DPDP NavigatorAct 2023 · Rules 2025
8 Chapters · 44 Sections · 1 Schedule

The DPDP Act, 2023

The full statutory text, read chapter by chapter, with a plain-language explanation running alongside — never merged, always clearly labelled.

Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.

Reading mode
Chapter I

Preliminary

Establishes the short title, commencement, and the scope of who and what the Act covers.

Section 1 Short title and commencement
Official statutory text · Gazette of India
Plain-language explanation
  • The Act was passed and notified in the Gazette in August 2023, but it does not switch on all at once.
  • The Central Government brings individual sections into force through separate notifications — which is why some provisions (like the Data Protection Board) activated on a different timeline than the core obligations.
Section 2 Definitions
Official statutory text · Gazette of India
Plain-language explanation
  • These definitions decide who owes duties to whom. 'Data Fiduciary' is the party that decides why and how personal data is processed — in most other frameworks this role is closer to a 'controller'.
  • 'Data Processor' is a vendor acting on the Fiduciary's instructions — comparable to a 'processor' elsewhere, but under DPDP the Processor itself owes no direct statutory duty to the Data Principal; liability flows through the Fiduciary via contract.
  • 'Personal data' is deliberately broad — any data that can identify an individual, regardless of sensitivity category. DPDP does not create separate tiers for 'sensitive' personal data the way some other laws do.
  • A 'Consent Manager' is a DPDP-specific role: a registered intermediary that lets an individual manage consent across multiple Fiduciaries from one dashboard.
Section 3 Application of Act
Official statutory text · Gazette of India
Plain-language explanation
  • This is the extraterritorial hook: a foreign company with no Indian office can still fall under DPDP if it profiles, sells to, or otherwise offers goods/services to people located in India.
  • Purely offline, non-digitised personal data (e.g. a paper register never scanned) sits outside scope — but the moment it's digitised, it's in.
  • Data an individual chooses to make public themselves (e.g. a public social media profile) is carved out, as is purely personal/household use.
Chapter II

Obligations of Data Fiduciary

The operational core of the Act — lawful grounds for processing, notice, consent, children's data, and the day-to-day duties every Data Fiduciary must discharge.

Section 4 Grounds for processing of personal data
Official statutory text · Gazette of India
Plain-language explanation
  • DPDP recognises exactly two lawful bases for processing: (1) freely given consent, or (2) one of the specific 'legitimate uses' listed in Section 7 — there is no open-ended 'legitimate interest' ground like in some other privacy laws.
  • If your processing doesn't fit consent or a Section 7 legitimate use, it isn't lawful under this Act.
Section 5 Notice
Official statutory text · Gazette of India
Plain-language explanation
  • Notice must be itemised — a vague, single blanket statement covering 'all purposes' does not meet this bar.
  • It has to be understandable in plain language, provided upfront (not buried after data is already collected), and must tell the individual how to exercise rights and where to complain.
Section 6 Consent
Official statutory text · Gazette of India
Plain-language explanation
  • 'Comparable ease of withdrawal' is the operative test — a two-tap consent flow behind a five-step withdrawal process would not meet this standard.
  • Consent is purpose-limited and data-minimised by design: you can't collect broadly and later expand use because 'the box was ticked'.
  • Withdrawal has to propagate to every Data Processor you've shared that data with, not just stop at your own front door.
Section 7 Certain legitimate uses
Official statutory text · Gazette of India
Plain-language explanation
  • This is the closest DPDP gets to a general-purpose lawful basis outside consent, but it's a closed, enumerated list — not an open standard.
  • The 'voluntarily provided and did not object' ground is often used for things like a visitor signing a physical register or replying to an inbound query.
  • The employment ground is narrower than many assume: it must relate to hiring, terminating, or safeguarding the employer from loss/liability, subject to a reasonableness test.
Section 8 General obligations of Data Fiduciary
Official statutory text · Gazette of India
Plain-language explanation
  • This is the section carrying the most operational weight. Liability sits with the Fiduciary — you cannot contract it away, and a Data Principal's own failure to comply with their duties doesn't excuse you.
  • A valid, binding contract is mandatory before you can use any Data Processor for goods/services related processing.
  • 'Reasonable security safeguards' is undefined in the Act itself — the Rules and prevailing industry practice fill that in.
  • Breach intimation has two audiences: the Board and every affected individual — not a materiality-gated subset.
  • Erasure obligations run on a 'purpose no longer served OR consent withdrawn, whichever is earlier' test, and must cascade to processors.
Section 9 Processing of personal data of children
Official statutory text · Gazette of India
Plain-language explanation
  • 'Child' under the Act means anyone below 18 years — there is no lower age-of-consent carve-out for teenagers as seen in some other regimes.
  • Verifiable parental consent is required before collecting a child's data at all, not just for certain sensitive uses.
  • Behavioural tracking and targeted ads aimed at children are barred outright, subject to narrow, government-notified exemptions (e.g. for platforms that can demonstrate verifiably safe processing, such as certain edtech or healthcare services).
Section 10 Additional obligations of Significant Data Fiduciary
Official statutory text · Gazette of India
Plain-language explanation
  • SDF status is a designation applied by notification, not self-assessed — but the listed factors (scale, sensitivity, risk to democracy/security) give a strong signal of who is likely to be named.
  • An SDF's DPO must sit in India and report to the top of the organisation, not to a regional compliance function abroad.
  • Independent audits and DPIAs move an SDF from 'policy on paper' to demonstrable, periodically tested compliance.
Chapter III

