The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law. It governs how organizations collect, process, store, and share the personal data of individuals located in India, regardless of where the processing organization is based.
Any Data Fiduciary or Data Processor handling the personal data of individuals in India falls within scope. This includes domestic businesses, multinational companies serving Indian customers, government bodies, and not-for-profit organizations that process personal data at scale.
Organizations must obtain , specific, informed and revocable consent before processing personal data; process data only for the stated purpose; implement reasonable security safeguards; maintain accurate records; and notify both the Data Protection Board and affected individuals promptly in the event of a breach.
Individuals have the right to access information about how their data is processed, request correction or erasure, nominate a representative, withdraw consent at any time, and seek grievance redressal through the Data Protection Board.
The Act is being implemented in phases. Basic rules and registration requirements took effect first, followed by the consent manager framework, with full enforcement — including the complete penalty regime — to follow. Organizations should not wait for full enforcement to begin building compliant processes.
The Data Protection Board can levy financial penalties of up to Rs. 250 Crore per instance for serious violations, including failure to implement reasonable security safeguards or to report data breaches in a timely manner.