dpdpa_2023_eng
|

DPDP Act 2023 and DPDP Rules 2025 – Decoded

GRC Audit Intelligence · India Data Privacy
DPDP Act 2023 Rules Notified Nov 2025
India · Digital Personal Data Protection · Complete Guide

India’s DPDP Act & Rules — Decoded

India’s first comprehensive data protection law is now fully in force. Everything you need to know — from core principles to compliance deadlines — explained without the legalese.

₹250Cr
Max Penalty
May ’27
Full Compliance
7
Principles
6
Citizen Rights
90
Days to Respond
Enacted
Aug 2023
India’s first standalone data protection law
📅
13 Nov 2025 — DPDP Rules 2025 notified by MeitY, fully activating the framework
👥
6,915 inputs received during public consultation across 7 cities
🔄
Replaces fragmented IT Rules 2011 — phased transition underway
🏁
Full compliance mandatory by 13 May 2027
01 ——Introduction

What is the DPDP Act and why does it matter?

India’s first standalone data protection law reshapes how every organisation handles personal data of Indian citizens — domestically and globally.

The Digital Personal Data Protection Act, 2023 is India’s most significant piece of digital legislation. Enacted on 11 August 2023 and operationalised through DPDP Rules notified on 13 November 2025, it creates a clear legal framework governing how personal data of Indian citizens is collected, used, stored, and protected.

Before this Act, India’s data privacy landscape was patchy — governed by the ageing IT Act 2000 and limited Privacy Rules of 2011. The Supreme Court’s landmark 2017 ruling in Justice K.S. Puttaswamy v. Union of India declared privacy a fundamental right under Article 21 — and the DPDP Act is the legislative fulfilment of that ruling.

The Act applies to every organisation that handles digital personal data of Indian citizens — including foreign companies offering goods or services to people in India. Whether you’re a startup or a global corporation, the DPDP Act almost certainly applies to you.

DPDP Act 2023 Mindmap
Presidential Assent
11 Aug 2023
India’s first comprehensive standalone data protection legislation becomes law
13 Nov 2025 — DPDP Rules 2025 notified by MeitY, fully operationalising the Act
6,915 stakeholder inputs from 7 cities shaped the final Rules
Replaces IT (Reasonable Security Practices) Rules, 2011 — old regime continues during phased transition
Full compliance deadline: 13 May 2027 — 18 months from notification
02 ——Design Philosophy

Built on the SARAL framework

The government committed to making this law genuinely usable. SARAL stands for Simple, Accessible, Rational, and Actionable Law — a design principle baked into every provision.

S
Simple
Written in plain language with real-world illustrations. No dense legalese — the Act is designed to be read and understood by anyone.
A
Accessible
Available in English and all 22 Scheduled languages listed in the Eighth Schedule of the Constitution of India.
R
Rational
Proportionate obligations based on risk. A small startup and a global platform face different compliance burdens by design.
A
Actionable Law
Clear, specific, implementable compliance steps — not vague aspirational language that businesses cannot act on.
03 ——Applicability

Who does this law cover?

The Act’s reach is both deep within India and broad beyond its borders. Scope is the first thing any compliance programme must establish.

✅
Covered by the Act
Digital personal data collected online or digitised from offline sources within India
Foreign companies offering goods or services to individuals in India — regardless of where they are based
All sectors: IT, banking, healthcare, e-commerce, HR, manufacturing, R&D
Government bodies processing data for subsidies, benefits, and public services
Offline data subsequently converted to digital form
❌
Exempt from the Act
Personal or household use by individuals (e.g. a personal contact list)
Research, statistics, or archiving for public interest — where results don’t identify individuals
National security, public order, and crime prevention — must be formally notified
Publicly disclosed personal data, subject to specific conditions
Non-digital personal data that has never been digitised
04 ——Key Players

The who’s who of the DPDP framework

The Act introduces precise terminology for each role in the data ecosystem. Knowing your role determines your obligations.

👤
Individual
Data Principal
The person whose personal data is collected. A customer, employee, or citizen. Has the right to consent, correct, erase, nominate, and complain.
🏢
Organisation
Data Fiduciary
Decides why and how personal data is processed. Bears primary legal responsibility. Liability cannot be delegated — even when a processor is used.
⚙️
Vendor / Partner
Data Processor
Processes data on behalf of the Fiduciary under a contract. Think cloud providers, payroll vendors. Cannot appoint sub-processors without explicit DF approval.
🌟
High-Risk Tier
Significant Data Fiduciary
Designated by the Government based on volume, sensitivity, or national risk. Faces a substantially heavier compliance burden including DPO, DPIA, and audits.
🔐
New Intermediary
Consent Manager
A registered platform that helps individuals manage consent across services. Must be incorporated in India and registered with the Data Protection Board.
⚖️
Regulator
Data Protection Board
India’s fully digital enforcement authority. Four members, online complaint portal, fast-track adjudication. Operational since November 2025. Appeals go to TDSAT.
05 ——Visual Overview

DPDP Act 2023 — Mind Map

A complete visual of the Act’s architecture — from principles to enforcement.

