LIVE
1,218 regulations trackedEU AI Act — amendment 03.14India DPDP — §17 draft rulesColorado CPA — enforcement 2026-042.1M DSARs automatedSOC 2 Type II renewedSingapore PDPA advisory1,218 regulations trackedEU AI Act — amendment 03.14India DPDP — §17 draft rulesColorado CPA — enforcement 2026-042.1M DSARs automatedSOC 2 Type II renewedSingapore PDPA advisory
FaceOFF.world
← All regulations
DPDPIndia · Regulation spotlight

The Digital Personal Data Protection Act, 2023.

India’s first comprehensive data-protection law. It gives every individual real rights over their personal data and holds the organisations that process it accountable — with a consent-first framework and penalties up to ₹250 crore.

2023
enacted (11 Aug)
₹250 cr
max penalty / instance
1.4B+
people in scope
Why it matters

Why DPDP is a big deal.

World’s largest democracy

With well over a billion people online, DPDP governs the personal data of one of the biggest digital populations on earth — any business serving Indian users is in scope.

Extra-territorial reach

It applies to data processing outside India whenever goods or services are offered to Data Principals in India — so global companies must comply even without an Indian entity.

Serious penalties

Failure to take reasonable security safeguards can attract penalties of up to ₹250 crore per instance, adjudicated by the Data Protection Board of India.

Consent-first culture

Every use of personal data must rest on free, informed, specific consent (or a defined legitimate use) — reshaping how products collect and retain data in India.

Timeline

The road to the DPDP Act.

Six years from a landmark privacy judgment to an enacted law — and the phased rollout now underway.

1
Aug 2017

Right to privacy is fundamental

In K.S. Puttaswamy v. Union of India, a nine-judge Supreme Court bench holds that privacy is a fundamental right under Article 21 — the constitutional foundation for a data-protection law.

2
2017–2018

Srikrishna Committee

An expert committee chaired by Justice B.N. Srikrishna studies a framework and releases a report with the first draft Personal Data Protection Bill.

3
Dec 2019

PDP Bill 2019

The Personal Data Protection Bill is introduced in Parliament and referred to a Joint Parliamentary Committee for review.

4
Aug 2022

Bill withdrawn

After the JPC report and years of debate, the 2019 Bill is withdrawn to be replaced by a simpler, principles-based draft.

5
Nov 2022

Draft DPDP Bill

A leaner Digital Personal Data Protection Bill is released for public consultation.

6
Aug 2023

DPDP Act enacted

Passed by the Lok Sabha (7 Aug) and Rajya Sabha (9 Aug), the Act receives Presidential assent on 11 August 2023.

7
Jan 2025

Draft Rules published

The government releases the draft DPDP Rules for public consultation, detailing consent notices, breach reporting, and Consent Manager registration.

8
2025–2026

Phased enforcement

The Data Protection Board of India stands up and obligations take effect in phases, giving organisations a transition window to comply.

Scope

Who and what it covers.

DPDP governs digital personal data — data collected digitally, or collected on paper and later digitised.

Applies to

Processing of digital personal data within India, and processing outside India where it relates to offering goods or services to Data Principals in India.

Does not apply to

Personal data processed for purely personal or domestic purposes, and data made publicly available by the Principal or under a legal obligation.

Cross-border transfers

Transfers abroad are broadly permitted, except to countries specifically restricted by the Central Government — a “blacklist” rather than “allowlist” approach.

Key concepts

The players in the Act.

DP

Data Principal

The individual the personal data is about — including, for a child, their parent or lawful guardian.

DF

Data Fiduciary

Any person who, alone or with others, determines the purpose and means of processing personal data.

DPr

Data Processor

A person who processes personal data on behalf of a Data Fiduciary under a contract.

CM

Consent Manager

A registered, interoperable platform that lets Data Principals give, manage, review and withdraw consent.

SDF

Significant Data Fiduciary

A fiduciary notified based on data volume and sensitivity — with extra duties: a DPO in India, independent audits and DPIAs.

DPBI

Data Protection Board

The independent regulator that investigates breaches, hears complaints and imposes penalties.

Rights of the Data Principal

What individuals can demand.

