Digital Personal Data Protection Act 2023 – Complete Guide to DPDP Act, Rules, Compliance & Penalties

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's principal legislation governing the processing of digital personal data. The Act establishes a legal framework for processing digital personal data while recognizing the right of individuals to protect their personal data and the need to process such data for lawful purposes.
The Act received Presidential assent on 11 August 2023 and establishes important concepts such as the Data Principal, Data Fiduciary, Data Processor, Consent Manager and Significant Data Fiduciary. It also provides rights to individuals, obligations for organizations processing personal data, a framework for personal data breach management, the Data Protection Board of India, and monetary penalties for specified breaches.
The regulatory framework has subsequently been supplemented by the Digital Personal Data Protection Rules, 2025. The Rules were notified in November 2025, while a separate commencement notification provides for phased commencement of different provisions of the Act.
For organizations operating in India, DPDP compliance therefore involves understanding not only the original 2023 Act but also the applicable Rules, commencement dates and subsequent regulatory requirements.
What Is the Digital Personal Data Protection Act 2023?
The Digital Personal Data Protection Act, 2023 is an Indian law that regulates the processing of digital personal data.
The Act seeks to balance two important objectives:
- Protecting the personal data of individuals; and
- Allowing personal data to be processed for lawful purposes.
The legislation establishes obligations for organizations that determine the purpose and means of processing personal data and provides corresponding rights and duties for individuals whose personal data is processed.
In simple terms, the DPDP Act creates a framework governing how organisations collect, use, store, share and otherwise process digital personal data.
The Act is particularly relevant to businesses that collect information through:
- websites;
- mobile applications;
- online forms;
- e-commerce platforms;
- customer accounts;
- CRM systems;
- employee portals;
- recruitment platforms;
- online services;
- digital marketing systems; and
- other digital channels.
Current Status of the DPDP Act in India
The Digital Personal Data Protection Act was enacted in 2023, but its provisions are not all brought into force simultaneously.
The Central Government issued a commencement notification on 13 November 2025 providing for phased commencement.
Under that notification:
- specified provisions came into force on publication;
- certain provisions are scheduled to commence one year after publication; and
- a larger group of substantive provisions is scheduled to commence eighteen months after publication.
The Digital Personal Data Protection Rules, 2025 were notified separately on 14 November 2025. The Rules also contain phased commencement provisions. Rules 1, 2 and 17 to 21 came into force upon publication, Rule 4 is scheduled to commence one year after publication, and Rules 3, 5 to 16, 22 and 23 are scheduled to commence eighteen months after publication.
Therefore, organisations should distinguish between:
- The DPDP Act, 2023 → primary legislation
- The DPDP Rules, 2025 → detailed implementation framework
- Commencement notifications → determine when particular provisions become operational
This distinction is important when assessing the current compliance position.
Who Does the DPDP Act Apply To?
Section 3 of the DPDP Act sets out its application.
The Act applies to the processing of digital personal data within India where the personal data is:
- Collected from a Data Principal in digital form; or
- Collected in non-digital form and subsequently digitised.
The Act can also apply to processing outside India where such processing is connected with offering goods or services to Data Principals within India.
This means that the geographical location of a company's headquarters alone does not determine whether the DPDP framework may be relevant.
A foreign organisation offering goods or services to individuals in India may need to examine whether its processing activities fall within the Act.
Important Definitions Under the DPDP Act 2023
Understanding the terminology used in the Act is essential for DPDP compliance.
Data Principal
A Data Principal is the individual to whom the personal data relates.
In relation to a child, the definition also includes the parent or lawful guardian. In relation to a person with disability who has a lawful guardian, the definition includes the lawful guardian acting on behalf of that individual.
Data Fiduciary
A Data Fiduciary means a person who, alone or together with other persons, determines the purpose and means of processing personal data.
In practical terms, an organisation deciding why personal data is collected and how it is processed may fall within the role of a Data Fiduciary.
Data Processor
A Data Processor is a person who processes personal data on behalf of a Data Fiduciary.
Examples can include certain third-party service providers handling personal data on behalf of another organisation.
Consent Manager
A Consent Manager is an entity intended to provide a platform through which a Data Principal can give, manage, review and withdraw consent through an accessible, transparent and interoperable system.
