DPDP Wiki Talk to us

/Guides · Everyone

What is the DPDP Act? A plain-English introduction

A plain-English introduction to India's Digital Personal Data Protection Act, 2023, covering what it applies to, who it names and how the Rules fit.

Interpretation · not legal adviceUpdated 9 September 20267 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

The Digital Personal Data Protection Act, 2023 is India's general law on what may be done with personal data held in digital form. It says when personal data may be processed, what the organisation doing the processing owes to the person the data is about, and who enforces that. This guide walks through the shape of the Act, the roles it names and how the DPDP Rules, 2025 sit on top of it.

What the Act is#

The Act is No. 22 of 2023 and it received assent on 11 August 2023. Its long title describes it as an Act "to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto" (the Act).

Passing the Act did not switch it on. Section 1(2) says the Act comes into force on a date the Central Government appoints by notification, and that "different dates may be appointed for different provisions". That is what happened, through G.S.R. 843(E) of 13 November 2025.

What the Act covers#

Three definitions in section 2 do most of the work. "Personal data" means "any data about an individual who is identifiable by or in relation to such data" (section 2(t)). "Digital personal data" is personal data in digital form (section 2(n)). "Processing" is a wholly or partly automated operation on digital personal data, and the definition lists collection, storage, retrieval, use, sharing, disclosure, erasure and destruction among others (section 2(x)).

Section 3 sets the boundary. The Act applies to processing of digital personal data inside India where the data was collected in digital form, or collected on paper and digitised afterwards. It also reaches processing outside India, if that processing is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India". It does not apply to personal data processed by an individual for a personal or domestic purpose, nor to personal data the individual has made publicly available herself, or that someone else is legally obliged to make public.

The people and bodies the Act names#

Most of the Act is written in terms of a small cast of defined roles.

RoleDefinitionWhat it means in practice
Data Principalsection 2(j)The individual the data is about. For a child it includes the parents or lawful guardian, and for a person with disability her lawful guardian.
Data Fiduciarysection 2(i)Any person who alone or with others "determines the purpose and means of processing of personal data". This is the party that carries the obligations.
Data Processorsection 2(k)Any person who processes personal data on behalf of a Data Fiduciary. For activity related to offering goods or services, a Data Fiduciary may engage one "only under a valid contract" (section 8(2)).
Consent Managersection 2(g)A person registered with the Board, acting as a single point of contact so a Data Principal can give, manage, review and withdraw consent in one place.
Significant Data Fiduciarysection 2(z), section 10A Data Fiduciary, or class of them, notified by the Central Government on factors such as volume and sensitivity of data and risk to Data Principals. Extra duties follow.
Data Protection Officersection 2(l)An individual appointed by a Significant Data Fiduciary, based in India, answerable to its board and the contact point for grievances (section 10(2)(a)).
Data Protection Board of Indiasection 2(c), section 18The body that inquires into breaches and imposes penalties. Established with effect from 13 November 2025 by G.S.R. 844(E); G.S.R. 845(E) notified that it "shall consist of four members".

"Person" here includes an individual, a Hindu undivided family, a company, a firm, an association of persons, the State and every artificial juristic person (section 2(s)). A Data Fiduciary can therefore be a government body as easily as a business.

How the Act is built#

Forty-four sections across nine chapters, plus a Schedule of penalties.

ChapterSectionsWhat it deals with
I. Preliminary1 to 3Commencement, definitions, scope.
II. Obligations of Data Fiduciary4 to 10Grounds for processing, notice, consent, legitimate uses, general duties, children's data, Significant Data Fiduciaries.
III. Rights and duties of Data Principal11 to 15Access, correction and erasure, grievance redressal, nomination, and the duties the individual owes.
IV. Special provisions16 and 17Restricting transfers to notified countries, and the exemptions.
V. Data Protection Board of India18 to 26Establishing the Board, who sits on it, how they are appointed and removed.
VI. Powers, functions and procedure of the Board27 and 28What the Board may inquire into, and how.
VII. Appeal and alternate dispute resolution29 to 32Appeals to the Appellate Tribunal, mediation, voluntary undertakings.
VIII. Penalties and adjudication33 and 34How penalties are set, and where the money goes.
IX. Miscellaneous35 to 44Rule-making power, directions, the relationship with other laws, consequential amendments.

The centre of gravity is Chapter II. Section 4 allows processing only for a lawful purpose and only on one of two bases: the Data Principal's consent, or one of the "certain legitimate uses" in section 7. Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action" (section 6(1)), preceded or accompanied by a notice (section 5).

How the Rules fit#

Section 40 lets the Central Government make rules to carry out the purposes of the Act, subject to previous publication, and lists twenty-six specific matters those rules may cover, from the manner of giving notice to the form of a personal data breach report. Wherever the Act says "as may be prescribed", it is pointing at rules made under section 40. Section 41 requires every rule, and notifications under sections 16 and 42, to be laid before both Houses of Parliament.

The Central Government used that power on 13 November 2025 to make the Digital Personal Data Protection Rules, 2025 through G.S.R. 846(E), after publishing a draft in January 2025 and considering the objections received. There are 23 rules and seven schedules, with their own timetable in rule 1.

When each part starts#

G.S.R. 843(E) split the Act into three groups. The definitions, the Board chapter and the rule-making powers started on 13 November 2025. The Consent Manager registration machinery starts one year later. Everything else, including the application clause, the duties of Data Fiduciaries, the rights of Data Principals and the penalties, starts eighteen months after publication.

What a breach can cost#

If the Board concludes after an inquiry that a breach is significant, it may impose the monetary penalty specified in the Schedule, after giving the person a hearing (section 33(1)). The Schedule's highest figure "may extend to two hundred and fifty crore rupees", for failing to take reasonable security safeguards under section 8(5). Failing to report a personal data breach, and breaching the children's data obligations, each carry up to two hundred crore rupees. Any other breach of the Act or the rules carries up to fifty crore rupees.

The amount is not automatic. Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach, the data affected, whether it was repeated, any gain made or loss avoided, and the likely impact of the penalty. The Central Government may amend the Schedule by notification, but not so as to more than double any penalty as originally enacted (section 42).

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.