/FAQ
DPDP basics
What the DPDP Act covers, who it applies to, what digital personal data means, what the 2025 Rules add, and how much of it is in force.
What is the Digital Personal Data Protection Act, 2023?
It is India's law on the handling of personal data in digital form. Parliament enacted it as Act No. 22 of 2023 and the President assented on 11 August 2023, the day it was published in the Gazette of India. Its long title says it provides "for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes". The Act runs to 44 sections across nine chapters, with a Schedule that fixes the maximum penalty for each kind of breach (the Schedule). Section 1(2) lets the Central Government bring different provisions into force on different dates, which is exactly what happened.
Who does the DPDP Act apply to?
Three roles carry the law. A Data Fiduciary is the person who alone or with others "determines the purpose and means of processing of personal data" (section 2(i)). A Data Processor processes personal data on behalf of a Data Fiduciary (section 2(k)). A Data Principal is the individual the data is about (section 2(j)). Nearly every obligation sits with the Data Fiduciary, and it stays there even where a contract says otherwise or the Data Principal fails to perform her own duties (section 8(1)). "Person" is defined widely: an individual, a Hindu undivided family, a company, a firm, an association of persons or body of individuals, the State, and every artificial juristic person (section 2(s)).
What does "digital personal data" mean?
It means personal data in digital form (section 2(n)). Personal data is "any data about an individual who is identifiable by or in relation to such data" (section 2(t)), and data is a representation of information, facts, concepts, opinions or instructions suitable for communication, interpretation or processing (section 2(h)). So an employee number in a payroll system, a customer mobile number in a sales database, or a photograph linked to a name all qualify. Processing means a wholly or partly automated operation on digital personal data, and expressly includes collection, storage, use, sharing, disclosure, restriction, erasure and destruction (section 2(x)).
Does the DPDP Act apply to paper records and physical files?
Not while they stay on paper. The Act applies to processing of digital personal data within India where the personal data was collected in digital form, or "in non-digital form and digitised subsequently" (section 3(a)). A signed paper form sitting in a filing cabinet is outside the Act. The moment it is scanned or keyed into a system, the data in that system is covered. One timing point: section 3 itself only comes into force eighteen months after publication of G.S.R. 843(E), that is on 13 May 2027.
Does the DPDP Act apply to companies outside India?
Yes, in one situation. The Act also applies to processing of digital personal data outside India "if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India" (section 3(b)). No turnover figure, user count or local-office requirement is attached to that test. Separately, section 16(1) allows the Central Government to restrict transfers of personal data to countries it notifies, and rule 15 attaches conditions to making personal data available to a foreign State or to an entity under its control.
Does the DPDP Act apply to me as an individual?
In two ways, and one of them is an exclusion. As a Data Principal you hold the rights in sections 11 to 14 and the duties in section 15. As someone who processes data, an individual can be a Data Fiduciary, because "person" includes an individual (section 2(s)). But the Act does not apply to "personal data processed by an individual for any personal or domestic purpose" (section 3(c)(i)). The exclusion turns on the purpose being personal or domestic, not on the size of the person doing the processing.
Is publicly available personal data covered by the Act?
No, in two defined cases. The Act does not apply to personal data that is made, or caused to be made, publicly available by the Data Principal to whom it relates, or by any other person who is under an obligation under Indian law to make that personal data publicly available (section 3(c)(ii)). The Act gives its own illustration: X, an individual, while blogging her views, has publicly made available her personal data on social media, and in that case the provisions of the Act do not apply. What matters is who put the data in the public domain and under what obligation.
What are the DPDP Rules, 2025?
They are the subordinate legislation that makes the Act operable, notified as G.S.R. 846(E) on 13 November 2025 under the rule-making power in section 40. There are 23 rules and seven Schedules. They set out what a notice must say (rule 3), how a Consent Manager registers (rule 4), the minimum security safeguards (rule 6), breach intimation (rule 7), erasure timelines (rule 8), verifiable consent for children (rule 10), extra duties for Significant Data Fiduciaries (rule 13), how rights are exercised (rule 14), transfers outside India (rule 15), and the Board's appointments, meetings and appeals (rules 17 to 22).
Is the DPDP Act in force yet?
Only in part. G.S.R. 843(E) brought section 1(2), section 2, sections 18 to 26, sections 35, 38, 39, 40, 41, 42, 43 and sub-sections (1) and (3) of section 44 into force on the date of its publication, 13 November 2025. Section 6(9) and section 27(1)(d) come into force one year after that date. Sections 3 to 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 17, the rest of section 27, sections 28 to 34, 36, 37 and section 44(2) come into force eighteen months after that date. The Rules follow the same three-step pattern (rule 1). None of the duties on Data Fiduciaries in Chapter II are in force today.
/MYND · DPDP practice
Have a question about your own situation?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.