The DPDP Act, 2023
The full statutory text, read chapter by chapter, with a plain-language explanation running alongside — never merged, always clearly labelled.
Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.
Preliminary
Establishes the short title, commencement, and the scope of who and what the Act covers.
This Act may be called the Digital Personal Data Protection Act, 2023.
It shall come into force on such date as the Central Government may, by notification, appoint, and different dates may be appointed for different provisions of this Act.
- The Act was passed and notified in the Gazette in August 2023, but it does not switch on all at once.
- The Central Government brings individual sections into force through separate notifications — which is why some provisions (like the Data Protection Board) activated on a different timeline than the core obligations.
'Data Principal' means the individual to whom the personal data relates and where such individual is a child, includes the parents or lawful guardian of such child; and where such individual is a person with disability, includes her lawful guardian, acting on her behalf.
'Data Fiduciary' means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
'Data Processor' means any person who processes personal data on behalf of a Data Fiduciary.
'Personal data' means any data about an individual who is identifiable by or in relation to such data.
'Processing' in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.
'Consent Manager' means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
'Significant Data Fiduciary' means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.
'Board' means the Data Protection Board of India established under section 18.
- These definitions decide who owes duties to whom. 'Data Fiduciary' is the party that decides why and how personal data is processed — in most other frameworks this role is closer to a 'controller'.
- 'Data Processor' is a vendor acting on the Fiduciary's instructions — comparable to a 'processor' elsewhere, but under DPDP the Processor itself owes no direct statutory duty to the Data Principal; liability flows through the Fiduciary via contract.
- 'Personal data' is deliberately broad — any data that can identify an individual, regardless of sensitivity category. DPDP does not create separate tiers for 'sensitive' personal data the way some other laws do.
- A 'Consent Manager' is a DPDP-specific role: a registered intermediary that lets an individual manage consent across multiple Fiduciaries from one dashboard.
Subject to the provisions of this Act, it applies to the processing of digital personal data within the territory of India where the personal data is collected in digital form, or in non-digital form and subsequently digitised.
It also applies to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India.
Nothing in this Act shall apply to personal data that is processed by an individual for any personal or domestic purpose, and personal data that is made or caused to be made publicly available by the Data Principal or any other person who is under an obligation to make such personal data publicly available.
- This is the extraterritorial hook: a foreign company with no Indian office can still fall under DPDP if it profiles, sells to, or otherwise offers goods/services to people located in India.
- Purely offline, non-digitised personal data (e.g. a paper register never scanned) sits outside scope — but the moment it's digitised, it's in.
- Data an individual chooses to make public themselves (e.g. a public social media profile) is carved out, as is purely personal/household use.
Obligations of Data Fiduciary
The operational core of the Act — lawful grounds for processing, notice, consent, children's data, and the day-to-day duties every Data Fiduciary must discharge.
A person may process personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose for which the Data Principal has given her consent, or for certain legitimate uses.
For the purposes of this sub-section, 'lawful purpose' means any purpose which is not expressly forbidden by law.
- DPDP recognises exactly two lawful bases for processing: (1) freely given consent, or (2) one of the specific 'legitimate uses' listed in Section 7 — there is no open-ended 'legitimate interest' ground like in some other privacy laws.
- If your processing doesn't fit consent or a Section 7 legitimate use, it isn't lawful under this Act.
Where personal data of a Data Principal is to be processed on the basis of consent, the Data Fiduciary shall, before or at the time of seeking consent, give the Data Principal an itemised notice in clear and plain language containing a description of the personal data sought to be collected and the purpose of processing, the manner in which she may exercise her rights, and the manner in which she may make a complaint to the Board.
- Notice must be itemised — a vague, single blanket statement covering 'all purposes' does not meet this bar.
- It has to be understandable in plain language, provided upfront (not buried after data is already collected), and must tell the individual how to exercise rights and where to complain.
The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.
Any part of consent which constitutes an infringement of the provisions of this Act, the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement.
The Data Principal may withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given, and the consequences of such withdrawal shall be borne by the Data Principal.
Every Data Fiduciary shall, upon receipt of a communication for withdrawal of consent, cause the Data Processor to also cease processing the personal data.
- 'Comparable ease of withdrawal' is the operative test — a two-tap consent flow behind a five-step withdrawal process would not meet this standard.
