India definition
The DPDP Act, India's Digital Personal Data Protection Act, 2023, is the country's primary law governing the processing of digital personal data. It requires organizations, called data fiduciaries, to process personal data lawfully, mainly with consent or for defined legitimate uses, to protect it with reasonable security safeguards, and to respect individuals' rights.
Who does the DPDP Act apply to?
The Act applies to the processing of digital personal data within India, whether collected digitally or collected offline and later digitized. It also applies to processing outside India when it is connected with offering goods or services to individuals in India. Personal data means data about an individual who is identifiable by or in relation to such data. Certain processing is excluded, including personal or domestic use and personal data that the individual has made publicly available.
Key terms include the data principal, the individual the data relates to; the data fiduciary, which decides the purpose and means of processing; and the data processor, which processes data on a fiduciary's behalf. The government can designate significant data fiduciaries, which carry additional duties such as appointing a data protection officer and conducting periodic audits and impact assessments.
Key obligations for data fiduciaries
The Act sets out duties that affect both legal processes and product design. Many of them, such as notices, consent flows, retention and breach handling, need to be built into applications and data platforms rather than handled only in policy documents. The main obligations are summarized below.
- Process data only with valid consent or for specified legitimate uses.
- Give clear notice describing the data collected and its purpose.
- Make withdrawing consent as easy as giving it.
- Implement reasonable security safeguards to prevent breaches.
- Notify the Data Protection Board and affected individuals of breaches.
- Erase data when the purpose is served or consent is withdrawn, subject to legal retention.
- Publish contact details for grievances and respond to them.
Consent, children and individual rights
Consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and limited to the data necessary for the stated purpose. Registered consent managers can help individuals give, manage and withdraw consent. For children, meaning individuals under 18, fiduciaries need verifiable parental consent and must not carry out tracking, behavioral monitoring or targeted advertising directed at children, subject to exemptions the government may notify.
Data principals have rights to obtain information about processing, to correction, completion, updating and erasure of their data, to grievance redressal, and to nominate another person to exercise rights in case of death or incapacity. Fiduciaries must provide simple ways to exercise these rights, such as in-app request forms with tracked responses.
Penalties and practical steps
The Data Protection Board of India enforces the Act and can impose significant financial penalties, with the highest amounts, up to 250 crore rupees per instance, linked to failures to take reasonable security safeguards. The Digital Personal Data Protection Rules, 2025, notified in November 2025, phase obligations in: under the current schedule, consent manager provisions apply from November 2026 and most substantive duties, such as notice, consent, security safeguards, breach notification and children's data, from May 2027. Proposals to shorten this timeline have been discussed, so confirm current dates when planning. Practical steps include mapping personal data, updating notices and consent flows, defining retention, strengthening security and preparing breach response.
Nexzem helps Indian and global companies build DPDP-ready applications and data practices. This page is general information, not legal advice; consult a qualified Indian data protection lawyer about your specific obligations. Treat compliance as an ongoing program, since rules, guidance and Board decisions will continue to clarify expectations.