Right to access

A clear summary of what personal data is processed and the activities it is used for.

Correction & erasure

Ask for inaccurate data to be corrected, completed or updated — and for data no longer needed to be erased.

Grievance redressal

A readily available means to raise grievances with the Data Fiduciary or Consent Manager before escalating to the Board.

Right to nominate

Nominate another individual to exercise these rights in the event of death or incapacity.

Withdraw consent

Withdraw consent as easily as it was given, stopping further processing that relied on it.

Duties of the Data Fiduciary

What organisations must do.

Notice & consent

Give a clear, itemised notice — available in English and India’s scheduled languages — and obtain free, specific, informed, unambiguous consent.

Purpose limitation

Process personal data only for the specified lawful purpose the Principal consented to, and no further.

Security safeguards

Implement reasonable technical and organisational measures to prevent personal-data breaches.

Breach notification

Notify the Data Protection Board and affected Data Principals in the event of a personal-data breach.

Children’s data

Obtain verifiable parental consent for under-18s; no tracking, behavioural monitoring or targeted advertising directed at children.

Retention & erasure

Erase personal data once consent is withdrawn or the purpose is served, unless retention is legally required.

Penalties

The cost of getting it wrong.

The Data Protection Board can impose financial penalties per instance of non-compliance — here are the headline figures.

BreachUp to
Failure to take reasonable security safeguards to prevent a personal-data breach₹250 crore
Failure to notify the Board or affected Principals of a breach₹200 crore
Breach of obligations relating to children’s personal data₹200 crore
Breach of additional Significant Data Fiduciary obligations₹150 crore
Breach of Data Principal duties (e.g. false or frivolous complaints)₹10,000
Breach of any other provision or rule₹50 crore

Figures reflect the maximum penalties in the Act’s schedule; the Board sets the actual amount case by case. For general guidance only, not legal advice.

Enforcement timeline

A phased rollout, not a big bang.

The draft rules stage the Act’s obligations across three phases, giving organisations a transition window before mandatory compliance begins.

Phase 1Immediate

Effective immediately (13 Nov ’25)

  • The Data Protection Board of India (DPB) is set up.
  • The Board’s governance and rule-making powers begin.
Phase 2+12 months

After 12 months (Nov ’26)

  • The Consent Manager registration framework becomes active — managers must obtain independent certification and amend their MOA/AOA to embed obligations.
  • Technical and operational standards for consent management are introduced.
Phase 3+18 months

After 18 months (May ’27)

Mandatory compliance begins. Organisations must follow:

  • Notice & consent requirements
  • Security safeguards
  • Breach notifications
  • Data-principal rights
  • Retention & deletion rules
  • Cross-border transfer rules
  • Significant Data Fiduciary (SDF) duties
  • Penalties under the Act become active
Time-phased enforcement & registration: Consent Manager registration requirements begin after 1 year, and full compliance begins at 18 months.
Readiness roadmap

DPDP Act readiness roadmap.

A practical three-stage path from establishing the foundation to sustaining compliance over time.

Phase 1Build

Establish the compliance foundation

  • Conduct applicability and gap assessment across legal, technical, operational and third-party dimensions.
  • Map and inventory personal data across systems, business units, cloud platforms and vendors.
  • Update notices, policies, contracts and governance frameworks.
  • Perform impact assessments for high-risk processing.
  • Develop a prioritised roadmap with ownership and timelines.
Phase 2Implement

Operationalise DPDP requirements

  • Deploy consent management, including age verification where required.
  • Implement workflows for data-principal rights with defined service levels.
  • Define and enforce retention and disposal schedules.
  • Strengthen technical and organisational safeguards.
  • Update breach detection, response and notification processes.
  • Formalise processor controls through contracts and due diligence.
Phase 3Manage

Sustain and demonstrate compliance

  • Establish continuous monitoring and management reporting.
  • Conduct periodic independent and vendor audits.
  • Embed privacy by design into new initiatives.
  • Maintain auditable handling of data-principal requests.
  • Regularly test breach preparedness through simulations and drills.

Ready for India’s DPDP Act?

Run a free scan and the copilot maps your data and consent flows against every DPDP obligation — with citations.

Request demo →