India now has a comprehensive data privacy law, and it reaches far beyond India’s borders. Any organisation that processes the personal data of people in India falls within its scope, whether it operates from Bengaluru or Boston. The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023, and with the DPDP Rules 2025 notified on 13 November 2025, its obligations are now moving into force on a fixed schedule that ends on 13 May 2027. With penalties reaching ₹250 crore for a single security failure, this is not a law to approach at the last minute.
This guide explains the DPDP Act in plain language: what it is, who it applies to, the obligations it places on organisations, the rights it gives individuals, how it is enforced, how it compares to GDPR, and exactly what your organisation needs to do before the compliance deadline.
What is the DPDP Act 2023?
The DPDP Act 2023 is India’s first standalone law dedicated to protecting digital personal data. Before it, data protection in India rested on a handful of provisions in the Information Technology Act, 2000 and the IT Rules of 2011, a framework never built for the scale of today’s data economy.
The path to the Act was long. After the Supreme Court held in the 2017 Puttaswamy judgment that privacy is a fundamental right under the Constitution, the government worked through draft bills in 2018, 2019, and 2022, each revised after public feedback, before Parliament passed the final version in August 2023.
Its stated purpose is to balance two things: the right of individuals to protect their personal data, and the need of organisations to process that data for lawful purposes. Everything in the Act flows from that balance.
Who does the DPDP Act apply to?
The Act applies to the processing of digital personal data in two situations, and the second one is why companies outside India need to pay attention.
Within India: Any processing of digital personal data collected inside India, whether it was collected online or collected on paper and later digitised.
Outside India: Any processing of that data outside India, when it relates to offering goods or services to individuals located in India.
In practice, a US-based SaaS company serving Indian users falls squarely under the Act, even if its servers never touch Indian soil.
On what data is covered: the Act governs digital personal data, meaning any data about an identifiable individual in digital form, including data that started on paper and was later digitised. Purely non-digital records are outside its scope. A notable design choice sets it apart from GDPR: the DPDP Act creates no separate category of “sensitive personal data.” All personal data is treated under one framework, though the government can impose extra duties on large-scale processors.
The Act also carves out exemptions under Section 17. Processing tied to the investigation of offences, court and tribunal functions, national security, approved research or statistical work, purely personal or domestic use, or data an individual has voluntarily made public sits outside the usual obligations.
Key roles: data fiduciary, data principal, and data processor
The Act is built on three roles. Getting them straight is the first step to understanding your own obligations.
| Term | Definition | GDPR equivalent |
| Data Fiduciary | Any person or organisation that, alone or with others, determines the purpose and means of processing personal data | Data Controller |
| Data Principal | The individual the personal data relates to. For a child, this includes the parent or lawful guardian | Data Subject |
| Data Processor | Any person who processes personal data on behalf of a Data Fiduciary | Data Processor |
One practical point carries real weight: a Data Processor is liable only to the extent of its contract with the Data Fiduciary. The primary regulatory responsibility, and the largest penalty exposure, sits with the Data Fiduciary. If your organisation decides what data to collect and why, you are a Data Fiduciary, and the obligations below are yours.
Obligations of data fiduciaries
The core duties of every Data Fiduciary run through the Act and are detailed further in the DPDP Rules 2025. These are the requirements to build toward.
Consent as the primary basis: Personal data may be processed only for a lawful purpose (Section 4), and consent is the main lawful basis. Under Section 6, that consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, tied to the stated purpose, and as easy to withdraw as it was to give. The Rules add that a consent request must come with a standalone, plain-language notice, available in English and the languages listed in the Constitution’s Eighth Schedule.
A second, narrower basis: The Act also allows processing for certain “legitimate uses” without consent, in defined situations such as delivering a government subsidy or benefit, complying with a legal obligation, or specified employment purposes.
Notice: Before processing, and under Section 5, a Data Fiduciary must give the individual an itemised description of the personal data being collected, the specific purpose, and a link to withdraw consent, exercise rights, or complain to the Data Protection Board.
Purpose limitation and data minimisation: Data may be used only for the purpose it was collected for, and only data necessary for that purpose may be collected. Once the purpose is met or consent is withdrawn, the data is required to be erased. Reusing data for a new purpose needs fresh consent.
Accuracy: Where data will be used to make a decision that affects the individual, or shared with another Data Fiduciary, reasonable steps are required to keep it accurate and complete.
Security safeguards: Reasonable security measures are required under Section 8 to prevent a personal data breach, across every stage of processing. The Rules specify measures such as encryption, access control, and monitoring, and require access logs and processing logs to be retained for at least one year. Knowing where your personal data actually lives is the starting point here, which is why a live data inventory across cloud, SaaS, and endpoints, the kind data security intelligence provides, is the foundation the rest of these safeguards stand on.