- Consent is purpose-limited and data-minimised by design: you can't collect broadly and later expand use because 'the box was ticked'.
- Withdrawal has to propagate to every Data Processor you've shared that data with, not just stop at your own front door.
A Data Fiduciary may process personal data of a Data Principal for the specified legitimate uses, including where the Data Principal has voluntarily provided her personal data and has not indicated that she does not consent to its use; for the performance of any function under law, or in compliance with any judgment or order; for compliance with any judgment, decree or order; for responding to a medical emergency involving a threat to life; for taking measures to provide medical treatment during an epidemic or disease outbreak; for taking measures to ensure safety or provide assistance during any disaster or breakdown of public order; and for employment purposes, or those related to safeguarding the employer from loss, subject to reasonableness.
- This is the closest DPDP gets to a general-purpose lawful basis outside consent, but it's a closed, enumerated list — not an open standard.
- The 'voluntarily provided and did not object' ground is often used for things like a visitor signing a physical register or replying to an inbound query.
- The employment ground is narrower than many assume: it must relate to hiring, terminating, or safeguarding the employer from loss/liability, subject to a reasonableness test.
A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.
A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.
Where personal data processed by a Data Fiduciary is likely to be used to make a decision that affects the Data Principal, or disclosed to another Data Fiduciary, the Data Fiduciary shall ensure its completeness, accuracy and consistency.
A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.
A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.
A Data Fiduciary shall, unless retention is necessary for compliance with any law, erase personal data upon the Data Principal withdrawing consent or as soon as it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and shall cause its Data Processor to erase any personal data made available to it for processing.
A Data Fiduciary shall publish the business contact information of a Data Protection Officer, if applicable, or a person able to answer questions raised by the Data Principal about processing of her personal data.
A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.
- This is the section carrying the most operational weight. Liability sits with the Fiduciary — you cannot contract it away, and a Data Principal's own failure to comply with their duties doesn't excuse you.
- A valid, binding contract is mandatory before you can use any Data Processor for goods/services related processing.
- 'Reasonable security safeguards' is undefined in the Act itself — the Rules and prevailing industry practice fill that in.
- Breach intimation has two audiences: the Board and every affected individual — not a materiality-gated subset.
- Erasure obligations run on a 'purpose no longer served OR consent withdrawn, whichever is earlier' test, and must cascade to processors.
The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian, obtain verifiable consent of the parent of such child or the lawful guardian.
A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child.
A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
The Central Government may, by notification, exempt certain classes of Data Fiduciaries or processing for such purposes from the applicability of these provisions, having regard to factors such as verifiably safe processing and the volume of personal data processed.
- 'Child' under the Act means anyone below 18 years — there is no lower age-of-consent carve-out for teenagers as seen in some other regimes.
- Verifiable parental consent is required before collecting a child's data at all, not just for certain sensitive uses.
- Behavioural tracking and targeted ads aimed at children are barred outright, subject to narrow, government-notified exemptions (e.g. for platforms that can demonstrate verifiably safe processing, such as certain edtech or healthcare services).
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, having regard to relevant factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
A Significant Data Fiduciary shall appoint a Data Protection Officer based in India, who shall be responsible to the Board of Directors or similar governing body and shall be the point of contact for grievance redressal.
A Significant Data Fiduciary shall appoint an independent data auditor to carry out data audits, and undertake periodic Data Protection Impact Assessments and other prescribed measures.
- SDF status is a designation applied by notification, not self-assessed — but the listed factors (scale, sensitivity, risk to democracy/security) give a strong signal of who is likely to be named.
- An SDF's DPO must sit in India and report to the top of the organisation, not to a regional compliance function abroad.
- Independent audits and DPIAs move an SDF from 'policy on paper' to demonstrable, periodically tested compliance.
Rights and Duties of Data Principal
The rights individuals can actively exercise over their own data, alongside the duties the Act places on them in return.
A Data Principal shall have the right to obtain from a Data Fiduciary a summary of personal data being processed, the processing activities undertaken, the identities of all Data Fiduciaries and Data Processors with whom personal data has been shared, along with a description of the data shared, and any other information related to her personal data as may be prescribed.