The DPDP Rules, 2025 further provide requirements relating to registration and functioning of Consent Managers.
Significant Data Fiduciary
The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary after considering specified factors.
These include matters such as:
- volume and sensitivity of personal data;
- risk to the rights of Data Principals;
- potential impact on sovereignty and integrity of India;
- risk to security of the State;
- potential impact on electoral democracy;
- security of the State; and
- public order.
What Is Personal Data Under the DPDP Act?
The Act defines personal data broadly as any data about an individual who is identifiable by or in relation to such data.
The legislation specifically focuses on digital personal data.
This can include information that enables an individual to be identified, directly or in combination with other information.
Depending on the circumstances, organisations may process personal data such as:
- names;
- contact details;
- account information;
- identification-related information;
- employee information;
- customer information;
- online identifiers; and
- other information associated with an identifiable individual.
The precise treatment depends on the Act, Rules and the circumstances of the processing.
Notice Requirements Under the DPDP Act
A Data Fiduciary is required to provide notice to the Data Principal in connection with a request for consent.
The notice must provide specified information relating to the processing.
The Act requires information including:
- the personal data proposed to be processed;
- the purpose for which the personal data is proposed to be processed;
- the manner in which rights can be exercised; and
- the manner in which a complaint can be made to the Board.
The DPDP Rules, 2025 provide more detailed requirements for notices.
The Rules state that the notice must be presented and understandable independently of other information and must use clear and plain language. It must include an itemised description of personal data and the specified purpose or purposes of processing.
This makes the privacy notice an important part of a business's DPDP compliance framework.
Obligations of a Data Fiduciary
Data Fiduciaries have significant responsibilities under the DPDP Act.
Responsibility for Processing
A Data Fiduciary remains responsible for compliance with the Act and Rules in relation to processing carried out by it or on its behalf by a Data Processor.
Appointment of Data Processors
A Data Fiduciary may engage a Data Processor for carrying out processing activities on its behalf subject to the applicable requirements, including contractual arrangements.
Accuracy of Personal Data
Where personal data is likely to be used to make a decision affecting the Data Principal or is likely to be disclosed to another Data Fiduciary, appropriate steps must be taken to ensure completeness, accuracy and consistency.
Technical and Organisational Measures
The Data Fiduciary is required to implement appropriate technical and organisational measures to ensure effective observance of the Act and Rules.
Security Safeguards
A Data Fiduciary must protect personal data in its possession or control by taking reasonable security safeguards to prevent personal data breaches.
Personal Data Breach Notification
In the event of a personal data breach, the Data Fiduciary must notify the Board and affected Data Principals in the prescribed manner.
Erasure of Personal Data
Unless retention is required by law, personal data must be erased when the Data Principal withdraws consent or when it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, subject to the statutory framework.
Grievance Redressal
A Data Fiduciary must establish an effective mechanism for redressing grievances of Data Principals.
Cross-Border Transfer of Personal Data
The DPDP Act provides a framework under which the Central Government may restrict the transfer of personal data by a Data Fiduciary for processing to specified countries or territories outside India through notification.
The Act also recognises that other Indian laws may impose a higher degree of protection or additional restrictions relating to the transfer of personal data outside India.
Businesses operating internationally should therefore evaluate cross-border data flows as part of their DPDP compliance assessment.
Digital Personal Data Protection Rules 2025
The Digital Personal Data Protection Rules, 2025 provide detailed rules for implementing the Digital Personal Data Protection Act, 2023.
The final Rules were notified by the Ministry of Electronics and Information Technology in November 2025.
The Rules address areas including:
- notices to Data Principals;
- Consent Managers;
- security safeguards;
- personal data breach notifications;
- processing children's personal data;
- rights of Data Principals;
- obligations of Data Fiduciaries;
- Significant Data Fiduciaries;
- the Data Protection Board; and
- other operational aspects of the Act.
The Rules require notices to be understandable independently of other information and to use clear and plain language. They also specify that notices should include an itemised description of personal data and the specific purpose or purposes of processing.
DPDP Act and DPDP Rules Implementation Timeline
The DPDP framework uses a phased implementation structure.
13 November 2025 – Initial Commencement
The commencement notification brought specified provisions of the Act into force on publication.
