Data Protection

DPDP Act Complete Guide: Everything You Need to Know About India's Data Protection Law

The Digital Personal Data Protection Act 2023 is India's first comprehensive privacy law. This guide covers every obligation, every right, every penalty, and a step-by-step compliance roadmap — updated for 2026.

Table of Contents
  1. What is the DPDP Act 2023?
  2. Who does it apply to?
  3. Key definitions
  4. 8 core obligations
  5. Data Principal rights
  6. Significant Data Fiduciaries
  7. Cross-border transfers
  8. Penalties
  9. DPDP vs GDPR
  10. Compliance checklist
  11. How long does compliance take?
  12. FAQ
Quick Answer

The DPDP Act 2023 requires every organisation that processes personal data of Indian individuals to: obtain valid consent, publish a DPDP notice, minimise data collection, maintain accuracy, limit storage, implement security safeguards, provide grievance redressal, and notify breaches. The compliance deadline is May 13, 2027. Penalties reach ₹250 crore per violation.

What is the DPDP Act 2023?

The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive data privacy law. It was passed by Parliament and signed into law on August 11, 2023. The Rules under the Act were notified in January 2025, starting the compliance clock for all organisations processing personal data of Indian individuals.

Before the DPDP Act, India had no unified data protection legislation. Organisations were governed only by the Information Technology Act 2000 and its rules — a patchwork framework with weak enforcement and no individual rights. The DPDP Act changes this fundamentally, creating enforceable rights for individuals and hard financial penalties for organisations that mishandle personal data.

The Act draws from global data protection frameworks — particularly the EU's General Data Protection Regulation (GDPR) — but is specifically designed for India's digital economy and regulatory context. It uses Indian-specific terminology (Data Fiduciary, Data Principal) and creates an India-specific enforcement body, the Data Protection Board of India.

📅
Compliance Deadline

May 13, 2027 — the deadline for full DPDP Act compliance. The Rules were notified in January 2025. All organisations processing personal data of Indian individuals must be compliant by this date or face penalties assessed by the Data Protection Board of India.

Who does the DPDP Act apply to?

The DPDP Act applies to any entity that processes digital personal data of individuals in India (called Data Principals). This includes Indian businesses of all sizes, foreign companies with Indian users, and non-profit organisations. There is no minimum turnover threshold or employee-count exemption.

What is a Data Fiduciary?

A Data Fiduciary is any person, company, government body, or other entity that alone or jointly with others determines the purpose and means of processing personal data. If your organisation decides what data to collect and why — you are a Data Fiduciary and must comply with all DPDP obligations.

Common examples of Data Fiduciaries in India: e-commerce platforms, fintech apps, NBFC lenders, hospitals, schools, HR software vendors, SaaS companies, marketing agencies, and any startup that collects user sign-up data.

What is a Data Processor?

A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary. Data Processors are not directly regulated by the DPDP Act in the same way — but Data Fiduciaries are responsible for ensuring their Data Processors also protect data adequately through contractual safeguards.

Exemptions from DPDP Act

The following are exempt from DPDP Act obligations:

  • Personal or domestic purposes — individuals processing data for purely personal use
  • Publicly available data — data that the Data Principal themselves has made public
  • Research, archiving, and statistical purposes — subject to standards prescribed by the government
  • Certain government functions — national security, public order, and prevention of offences
  • Journalistic activity — processing for journalistic or editorial purposes, subject to the Press Council of India Act

Key definitions under the DPDP Act

Understanding the DPDP Act requires clarity on its specific terminology, which differs from both common usage and GDPR.

DPDP TermMeaningGDPR Equivalent
Data PrincipalThe individual whose personal data is being processedData Subject
Data FiduciaryThe entity that determines the purpose and means of processingData Controller
Data ProcessorAn entity that processes data on behalf of a Data FiduciaryData Processor
Significant Data Fiduciary (SDF)A Data Fiduciary designated by the government due to the sensitivity or volume of data processedNo direct equivalent
Personal DataAny data about an identifiable individualPersonal Data
Digital Personal DataPersonal data in digital form, or non-digital personal data that is digitisedBroader under GDPR
Consent ManagerA registered entity through which Data Principals manage their consentNo direct equivalent
Data Protection BoardThe statutory body that adjudicates complaints and imposes penaltiesSupervisory Authority (e.g. ICO, CNIL)

The 8 core obligations of a Data Fiduciary

Every Data Fiduciary must fulfil the following 8 obligations. These are not optional — failure to comply with any of them exposes the organisation to penalties from the Data Protection Board.

