Digital Personal Data Protection Act 2023 – Complete Guide to DPDP Act, Rules, Compliance & Penalties

Banner for Digital Personal Data Protection Act 2023 featuring a map of India with a security shield, a law book titled DPDP ACT 2023, a gavel, and icons for empowered individuals and secure digital ecosystems.

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's principal legislation governing the processing of digital personal data. The Act establishes a legal framework for processing digital personal data while recognizing the right of individuals to protect their personal data and the need to process such data for lawful purposes.

The Act received Presidential assent on 11 August 2023 and establishes important concepts such as the Data Principal, Data Fiduciary, Data Processor, Consent Manager and Significant Data Fiduciary. It also provides rights to individuals, obligations for organizations processing personal data, a framework for personal data breach management, the Data Protection Board of India, and monetary penalties for specified breaches.

The regulatory framework has subsequently been supplemented by the Digital Personal Data Protection Rules, 2025. The Rules were notified in November 2025, while a separate commencement notification provides for phased commencement of different provisions of the Act.

For organizations operating in India, DPDP compliance therefore involves understanding not only the original 2023 Act but also the applicable Rules, commencement dates and subsequent regulatory requirements.

What Is the Digital Personal Data Protection Act 2023?

The Digital Personal Data Protection Act, 2023 is an Indian law that regulates the processing of digital personal data.

The Act seeks to balance two important objectives:

  • Protecting the personal data of individuals; and
  • Allowing personal data to be processed for lawful purposes.

The legislation establishes obligations for organizations that determine the purpose and means of processing personal data and provides corresponding rights and duties for individuals whose personal data is processed.

In simple terms, the DPDP Act creates a framework governing how organisations collect, use, store, share and otherwise process digital personal data.

The Act is particularly relevant to businesses that collect information through:

  • websites;
  • mobile applications;
  • online forms;
  • e-commerce platforms;
  • customer accounts;
  • CRM systems;
  • employee portals;
  • recruitment platforms;
  • online services;
  • digital marketing systems; and
  • other digital channels.

Current Status of the DPDP Act in India

The Digital Personal Data Protection Act was enacted in 2023, but its provisions are not all brought into force simultaneously.

The Central Government issued a commencement notification on 13 November 2025 providing for phased commencement.

Under that notification:

  • specified provisions came into force on publication;
  • certain provisions are scheduled to commence one year after publication; and
  • a larger group of substantive provisions is scheduled to commence eighteen months after publication.

The Digital Personal Data Protection Rules, 2025 were notified separately on 14 November 2025. The Rules also contain phased commencement provisions. Rules 1, 2 and 17 to 21 came into force upon publication, Rule 4 is scheduled to commence one year after publication, and Rules 3, 5 to 16, 22 and 23 are scheduled to commence eighteen months after publication.

Therefore, organisations should distinguish between:

  • The DPDP Act, 2023 → primary legislation
  • The DPDP Rules, 2025 → detailed implementation framework
  • Commencement notifications → determine when particular provisions become operational

This distinction is important when assessing the current compliance position.

Who Does the DPDP Act Apply To?

Section 3 of the DPDP Act sets out its application.

The Act applies to the processing of digital personal data within India where the personal data is:

  • Collected from a Data Principal in digital form; or
  • Collected in non-digital form and subsequently digitised.

The Act can also apply to processing outside India where such processing is connected with offering goods or services to Data Principals within India.

This means that the geographical location of a company's headquarters alone does not determine whether the DPDP framework may be relevant.

A foreign organisation offering goods or services to individuals in India may need to examine whether its processing activities fall within the Act.

Important Definitions Under the DPDP Act 2023

Understanding the terminology used in the Act is essential for DPDP compliance.

Data Principal

A Data Principal is the individual to whom the personal data relates.

In relation to a child, the definition also includes the parent or lawful guardian. In relation to a person with disability who has a lawful guardian, the definition includes the lawful guardian acting on behalf of that individual.

