The Digital Personal Data Protection Act, 2023.
India’s first comprehensive data-protection law. It gives every individual real rights over their personal data and holds the organisations that process it accountable — with a consent-first framework and penalties up to ₹250 crore.
Why DPDP is a big deal.
World’s largest democracy
With well over a billion people online, DPDP governs the personal data of one of the biggest digital populations on earth — any business serving Indian users is in scope.
Extra-territorial reach
It applies to data processing outside India whenever goods or services are offered to Data Principals in India — so global companies must comply even without an Indian entity.
Serious penalties
Failure to take reasonable security safeguards can attract penalties of up to ₹250 crore per instance, adjudicated by the Data Protection Board of India.
Consent-first culture
Every use of personal data must rest on free, informed, specific consent (or a defined legitimate use) — reshaping how products collect and retain data in India.
The road to the DPDP Act.
Six years from a landmark privacy judgment to an enacted law — and the phased rollout now underway.
Right to privacy is fundamental
In K.S. Puttaswamy v. Union of India, a nine-judge Supreme Court bench holds that privacy is a fundamental right under Article 21 — the constitutional foundation for a data-protection law.
Srikrishna Committee
An expert committee chaired by Justice B.N. Srikrishna studies a framework and releases a report with the first draft Personal Data Protection Bill.
PDP Bill 2019
The Personal Data Protection Bill is introduced in Parliament and referred to a Joint Parliamentary Committee for review.
Bill withdrawn
After the JPC report and years of debate, the 2019 Bill is withdrawn to be replaced by a simpler, principles-based draft.
Draft DPDP Bill
A leaner Digital Personal Data Protection Bill is released for public consultation.
DPDP Act enacted
Passed by the Lok Sabha (7 Aug) and Rajya Sabha (9 Aug), the Act receives Presidential assent on 11 August 2023.
Draft Rules published
The government releases the draft DPDP Rules for public consultation, detailing consent notices, breach reporting, and Consent Manager registration.
Phased enforcement
The Data Protection Board of India stands up and obligations take effect in phases, giving organisations a transition window to comply.
Who and what it covers.
DPDP governs digital personal data — data collected digitally, or collected on paper and later digitised.
Applies to
Processing of digital personal data within India, and processing outside India where it relates to offering goods or services to Data Principals in India.
Does not apply to
Personal data processed for purely personal or domestic purposes, and data made publicly available by the Principal or under a legal obligation.
Cross-border transfers
Transfers abroad are broadly permitted, except to countries specifically restricted by the Central Government — a “blacklist” rather than “allowlist” approach.
The players in the Act.
Data Principal
The individual the personal data is about — including, for a child, their parent or lawful guardian.
Data Fiduciary
Any person who, alone or with others, determines the purpose and means of processing personal data.
Data Processor
A person who processes personal data on behalf of a Data Fiduciary under a contract.
Consent Manager
A registered, interoperable platform that lets Data Principals give, manage, review and withdraw consent.
Significant Data Fiduciary
A fiduciary notified based on data volume and sensitivity — with extra duties: a DPO in India, independent audits and DPIAs.
Data Protection Board
The independent regulator that investigates breaches, hears complaints and imposes penalties.
What individuals can demand.
Right to access
A clear summary of what personal data is processed and the activities it is used for.
Correction & erasure
Ask for inaccurate data to be corrected, completed or updated — and for data no longer needed to be erased.
Grievance redressal
A readily available means to raise grievances with the Data Fiduciary or Consent Manager before escalating to the Board.
Right to nominate
Nominate another individual to exercise these rights in the event of death or incapacity.
Withdraw consent
Withdraw consent as easily as it was given, stopping further processing that relied on it.
What organisations must do.
Notice & consent
Give a clear, itemised notice — available in English and India’s scheduled languages — and obtain free, specific, informed, unambiguous consent.
Purpose limitation
Process personal data only for the specified lawful purpose the Principal consented to, and no further.
Security safeguards
Implement reasonable technical and organisational measures to prevent personal-data breaches.
Breach notification
Notify the Data Protection Board and affected Data Principals in the event of a personal-data breach.
Children’s data
Obtain verifiable parental consent for under-18s; no tracking, behavioural monitoring or targeted advertising directed at children.
Retention & erasure
Erase personal data once consent is withdrawn or the purpose is served, unless retention is legally required.
The cost of getting it wrong.
The Data Protection Board can impose financial penalties per instance of non-compliance — here are the headline figures.
Figures reflect the maximum penalties in the Act’s schedule; the Board sets the actual amount case by case. For general guidance only, not legal advice.
A phased rollout, not a big bang.
The draft rules stage the Act’s obligations across three phases, giving organisations a transition window before mandatory compliance begins.
Effective immediately (13 Nov ’25)
- The Data Protection Board of India (DPB) is set up.
- The Board’s governance and rule-making powers begin.
After 12 months (Nov ’26)
- The Consent Manager registration framework becomes active — managers must obtain independent certification and amend their MOA/AOA to embed obligations.
- Technical and operational standards for consent management are introduced.
After 18 months (May ’27)
Mandatory compliance begins. Organisations must follow:
- Notice & consent requirements
- Security safeguards
- Breach notifications
- Data-principal rights
- Retention & deletion rules
- Cross-border transfer rules
- Significant Data Fiduciary (SDF) duties
- Penalties under the Act become active
DPDP Act readiness roadmap.
A practical three-stage path from establishing the foundation to sustaining compliance over time.
Establish the compliance foundation
- Conduct applicability and gap assessment across legal, technical, operational and third-party dimensions.
- Map and inventory personal data across systems, business units, cloud platforms and vendors.
- Update notices, policies, contracts and governance frameworks.
- Perform impact assessments for high-risk processing.
- Develop a prioritised roadmap with ownership and timelines.
Operationalise DPDP requirements
- Deploy consent management, including age verification where required.
- Implement workflows for data-principal rights with defined service levels.
- Define and enforce retention and disposal schedules.
- Strengthen technical and organisational safeguards.
- Update breach detection, response and notification processes.
- Formalise processor controls through contracts and due diligence.
Sustain and demonstrate compliance
- Establish continuous monitoring and management reporting.
- Conduct periodic independent and vendor audits.
- Embed privacy by design into new initiatives.
- Maintain auditable handling of data-principal requests.
- Regularly test breach preparedness through simulations and drills.
Turn DPDP duties into working software.
Every obligation above maps to a FaceOFF product — with the copilot citing the exact clause behind each control.
Consent Management
Capture free, specific, informed consent with itemised notices and honour withdrawal instantly — Consent-Manager ready.
Explore →DSAR Management
Fulfil access, correction, erasure and nomination requests from Data Principals within statutory timelines.
Explore →Intelligent Data Mapper
Discover and map personal data across systems so you know exactly what you hold and why — the basis of every DPDP duty.
Explore →PIA / DPIA Assessment
Run the DPIAs and independent-audit evidence that Significant Data Fiduciaries are required to maintain.
Explore →Audit & Evidence Management
Keep a living, timestamped evidence trail — ready for the Data Protection Board if a breach is ever questioned.
Explore →Ready for India’s DPDP Act?
Run a free scan and the copilot maps your data and consent flows against every DPDP obligation — with citations.