  1. 1
    Obtain valid consent

    Consent must be free, specific, informed, unconditional, and unambiguous. It must be obtained through a clear affirmative action — a pre-ticked checkbox does not constitute consent. Consent must be as easy to withdraw as it is to give. Where a legitimate use (Legitimate Interest equivalent under DPDP) applies, consent may not be required — but the list of legitimate uses is narrower than GDPR Article 6.

  2. 2
    Provide a DPDP notice

    Before or at the time of requesting consent, Data Fiduciaries must provide a clear notice in plain language explaining: what personal data will be collected, the purpose for which it will be processed, how Data Principals can exercise their rights, and how to contact the grievance officer. The notice must be available in all 22 scheduled languages of India upon request.

  3. 3
    Data minimisation

    Collect only the personal data that is necessary for the stated purpose. If your checkout flow collects date of birth but you have no legitimate reason to require it, you must stop collecting it. This principle applies to every data field — it is a constraint on collection design, not just a policy commitment.

  4. 4
    Data accuracy

    Personal data must be accurate and complete. Where inaccurate or incomplete data could result in adverse action against a Data Principal — such as a credit decision or employment outcome — Data Fiduciaries must take reasonable steps to ensure accuracy before acting on the data.

  5. 5
    Storage limitation

    Personal data must not be retained for longer than is necessary for the purpose for which it was collected. Once the purpose is served and there is no legal obligation to retain, the data must be deleted. Data Fiduciaries must establish and implement retention schedules and automated deletion processes.

  6. 6
    Security safeguards

    Reasonable technical and organisational security measures must be implemented to protect personal data from breaches. The Act does not prescribe specific technical controls — the standard is "reasonable" based on the nature and sensitivity of the data, the volume processed, and the state of technology. ISO 27001 certification is one widely accepted framework for demonstrating reasonable security.

  7. 7
    Grievance redressal

    Every Data Fiduciary must provide an accessible grievance mechanism for Data Principals. This includes appointing a Grievance Officer (name and contact details must be published), establishing a process for receiving and resolving complaints, and responding within timeframes specified in the Rules. Data Principals can escalate unresolved grievances to the Data Protection Board.

  8. 8
    Breach notification

    In the event of a personal data breach, Data Fiduciaries must notify both the Data Protection Board and each affected Data Principal without undue delay. The notification must describe the nature of the breach, the categories and volume of data affected, likely consequences, and measures taken or proposed. There is no specific 72-hour window as in GDPR, but "without undue delay" will be interpreted strictly by the Board.

Free Tool
Check your DPDP compliance gaps in 10 minutes

42-item interactive checklist across 8 categories — consent, notice, rights, security, breach, and more.

Use the Checklist →

The 8 rights of Data Principals

Individuals (Data Principals) whose data is processed have the following enforceable rights under the DPDP Act. Data Fiduciaries must build processes to fulfil these rights within the timeframes prescribed in the Rules.

Right 01
Right to information

The right to obtain a summary of what personal data the Data Fiduciary holds and how it is being processed.

Right 02
Right to correction

The right to correct inaccurate personal data or complete incomplete data held by the Data Fiduciary.

Right 03
Right to erasure

The right to have personal data erased when it is no longer necessary for the purpose or when consent is withdrawn.

Right 04
Right to grievance redressal

The right to file a complaint with the Data Fiduciary's Grievance Officer and to escalate to the Data Protection Board if unresolved.

Right 05
Right to nominate

The right to nominate another individual to exercise data protection rights on their behalf in the event of death or incapacity — unique to the DPDP Act.

Right 06
Right to withdraw consent

The right to withdraw consent at any time. Withdrawal must be as easy as giving consent. Processing must cease once consent is withdrawn, subject to any lawful basis for continued processing.

Right 07
Right to access information

The right to receive a summary of the personal data processed, identities of all Data Processors the data has been shared with, and any other information prescribed by the Rules.

Right 08
Right to approach the Board

If a grievance is not resolved by the Data Fiduciary, the Data Principal can file a complaint directly with the Data Protection Board of India for adjudication.

Significant Data Fiduciaries — additional obligations

The Government of India may designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume or sensitivity of data they process, or their potential impact on national security or electoral processes. SDFs face additional obligations beyond the standard 8.

⚠️
Who may be designated as an SDF

Large social media platforms, large e-commerce marketplaces, critical information infrastructure operators, companies processing health or financial data at scale, and any entity whose data processing poses significant risk to Data Principals' rights. The government has not yet published the final SDF list.