Breach notification: On becoming aware of a personal data breach, a Data Fiduciary must inform each affected individual without delay, describing the breach, its likely consequences, and the steps being taken, and must give the Data Protection Board an initial intimation without delay followed by a detailed report within 72 hours, as set out in Rule 7 of the DPDP Rules 2025. Every breach must be reported. The Act sets no minimum threshold, so there is no “too small to report.”
Grievance redressal: A Data Fiduciary must publish a contact point for questions and complaints, and respond to grievances within the timeframe set by the Rules, a maximum of 90 days.
Rights of data principals
Here is where accuracy matters, because this is widely misstated. The DPDP Act grants individuals four statutory rights, set out in Sections 11 to 14. It does not include several rights that GDPR does.
| Right (section) | What it means for your organisation |
| Right to access information (Section 11) | Individuals can ask for a summary of the personal data being processed, the processing activities, and the identities of others the data has been shared with |
| Right to correction and erasure (Section 12) | Individuals can ask to correct, complete, or update their data, and to erase it once the purpose it was collected for has ended |
| Right of grievance redressal (Section 13) | Individuals can raise a complaint with the Data Fiduciary, and escalate to the Data Protection Board if unsatisfied, without needing a lawyer or a fee |
| Right to nominate (Section 14) | Individuals can nominate another person to exercise their rights in the event of death or incapacity, a feature GDPR does not have |
Two things sit alongside these rights. Individuals can withdraw consent at any time under Section 6, with the same ease as giving it, though withdrawal does not undo processing already carried out lawfully. And Section 15 imposes duties on individuals, such as not filing false or frivolous complaints, a breach of which can attract a penalty of up to ₹10,000.
What the DPDP Act does not give, and this is a genuine difference from GDPR, is a right to data portability, a right to object to processing, or a right against decisions made solely by automated means.
Consent Managers: a role unique to the DPDP framework
The DPDP framework introduces a role that GDPR has no direct parallel for: the Consent Manager. This is a registered intermediary, accountable to the individual, through which a person can give, manage, review, and withdraw consent across every Data Fiduciary they deal with, from a single interface.
Consent Managers must register with the Data Protection Board, and the Rules set the bar deliberately high. A Consent Manager is required to maintain a minimum net worth of ₹2 crore, to run a secure and interoperable platform, and to retain a record of every consent given or withdrawn for at least seven years. Registration opens on 13 November 2026. For most organisations, the practical effect is that consent will increasingly be brokered through these intermediaries rather than collected in isolation, so consent architecture is worth building with that model in mind from the start.
Children’s data and Significant Data Fiduciaries
The Act reserves some of its strictest rules for two situations.
Children’s data: A child is anyone under 18 (Section 2(f)). Before processing a child’s personal data, and under Section 9, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. The Act also prohibits tracking or behavioural monitoring of children, targeted advertising directed at them, and any processing likely to harm their well-being. Similar guardian-consent protections apply to persons with disabilities who cannot make legal decisions for themselves. The Rules exempt some processing from parental consent, including healthcare, education administration, and government welfare.
Significant Data Fiduciaries (SDFs): Under Section 10, the government can designate certain Data Fiduciaries as SDFs, based on the volume and sensitivity of data they process, the risk to individuals, and national-security considerations. SDFs carry extra obligations: an annual Data Protection Impact Assessment, an annual independent audit, appointment of a Data Protection Officer based in India, appointment of an independent data auditor, algorithmic transparency duties, and potential data-localisation requirements for specified data. The official list of SDFs had not been published as of early 2026.
The penalty framework: what non-compliance costs
Enforcement runs on financial penalties set out in the Schedule to the Act and imposed by the Data Protection Board. The amounts are fixed rupee ceilings, not a percentage of turnover, and they apply per breach instance.
| Violation | Maximum penalty |
| Failure to take reasonable security safeguards, resulting in a personal data breach | Up to ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | Up to ₹200 crore |
| Breach of obligations relating to children’s data | Up to ₹200 crore |
| Breach of a Significant Data Fiduciary’s additional obligations | Up to ₹150 crore |
| Breach of consent, notice, or any other provision of the Act or Rules | Up to ₹50 crore |
| Breach of a data principal’s duties | Up to ₹10,000 |
A few points that shape how this actually works. The figures are ceilings set out in the Schedule to the Act, and under Section 33 the Board sets the real amount case by case, weighing the nature, gravity, and duration of the breach, the type of personal data affected, the harm caused, whether the organisation acted to mitigate it, and whether it gained from the failure. The Act provides no cure period, so there is no grace window to fix non-compliance before a penalty applies, though the Board must give an organisation a chance to be heard first. The Act carries no criminal penalties. And penalties are credited to the Consolidated Fund of India, they do not flow to affected individuals as compensation.
The Data Protection Board of India
The Data Protection Board of India, established under Chapter 5 of the Act, is the independent body that enforces it. It operates as a digital-first, largely paperless regulator based in the National Capital Region, with members appointed by the Central Government, and it was constituted when the Rules were notified.