Data Fiduciary

A Data Fiduciary means a person who, alone or together with other persons, determines the purpose and means of processing personal data.

In practical terms, an organisation deciding why personal data is collected and how it is processed may fall within the role of a Data Fiduciary.

Data Processor

A Data Processor is a person who processes personal data on behalf of a Data Fiduciary.

Examples can include certain third-party service providers handling personal data on behalf of another organisation.

Consent Manager

A Consent Manager is an entity intended to provide a platform through which a Data Principal can give, manage, review and withdraw consent through an accessible, transparent and interoperable system.

The DPDP Rules, 2025 further provide requirements relating to registration and functioning of Consent Managers.

Significant Data Fiduciary

The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary after considering specified factors.

These include matters such as:

  • volume and sensitivity of personal data;
  • risk to the rights of Data Principals;
  • potential impact on sovereignty and integrity of India;
  • risk to security of the State;
  • potential impact on electoral democracy;
  • security of the State; and
  • public order.

What Is Personal Data Under the DPDP Act?

The Act defines personal data broadly as any data about an individual who is identifiable by or in relation to such data.

The legislation specifically focuses on digital personal data.

This can include information that enables an individual to be identified, directly or in combination with other information.

Depending on the circumstances, organisations may process personal data such as:

  • names;
  • contact details;
  • account information;
  • identification-related information;
  • employee information;
  • customer information;
  • online identifiers; and
  • other information associated with an identifiable individual.

The precise treatment depends on the Act, Rules and the circumstances of the processing.

Notice Requirements Under the DPDP Act

A Data Fiduciary is required to provide notice to the Data Principal in connection with a request for consent.

The notice must provide specified information relating to the processing.

The Act requires information including:

  • the personal data proposed to be processed;
  • the purpose for which the personal data is proposed to be processed;
  • the manner in which rights can be exercised; and
  • the manner in which a complaint can be made to the Board.

The DPDP Rules, 2025 provide more detailed requirements for notices.

The Rules state that the notice must be presented and understandable independently of other information and must use clear and plain language. It must include an itemised description of personal data and the specified purpose or purposes of processing.

This makes the privacy notice an important part of a business's DPDP compliance framework.

Obligations of a Data Fiduciary

Data Fiduciaries have significant responsibilities under the DPDP Act.

Responsibility for Processing

A Data Fiduciary remains responsible for compliance with the Act and Rules in relation to processing carried out by it or on its behalf by a Data Processor.

Appointment of Data Processors

A Data Fiduciary may engage a Data Processor for carrying out processing activities on its behalf subject to the applicable requirements, including contractual arrangements.

Accuracy of Personal Data

Where personal data is likely to be used to make a decision affecting the Data Principal or is likely to be disclosed to another Data Fiduciary, appropriate steps must be taken to ensure completeness, accuracy and consistency.

Technical and Organisational Measures

The Data Fiduciary is required to implement appropriate technical and organisational measures to ensure effective observance of the Act and Rules.

Security Safeguards

A Data Fiduciary must protect personal data in its possession or control by taking reasonable security safeguards to prevent personal data breaches.

Personal Data Breach Notification

In the event of a personal data breach, the Data Fiduciary must notify the Board and affected Data Principals in the prescribed manner.

Erasure of Personal Data

Unless retention is required by law, personal data must be erased when the Data Principal withdraws consent or when it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, subject to the statutory framework.

Grievance Redressal

A Data Fiduciary must establish an effective mechanism for redressing grievances of Data Principals.

Cross-Border Transfer of Personal Data

The DPDP Act provides a framework under which the Central Government may restrict the transfer of personal data by a Data Fiduciary for processing to specified countries or territories outside India through notification.

The Act also recognises that other Indian laws may impose a higher degree of protection or additional restrictions relating to the transfer of personal data outside India.