🧠 Mind Map — Digital Personal Data Protection Act, 2023
DPDP Act 2023 India’s Privacy Law 7 Core Principles Consent · Purpose · Minimisation · Security… Key Actors Data Principal · Fiduciary Processor · SDF · Board DP Rights Access · Correction · Erasure Grievance · Nominate Consent & Notice Free · Specific · Informed Unambiguous · Reversible Significant Data Fiduciaries DPO · DPIA · Annual Audit Localisation (selective) Enforcement Data Protection Board Penalties up to ₹250 Cr Cross-Border Govt-restricted countries Children’s Data Parental Consent Enacted 11 August 2023 · Rules Notified 13 November 2025 · Full Force 13 May 2027
06 ——Foundations

The 7 Core Principles

Every data processing decision must be governed by these principles. They apply to every Data Fiduciary without exception.

1
🤝
Consent & Transparency
Free, specific, informed, unambiguous consent only
2
🎯
Purpose Limitation
Use data only for the stated purpose
3
⚖️
Data Minimisation
Collect only what is strictly necessary
4
✓
Accuracy
Keep personal data accurate and current
5
⏱
Storage Limitation
Delete once the purpose is served
6
🔒
Security Safeguards
Appropriate technical & organisational measures
7
📋
Accountability
Responsibility stays with the Fiduciary
07 ——Citizen Empowerment

Six rights every Indian citizen now holds

The DPDP Act gives every individual six enforceable rights. Data Fiduciaries must respond within 90 days.

01
📂
Right to Access
Ask any organisation what personal data they hold about you and how it is being processed — in plain language.
02
✏️
Right to Correction
Demand correction of inaccurate, incomplete, or misleading data held by any Data Fiduciary.
03
🗑️
Right to Erasure
Request deletion of personal data when you withdraw consent or the purpose is no longer valid.
04
↩️
Right to Withdraw Consent
Withdraw consent at any time — as easily as you gave it. Processing must stop upon withdrawal.
05
📣
Right to Grievance
Raise complaints with the Data Fiduciary first, then escalate to the Data Protection Board.
06
🙋
Right to Nominate
Appoint another person to exercise your data rights in the event of death or incapacity.
08 ——Business Compliance

What every organisation must do

From a startup with a newsletter to a bank with millions of customers — all Data Fiduciaries share these seven core obligations.

01
Required
Issue a Clear Privacy Notice
Before collecting data, publish a notice in plain language — English or any of the 22 Scheduled languages. The notice must state what data is collected, why, how individuals can exercise rights, and how to file a complaint with the Board.
02
Required
Obtain Valid Consent
Consent must be free, specific, informed, unconditional, and unambiguous. Consent for phone contacts is void if your app doesn’t need contacts. Withdrawal must be as easy as giving consent — no dark patterns allowed.
03
Critical
Implement Security Safeguards
Encryption, role-based access controls, access logging, regular backups, breach detection, and investigation protocols must be in place for every system handling personal data — including systems managed by third-party processors.
04
Critical
Report Every Data Breach
Unlike GDPR or Australian law, the DPDP Act has no minimum harm threshold. Every personal data breach — regardless of size or impact — must be promptly reported to the Board and to affected individuals. Penalty for failure: up to ₹200 Crore.
05
Required
Erase Data When Purpose is Served
Once the specified purpose is complete or consent withdrawn, stop retaining data. For certain Fiduciary categories, a 3-year retention cap applies from the date Rules came into force or from the last interaction — whichever is later.
06
Required
Appoint a Grievance Officer
Every Fiduciary must designate and publicly name a point of contact for Data Principal queries. The officer must respond within 30 days. For Significant Data Fiduciaries, this escalates to a full DPO role with Board-facing responsibilities.
07
Required
Issue Retrospective Notices
For data collected before the Act came into force, Fiduciaries must retroactively notify individuals of their rights and how to exercise them. Processing can continue until consent is explicitly withdrawn.
09 ——Special Provisions

Children’s data — the strictest zone

The Act places the strongest protections around personal data of anyone under 18 years of age.

