
The DPDP Act — short for the Digital Personal Data Protection Act, 2023 — is India’s primary law governing how organizations collect, store, and use the personal data of individuals in digital form. It was passed by both houses of Parliament in August 2023 and received Presidential assent on August 11, 2023, as Act No. 22 of 2023.
For two years, the Act existed largely on paper, waiting for its implementing rules. That changed in November 2025, when the Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025, putting the law into a phased, enforceable rollout that runs through May 2027. If you’re researching DPDP in 2026, this timeline — not just the original 2023 text — is what actually determines your compliance obligations right now.
This guide covers what the DPDP Act says, who it applies to, what’s changed with the 2025 Rules, and how it compares to the GDPR.
What Is the DPDP Act?
The DPDP Act regulates the processing of digital personal data — information about an identifiable individual that is processed in digital form, or collected offline and later digitized. It replaces the old data-protection provisions under Section 43A of the Information Technology Act, 2000, and the associated 2011 IT Rules.
The Act is built around a small set of actors:
- Data Principal — the individual to whom the personal data relates (equivalent to a “data subject” under the GDPR). Where the individual is a child, their parent or lawful guardian exercises these rights.
- Data Fiduciary — the entity that determines the purpose and means of processing personal data (equivalent to a “data controller”).
- Data Processor — an entity that processes personal data on behalf of a Data Fiduciary.
- Significant Data Fiduciary (SDF) — a Data Fiduciary the government designates for extra obligations, based on factors like the volume and sensitivity of data it handles.
- Consent Manager — a registered, interoperable platform through which a Data Principal can give, manage, review, and withdraw consent across multiple services.
- Data Protection Board of India (DPB) — the adjudicatory and enforcement body set up under the Act. It is not a rule-making regulator like some other countries’ data protection authorities; its role is enforcement and dispute resolution, and it sits under significant central government control over its composition.
Who the DPDP Act Applies To
The Act applies to the processing of digital personal data:
- Within India, whether the data originated online or was collected offline and later digitized.
- Outside India, if that processing relates to offering goods or services to individuals located in India.
It does not apply to personal data:
- Processed by an individual for a purely personal or domestic purpose.
- That has been made publicly available by the Data Principal themselves, or by someone else under a legal obligation to do so.
Core Obligations for Organizations (Data Fiduciaries)
Strip away the legal language and the DPDP Act asks Data Fiduciaries to do a few concrete things:
- Get valid consent. Consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. Requests for consent must be accompanied by a notice, in clear language, explaining what data is collected and why.
- Limit collection and use. Personal data should be processed only for the purpose it was collected for, and only the data necessary for that purpose should be collected.
- Keep data accurate and secure. Fiduciaries must implement “reasonable security safeguards” to prevent breaches, and correct or update inaccurate data on request.
- Notify breaches. Both the Data Protection Board and affected Data Principals must be informed of a personal data breach.
- Honor withdrawal of consent. If a Data Principal withdraws consent, the Fiduciary must stop processing that data (and instruct any processor to do the same) unless another legal ground applies.
- Erase data when no longer needed. Data should generally be deleted once its purpose is fulfilled or consent is withdrawn, subject to any other law requiring retention.
- Handle children’s data with extra care. Processing a child’s personal data requires verifiable parental consent, and Fiduciaries are barred from behavioral monitoring or targeted advertising directed at children.
Significant Data Fiduciaries face additional duties: appointing a data protection officer based in India, appointing an independent data auditor, and carrying out periodic Data Protection Impact Assessments (DPIAs).
Rights of Data Principals
Individuals covered by the Act have the right to:
- Obtain a summary of the personal data being processed and the processing activities.
- Correct, complete, or update their personal data.
- Erase personal data that is no longer necessary for the purpose it was collected.
- Withdraw consent as easily as it was given.
- Nominate another individual to exercise these rights on their behalf in the event of death or incapacity.
- File grievances with the Data Fiduciary and, if unresolved, escalate to the Data Protection Board.
Cross-Border Data Transfers
Unlike the GDPR’s “adequacy decision” model, the DPDP Act takes a negative-list approach: personal data can generally be transferred outside India, except to countries the central government specifically restricts by notification. The government also retains discretion to require that certain sensitive or critical categories of data be processed only within India, though the Act does not impose blanket data localization.