Additional SDF obligations

  • Data Protection Officer (DPO): Must appoint a DPO who is based in India, represents the SDF, and is the point of contact for the Data Protection Board. Unlike GDPR, the DPO does not need to be independent — but must be a senior official.
  • Data Protection Impact Assessment (DPIA): Must conduct DPIAs before undertaking any new processing activity that may pose high risk to Data Principals.
  • Independent data audit: Must appoint an independent data auditor to assess the SDF's compliance with the Act and prescribed standards.
  • Additional standards: The government may prescribe additional processing standards, data retention limits, or security requirements specific to SDFs.

Cross-border data transfers under the DPDP Act

The DPDP Act permits cross-border transfers of personal data to countries or territories notified by the Government of India. This is a positive whitelist approach — unlike GDPR's adequacy decisions, India will publish a list of permitted destination countries. Transfers to countries not on the whitelist will be restricted.

The government has not yet published the final whitelist. Until it does, organisations should continue current practices while preparing their data flow mapping to understand which cross-border transfers they rely on. Transfers to countries for state security or diplomatic reasons may be restricted even if otherwise on the whitelist.

Key implication for Indian businesses: SaaS companies using US-based cloud infrastructure (AWS, Azure, GCP) should assess whether their US data processing arrangements will be permitted under the final rules. Most major cloud providers are expected to be on the whitelist, but data residency requirements may apply to certain categories of sensitive data.

DPDP Act penalties — the full schedule

The Data Protection Board of India assesses penalties for violations of the DPDP Act. Penalties are per violation and can accumulate across multiple breaches. The Board considers the nature, gravity, and duration of the violation when determining the penalty amount.

ViolationMaximum Penalty
Failure to implement adequate security safeguards resulting in a personal data breach ₹250 crore
Failure to notify the Data Protection Board and affected Data Principals of a breach ₹200 crore
Failure to fulfil obligations in relation to children's data and Significant Data Fiduciaries' additional obligations ₹200 crore
Non-fulfilment of Data Principal rights ₹50 crore
Non-compliance with any other provision of the Act or Rules ₹50 crore
Non-compliance with a direction of the Data Protection Board ₹150 crore
💡
How penalties are assessed

The Data Protection Board considers the nature, gravity, and duration of the violation; whether it was intentional or negligent; whether the organisation cooperated with the Board; the number of Data Principals affected; and the organisation's prior compliance history. Unlike GDPR, there is no explicit turnover-based cap — a ₹250 crore penalty falls equally on a Series A startup and a large enterprise.

DPDP Act vs GDPR — side-by-side comparison

Many Indian businesses also serve EU customers and must comply with both the DPDP Act and GDPR. Here is how the two frameworks compare:

DimensionDPDP Act 2023GDPR
Scope of dataDigital personal data onlyAll personal data (digital and non-digital)
Territorial scopeData of Indian individuals processed in India or abroadData of EU individuals processed anywhere in the world
Legal bases for processingConsent + narrow list of Legitimate Uses6 lawful bases including Legitimate Interests
DPO requirementOnly for Significant Data FiduciariesBased on type of processing (Article 37)
DPIA requirementOnly for Significant Data FiduciariesRequired for high-risk processing (Article 35)
Maximum penalty₹250 crore per violation€20 million or 4% of global annual turnover
Breach notification window"Without undue delay" (no fixed window)72 hours to supervisory authority
Right to portabilityNot explicitly includedYes (Article 20)
Right to nominateYes — unique to DPDP ActNo direct equivalent
Cross-border transfersWhitelist approach (permitted countries)Adequacy decisions + SCCs + BCRs
Enforcement bodyData Protection Board of IndiaNational supervisory authorities (ICO, CNIL, etc.)

DPDP Act compliance checklist — key items

Full DPDP compliance requires action across 8 categories. Below are the highest-priority items. For the complete 42-item interactive checklist, see our DPDP Act Compliance Checklist.

Priority compliance actions
  • Conduct a data mapping exercise — document all personal data collected, its purpose, storage location, and data flows to third parties
  • Audit existing consent mechanisms — are they specific, informed, and as easy to withdraw as to give?
  • Draft and publish a DPDP-compliant privacy notice in plain language (with multilingual support mechanism)
  • Appoint a Grievance Officer and publish their name and contact details on your website
  • Build workflows to fulfil Data Principal rights requests (access, correction, erasure, withdrawal)
  • Implement a breach detection and notification process — define who notifies the Board, who notifies affected individuals, and the internal escalation path
  • Review vendor and partner contracts — ensure Data Processors have adequate security obligations and data processing agreements in place
  • Implement data retention schedules and automated deletion for personal data no longer needed for its purpose
See all 42 checklist items →

How long does DPDP compliance take?

