/Guides · Everyone
What is the DPDP Act? A plain-English introduction
A plain-English introduction to India's Digital Personal Data Protection Act, 2023, covering what it applies to, who it names and how the Rules fit.
The Digital Personal Data Protection Act, 2023 is India's general law on what may be done with personal data held in digital form. It says when personal data may be processed, what the organisation doing the processing owes to the person the data is about, and who enforces that. This guide walks through the shape of the Act, the roles it names and how the DPDP Rules, 2025 sit on top of it.
What the Act is#
The Act is No. 22 of 2023 and it received assent on 11 August 2023. Its long title describes it as an Act "to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto" (the Act).
Passing the Act did not switch it on. Section 1(2) says the Act comes into force on a date the Central Government appoints by notification, and that "different dates may be appointed for different provisions". That is what happened, through G.S.R. 843(E) of 13 November 2025.
What the Act covers#
Three definitions in section 2 do most of the work. "Personal data" means "any data about an individual who is identifiable by or in relation to such data" (section 2(t)). "Digital personal data" is personal data in digital form (section 2(n)). "Processing" is a wholly or partly automated operation on digital personal data, and the definition lists collection, storage, retrieval, use, sharing, disclosure, erasure and destruction among others (section 2(x)).
Section 3 sets the boundary. The Act applies to processing of digital personal data inside India where the data was collected in digital form, or collected on paper and digitised afterwards. It also reaches processing outside India, if that processing is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India". It does not apply to personal data processed by an individual for a personal or domestic purpose, nor to personal data the individual has made publicly available herself, or that someone else is legally obliged to make public.
The people and bodies the Act names#
Most of the Act is written in terms of a small cast of defined roles.
| Role | Definition | What it means in practice |
|---|---|---|
| Data Principal | section 2(j) | The individual the data is about. For a child it includes the parents or lawful guardian, and for a person with disability her lawful guardian. |
| Data Fiduciary | section 2(i) | Any person who alone or with others "determines the purpose and means of processing of personal data". This is the party that carries the obligations. |
| Data Processor | section 2(k) | Any person who processes personal data on behalf of a Data Fiduciary. For activity related to offering goods or services, a Data Fiduciary may engage one "only under a valid contract" (section 8(2)). |
| Consent Manager | section 2(g) | A person registered with the Board, acting as a single point of contact so a Data Principal can give, manage, review and withdraw consent in one place. |
| Significant Data Fiduciary | section 2(z), section 10 | A Data Fiduciary, or class of them, notified by the Central Government on factors such as volume and sensitivity of data and risk to Data Principals. Extra duties follow. |
| Data Protection Officer | section 2(l) | An individual appointed by a Significant Data Fiduciary, based in India, answerable to its board and the contact point for grievances (section 10(2)(a)). |
| Data Protection Board of India | section 2(c), section 18 | The body that inquires into breaches and imposes penalties. Established with effect from 13 November 2025 by G.S.R. 844(E); G.S.R. 845(E) notified that it "shall consist of four members". |
"Person" here includes an individual, a Hindu undivided family, a company, a firm, an association of persons, the State and every artificial juristic person (section 2(s)). A Data Fiduciary can therefore be a government body as easily as a business.
How the Act is built#
Forty-four sections across nine chapters, plus a Schedule of penalties.
| Chapter | Sections | What it deals with |
|---|---|---|
| I. Preliminary | 1 to 3 | Commencement, definitions, scope. |
| II. Obligations of Data Fiduciary | 4 to 10 | Grounds for processing, notice, consent, legitimate uses, general duties, children's data, Significant Data Fiduciaries. |
| III. Rights and duties of Data Principal | 11 to 15 | Access, correction and erasure, grievance redressal, nomination, and the duties the individual owes. |
| IV. Special provisions | 16 and 17 | Restricting transfers to notified countries, and the exemptions. |
| V. Data Protection Board of India | 18 to 26 | Establishing the Board, who sits on it, how they are appointed and removed. |
| VI. Powers, functions and procedure of the Board | 27 and 28 | What the Board may inquire into, and how. |
| VII. Appeal and alternate dispute resolution | 29 to 32 | Appeals to the Appellate Tribunal, mediation, voluntary undertakings. |
| VIII. Penalties and adjudication | 33 and 34 | How penalties are set, and where the money goes. |
| IX. Miscellaneous | 35 to 44 | Rule-making power, directions, the relationship with other laws, consequential amendments. |
The centre of gravity is Chapter II. Section 4 allows processing only for a lawful purpose and only on one of two bases: the Data Principal's consent, or one of the "certain legitimate uses" in section 7. Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action" (section 6(1)), preceded or accompanied by a notice (section 5).
How the Rules fit#
Section 40 lets the Central Government make rules to carry out the purposes of the Act, subject to previous publication, and lists twenty-six specific matters those rules may cover, from the manner of giving notice to the form of a personal data breach report. Wherever the Act says "as may be prescribed", it is pointing at rules made under section 40. Section 41 requires every rule, and notifications under sections 16 and 42, to be laid before both Houses of Parliament.
The Central Government used that power on 13 November 2025 to make the Digital Personal Data Protection Rules, 2025 through G.S.R. 846(E), after publishing a draft in January 2025 and considering the objections received. There are 23 rules and seven schedules, with their own timetable in rule 1.
When each part starts#
G.S.R. 843(E) split the Act into three groups. The definitions, the Board chapter and the rule-making powers started on 13 November 2025. The Consent Manager registration machinery starts one year later. Everything else, including the application clause, the duties of Data Fiduciaries, the rights of Data Principals and the penalties, starts eighteen months after publication.
What a breach can cost#
If the Board concludes after an inquiry that a breach is significant, it may impose the monetary penalty specified in the Schedule, after giving the person a hearing (section 33(1)). The Schedule's highest figure "may extend to two hundred and fifty crore rupees", for failing to take reasonable security safeguards under section 8(5). Failing to report a personal data breach, and breaching the children's data obligations, each carry up to two hundred crore rupees. Any other breach of the Act or the rules carries up to fifty crore rupees.
The amount is not automatic. Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach, the data affected, whether it was repeated, any gain made or loss avoided, and the likely impact of the penalty. The Central Government may amend the Schedule by notification, but not so as to more than double any penalty as originally enacted (section 42).
Key provisions#
- Section 1, commencement
- Section 2, definitions
- Section 3, application
- Section 4, grounds for processing
- Section 6, consent
- Section 8, general obligations
- Section 18, establishment of Board
- Section 33, penalties
- The Schedule, penalties
- Section 40, power to make rules
- G.S.R. 843(E), commencement
- The DPDP Rules, 2025
/MYND · DPDP practice
Want help applying this?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.