About DPDP

Understanding The DPDP Act, 2023

India's Digital Personal Data Protection Act establishes a comprehensive framework for how personal data must be collected, processed, and protected.

What The Act Sets Out To Do

The DPDP Act gives individuals — termed Data Principals — enforceable rights over their personal data, while placing clear obligations on the organizations, or Data Fiduciaries, that process it. It replaces a patchwork of older rules with a single, modern framework aligned with global standards.

At its core, the Act requires that personal data be processed lawfully, for a specified purpose, with informed consent, and only for as long as necessary. Organizations must maintain audit-ready records, secure the data they hold, and report breaches promptly to both the Data Protection Board and affected individuals.

Enforcement is being phased in over several years, giving organizations a window to build compliant processes before the full penalty regime takes effect — but that window is narrowing.

Key Concepts

The Vocabulary Of The DPDP Act

Data Principal

The individual to whom the personal data relates — the person whose data is being processed.

Data Fiduciary

The entity that determines the purpose and means of processing personal data.

Data Processor

An entity that processes personal data on behalf of a Data Fiduciary.

Consent Manager

A registered intermediary through which a Data Principal can give, manage, and withdraw consent.

Significant Data Fiduciary

Fiduciaries notified by the government due to volume or sensitivity of data processed, with added obligations.

Data Protection Board

The adjudicating body established to enforce the DPDP Act and rule on grievances.

Enforcement Timeline

How The DPDP Act Rolls Out

Phase 1 Nov 2025 Active

Basic Rules

Foundational rules and registration requirements come into effect.

Phase 2 Nov 2026

Consent System

Consent manager framework and verifiable consent mechanisms become mandatory.

Phase 3 May 2027

Full Enforcement

Complete enforcement of the DPDP Act including penalty provisions across all fiduciaries.

Penalties Up To ₹250 Crores

The Data Protection Board can levy financial penalties of up to ₹250 Crore per instance for serious non-compliance, including failure to implement reasonable security safeguards or report data breaches.

Rights Of The Data Principal

  • Right to access information about personal data processing
  • Right to correction and erasure of personal data
  • Right to grievance redressal
  • Right to nominate a representative
  • Right to withdraw consent at any time
Resources

Downloadable Whitepapers

In-depth guides to help your team understand and act on DPDP requirements.

DPDP Act 2023: Complete Compliance Guide

6 sections · PDF

View / Download PDF

Consent Management Implementation Playbook

5 sections · PDF

View / Download PDF

DPDP Readiness Self-Assessment Checklist

4 sections · PDF

View / Download PDF
FAQs

Frequently Asked Questions

The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law governing how organizations collect, process, and store the personal data of individuals in India.
Any organization — Data Fiduciary or Data Processor — that processes the personal data of individuals in India, whether located in India or abroad, falls within scope of the Act.
Penalties under the DPDP Act can reach up to ₹250 Crore per instance, depending on the nature and severity of the breach or violation, as determined by the Data Protection Board.
A typical readiness assessment takes 3 to 6 weeks depending on organization size, number of systems, and data complexity. We provide a tailored timeline after an initial scoping call.
Consent Managers become central to verifiable consent under Phase 2 of the Act. Whether you need to integrate with one depends on your data collection model — we assess this during the readiness phase.
A Significant Data Fiduciary is an entity notified by the government based on factors like volume and sensitivity of data processed, triggering additional obligations such as data protection impact assessments and audits.

Start Your DPDP Compliance Journey Today

Get a readiness assessment and a clear roadmap to compliance within weeks, not months.