- This is broader than a plain 'what do you have on me' request — it extends to who you've shared it with and what categories were shared, not just your own copy of it.
A Data Principal shall have the right to correction, completion, updating and erasure of her personal data, and the Data Fiduciary shall, upon receipt of such a request, correct inaccurate or misleading data, complete incomplete data, update relevant data, and erase data that is no longer necessary for the purpose for which it was processed, unless retention is necessary for a specified purpose or compliance with law.
- Correction and erasure travel together with completion and updating — the right isn't limited to fixing errors, it also covers finishing incomplete records.
A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission regarding the performance of its obligations, and the Data Fiduciary or Consent Manager shall respond to such grievances within such period as may be prescribed.
A Data Principal shall exhaust the opportunity of grievance redressal provided under this section before approaching the Board.
- You cannot escalate straight to the Data Protection Board — the individual must first give the Fiduciary a chance to resolve the complaint directly.
A Data Principal shall have the right to nominate any other individual to exercise her rights under this Act in the event of her death or incapacity.
- This is a novel feature relative to most global privacy laws — DPDP explicitly lets you designate a nominee to step into your data rights, similar to a nominee on a bank account.
Every Data Principal shall comply with the provisions of all applicable laws while exercising rights under this Act, and ensure not to impersonate another person while providing personal data, suppress material information, register a false or frivolous grievance or complaint, and furnish only such information as is verifiably authentic while exercising the right to correction or erasure.
- Rights come with reciprocal duties: providing false identity information, filing frivolous complaints, or submitting fabricated correction requests are themselves statutory breaches, enforceable with the modest ₹10,000 penalty under the Schedule.
Special Provisions
Cross-border data transfer and the carve-outs where the Act's obligations are relaxed or disapplied.
The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.
Nothing in this section shall restrict the application of any other law for the time being in force relating to the transfer of personal data outside the territory of India, and where such other law provides for a higher degree of protection or restriction on such transfer, the same shall continue to apply.
- DPDP takes a 'blacklist' approach to cross-border transfer, rather than the 'adequacy allowlist' model used elsewhere — transfers are permitted by default unless a specific destination is restricted by notification.
- Sector-specific data-localisation rules (e.g. for payments data under RBI norms) sit on top of, and are not weakened by, this section.
The provisions of sections 5, 6, 8 and 9, and section 10 shall not apply where processing of personal data is necessary for enforcing any legal right or claim, or is required by any court or tribunal in India for the performance of any judicial or quasi-judicial function.
The Central Government may, by notification, exempt Data Fiduciaries, including start-ups, from the application of the provisions of Chapter II and Chapter III, having regard to the volume and nature of personal data processed.
The Central Government may exempt any instrumentality of the State from the application of any provision of this Act, in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order, or preventing incitement to any cognisable offence.
Processing of personal data necessary for research, archiving or statistical purposes, if such processing is not used to take any decision specific to a Data Principal, and is carried on in accordance with such standards as may be prescribed, shall be exempt from the application of this Act.
- The 'start-up' exemption is a notification-based carve-out, not automatic — a company merely calling itself a startup does not opt out of Chapter II/III without a specific government notification naming it or its class.
- The government-instrumentality exemption is broad and has drawn the most public debate, since it can exempt state agencies from the Act for reasons like public order or security.
- Research/archiving/statistical exemptions only apply if the output is never used to make a decision about a specific individual.
Data Protection Board of India
Establishes the Board as the Act's dedicated regulator — its composition, independence, and administrative machinery.
The Central Government shall, by notification, establish the Data Protection Board of India for the purposes of this Act, as a body corporate, to exercise the powers conferred, and perform the functions assigned to it under this Act.
- The Board is a dedicated digital-first regulator (designed to function largely online) rather than an extension of an existing authority — comparable in role to a data protection authority elsewhere, but with a narrower remit focused on adjudication rather than broad rule-making.
Provides for the appointment, number, qualifications, and terms of service of the Chairperson and Members of the Board, as prescribed by the Central Government.
- Members are appointed by the Central Government rather than through an independent judicial-style selection panel, which has been a point of commentary on the Board's institutional independence.
This block of sections covers salary and allowances, term limits, grounds for removal, the Board's power to regulate its own procedure, its officers and staff, and financial administration including accounts and audit.