Its core functions are to receive and investigate complaints from individuals, to act on its own initiative where significant breaches surface, to impose penalties within the Schedule’s limits, to accept voluntary undertakings from organisations that agree to remedy non-compliance, and to direct corrective action such as data deletion or security fixes.
Appeals against a Board order lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), with further recourse available through the courts. The Board became operational on 13 November 2025, which means complaints can already be filed even though the full compliance obligations arrive later.
Cross-border data transfers
The DPDP Act takes a deliberately open approach to moving data out of India, and this surprised many observers who expected strict localisation.
Under Section 16, personal data may be transferred to any country, except those the Central Government specifically restricts by notification. This is a “negative list” model, permissive by default, unlike GDPR’s adequacy approach. As of early 2026, no countries had been placed on the restricted list. The one caveat is that for Significant Data Fiduciaries, the government retains the power to require that certain categories of personal data stay within India.
DPDP compliance timeline: what applies when
The DPDP Rules 2025 brought the Act into force in three phases, giving organisations a defined runway. The dates below are the ones to plan against.
| Date | What comes into force |
| 11 Aug 2023 | DPDP Act receives Presidential assent |
| 13 Nov 2025 | DPDP Rules 2025 notified. Data Protection Board constituted and operational. Definitions and the Board’s governance provisions in force |
| 13 Nov 2026 | Enforcement and penalty powers begin. Consent Manager registration opens |
| 13 May 2027 | All substantive obligations in force: notice, consent, data principal rights, retention and erasure, breach reporting, security safeguards, SDF duties, and cross-border conditions |
The practical read is simple. The regulator already exists and can already take complaints, so the absence of a penalty deadline is not the absence of risk. The substantive work, mapping data, rebuilding consent, and hardening security, takes several quarters, so the runway to May 2027 is shorter than it looks.
DPDP Act vs GDPR: the key differences
For organisations that already run a GDPR programme, the instinct is to reuse it. That works only up to a point, because the two laws differ in ways that matter.
| Dimension | DPDP Act 2023 (India) | GDPR (EU) |
| Scope | Digital personal data only | All personal data, digital and non-digital |
| Sensitive data | No separate category | Special categories with stricter rules |
| Lawful bases | Consent plus limited legitimate uses | Six lawful bases, including legitimate interests |
| Cross-border transfer | Negative list, permissive by default | Adequacy decisions, SCCs, BCRs |
| Penalties | Fixed ceilings up to ₹250 crore per instance | Up to 4% of global annual turnover or €20 million |
| Right to nominate | Yes, unique to the DPDP Act | Not provided |
| Portability, objection, automated-decision rights | Not provided | Provided |
| DPO requirement | Only for Significant Data Fiduciaries | Required for certain processing |
| Child’s age | Under 18 | Under 16, with flexibility down to 13 |
| Criminal penalties | None | Varies by member state |
Building your controls to the stricter standard on each point is usually the safest way to cover both regimes at once.
What your organisation must do before May 2027
Here is a prioritised plan for compliance and security teams, sequenced against the runway.
Now: Run a data audit that maps all personal data you collect, store, and process across cloud, SaaS, on-premises, and endpoints, then classify each dataset by its lawful basis and confirm that basis matches your actual use. Follow it with a gap assessment against the Act and the Rules to see where you already comply and where you do not. You cannot govern data you cannot see, so discovery comes first.
Next few quarters: Redesign consent flows to meet the free, specific, informed, unconditional, and unambiguous standard, with withdrawal that is just as easy. Draft standalone, plain-language notices in the required languages. Build a breach-response playbook that can detect an incident and produce the Board notification inside 72 hours, and update Data Processor contracts to carry DPDP-compliant security, breach-support, and deletion clauses. Detecting a breach in time is its own challenge, which is where real-time detection of risky data movement, the job AI data detection and response does, closes the gap between a breach happening and you reporting it.
Before the deadline: Run a full internal or third-party audit against the Act and Rules, issue any required notices to individuals whose data you already hold, and switch on automated retention and erasure so data is deleted once its purpose ends or consent is withdrawn.
Where Matters.AI fits into DPDP compliance
DPDP compliance covers a lot of ground, consent management, purpose mapping, breach response, retention policy, and no single tool handles all of it end to end. Where Matters.AI fits is narrower: knowing where personal data actually lives across cloud, SaaS, endpoints, and on-premises systems, and catching risky movement of that data as it happens rather than finding out during a retrospective audit. That visibility is one piece of a DPDP program, not the whole of it.
See how this fits into your broader DPDP work on the Matters.AI DPDP compliance page, where you can also book a demo.
Frequently asked questions
This guide reflects the DPDP Act 2023 and the DPDP Rules 2025 as notified on 13 November 2025. Because enforcement dates and designations continue to develop, verify time-sensitive details against the official gazette before finalising your compliance position. This is general information, not legal advice.