For most Indian businesses, achieving full DPDP Act compliance takes 4–9 months depending on the complexity of your data ecosystem, current security maturity, and how quickly your technical teams can implement consent and rights-management workflows.

Compliance ActivityTypical DurationWho Does It
Data mapping and inventory4–6 weeksPrivacy/legal + engineering
Gap assessment against DPDP obligations2–3 weeksPrivacy/legal + DPO
Consent mechanism design and implementation4–8 weeksProduct + engineering
Privacy notice drafting and multilingual review2–4 weeksLegal + communications
Data Principal rights workflow implementation4–6 weeksEngineering + legal
Security controls and DLP implementation6–12 weeksSecurity team / CISO
Breach notification procedure and runbook2–3 weeksSecurity + legal
Staff training programme2–4 weeksHR + privacy team
Vendor contract review and DPA execution4–8 weeksLegal + procurement

Given the May 13, 2027 deadline, organisations that have not yet begun should start immediately. Data mapping alone typically uncovers unexpected data flows and third-party sharing that require additional remediation time. Starting in late 2026 leaves minimal margin for setbacks.

NxgSecure
DPDP compliance managed for you — start to finish

Data mapping, consent implementation, privacy notice, rights workflows, breach procedures, and DPO advisory. One team, one programme, one deadline.

See How It Works →

Frequently asked questions about the DPDP Act

  • The DPDP Act 2023 was enacted on August 11, 2023. The Rules were notified in January 2025. Most provisions of the Act are now in force, with the compliance deadline set at May 13, 2027. The Data Protection Board of India is being constituted and is expected to begin accepting complaints before the compliance deadline. Organisations should treat compliance as active and urgent — not a future obligation.
  • Yes. The DPDP Act applies to the processing of any personal data of Indian individuals — including employee data, vendor contact data, and customer contact data at B2B companies. If your HR system holds employee records, your CRM holds contact names and emails of business contacts, or your support platform holds names and phone numbers — you are processing personal data and the Act applies. B2B companies must comply with consent obligations, storage limitation, security safeguards, and breach notification at minimum.
  • Yes. There is no turnover or employee-count threshold in the DPDP Act. Any organisation that processes digital personal data of Indian individuals must comply, regardless of size. However, the government may prescribe different compliance timelines or reduced obligations for certain categories of Data Fiduciaries — this has not been announced yet. Until such carve-outs are notified, all organisations should plan for full compliance.
  • Existing privacy policies are unlikely to be fully DPDP-compliant without revision. The DPDP Act requires a specific DPDP Notice that is separate from (or clearly incorporated into) your privacy policy. The notice must be in plain language, must clearly state the purpose of processing, and must explain how Data Principals can exercise their rights. Most legacy privacy policies drafted under the IT Act framework will need to be substantially rewritten. Consent mechanisms embedded in existing terms of service (checkbox at registration) also need to be reviewed for DPDP compliance.
  • The DPDP Act defines a child as anyone under 18 years of age. Processing the personal data of a child requires verifiable parental consent. Data Fiduciaries must not undertake processing that adversely affects children's wellbeing, track or behaviorally target children, or process data in a manner that causes harm. Platforms likely to be accessed by children must implement age-verification mechanisms. Violation of children's data obligations attracts a penalty of up to ₹200 crore.
  • The Data Protection Board of India (DPBI) is the statutory body created under the DPDP Act to adjudicate complaints and enforce penalties. Data Principals whose grievances are not resolved by a Data Fiduciary's grievance officer can file complaints with the Board. The Board investigates, issues show-cause notices, conducts hearings, and can impose financial penalties up to ₹250 crore. The Board is not yet fully constituted but is expected to be operational before the May 2027 compliance deadline.
  • The DPDP Act itself does not mandate data localisation (keeping data within India). However, cross-border transfers are only permitted to countries on the government's whitelist of permitted destinations. The government can also restrict transfers to specific countries or restrict transfers of specific categories of data. Sector-specific regulations (RBI, IRDAI, SEBI) may impose additional localisation requirements independently of the DPDP Act — these remain in force.
MJ
Mayank Jain
Co-Founder & CEO, NxgSecure | CISA | Data Protection Practitioner

Mayank has 18+ years of experience in information security and compliance, and has led DPDP readiness programmes for Indian enterprises across BFSI, healthtech, and SaaS. NxgSecure is India's managed GRC and compliance partner, helping businesses achieve ISO 27001, DPDP, and SOC 2 compliance without building an in-house security team.