- Day-to-day relevance for organisations is limited here — this is institutional plumbing for how the regulator itself is staffed, funded, and governed.
Powers, Functions and Procedure of the Board
What the Board can actually do — investigate, direct remedial action, and how appeals against its orders work.
On receipt of an intimation of a personal data breach, or a complaint, or a reference from the Central Government, the Board may inquire into the matter and, if satisfied a breach has occurred, direct remedial or mitigating measures, impose penalties, and direct any urgent measures necessary to remedy a personal data breach or prevent further harm.
- The Board acts on three triggers: a Fiduciary's own breach intimation, an individual's complaint, or a government reference — it does not proactively audit organisations at will the way some regulators do.
The Board shall function as a digital office, may conduct proceedings electronically, and shall follow such procedure as may be prescribed while conducting inquiries, giving the affected parties an opportunity of being heard before any order is passed.
- Proceedings are designed to run largely paperless and online, and natural-justice safeguards (a hearing before an adverse order) are built in.
Any person aggrieved by an order or direction of the Board may prefer an appeal to the Appellate Tribunal designated under this Act, within such period and in such manner as may be prescribed.
- The designated Appellate Tribunal for DPDP appeals is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), reusing existing tribunal infrastructure rather than creating a new one.
Penalties and Adjudication
Financial consequences for non-compliance, capped by the Schedule to the Act, plus the voluntary-undertaking route.
The Board may accept a voluntary undertaking from any person in respect of any matter related to compliance with this Act, in lieu of, or during the pendency of, an inquiry, which may include a commitment to take specified action within a specified time or to refrain from taking specified action.
- This gives organisations a settlement-style path — offering fixes and safeguards to the Board can stop or shorten a formal inquiry.
If the Board determines, on conclusion of an inquiry, that non-compliance by a person is significant, it may impose such financial penalty as specified in the Schedule to this Act, after giving the person a reasonable opportunity of being heard.
- Penalties are capped by category in the Schedule rather than set as an uncapped percentage of turnover — see the Schedule summary below.
All sums realised by way of penalties under this Act shall be credited to the Consolidated Fund of India.
- Unlike some regimes where a share of penalties can fund the regulator, DPDP penalties flow straight to general government revenue.
Miscellaneous
Central Government's residual powers — calling for information, exemptions, rule-making, and consequential amendments to other laws including the Right to Information Act.
This block protects action taken in good faith under the Act, empowers the Central Government to call for information from the Board or Data Fiduciaries for the purposes of the Act, provides for the Board's power to review its own orders, and preserves the applicability of other laws that are not inconsistent with this Act.
- The information-calling power lets the government request data directly from the Board or from Fiduciaries in specified circumstances, separate from the Board's own inquiry powers.
The Central Government may, by notification, make rules to carry out the provisions of this Act, and every rule and notification made under this Act shall be laid before each House of Parliament.
- This is the enabling provision behind the DPDP Rules, 2025 — the Act deliberately leaves operational detail (breach intimation timelines, consent manager standards, significant-data-fiduciary criteria) to be filled in by delegated rule-making rather than fixed in the Act's own text.
This Act amends certain provisions of other enactments consequential to its enactment, including an amendment to Section 8(1)(j) of the Right to Information Act, 2005 concerning the disclosure of personal information.
- The RTI Act amendment removed the earlier 'public interest' balancing test for withholding personal information under RTI, which drew significant public debate over its effect on transparency requests involving personal data of public officials.
The Schedule — Financial Penalties
Penalty ceilings the Data Protection Board may impose per instance of significant non-compliance, as set out in the Schedule to the Act.
| Non-compliance | Provision | Maximum Penalty |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | Section 8(5) | Up to ₹250 crore |
| Failure to notify the Board and affected Data Principals of a breach | Section 8(6) | Up to ₹200 crore |
| Non-compliance with additional obligations regarding children's data | Section 9 | Up to ₹200 crore |
| Non-compliance with additional obligations of a Significant Data Fiduciary | Section 10 | Up to ₹150 crore |
| Breach of duties by a Data Principal (e.g. false information, frivolous complaints) | Section 15 | Up to ₹10,000 |
| Non-compliance with any other provision of the Act or Rules | General | Up to ₹50 crore |