Businesses operating internationally should therefore evaluate cross-border data flows as part of their DPDP compliance assessment.

Digital Personal Data Protection Rules 2025

The Digital Personal Data Protection Rules, 2025 provide detailed rules for implementing the Digital Personal Data Protection Act, 2023.

The final Rules were notified by the Ministry of Electronics and Information Technology in November 2025.

The Rules address areas including:

  • notices to Data Principals;
  • Consent Managers;
  • security safeguards;
  • personal data breach notifications;
  • processing children's personal data;
  • rights of Data Principals;
  • obligations of Data Fiduciaries;
  • Significant Data Fiduciaries;
  • the Data Protection Board; and
  • other operational aspects of the Act.

The Rules require notices to be understandable independently of other information and to use clear and plain language. They also specify that notices should include an itemised description of personal data and the specific purpose or purposes of processing.

DPDP Act and DPDP Rules Implementation Timeline

The DPDP framework uses a phased implementation structure.

13 November 2025 – Initial Commencement

The commencement notification brought specified provisions of the Act into force on publication.

One Year After Publication

Certain provisions identified in the commencement notification are scheduled to come into force one year after publication.

Eighteen Months After Publication

A larger set of substantive provisions, including Sections 3 to 5, most of Section 6, Sections 7 to 10, Sections 11 to 17 and various enforcement provisions, is scheduled to come into force eighteen months after publication of the commencement notification.

The Rules have a corresponding phased structure, with Rules 1, 2 and 17 to 21 commencing on publication, Rule 4 after one year and Rules 3, 5 to 16, 22 and 23 after eighteen months.

Why the Implementation Timeline Matters

Businesses should not interpret phased commencement as a reason to postpone data-governance preparation.

A practical compliance programme may require time to:

  • identify personal data;
  • map data flows;
  • review notices;
  • review consent mechanisms;
  • update contracts;
  • establish rights-request processes;
  • assess security controls;
  • establish breach procedures;
  • review retention and deletion;
  • assess children's data processing; and
  • evaluate third-party processors.

Difference Between DPDP Act and DPDP Rules

DPDP Act, 2023DPDP Rules, 2025
Primary legislationDetailed implementation rules
Establishes statutory rights and obligationsProvides operational requirements
Defines Data Principal and Data FiduciaryProvides detailed requirements for notices and other processes
Establishes Data Protection Board frameworkProvides procedural details relating to implementation
Specifies penalty frameworkProvides additional operational requirements
Provides overall legal frameworkProvides implementation details

Benefits of a Structured DPDP Compliance Programme

A structured data protection programme can help an organisation establish clearer processes for managing personal data.

It can help businesses:

  • understand what personal data they hold;
  • identify unnecessary data collection;
  • improve data governance;
  • establish clearer responsibilities;
  • manage third-party processors;
  • prepare for personal data breaches;
  • respond to Data Principal requests;
  • document processing activities; and
  • establish repeatable privacy processes.

The specific compliance requirements applicable to a business depend on its processing activities, role, sector, data and the provisions in force.

Conclusion

The Digital Personal Data Protection Act 2023 establishes India's statutory framework for protecting digital personal data while enabling lawful processing.

For organisations, the framework extends beyond simply creating a privacy policy. Businesses need to understand their role as a Data Fiduciary or Data Processor, identify the personal data they process, establish appropriate notices and consent mechanisms, manage third-party processors, implement security safeguards, establish breach-response procedures and create mechanisms for handling applicable Data Principal rights.

The Digital Personal Data Protection Rules, 2025 provide further operational requirements, while the Government's commencement notification establishes a phased implementation structure.

As DPDP implementation progresses, organisations should align their privacy, cybersecurity, legal, HR, marketing, technology and vendor-management processes with the provisions applicable to their activities.

For a business, the most practical starting point is a DPDP compliance assessment and data-mapping exercise that identifies what personal data is collected, why it is processed, where it is stored, who has access to it, which third parties process it and how the data is ultimately retained or deleted.

