Understanding The DPDP Act, 2023
India's Digital Personal Data Protection Act establishes a comprehensive framework for how personal data must be collected, processed, and protected.
What The Act Sets Out To Do
The DPDP Act gives individuals — termed Data Principals — enforceable rights over their personal data, while placing clear obligations on the organizations, or Data Fiduciaries, that process it. It replaces a patchwork of older rules with a single, modern framework aligned with global standards.
At its core, the Act requires that personal data be processed lawfully, for a specified purpose, with informed consent, and only for as long as necessary. Organizations must maintain audit-ready records, secure the data they hold, and report breaches promptly to both the Data Protection Board and affected individuals.
Enforcement is being phased in over several years, giving organizations a window to build compliant processes before the full penalty regime takes effect — but that window is narrowing.
The Vocabulary Of The DPDP Act
Data Principal
The individual to whom the personal data relates — the person whose data is being processed.
Data Fiduciary
The entity that determines the purpose and means of processing personal data.
Data Processor
An entity that processes personal data on behalf of a Data Fiduciary.
Consent Manager
A registered intermediary through which a Data Principal can give, manage, and withdraw consent.
Significant Data Fiduciary
Fiduciaries notified by the government due to volume or sensitivity of data processed, with added obligations.
Data Protection Board
The adjudicating body established to enforce the DPDP Act and rule on grievances.
How The DPDP Act Rolls Out
Basic Rules
Foundational rules and registration requirements come into effect.
Consent System
Consent manager framework and verifiable consent mechanisms become mandatory.
Full Enforcement
Complete enforcement of the DPDP Act including penalty provisions across all fiduciaries.
Penalties Up To ₹250 Crores
The Data Protection Board can levy financial penalties of up to ₹250 Crore per instance for serious non-compliance, including failure to implement reasonable security safeguards or report data breaches.
Rights Of The Data Principal
- Right to access information about personal data processing
- Right to correction and erasure of personal data
- Right to grievance redressal
- Right to nominate a representative
- Right to withdraw consent at any time
Downloadable Whitepapers
In-depth guides to help your team understand and act on DPDP requirements.