Rights and Duties of Data Principal

The rights individuals can actively exercise over their own data, alongside the duties the Act places on them in return.

Section 11 Right to access information about personal data
Official statutory text · Gazette of India
Plain-language explanation
  • This is broader than a plain 'what do you have on me' request — it extends to who you've shared it with and what categories were shared, not just your own copy of it.
Section 12 Right to correction and erasure of personal data
Official statutory text · Gazette of India
Plain-language explanation
  • Correction and erasure travel together with completion and updating — the right isn't limited to fixing errors, it also covers finishing incomplete records.
Section 13 Right of grievance redressal
Official statutory text · Gazette of India
Plain-language explanation
  • You cannot escalate straight to the Data Protection Board — the individual must first give the Fiduciary a chance to resolve the complaint directly.
Section 14 Right to nominate
Official statutory text · Gazette of India
Plain-language explanation
  • This is a novel feature relative to most global privacy laws — DPDP explicitly lets you designate a nominee to step into your data rights, similar to a nominee on a bank account.
Section 15 Duties of Data Principal
Official statutory text · Gazette of India
Plain-language explanation
  • Rights come with reciprocal duties: providing false identity information, filing frivolous complaints, or submitting fabricated correction requests are themselves statutory breaches, enforceable with the modest ₹10,000 penalty under the Schedule.
Chapter IV

Special Provisions

Cross-border data transfer and the carve-outs where the Act's obligations are relaxed or disapplied.

Section 16 Processing of personal data outside India
Official statutory text · Gazette of India
Plain-language explanation
  • DPDP takes a 'blacklist' approach to cross-border transfer, rather than the 'adequacy allowlist' model used elsewhere — transfers are permitted by default unless a specific destination is restricted by notification.
  • Sector-specific data-localisation rules (e.g. for payments data under RBI norms) sit on top of, and are not weakened by, this section.
Section 17 Exemptions
Official statutory text · Gazette of India
Plain-language explanation
  • The 'start-up' exemption is a notification-based carve-out, not automatic — a company merely calling itself a startup does not opt out of Chapter II/III without a specific government notification naming it or its class.
  • The government-instrumentality exemption is broad and has drawn the most public debate, since it can exempt state agencies from the Act for reasons like public order or security.
  • Research/archiving/statistical exemptions only apply if the output is never used to make a decision about a specific individual.
Chapter V

Data Protection Board of India

Establishes the Board as the Act's dedicated regulator — its composition, independence, and administrative machinery.

