· 9 min read
By Correct Editorial — Compliance Research Desk
DPDP Act 2023: An Overview for Businesses
Published on: July 29, 2026
The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) is India's first horizontal privacy statute, and after the notification of the Digital Personal Data Protection Rules, 2025 on 13 November 2025 (G.S.R. 846(E), gazetted 14 November 2025), it has stopped being a policy discussion and become a project plan. Most operative obligations switch on for businesses on 13 May 2027, which is roughly ten months from today.
This primer is deliberately narrow: it explains what the law is, who it binds, what it demands, and when. If you already know the framework and want a phased implementation programme with owners and milestones, read our companion piece, DPDP Act Compliance: A Practical Roadmap for Indian Businesses. Deeper dives on the four topics most teams get wrong are linked throughout.
What Does the DPDP Act Actually Regulate?
The Act regulates the processing of digital personal data — any data about an identifiable individual, in digital form, whether collected digitally or digitised after collection. It does not regulate paper records that stay on paper, non-personal or fully anonymised datasets, or personal data that the individual has herself made publicly available.
Three definitions carry the entire statute:
- Data Principal (Section 2(j)) — the individual the data is about. For a child, this includes the parent or lawful guardian; for a person with disability, her lawful guardian.
- Data Fiduciary (Section 2(i)) — any person who, alone or with others, determines the purpose and means of processing. This is the accountable party.
- Data Processor (Section 2(k)) — any person who processes personal data on behalf of a Data Fiduciary.
The word "fiduciary" is not decorative. Parliament chose it over "controller" to signal a duty of care owed to the individual, not merely a compliance relationship with a regulator. Getting your own classification right is the first architectural decision, and we unpack it in Data Fiduciary vs Data Processor: Key Differences.
Who Is Covered, and Does It Reach Foreign Companies?
The Act applies to processing of digital personal data within India, and extraterritorially to processing outside India where it is in connection with offering goods or services to Data Principals in India. There is no revenue threshold, no employee-count carve-out, and no sectoral exemption for regulated entities.
In practice this captures:
- Indian companies, LLPs, partnerships, and sole proprietors processing customer, employee, or vendor data digitally
- Foreign SaaS, cloud, analytics, and AI vendors with Indian users, even without an Indian entity
- Government instrumentalities, subject to the specific exemptions in Section 17(2)
- Non-profits, educational institutions, hospitals, and clinics
The Act does not apply to personal data processed by an individual for purely personal or domestic purposes, nor to personal data about a Data Principal that she has made or caused to be made publicly available — for example, a professional who publishes her own contact details, or disclosures a listed company officer is legally required to make.
When Do the Obligations Bite?
The government split commencement across three dates using two instruments: G.S.R. 843(E) for the Act's sections and the commencement clause in the Rules. Read the table as your compliance calendar.
| Effective date | What switches on | Practical meaning |
|---|---|---|
| 13 November 2025 | Definitions (Section 2), Data Protection Board provisions (Sections 18–26), rule-making powers, and Rules 1, 2 and 17–21 | The Board and its appointment machinery exist; no business-facing penalties yet |
| 13 November 2026 | Section 6(9) and Section 27(1)(d) of the Act, plus Rule 4 and the First Schedule | The Consent Manager registration regime opens |
| 13 May 2027 | Sections 3 to 5, most of Section 6, Sections 7 to 17, Sections 28 to 34, and Rules 3, 5 to 16, 22 and 23 | Notice, consent, security, breach reporting, rights, cross-border rules and penalties all become enforceable |
The eighteen-month runway is not a grace period after enforcement begins — it is the period before enforcement begins. On 13 May 2027 the Board can inquire into conduct and impose penalties from day one. Organisations that begin building in mid-2026 have roughly three quarters to design, implement, and test. Those that start in 2027 will be retrofitting under pressure.
What Must a Data Fiduciary Do?
Six obligations account for most of the operational work.
