules 1, 2 and 17–21 came into force upon publication.
Rule 4 becomes effective one year after publication.
Rules 3, 5–16, 22 and 23 become effective eighteen months after publication.
Therefore, as organisations plan their compliance programmes in late 2026:
The absence of immediate applicability of every provision should not be mistaken for absence of implementation urgency.
22. DPDP Compliance Is Particularly Relevant to HR
The HR function is one of the biggest internal processors of personal data.
Consider a typical employee lifecycle.
Recruitment
- CV;
- photograph;
- contact details;
- education;
- employment history;
- background verification;
- references.
Joining
- Aadhaar/PAN;
- bank details;
- emergency contacts;
- nominee information;
- statutory forms;
- medical information.
Employment
- attendance;
- leave;
- performance;
- compensation;
- appraisal;
- disciplinary records;
- training;
- employee engagement.
Benefits
- health insurance;
- dependants;
- medical claims;
- retirement benefits.
Exit
- full and final settlement;
- exit documentation;
- references;
- statutory records;
- litigation-related retention.
This means:
DPDP compliance is not just an IT project. It is an HR governance project.
23. What HR Leaders Should Start Doing
HR leaders should consider creating a Personal Data Inventory.
For every major HR process, identify:
| Question | Example |
|---|---|
| What data is collected? | PAN, bank details, IDs, Health Records |
| Whose data? | Employee |
| Why is it collected? | Payroll, Background Verification, Health |
| Where is it stored? | HRMS, Third Party Vendor |
| Who can access it? | HR/Payroll Team/Finance/IT |
| Who receives it? | Payroll processor/HR |
| How long is it retained? | As per applicable requirement |
| What happens after retention? | Deletion/archiving |
| Is it shared externally? | Yes |
| What security controls exist? | Access control/encryption |
This simple exercise can expose significant gaps.
24. The Biggest Mistake Businesses Can Make
The biggest mistake would be to treat DPDP implementation as:
“Draft a privacy policy and move on.”
That approach is unlikely to provide meaningful compliance.
DPDP requires alignment across multiple functions:
Board/Management + Legal + HR + IT + Cybersecurity + Procurement + Business + Compliance + Internal Audit
A privacy policy is only one component of a broader governance framework.
25. DPDP and Existing Compliance Frameworks
DPDP does not operate in isolation.
Organisations may also need to consider:
- Information Technology Act;
- sector-specific regulations;
- contractual obligations;
- employment laws;
- financial-sector requirements;
- cybersecurity requirements;
- telecom regulations;
- healthcare requirements;
- regulatory record-retention requirements;
- contractual confidentiality obligations.
For HR, this becomes especially important because personal data may need to be retained for statutory, legal or litigation purposes.
Therefore:
“Delete everything immediately” is not a DPDP strategy either.
Organisations need a properly documented data retention and deletion framework, aligned with applicable legal and business requirements.
26. DPDP Is Also a Vendor-Management Issue
A company may have strong internal controls but still face significant exposure through third-party vendors.
Imagine:
Company → HRMS → Payroll Vendor → Cloud Provider
or
Company → Recruitment Platform → Background Verification Agency
The data may move across several organisations.
Therefore, procurement teams should introduce DPDP considerations into:
- vendor due diligence;
- RFPs;
- contracts;
- data-processing clauses;
- security assessments;
- audit rights;
- breach notification clauses;
- termination provisions;
- data deletion/return requirements.
Data privacy should become part of vendor governance—not an afterthought during contract review.
27. DPDP and Employee Experience
There is another dimension that organisations should not overlook.
Employees increasingly want to know:
What information does my employer hold about me?
Why does the organisation need it?
Who has access to it?
How long will it be retained?
Is my data being shared with third parties?
A transparent privacy framework can therefore strengthen employee trust.
The objective should not be to create complicated legal documents that employees never read.
It should be to create a workplace where employees understand:
“My organisation knows what data it holds about me, why it holds it and how it protects it.”
28. DPDP Should Be Viewed as a Governance Transformation
The most important conceptual shift is this:
Data protection is no longer merely a technology issue.
It is increasingly a question of:
- governance;
- accountability;
- risk;
- process design;
- employee trust;
- customer trust;
- vendor management;
- cybersecurity;
- compliance.
For HR leaders, it represents another major dimension of HR governance.
For CFOs and tax/compliance professionals, it creates a new area of enterprise risk.
For legal teams, it creates a new contractual and regulatory framework.
For CIOs and CISOs, it strengthens the need to connect privacy governance with information security.
And for boards, it creates a new area of oversight.
29. What Should Organisations Do Now?
With the major operational provisions scheduled to commence in May 2027, organisations should not wait until the effective date.
A practical roadmap could be:
Phase 1 – Understand
What personal data do we have?
Phase 2 – Map
Where does the data move?
Phase 3 – Assess
Why are we processing it and under what legal basis?
Phase 4 – Govern
Who is accountable?
Phase 5 – Remediate
What gaps exist in our policies, contracts, systems and controls?
Phase 6 – Implement
Can we operationalise rights, consent, retention and breach response?
Phase 7 – Test
Can we actually respond to a Data Principal request or data breach?
Phase 8 – Audit
Can we demonstrate compliance with evidence?
This final question is critical.
Compliance is not merely having a policy. Compliance is being able to demonstrate that the policy works.
Conclusion
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 mark a significant transformation in India’s personal-data governance landscape.
The framework introduces:
- clearer responsibilities for Data Fiduciaries;
- rights for Data Principals;
- obligations relating to security and breach management;
- special protection for children;
- enhanced obligations for Significant Data Fiduciaries;
- Consent Managers;
- a dedicated Data Protection Board;
- and substantial financial penalties for non-compliance.
The Government has adopted a phased commencement mechanism, giving organisations time to prepare. But the implementation window should be viewed as an opportunity—not a reason to postpone action.
For Indian businesses, the real challenge will not be understanding the law.
It will be translating the law into everyday business processes.
For HR, that means rethinking how employee data is collected, used, shared, stored and deleted.
For businesses, it means bringing privacy into procurement, technology, contracts, cybersecurity and governance.
And for leadership, it means recognising that:
Personal data is not merely information sitting in an HRMS, CRM or cloud server. It represents an individual’s identity, trust and rights—and protecting it is now a business responsibility.
The DPDP journey should therefore begin well before the statutory deadline.






