What Is Digital Personal Data Protection Act, 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection law, enacted in August 2023 after more than five years of legislative iteration. The Act governs the processing of digital personal data within India and the processing of digital personal data outside India when such processing is in connection with offering goods or services to data principals (the Act's term for data subjects) in India. DPDP Act is built around a rights/obligations framework: data principals have rights concerning information, correction and erasure, grievance redressal, nomination, and withdrawal of consent; data fiduciaries (controllers) have corresponding obligations centered on notice, consent, data minimization, purpose limitation, and breach notification. The Act designates certain 'Significant Data Fiduciaries' based on volume and sensitivity for heightened obligations including Data Protection Officers and audits, subject to the Act, rules, notifications, and commencement dates. The Data Protection Board of India is the statutory adjudicatory authority under the Act, with powers to issue directions and impose financial penalties up to ₹250 crore per contravention where the Schedule and applicable provisions allow. MeitY notified the DPDP Rules and established the Board by notifications dated 13 November 2025, with staged commencement dates; a May 2026 notice concerns later appointment activity. Check the current enforcement timeline before relying on an obligation that has not yet commenced.
At a glance
- Full name
- Digital Personal Data Protection Act, 2023
- Short code
- DPDP Act
- Jurisdiction
- India
- Enacted
- 2023
- Last major update
- Digital Personal Data Protection Rules and Data Protection Board notified 13 November 2025 with phased commencement; 2026 appointment activity
- Regulator
- Data Protection Board of India
- Private right of action
- No
- Statutory citation
- Act No. 22 of 2023
Scope, who DPDP Act covers
Protected data
Data subject rights
Right to obtain information about processing (Section 11), summary of personal data processed and with whom shared
Right to correction, completion, updating, and erasure (Section 12)
Right of grievance redressal (Section 13), readily available means to register grievances
Right to nominate (Section 14), designate an individual to exercise rights on death or incapacity
Right to withdraw consent for consent-based processing (Section 6), subject to the Act and disclosed consequences
Notable features
DPDP Act relies heavily on delegated rulemaking by the Central Government. It introduces a nomination right in Section 14, allowing a data principal to name another individual to exercise rights on death or incapacity. The Act also contains exemptions for the State and certain processing in the interest of national security, public order, or prevention of offences; the exact effect depends on the text and any applicable notification or rule.
Enforcement & penalties
Regulator: Data Protection Board of India
Penalties: Schedule to the Act sets maximum penalties per contravention: up to ₹250 crore for failing to take reasonable security safeguards; ₹200 crore for failing to notify breaches; ₹200 crore for violations relating to children's data; ₹150 crore for violations of Significant Data Fiduciary obligations. The Data Protection Board determines penalties case-by-case based on nature, gravity, duration, and impact.
Private right of action: DPDP Act does not grant a private right of action. Enforcement runs exclusively through the Data Protection Board of India. Data principals can file complaints with the Board, which may impose financial penalties (remitted to the Consolidated Fund of India). Individual damages typically require parallel civil/tort claims under general Indian law.
Relevance to data brokers
DPDP Act can apply to processing outside India when it is connected with offering goods or services to data principals in India. A data broker should assess the Act, rules, commencement dates, exemptions, and any sectoral law before drawing a compliance conclusion. Indian residents can use the grievance and Board routes that are available under the current implementation.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does DPDP Act replace the Information Technology Rules (SPDI Rules 2011)?+
Yes, once Section 44(3) of DPDP Act is fully in force, it repeals Section 43A of the IT Act 2000 (the basis for the 2011 Sensitive Personal Data or Information Rules). Until rules are fully notified and in force, the SPDI Rules continue to apply for sensitive data categories they covered.
How do I file a complaint under DPDP Act?+
Under Section 13, you must first approach the data fiduciary's grievance officer. If the data fiduciary fails to resolve the complaint within a prescribed period, you can escalate to the Data Protection Board of India. The Board's process for accepting complaints has been established via notification under Section 28.
What is a Significant Data Fiduciary?+
A data fiduciary notified by the Central Government as 'Significant' based on factors such as volume and sensitivity of personal data processed, risk of harm to data principals, public-order implications, and security of the state. Significant Data Fiduciaries have additional obligations under Section 10, subject to the Act, Rules, notifications, and commencement dates.
Does DPDP Act apply to foreign data brokers?+
It may. Section 3(b) can extend the Act to processing outside India when it is connected with offering goods or services to data principals in India. Whether a particular foreign broker falls within scope depends on the activity, the current commencement position, exemptions, and other applicable law.
Official sources & citations
Other international privacy regimes
DPDP Act sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
