India's data protection law
The Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection (DPDP) Act, 2023 establishes India's comprehensive legal framework for the processing of digital personal data, protecting individuals' privacy rights and defining organisations' data protection responsibilities. Implementation is being phased in from November 2025 through 2027.
This page explains the Act's structure in plain language; it isn't legal advice. For the full section-by-section text, see our DPDP Act guide.
Enforcement timeline
DPDP Rules 2025. Three phases, one hard deadline
Active
Data Protection Board operational
Complaints are being accepted now.
Consent Managers come into force
Implementation has to start well before this date, not on it.
Deadline
Full enforcement
The hard deadline for complete DPDP compliance.
The law, in brief
What the DPDP Act is, and who it binds.
What is the DPDP Act?
India's law for processing digital personal data — data collected online, or collected offline and digitised afterward. It applies inside India, and to processing outside India wherever it relates to offering goods or services to people here.
“Personal data” means any data about an individual who is identifiable by or in relation to such data.— Section 2(t)
Who does it apply to?
DPDP applies by what you do with personal data, not by your size or where you're based.
- Any organisation processing digital personal data within India
- Any organisation outside India offering goods or services to people in India
- Data Processors handling personal data on another fiduciary's behalf
Section 33 and the Schedule
Penalties for non-compliance
Violations of the DPDP Act may attract substantial financial penalties, with penalties of up to ₹250 crore for certain breaches. Aggregate penalties for multiple breaches may exceed ₹250 crore.
₹250 cr
Failing to take reasonable security safeguards to prevent a personal data breach.
Section 8(5) · Schedule Sl. No. 1
₹200 cr
Failing to notify the Board and affected Data Principals of a personal data breach.
Section 8(6) · Schedule Sl. No. 2
₹200 cr
Breaching the additional obligations that apply to a child's personal data.
Section 9 · Schedule Sl. No. 3
A Significant Data Fiduciary's obligations carry a further ₹150 crore ceiling; any other breach of the Act or its rules, up to ₹50 crore.
Key roles
Three roles the Act defines — and treats differently.
Data Principal
The individual the personal data is about.
- Section 11 (Right to Access Information): grants rights to a summary of processing and shared entities
- Section 12 (Right to Correction and Erasure): allows demanding correction, completion, updating, and erasure
- Section 13 (Right to Grievance Redressal): mandates internal grievance mechanisms before approaching the Board
- Section 14 (Right to Nominate): permits nominating another person to exercise rights upon death or incapacity
Chapter III, Sections 11–14
Data Fiduciary
Any person who alone or with others determines the purpose and means of processing.
- Section 5 (Notice): a clear, easy-to-understand notice before or when collecting data, detailing what is collected and why
- Section 6 (Consent): free, specific, informed, unconditional consent, with an easy way to withdraw it later
- Section 7 (Certain Legitimate Uses): processing without consent for specific public-interest cases — state functions, subsidies, medical emergencies, employment safety
- Section 8 (General Obligations): data accuracy, storage limitation, security safeguards, processor contracts, and 72-hour breach reporting
Sections 2(i), 5–8
Significant Data Fiduciary
Notified by the Central Government by data volume, sensitivity, and risk.
- Appoint an India-based Data Protection Officer, reporting to the board
- Appoint an independent data auditor
- Run a periodic Data Protection Impact Assessment
- Undergo a periodic audit
Section 10
Sections 6 and Rule 6
Lawful starts with consent, and stays lawful with safeguards.
Consent requirements
Section 6(1)
Security safeguards
- 1Encryption, obfuscation, masking, or virtual tokens over the data itself
- 2Access control over the computer resources involved
- 3Logs, monitoring, and review to detect unauthorised access
- 4Backups for continued processing if data is lost or compromised
- 5Contracts that bind processors to the same safeguards
- 6Breach-related logs and data retained for one year
Rule 6, Digital Personal Data Protection Rules, 2025
Data retention
- 3 years from last activity — large-scale e-commerce (2 crore+ registered users), online gaming (50 lakh+), and social media (2 crore+) platforms named in the Third Schedule.
- Every other Data Fiduciary — erase once the stated purpose is served, unless another law requires longer retention.
- A 48-hour erasure notice goes to the Data Principal first.
Rule 8(1)–(2) and Third Schedule
Breach notification
72 hours
for the Board's full follow-up report, after an initial notice sent without delay.
- Without delay — initial notice to the Board, and to every affected Data Principal. A Data Principal's notice ends there; there's no second stage for her.
- Within 72 hours — the Board alone also gets the full follow-up: cause, impact, and mitigation in detail.
Section 8(6) and Rule 7
Section 9
A child's data gets extra protection.
Verifiable consent required
Before processing a child's — or a person with a disability's — personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. Processing can't harm a child's well-being, and tracking, behavioural monitoring, or targeted advertising directed at children is barred outright.
Exemptions with conditions
The bar on tracking and monitoring doesn't apply to clinical establishments and healthcare professionals treating the child, educational institutions monitoring for safety or learning, childcare centres and crèches, or their contracted child transport — each limited strictly to that stated purpose.
Fourth Schedule, Part A
Section 16
Cross-border transfer is allowed by default.
The Act sets no data-localisation rule and no case-by-case approval. The Central Government can restrict transfers to specific notified countries or territories; everywhere else, transfer for processing is permitted — without prejudice to any other Indian law that sets a stricter standard for particular data.
One platform. Complete privacy lifecycle.
Everything you need for DPDP compliance
Discover & Map
Find and classify personal data across every connected system.
- Personal data discovery
- Data inventory & classification
- RoPA automation
Govern & Protect
Assess risk, manage processors, and handle breaches.
- DPIA & privacy by design
- Vendor & processor risk
- Breach response
Assure & Prove
Audit-ready evidence, always.
- Evidence register
- Audit management
- Board reporting
Ready to get compliant?
PrivacySuraksha turns these obligations into a working system: automated discovery, consent evidence, and audit-ready records.