Frequently Asked Questions About the DPDP Act 2023

1. What is the Digital Personal Data Protection Act 2023?

The Digital Personal Data Protection Act, 2023 is Indian legislation governing the processing of digital personal data and establishing rights for Data Principals and obligations for Data Fiduciaries.

2. When was the DPDP Act 2023 enacted?

The Digital Personal Data Protection Act received Presidential assent on 11 August 2023.

3. What are the DPDP Rules 2025?

The Digital Personal Data Protection Rules, 2025 are rules made under the DPDP Act to provide detailed implementation requirements. They were notified in November 2025.

4. Who is a Data Fiduciary?

A Data Fiduciary is a person who, alone or together with another person, determines the purpose and means of processing personal data.

5. Who is a Data Principal?

A Data Principal is the individual to whom the personal data relates. The Act contains additional provisions for children and persons with lawful guardians.

6. Who is a Data Processor?

A Data Processor processes personal data on behalf of a Data Fiduciary.

7. Can consent be withdrawn under the DPDP Act?

Yes. Where processing is based on consent, a Data Principal can withdraw consent, and the withdrawal mechanism should be as easy as the mechanism through which consent was given.

8. What rights are available to Data Principals?

The Act provides rights including access to information, correction and erasure, grievance redressal and nomination, subject to the applicable statutory conditions.

9. What is the maximum penalty under the DPDP Act?

The Schedule specifies a maximum penalty of ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach.

10. Does the DPDP Act apply to foreign companies?

The Act can apply to processing outside India where the processing is connected with offering goods or services to Data Principals within India.

11. What is the Data Protection Board of India?

The Data Protection Board of India is the statutory body established under the Act to perform specified functions relating to breaches, complaints, directions, penalties and other matters under the DPDP framework.

Many of our users also read

Regulatory Oversight:

This compliance advisory was vetted by our Senior Consultant (Enforcement & Vigilance), a former BIS Director (Enforcement). He specializes in post-certification compliance, helping companies navigate surveillance audits and legal adherence to BIS mandates.

About the Author

Dhruv Aggarwal

Head of Operations at Sun Certifications India

Experience: 10+ years & Handled 1000+ projects

Awarded by many Indian and International organisations

BIS QCO Updates
BIS certification for Work chairs

BIS certification for Work chairs

BIS certification for Chairs and stools

BIS certification for Chairs and stools

BIS Notification for Tables and desks

BIS Notification for Tables and desks

BIS Notification for Storage units

BIS Notification for Storage units

BIS Notification for Bunk beds

BIS Notification for Bunk beds

BIS Notification for Solar DC Cable and Fire Survival Cable

BIS Notification for Solar DC Cable and Fire Survival Cable

BIS Notification for Wrought Aluminium and Aluminium Alloys, Forging Stock and Forgings

BIS Notification for Wrought Aluminium and Aluminium Alloys, Forging Stock and Forgings

BIS Notification for H Acid

BIS Notification for H Acid

BIS Notification for K Acid

BIS Notification for K Acid

BIS Notification for Vinyl Sulphone

BIS Notification for Vinyl Sulphone

BIS Notification for Electric Fence Energizers

BIS Notification for Electric Fence Energizers

BIS Notification for Clothes Washing Machines

BIS Notification for Clothes Washing Machines

BIS Notification for Gypsum Plaster Boards

BIS Notification for Gypsum Plaster Boards

BIS Notification for Aluminium alloy tubes for irrigation purposes -welded tubes

BIS Notification for Aluminium alloy tubes for irrigation purposes -welded tubes

BIS Notification for Aluminium alloy tube for irrigation purposes – extruded tube

BIS Notification for Aluminium alloy tube for irrigation purposes – extruded tube

BIS Notification for EC Grade Aluminium Rod produced by Continuous Casting and Rolling