1. Give notice before or at the time of seeking consent. Rule 3 requires the notice to be a standalone, plain-language document containing an itemised description of the personal data collected, the specified purpose with a specific description of the goods, services, or uses enabled, and the communication link plus other means by which the individual can withdraw consent, exercise rights, and complain to the Board.
2. Process on a lawful basis. Either free, specific, informed, unconditional and unambiguous consent with a clear affirmative action (Section 6), or one of the legitimate uses in Section 7 — voluntary provision of data for a stated purpose, State provision of subsidies and benefits, compliance with law, court orders, medical emergencies, epidemics, disasters, and specified employment purposes.
3. Limit and erase. Collect only what is necessary for the stated purpose, and erase when consent is withdrawn or the purpose is served, whichever is earlier, unless a law requires retention (Section 8(7)). The Third Schedule to the Rules adds a hard rule for large platforms: e-commerce entities and social media intermediaries with not less than two crore registered users in India, and online gaming intermediaries with not less than fifty lakh registered users, must erase personal data three years after the individual last engaged, with a 48-hour advance intimation before erasure.
4. Secure the data. Rule 6 makes "reasonable security safeguards" concrete: encryption, obfuscation, masking or tokenisation; access controls on computer resources; logging and monitoring for detection and investigation; backups for continuity; retention of logs for one year; contractual security obligations on processors; and appropriate technical and organisational measures overall.
5. Report breaches. Intimate every affected individual without delay and file a detailed report with the Board within 72 hours. The mechanics are demanding enough to warrant their own article — see Data Breach Compliance Under the DPDP Act.
6. Answer people. Publish the contact details of a person who can answer processing questions (Rule 9), publish how rights requests are made, and operate a grievance system that responds within 90 days (Rule 14(3)).
What Rights Do Individuals Get?
Data Principals have five enforceable rights, all exercisable against the Data Fiduciary to whom they gave consent:
- Access — a summary of personal data processed, the processing activities, and the identities of other fiduciaries with whom it was shared (Section 11)
- Correction, completion, updating and erasure (Section 12)
- Grievance redressal through the fiduciary's own mechanism, which must be exhausted before approaching the Board (Section 13)
- Nomination of another individual to exercise rights in the event of death or incapacity (Section 14)
- Withdrawal of consent with ease comparable to giving it (Section 6(4) to 6(6))
Section 15 also imposes duties on individuals — not to impersonate, suppress material information, file frivolous complaints, or furnish false particulars — with a penalty up to ₹10,000. It is a distinctly Indian feature with no GDPR analogue.
Who Is a Significant Data Fiduciary?
The Central Government may notify any fiduciary or class of fiduciaries as a Significant Data Fiduciary (SDF) based on the volume and sensitivity of data processed, risk to Data Principals, risk to electoral democracy, sovereignty, security of the State, and public order (Section 10). No entity list has been notified yet, so this remains a forward-looking classification for large platforms, credit bureaus, health networks, and major consumer apps.
An SDF must appoint an India-based Data Protection Officer who reports to the board or governing body and serves as the grievance contact, appoint an independent data auditor, and under Rule 13 conduct a Data Protection Impact Assessment and audit every twelve months, furnish significant observations to the Board, exercise algorithmic due diligence so that its technical measures do not risk Data Principal rights, and observe any localisation restriction the Central Government specifies for particular categories of personal data.
What Are the Penalties, and Who Enforces Them?
The Data Protection Board of India is the adjudicating authority. It functions as a digital office under Rule 20 — complaints, hearings, and orders are online by design. It can inquire on complaint or reference, direct urgent remedial measures, accept a voluntary undertaking under Section 32 (which bars further proceedings on the same matter unless the undertaking is breached), and impose penalties under Section 33 after a hearing. Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal within 60 days (Section 29).
