Skip to content

What is DPDP Act (India)?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

India definition

The DPDP Act, India's Digital Personal Data Protection Act, 2023, is the country's primary law governing the processing of digital personal data. It requires organizations, called data fiduciaries, to process personal data lawfully, mainly with consent or for defined legitimate uses, to protect it with reasonable security safeguards, and to respect individuals' rights.

Who does the DPDP Act apply to?

The Act applies to the processing of digital personal data within India, whether collected digitally or collected offline and later digitized. It also applies to processing outside India when it is connected with offering goods or services to individuals in India. Personal data means data about an individual who is identifiable by or in relation to such data. Certain processing is excluded, including personal or domestic use and personal data that the individual has made publicly available.

Key terms include the data principal, the individual the data relates to; the data fiduciary, which decides the purpose and means of processing; and the data processor, which processes data on a fiduciary's behalf. The government can designate significant data fiduciaries, which carry additional duties such as appointing a data protection officer and conducting periodic audits and impact assessments.

Key obligations for data fiduciaries

The Act sets out duties that affect both legal processes and product design. Many of them, such as notices, consent flows, retention and breach handling, need to be built into applications and data platforms rather than handled only in policy documents. The main obligations are summarized below.

  • Process data only with valid consent or for specified legitimate uses.
  • Give clear notice describing the data collected and its purpose.
  • Make withdrawing consent as easy as giving it.
  • Implement reasonable security safeguards to prevent breaches.
  • Notify the Data Protection Board and affected individuals of breaches.
  • Erase data when the purpose is served or consent is withdrawn, subject to legal retention.
  • Publish contact details for grievances and respond to them.

Consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and limited to the data necessary for the stated purpose. Registered consent managers can help individuals give, manage and withdraw consent. For children, meaning individuals under 18, fiduciaries need verifiable parental consent and must not carry out tracking, behavioral monitoring or targeted advertising directed at children, subject to exemptions the government may notify.

Data principals have rights to obtain information about processing, to correction, completion, updating and erasure of their data, to grievance redressal, and to nominate another person to exercise rights in case of death or incapacity. Fiduciaries must provide simple ways to exercise these rights, such as in-app request forms with tracked responses.

Penalties and practical steps

The Data Protection Board of India enforces the Act and can impose significant financial penalties, with the highest amounts, up to 250 crore rupees per instance, linked to failures to take reasonable security safeguards. The Digital Personal Data Protection Rules, 2025, notified in November 2025, phase obligations in: under the current schedule, consent manager provisions apply from November 2026 and most substantive duties, such as notice, consent, security safeguards, breach notification and children's data, from May 2027. Proposals to shorten this timeline have been discussed, so confirm current dates when planning. Practical steps include mapping personal data, updating notices and consent flows, defining retention, strengthening security and preparing breach response.

Nexzem helps Indian and global companies build DPDP-ready applications and data practices. This page is general information, not legal advice; consult a qualified Indian data protection lawyer about your specific obligations. Treat compliance as an ongoing program, since rules, guidance and Board decisions will continue to clarify expectations.

India: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Does the DPDP Act apply to foreign companies?

Yes, in some cases. The Act applies to processing of digital personal data outside India if it is connected with offering goods or services to data principals in India. A foreign ecommerce or SaaS company serving Indian users can therefore have obligations under the Act, alongside any laws in its home country.

How is the DPDP Act different from GDPR?

The DPDP Act covers digital personal data and relies mainly on consent plus a defined list of legitimate uses, while GDPR offers six lawful bases and covers personal data in any form. The DPDP Act defines children as under 18, uses a different enforcement model through the Data Protection Board, and has different penalty structures and cross-border transfer rules.

What is a data fiduciary under the DPDP Act?

A data fiduciary is any person, company or entity that alone or with others determines the purpose and means of processing personal data. It is similar to a controller under GDPR. Data fiduciaries carry the main obligations under the Act, including those relating to consent, security safeguards, breach notification and responding to data principals.

Keep exploring the cybersecurity & compliance glossary

Need India in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.