BIS Notification for EC Grade Aluminium Rod produced by Continuous Casting and Rolling

BIS Notification for Wrought aluminium and aluminium alloy bars, rods and sections

BIS Notification for Wrought aluminium and aluminium alloy bars, rods and sections

BIS Notification for Gypsum Plaster Boards

BIS Notification for Gypsum Plaster Boards

Client Testimonials
Ms.Eliyawati
Ms.Eliyawati

PT Quty Karunia, BIS Licensee in Vietnam

Sun Certifications India provided excellent BIS Certification services. Their unparalleled service and sincerity gained our trust. One of the best BIS consultants in India!

Ms.Belle
Ms.Belle

Thantawan Industries Ltd, BIS Licensee in Thailand

Sun Certifications India supported us throughout the BIS certification process. Their responsive customer service and punctuality are exceptional. Highly recommend for hassle-free BIS certification.

Ms.Jun Min Sim
Ms.Jun Min Sim

Leaderart Industries, BIS Licensee in Malaysia

Sun Certifications India helped us acquire BIS Certification, doubling our engagement in India. Their services are fast, genuine, and up-to-date with latest BIS norms.

Ms. Fatima
Ms. Fatima

Aluminium Bahrain (ALBA), BIS Licensee in Bahrain

Excellent BIS certification support, highly reliable consultants.

Mr. Yousef
Mr. Yousef

Bahrain Aluminium Manufacturing Company, BIS Licensee in Bahrain

Smooth BIS registration process with expert consultants.

Mr. Satoshi
Mr. Satoshi

Daiki Aluminium Japan, BIS Licensee in Japan

Efficient BIS license assistance, great consultants.

Ms. Amanda
Ms. Amanda

Trimble Navigation, BIS Licensee in USA

Seamless BIS certification and registration support.

Ms. Martina
Ms. Martina

Remsa Italia, BIS Licensee in Italy

Helpful BIS consultants, simplified license process.

Ms. Nikola
Ms. Nikola

Aquazzura, BIS Licensee in Italy

We got our BIS certificate well within the timelines and at affordable prices, great work team Sun!

Ms. Ayu
Ms. Ayu

PT Quty, BIS Licensee in Indonesia

Excellent BIS registration service, highly recommended.

Mr. Huy
Mr. Huy

Danu Vina, BIS Licensee in Vietnam

Reliable BIS license consultants, fast process.

Mr. Minh
Mr. Minh

Hanh My Production Company, BIS Licensee in Vietnam

Expert BIS consultants, certification made easy.

Ms. Hoa
Ms. Hoa

Sedo Vina, BIS Licensee in Vietnam

Smooth BIS certificate registration, great support.

Ms. Hana
Ms. Hana

Misumi Japan, BIS Licensee in Japan

Trusted BIS consultants, quick certification process.

Ms. Nok
Ms. Nok

Thantawan Public Industry Company, BIS Licensee in Thailand

Professional BIS certification service, very efficient.

Mr. Luis
Mr. Luis

Cortizo Aluminios, BIS Licensee in Spain

Excellent BIS registration and license guidance.

Ms. Aisha
Ms. Aisha

Midal Cables, BIS Licensee in Bahrain

Expert BIS consultants, smooth certification process.

Why Choose Us
10+

Years Exp.

1599+

Our Clients

100%

Success Rate

20+

Countries Served

Expert Guidance

Our team brings 10e4+ years of experience in CDSCO and BIS compliance.

Time Efficient

We reduce approval time by up to 40% with streamlined processes.

Proven Success

100% success rate with 1500+ successful registrations.

Client-Centric

Dedicated account manager ensuring personalized service.

Our Performance
Speed
Success
Satisfaction
Request a Free Callback

Leave your details below and our experts will call you back within 24 hours to discuss your regulatory compliance needs.

By submitting this form, you agree to our Privacy Policy and consent to being contacted.

WhatsAppCall