Skip to content
DPDP deadline in
Learn more →
PrivacySuraksha - Privacy. Trust. Compliance

India's DPDP privacy operations platform

India's data protection law

The Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection (DPDP) Act, 2023 establishes India's comprehensive legal framework for the processing of digital personal data, protecting individuals' privacy rights and defining organisations' data protection responsibilities. Implementation is being phased in from November 2025 through 2027.

This page explains the Act's structure in plain language; it isn't legal advice. For the full section-by-section text, see our DPDP Act guide.

Enforcement timeline

DPDP Rules 2025. Three phases, one hard deadline

  1. Active

    Data Protection Board operational

    Complaints are being accepted now.

  2. Consent Managers come into force

    Implementation has to start well before this date, not on it.

  3. Deadline

    Full enforcement

    The hard deadline for complete DPDP compliance.

The law, in brief

What the DPDP Act is, and who it binds.

What is the DPDP Act?

India's law for processing digital personal data — data collected online, or collected offline and digitised afterward. It applies inside India, and to processing outside India wherever it relates to offering goods or services to people here.

“Personal data” means any data about an individual who is identifiable by or in relation to such data.— Section 2(t)

Who does it apply to?

DPDP applies by what you do with personal data, not by your size or where you're based.

  • Any organisation processing digital personal data within India
  • Any organisation outside India offering goods or services to people in India
  • Data Processors handling personal data on another fiduciary's behalf

Section 33 and the Schedule

Penalties for non-compliance

Violations of the DPDP Act may attract substantial financial penalties, with penalties of up to ₹250 crore for certain breaches. Aggregate penalties for multiple breaches may exceed ₹250 crore.

₹250 cr

Failing to take reasonable security safeguards to prevent a personal data breach.

Section 8(5) · Schedule Sl. No. 1

₹200 cr

Failing to notify the Board and affected Data Principals of a personal data breach.

Section 8(6) · Schedule Sl. No. 2

₹200 cr

Breaching the additional obligations that apply to a child's personal data.

Section 9 · Schedule Sl. No. 3

A Significant Data Fiduciary's obligations carry a further ₹150 crore ceiling; any other breach of the Act or its rules, up to ₹50 crore.

Key roles

Three roles the Act defines — and treats differently.

Sections 6 and Rule 6

Lawful starts with consent, and stays lawful with safeguards.

Consent requirements

Section 6(1)

Security safeguards

  • 1Encryption, obfuscation, masking, or virtual tokens over the data itself
  • 2Access control over the computer resources involved
  • 3Logs, monitoring, and review to detect unauthorised access
  • 4Backups for continued processing if data is lost or compromised
  • 5Contracts that bind processors to the same safeguards
  • 6Breach-related logs and data retained for one year

Rule 6, Digital Personal Data Protection Rules, 2025

Data retention

  • 3 years from last activity — large-scale e-commerce (2 crore+ registered users), online gaming (50 lakh+), and social media (2 crore+) platforms named in the Third Schedule.
  • Every other Data Fiduciary — erase once the stated purpose is served, unless another law requires longer retention.
  • A 48-hour erasure notice goes to the Data Principal first.

Rule 8(1)–(2) and Third Schedule

Breach notification

72 hours

for the Board's full follow-up report, after an initial notice sent without delay.

  • Without delay — initial notice to the Board, and to every affected Data Principal. A Data Principal's notice ends there; there's no second stage for her.
  • Within 72 hours — the Board alone also gets the full follow-up: cause, impact, and mitigation in detail.

Section 8(6) and Rule 7

Section 9

A child's data gets extra protection.

Verifiable consent required

Before processing a child's — or a person with a disability's — personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. Processing can't harm a child's well-being, and tracking, behavioural monitoring, or targeted advertising directed at children is barred outright.

Exemptions with conditions

The bar on tracking and monitoring doesn't apply to clinical establishments and healthcare professionals treating the child, educational institutions monitoring for safety or learning, childcare centres and crèches, or their contracted child transport — each limited strictly to that stated purpose.

Fourth Schedule, Part A

Section 16

Cross-border transfer is allowed by default.

The Act sets no data-localisation rule and no case-by-case approval. The Central Government can restrict transfers to specific notified countries or territories; everywhere else, transfer for processing is permitted — without prejudice to any other Indian law that sets a stricter standard for particular data.

One platform. Complete privacy lifecycle.

Everything you need for DPDP compliance

Ready to get compliant?

PrivacySuraksha turns these obligations into a working system: automated discovery, consent evidence, and audit-ready records.