Children & Persons with Disabilities
Stricter rules. Highest penalties. No exceptions.
Non-compliance with children’s data obligations attracts penalties of up to ₹200 Crore — the second-highest penalty in the entire Act. Any organisation whose platform could be accessed by minors must build robust age-verification and parental consent workflows before May 2027.
  • Verifiable parental or guardian consent required before processing any child’s data
  • Behavioural monitoring or targeted advertising directed at children is strictly prohibited
  • Any data processing likely to cause harm to a child is prohibited
  • Exceptions for healthcare, education, and essential services — without parental consent
  • If a person with a disability cannot make decisions independently, lawful guardian must consent
  • Penalties: up to ₹200 Crore for violations in this category
10 ——High-Risk Tier

Significant Data Fiduciaries — the top tier

Not all organisations face equal obligations. SDFs carry a substantially heavier compliance burden, reflecting the greater risks their processing poses.

The Central Government designates SDFs using a risk assessment. Likely candidates include social media platforms, large banks, insurance companies, health-tech firms, and AI platforms. Once designated, there is no opting out.

📊
High-Volume Processing
Entities processing data at massive scale — millions of records daily
🔒
Sensitive Data
Biometric, health, financial data with elevated individual risk
🏗️
Critical Infrastructure
Entities affecting national security or democratic processes
🤖
Emerging Technologies
AI platforms, data brokers, novel technology operators
Additional SDF Obligations
👔
Data Protection Officer (DPO) — Must be appointed, India-based, reporting to board or CEO. Primary contact for the Data Protection Board.
📋
Annual DPIA — Data Protection Impact Assessment every 12 months. Documents risks to Data Principals and mitigation strategies.
🔍
Independent Audit — Annual audit by a certified, independent data auditor evaluating full Act compliance.
🤖
Algorithmic Accountability — Transparency obligations around automated decision-making systems.
📍
Data Localisation — Certain specified data categories cannot leave India. Even metadata about data flows (traffic data) must remain onshore.
11 ——Enforcement

Penalties — what’s really at stake

The financial consequences of non-compliance are substantial. Every penalty tier in the Act’s schedule.

ViolationMaximum Penalty
Failure to implement adequate security safeguards leading to a personal data breach
₹250 Crore
Failure to notify the Data Protection Board and affected individuals of a breach
₹200 Crore
Non-fulfilment of additional obligations in relation to children’s data
₹200 Crore
Non-compliance by Significant Data Fiduciaries with additional obligations
₹150 Crore
Failure to fulfil general Data Fiduciary obligations under the Act
₹50 Crore
Breach of duties by the Data Principal (e.g. impersonation, false complaints)
₹10,000
⚠️ Zero-Threshold Breach Reporting
Unlike the EU GDPR (which requires a likelihood of harm to individuals) or Australia’s NDB scheme, the DPDP Act has no minimum threshold for breach reporting. Every personal data breach — large or small, harmful or not — must be reported to the Board and to affected individuals without delay.
12 ——Implementation

DPDP Rules 2025 — the how

Notified on 13 November 2025 after 6,915 stakeholder inputs, the Rules translate the Act’s principles into specific, implementable requirements.

📋
Privacy Notice Requirements
Every Data Fiduciary must issue a standalone consent notice that is independently understandable — no legal jargon. It must include the specific purpose for data collection, the type of personal data collected, contact details of the DPO or authorised representative, and direct links to withdraw consent, exercise rights, and file complaints. Notices must also be issued retroactively for all pre-Act data.
  • Available in English or any of the 22 Scheduled languages
  • Must be presented independently — not buried in T&Cs
  • Retrospective notices required for all pre-Act data
🔐
Consent Manager
A new registered intermediary helping individuals manage consent across platforms.
  • Incorporated in India
  • Registered with DPB
  • 7-year record retention
  • Live: November 2026
🛡️
Security Safeguards
Mandatory measures for every Data Fiduciary.
  • Encryption at rest & in transit
  • Role-based access controls
  • Access logging & monitoring
  • Regular data backups
  • Breach detection systems
⏳
Data Retention — 3-Year Rule
For certain Data Fiduciary categories, personal data must be erased 3 years from the date Rules came into force or from the last interaction — whichever is later. After this, data must be deleted unless the purpose is actively being served.
🌏
Cross-Border Data Transfers
Cross-border transfers are generally permitted — a notably more open approach than GDPR. However, the Central Government can restrict or prohibit transfers to specific countries by notification. For Significant Data Fiduciaries, certain sensitive data categories must remain within India entirely, including the metadata about data flows. A Government-constituted committee including MeitY officials will determine which categories qualify for localisation.
13 ——Visual Overview

DPDP Rules 2025 — Mind Map

The Rules’ key operational provisions and how they connect to each other.

