Context
The Digital Personal Data Protection Act, 2023 provides the legal framework for protecting digital personal data in India. The DPDP Rules, 2025 have also been notified, but most substantive provisions of the Act are scheduled to become operational from 13 May 2027.
Scope and Key Terms
The Act applies to personal data:
- Collected in digital form; or
- Collected offline and later digitised.
It also applies to processing outside India when goods or services are offered to individuals in India.
Key terms include:
- Data Principal: Individual to whom the data relates.
- Data Fiduciary: Entity deciding the purpose and manner of data processing.
- Data Processor: Entity processing data on behalf of a Data Fiduciary.
- Consent Manager: Registered platform that helps individuals manage consent.
Personal data used for domestic purposes or lawfully made publicly available is excluded.
Consent, Rights and Duties
Personal data may be processed with valid consent or for certain legitimate uses such as medical emergencies, government benefits, legal obligations and employment purposes.
Consent must be free, informed, specific and unambiguous. It can be withdrawn as easily as it was given.
Data Principals have the right to:
- Access information about their data.
- Correct, complete and update data.
- Seek erasure where retention is unnecessary.
- Obtain grievance redressal.
- Nominate another person to exercise their rights after death or incapacity.
They must not impersonate others, provide false information or file frivolous complaints.
Obligations of Data Fiduciaries
Data Fiduciaries must:
- Give clear notice before collecting data.
- Use data only for the stated purpose.
- Maintain accuracy and security safeguards.
- Report personal-data breaches.
- Delete data when the purpose is complete, unless retention is required by law.
- Establish a grievance-redressal mechanism.
For children below 18 years, verifiable parental consent is generally required. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
Significant Data Fiduciaries have additional duties such as appointing a Data Protection Officer, conducting audits and carrying out Data Protection Impact Assessments.
Data Protection Board and Penalties
The Act establishes the Data Protection Board of India to inquire into breaches, issue directions, accept voluntary undertakings and impose penalties.
Appeals against its orders lie before the Telecom Disputes Settlement and Appellate Tribunal.
Major penalties include:
- Up to ₹250 crore for failure to maintain security safeguards.
- Up to ₹200 crore for failure to report a data breach.
- Up to ₹200 crore for violating obligations relating to children.
- Up to ₹150 crore for violation of Significant Data Fiduciary obligations.
Significance and Concerns
The Act strengthens digital privacy, consent-based processing, accountability and protection against data breaches.
However, concerns remain regarding:
- Wide exemptions available to the government.
- Independence of the Data Protection Board.
- Absence of a separate category for sensitive personal data.
- Lack of a detailed compensation mechanism.
- Impact of the amendment to the RTI Act on transparency.