Section 18 Establishment of Board
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • The Board is a dedicated digital-first regulator (designed to function largely online) rather than an extension of an existing authority — comparable in role to a data protection authority elsewhere, but with a narrower remit focused on adjudication rather than broad rule-making.
Section 19 Composition and qualifications of Chairperson and Members
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • Members are appointed by the Central Government rather than through an independent judicial-style selection panel, which has been a point of commentary on the Board's institutional independence.
Section 20-26 Terms of service, resignation, removal, and administration
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • Day-to-day relevance for organisations is limited here — this is institutional plumbing for how the regulator itself is staffed, funded, and governed.
Chapter VI

Powers, Functions and Procedure of the Board

What the Board can actually do — investigate, direct remedial action, and how appeals against its orders work.

Section 27 Powers and functions of Board
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • The Board acts on three triggers: a Fiduciary's own breach intimation, an individual's complaint, or a government reference — it does not proactively audit organisations at will the way some regulators do.
Section 28 Procedure to be followed by Board
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • Proceedings are designed to run largely paperless and online, and natural-justice safeguards (a hearing before an adverse order) are built in.
Section 29 Appeal to Appellate Tribunal
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • The designated Appellate Tribunal for DPDP appeals is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), reusing existing tribunal infrastructure rather than creating a new one.
Chapter VII

Penalties and Adjudication

Financial consequences for non-compliance, capped by the Schedule to the Act, plus the voluntary-undertaking route.

Section 30 Voluntary undertaking
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • This gives organisations a settlement-style path — offering fixes and safeguards to the Board can stop or shorten a formal inquiry.
Section 31 Penalties
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • Penalties are capped by category in the Schedule rather than set as an uncapped percentage of turnover — see the Schedule summary below.
Section 32 Crediting sums realised by way of penalties to Consolidated Fund of India
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • Unlike some regimes where a share of penalties can fund the regulator, DPDP penalties flow straight to general government revenue.
Chapter VIII

Miscellaneous

Central Government's residual powers — calling for information, exemptions, rule-making, and consequential amendments to other laws including the Right to Information Act.

Section 33-37 Protection of action, information powers, and general exemptions
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • The information-calling power lets the government request data directly from the Board or from Fiduciaries in specified circumstances, separate from the Board's own inquiry powers.
Section 38-42 Rule-making power, laying before Parliament, and removal of difficulties
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • This is the enabling provision behind the DPDP Rules, 2025 — the Act deliberately leaves operational detail (breach intimation timelines, consent manager standards, significant-data-fiduciary criteria) to be filled in by delegated rule-making rather than fixed in the Act's own text.
Section 44 Amendment to other enactments
Structural summaryPermalink
Statutory summary
Plain-language explanation
  • The RTI Act amendment removed the earlier 'public interest' balancing test for withholding personal information under RTI, which drew significant public debate over its effect on transparency requests involving personal data of public officials.

The Schedule — Financial Penalties

Penalty ceilings the Data Protection Board may impose per instance of significant non-compliance, as set out in the Schedule to the Act.

Non-complianceProvisionMaximum Penalty
Failure to take reasonable security safeguards to prevent a personal data breachSection 8(5)Up to ₹250 crore
Failure to notify the Board and affected Data Principals of a breachSection 8(6)Up to ₹200 crore
Non-compliance with additional obligations regarding children's dataSection 9Up to ₹200 crore
Non-compliance with additional obligations of a Significant Data FiduciarySection 10Up to ₹150 crore
Breach of duties by a Data Principal (e.g. false information, frivolous complaints)Section 15Up to ₹10,000
Non-compliance with any other provision of the Act or RulesGeneralUp to ₹50 crore