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards (Section 8(5)) | ₹250 crore |
| Failure to notify a breach to the Board or affected individuals (Section 8(6)) | ₹200 crore |
| Breach of children's data obligations (Section 9) | ₹200 crore |
| Breach of Significant Data Fiduciary obligations (Section 10) | ₹150 crore |
| Breach of Data Principal duties (Section 15) | ₹10,000 |
| Any other breach of the Act or Rules | ₹50 crore |
Penalties are discretionary, not automatic. Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach, the type of data affected, repetition, gain realised or loss avoided, mitigation efforts and their timeliness, proportionality, and the likely impact on the entity. Documented, timely mitigation is therefore a direct financial lever, not just good hygiene.
Where Do the Exemptions Sit?
Section 17 carves out processing necessary for enforcing legal rights or claims, judicial and regulatory functions, prevention and investigation of offences, processing of non-Indian Data Principals' data under a contract with a foreign person, court-approved mergers and demergers, and ascertaining the financial position of loan defaulters. Section 17(2) exempts notified State instrumentalities on sovereignty and security grounds and, subject to standards in the Second Schedule, research, archiving and statistical processing. Section 17(3) allows the government to relieve notified fiduciaries — expressly including recognised startups — from Section 5, Sections 8(3) and 8(7), and Sections 10 and 11.
Note what is not exempt in Section 17(1): the general accountability duty in Section 8(1) and the security obligation in Section 8(5) survive.
What Should a Business Do in 2026?
- Build a data inventory. You cannot write an itemised notice without knowing every field you collect, why, where it lives, and who it goes to.
- Classify every relationship as fiduciary, processor, or joint — then paper it correctly.
- Redesign consent and notice to Rule 3 standards, including withdrawal parity. Decide whether you will integrate with a registered Consent Manager once that regime opens in November 2026.
- Close the Rule 6 gaps — encryption, access control, one-year logging, and processor contract clauses are the cheapest insurance against the ₹250 crore head.
- Write and rehearse the 72-hour breach playbook before you need it.
- Map your cross-border stack. Every foreign sub-processor should appear in a transfer register — see Cross-border Data Transfer Rules Explained.
- Assign accountability. One named executive, quarterly board reporting, evidence retained.
More explainers on Indian regulatory change are available at Correct Learn, including our guide to AI compliance under the DPDP Act for teams shipping models on personal data.
References
- Gazette of India — The Digital Personal Data Protection Act, 2023 — Gazetted text of Act 22 of 2023, including Section 33 and the Schedule of penalties.
- Ministry of Electronics and Information Technology — Nodal ministry for the DPDP framework, notifications, and consultation records.
- MeitY — Explanatory Note to the DPDP Rules, 2025 — Official rule-by-rule explanation issued with the notified Rules.
- Digital Personal Data Protection Rules, 2025 — notified text — Full text of G.S.R. 846(E) as published, including all seven Schedules.
- India Code — National repository of statutes — Consolidated bare Act with commencement notifications.
- Press Information Bureau — Government releases on the notification of the DPDP Rules and the Data Protection Board.
- Gazette of India portal — Search interface for G.S.R. 843(E) and G.S.R. 846(E) dated 13 November 2025.
Frequently asked questions
- What is the DPDP Act, 2023, in simple terms?
- It is India’s first comprehensive digital privacy statute (Act 22 of 2023). It requires any organisation that decides why and how digital personal data is processed to have a lawful basis, give a clear notice, secure the data, honour individual rights, and report breaches to the Data Protection Board of India.
- When does the DPDP Act become fully enforceable?
- The DPDP Rules, 2025 were notified on 13 November 2025 and gazetted on 14 November 2025. Most substantive obligations, including notice, consent, security safeguards, breach reporting, and data principal rights, commence on 13 May 2027 — an 18-month runway from notification.
- Does the DPDP Act apply to small businesses and startups?
- Yes. There is no turnover or headcount threshold. Section 17(3) allows the Central Government to notify certain data fiduciaries, including recognised startups, as exempt from a limited set of provisions, but the core duties of lawful processing, security, and breach intimation still apply.
- What is the maximum penalty under the DPDP Act?
- The Schedule to the Act, read with Section 33, allows penalties up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach or for children’s data violations, ₹150 crore for significant data fiduciary lapses, and ₹50 crore residually.