Penalties Under the DPDP Act
Non-compliance carries significant financial exposure — reported figures include penalties of up to ₹250 crore for failing to implement reasonable security safeguards, with separate (lower) penalty bands for failures like inadequate breach notification or violations of children’s data provisions. Penalties are assessed by the Data Protection Board on a case-by-case basis and can, in principle, stack across multiple violations arising from the same incident. There’s also a modest penalty (reportedly up to ₹10,000) for a Data Principal who breaches their own duties under the Act, such as furnishing false information.
Exact penalty figures are still being clarified through Board practice as enforcement ramps up — organizations should track official DPB guidance rather than relying solely on secondary summaries, including this one.
The DPDP Rules, 2025 and the Current Rollout Timeline
The DPDP Act’s substantive provisions couldn’t take legal effect until implementing rules were notified. MeitY notified the DPDP Rules, 2025 on November 13–14, 2025, along with a phased enforcement schedule:
| Date | What takes effect |
|---|---|
| November 2025 | DPDP Rules notified; Data Protection Board of India established (Delhi NCR, four members); Board’s complaint-handling mechanism goes live |
| November 2026 | Consent Manager registration framework opens |
| May 13, 2027 | Full compliance becomes mandatory — consent architecture, privacy notices, Data Principal rights mechanisms, breach notification, and the penalty regime all become enforceable |
As of mid-2026, the Data Protection Board is still being staffed and is operating in an awareness-and-guidance mode rather than active enforcement. Organizations are broadly expected to spend 2026 on gap assessments, consent-system redesign, and vendor/processor contract updates ahead of the May 2027 deadline.
How the DPDP Act Differs from the GDPR
They cover similar ground but aren’t identical:
- No sub-classification of sensitive data. The GDPR singles out “special category” data (health, biometric, religious belief, etc.) for extra protection. The DPDP Act applies broadly the same rules to all personal data, with the exception of specific children’s-data provisions.
- Consent Managers are a DPDP-specific concept. There’s no direct GDPR equivalent to this interoperable, user-facing consent infrastructure.
- Cross-border transfers work differently. The GDPR requires an adequacy decision or approved safeguards for transfers outside the EU. The DPDP Act instead allows transfers by default, except to government-notified restricted countries.
- The regulator’s role is narrower. The Data Protection Board of India is primarily adjudicatory, deciding on breaches and complaints referred to it — unlike the broader rule-making and investigatory powers of EU supervisory authorities.
- No standalone “right to be forgotten,” though the erasure right achieves a similar practical outcome in most cases.
Frequently Asked Questions About the DPDP Act
What does DPDP stand for?
DPDP stands for Digital Personal Data Protection — referring to India’s Digital Personal Data Protection Act, 2023.
When did the DPDP Act come into force?
The Act received Presidential assent on August 11, 2023, but its provisions came into force in phases, beginning with the DPDP Rules notification in November 2025. Full enforcement, including penalties, is expected from May 13, 2027.
Who does the DPDP Act apply to?
Any organization (“Data Fiduciary”) processing digital personal data in India, or processing such data outside India in connection with offering goods or services to individuals in India — including foreign companies serving Indian users.
What is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is the organization or entity that decides the purpose and means of processing personal data — comparable to a “data controller” under the GDPR.
What is the Data Protection Board of India?
It’s the adjudicatory and enforcement body established under the DPDP Act to handle breach investigations, grievances, and penalty decisions. It was constituted in November 2025.
How is the DPDP Act different from the GDPR?
The DPDP Act doesn’t create special categories of sensitive data, uses a negative-list (rather than adequacy-based) approach to cross-border transfers, introduces the Consent Manager concept, and gives its regulator a narrower, primarily adjudicatory role.
What are the penalties for non-compliance?
Penalties can reportedly run as high as ₹250 crore for serious lapses like failing to implement adequate security safeguards, decided case-by-case by the Data Protection Board once the penalty regime takes full effect in May 2027.
Do organizations need to comply with the DPDP Act right now?
The Act and Rules are already in force in phases. While the penalty regime isn’t fully active until May 2027, organizations are expected to be building compliant consent, breach-notification, and data-handling systems throughout 2026 rather than waiting for the deadline.
This article is for general informational purposes and reflects the DPDP Act, 2023 and DPDP Rules, 2025 as understood as of August 2026. It is not legal advice — consult a qualified professional for guidance specific to your organization.