DPDP Act 2023 and DPDP Rules 2025 – Decoded

India’s DPDP Act & Rules — Decoded
India’s first comprehensive data protection law is now fully in force. Everything you need to know — from core principles to compliance deadlines — explained without the legalese.
What is the DPDP Act and why does it matter?
India’s first standalone data protection law reshapes how every organisation handles personal data of Indian citizens — domestically and globally.
The Digital Personal Data Protection Act, 2023 is India’s most significant piece of digital legislation. Enacted on 11 August 2023 and operationalised through DPDP Rules notified on 13 November 2025, it creates a clear legal framework governing how personal data of Indian citizens is collected, used, stored, and protected.
Before this Act, India’s data privacy landscape was patchy — governed by the ageing IT Act 2000 and limited Privacy Rules of 2011. The Supreme Court’s landmark 2017 ruling in Justice K.S. Puttaswamy v. Union of India declared privacy a fundamental right under Article 21 — and the DPDP Act is the legislative fulfilment of that ruling.
The Act applies to every organisation that handles digital personal data of Indian citizens — including foreign companies offering goods or services to people in India. Whether you’re a startup or a global corporation, the DPDP Act almost certainly applies to you.
Built on the SARAL framework
The government committed to making this law genuinely usable. SARAL stands for Simple, Accessible, Rational, and Actionable Law — a design principle baked into every provision.
Who does this law cover?
The Act’s reach is both deep within India and broad beyond its borders. Scope is the first thing any compliance programme must establish.
The who’s who of the DPDP framework
The Act introduces precise terminology for each role in the data ecosystem. Knowing your role determines your obligations.
DPDP Act 2023 — Mind Map
A complete visual of the Act’s architecture — from principles to enforcement.
The 7 Core Principles
Every data processing decision must be governed by these principles. They apply to every Data Fiduciary without exception.
Six rights every Indian citizen now holds
The DPDP Act gives every individual six enforceable rights. Data Fiduciaries must respond within 90 days.
What every organisation must do
From a startup with a newsletter to a bank with millions of customers — all Data Fiduciaries share these seven core obligations.
Children’s data — the strictest zone
The Act places the strongest protections around personal data of anyone under 18 years of age.
Significant Data Fiduciaries — the top tier
Not all organisations face equal obligations. SDFs carry a substantially heavier compliance burden, reflecting the greater risks their processing poses.
The Central Government designates SDFs using a risk assessment. Likely candidates include social media platforms, large banks, insurance companies, health-tech firms, and AI platforms. Once designated, there is no opting out.
Penalties — what’s really at stake
The financial consequences of non-compliance are substantial. Every penalty tier in the Act’s schedule.
| Violation | Maximum Penalty |
|---|---|
| Failure to implement adequate security safeguards leading to a personal data breach | ₹250 Crore |
| Failure to notify the Data Protection Board and affected individuals of a breach | ₹200 Crore |
| Non-fulfilment of additional obligations in relation to children’s data | ₹200 Crore |
| Non-compliance by Significant Data Fiduciaries with additional obligations | ₹150 Crore |
| Failure to fulfil general Data Fiduciary obligations under the Act | ₹50 Crore |
| Breach of duties by the Data Principal (e.g. impersonation, false complaints) | ₹10,000 |
DPDP Rules 2025 — the how
Notified on 13 November 2025 after 6,915 stakeholder inputs, the Rules translate the Act’s principles into specific, implementable requirements.
- Available in English or any of the 22 Scheduled languages
- Must be presented independently — not buried in T&Cs
- Retrospective notices required for all pre-Act data
- Incorporated in India
- Registered with DPB
- 7-year record retention
- Live: November 2026
- Encryption at rest & in transit
- Role-based access controls
- Access logging & monitoring
- Regular data backups
- Breach detection systems
DPDP Rules 2025 — Mind Map
The Rules’ key operational provisions and how they connect to each other.
Three phases. One deadline.
The 18-month phased implementation window is generous — but time moves fast. Here’s exactly what becomes mandatory when.
Your DPDP compliance checklist
12 actions to get ahead of the May 2027 deadline. Start with the first four — they deliver the most immediate compliance value.
DPDP vs GDPR — key differences
India’s framework borrows heavily from GDPR’s philosophy but differs in significant ways. Essential reading for multinational organisations.
| Feature | India DPDP Act 2023 | EU GDPR |
|---|---|---|
| Primary legal basis | Consent is largely the only ground | Six lawful bases including legitimate interests |
| Legitimate interests | Not explicitly available | Available — subject to balancing test |
| Breach notification threshold | Any breach — zero minimum threshold | Likely risk of harm to individuals required |
| DPO requirement | Only for Significant Data Fiduciaries | Broader — public authorities, large-scale processing |
| Cross-border transfers | Generally permitted; Govt may restrict by country | Requires adequacy decision, SCCs, or BCRs |
| Maximum penalty | ₹250 Crore (~USD 30 million) | €20 million or 4% of global annual turnover |
| Data localisation | Selective — specified categories for SDFs only | No mandatory data localisation |
| Government exemptions | Broad — national security, public order, sovereignty | Narrower — proportionality and necessity tests |
| Right to data portability | Not explicitly included in the Act | Explicitly guaranteed under Article 20 |
| Enforcement body | Single Board — fully digital, 4 members | 27 national DPAs across EU member states |