🧠 Mind Map — DPDP Rules, 2025
DPDP Rules 2025 Notified 13 Nov 2025 Consent Manager Registered · Indian Co · 7yr records · Live Nov 2026 Privacy Notice Plain language · 22 languages DPO contact · Retrospective Security Safeguards Encrypt · Access Control Log · Backup · Detect Breach Notification No minimum threshold Board + individuals notified Data Retention 3-year cap · Erase when purpose served DP Rights Process 90-day response window Online portal · Mobile app Cross-Border Govt-restricted countries SDF Obligations DPO · DPIA · Audit 18-month phased compliance window · Full force: 13 May 2027
14 ——Compliance Roadmap

Three phases. One deadline.

The 18-month phased implementation window is generous — but time moves fast. Here’s exactly what becomes mandatory when.

Phase 1
13 November 2025
The Data Protection Board of India is established. Definitions, rule-making powers, and transitional arrangements become effective. The old IT Act regime continues in parallel. Start data mapping and governance frameworks immediately.
Board EstablishedRules NotifiedStart Data Mapping
Phase 2
13 November 2026
Consent Manager registration process opens. Organisations must ensure their consent mechanisms are fully DPDP-compliant. Review all data collection interfaces, forms, and APIs.
Consent ManagersConsent CompliancePrivacy Notices Live
Phase 3 — Full Force
13 May 2027
Every obligation is fully enforceable. Security safeguards, breach reporting, SDF requirements (DPO, DPIA, audits), Data Principal rights, and all penalties apply in full from this date.
Full PenaltiesSDF RequirementsAll Rights Live
15 ——Action Plan

Your DPDP compliance checklist

12 actions to get ahead of the May 2027 deadline. Start with the first four — they deliver the most immediate compliance value.

🗺️
1. Data Mapping
Inventory all personal data — what you collect, where it’s stored, how it flows, who processes it.
📄
2. Privacy Notices
Draft or update notices to DPDP standards. Translate into relevant Indian languages.
✅
3. Consent Mechanism
Ensure consent is free, specific, informed, and withdrawable as easily as given.
🔁
4. Retrospective Notices
Notify individuals whose data was collected before the Act came into force.
🔒
5. Security Audit
Upgrade encryption, access controls, logging, backups, and breach detection.
🚨
6. Breach Response Plan
Every breach must be reported — no threshold. Build an incident response protocol now.
📞
7. Grievance Officer
Designate and publicly name a contact point for Data Principal queries and complaints.
🤝
8. Vendor Contracts
Update Data Processing Agreements to ensure DPDP compliance flows to all vendors.
⭐
9. SDF Assessment
Evaluate SDF designation likelihood. Prepare DPO, DPIA, and audit frameworks if needed.
👶
10. Children’s Data Audit
If minors could access your service, build age-verification and parental consent workflows.
📚
11. Staff Training
Annual data privacy awareness training for all employees handling personal data.
🖥️
12. Rights Portal
Build a system to handle access, correction, and erasure requests within 90 days.
16 ——Global Context

DPDP vs GDPR — key differences

India’s framework borrows heavily from GDPR’s philosophy but differs in significant ways. Essential reading for multinational organisations.

FeatureIndia DPDP Act 2023EU GDPR
Primary legal basisConsent is largely the only groundSix lawful bases including legitimate interests
Legitimate interestsNot explicitly availableAvailable — subject to balancing test
Breach notification thresholdAny breach — zero minimum thresholdLikely risk of harm to individuals required
DPO requirementOnly for Significant Data FiduciariesBroader — public authorities, large-scale processing
Cross-border transfersGenerally permitted; Govt may restrict by countryRequires adequacy decision, SCCs, or BCRs
Maximum penalty₹250 Crore (~USD 30 million)€20 million or 4% of global annual turnover
Data localisationSelective — specified categories for SDFs onlyNo mandatory data localisation
Government exemptionsBroad — national security, public order, sovereigntyNarrower — proportionality and necessity tests
Right to data portabilityNot explicitly included in the ActExplicitly guaranteed under Article 20
Enforcement bodySingle Board — fully digital, 4 members27 national DPAs across EU member states
“Privacy is no longer optional — it is a legal obligation, a business imperative, and a fundamental right of every Indian citizen.”
Digital Personal Data Protection Act, 2023 · India

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.