One Year After Publication
Certain provisions identified in the commencement notification are scheduled to come into force one year after publication.
Eighteen Months After Publication
A larger set of substantive provisions, including Sections 3 to 5, most of Section 6, Sections 7 to 10, Sections 11 to 17 and various enforcement provisions, is scheduled to come into force eighteen months after publication of the commencement notification.
The Rules have a corresponding phased structure, with Rules 1, 2 and 17 to 21 commencing on publication, Rule 4 after one year and Rules 3, 5 to 16, 22 and 23 after eighteen months.
Why the Implementation Timeline Matters
Businesses should not interpret phased commencement as a reason to postpone data-governance preparation.
A practical compliance programme may require time to:
- identify personal data;
- map data flows;
- review notices;
- review consent mechanisms;
- update contracts;
- establish rights-request processes;
- assess security controls;
- establish breach procedures;
- review retention and deletion;
- assess children's data processing; and
- evaluate third-party processors.
Difference Between DPDP Act and DPDP Rules
| DPDP Act, 2023 | DPDP Rules, 2025 |
|---|---|
| Primary legislation | Detailed implementation rules |
| Establishes statutory rights and obligations | Provides operational requirements |
| Defines Data Principal and Data Fiduciary | Provides detailed requirements for notices and other processes |
| Establishes Data Protection Board framework | Provides procedural details relating to implementation |
| Specifies penalty framework | Provides additional operational requirements |
| Provides overall legal framework | Provides implementation details |
Benefits of a Structured DPDP Compliance Programme
A structured data protection programme can help an organisation establish clearer processes for managing personal data.
It can help businesses:
- understand what personal data they hold;
- identify unnecessary data collection;
- improve data governance;
- establish clearer responsibilities;
- manage third-party processors;
- prepare for personal data breaches;
- respond to Data Principal requests;
- document processing activities; and
- establish repeatable privacy processes.
The specific compliance requirements applicable to a business depend on its processing activities, role, sector, data and the provisions in force.
Conclusion
The Digital Personal Data Protection Act 2023 establishes India's statutory framework for protecting digital personal data while enabling lawful processing.
For organisations, the framework extends beyond simply creating a privacy policy. Businesses need to understand their role as a Data Fiduciary or Data Processor, identify the personal data they process, establish appropriate notices and consent mechanisms, manage third-party processors, implement security safeguards, establish breach-response procedures and create mechanisms for handling applicable Data Principal rights.
The Digital Personal Data Protection Rules, 2025 provide further operational requirements, while the Government's commencement notification establishes a phased implementation structure.
As DPDP implementation progresses, organisations should align their privacy, cybersecurity, legal, HR, marketing, technology and vendor-management processes with the provisions applicable to their activities.
For a business, the most practical starting point is a DPDP compliance assessment and data-mapping exercise that identifies what personal data is collected, why it is processed, where it is stored, who has access to it, which third parties process it and how the data is ultimately retained or deleted.
Frequently Asked Questions About the DPDP Act 2023
1. What is the Digital Personal Data Protection Act 2023?
The Digital Personal Data Protection Act, 2023 is Indian legislation governing the processing of digital personal data and establishing rights for Data Principals and obligations for Data Fiduciaries.
2. When was the DPDP Act 2023 enacted?
The Digital Personal Data Protection Act received Presidential assent on 11 August 2023.
3. What are the DPDP Rules 2025?
The Digital Personal Data Protection Rules, 2025 are rules made under the DPDP Act to provide detailed implementation requirements. They were notified in November 2025.
4. Who is a Data Fiduciary?
A Data Fiduciary is a person who, alone or together with another person, determines the purpose and means of processing personal data.
5. Who is a Data Principal?
A Data Principal is the individual to whom the personal data relates. The Act contains additional provisions for children and persons with lawful guardians.
6. Who is a Data Processor?
A Data Processor processes personal data on behalf of a Data Fiduciary.
7. Can consent be withdrawn under the DPDP Act?
Yes. Where processing is based on consent, a Data Principal can withdraw consent, and the withdrawal mechanism should be as easy as the mechanism through which consent was given.
8. What rights are available to Data Principals?
The Act provides rights including access to information, correction and erasure, grievance redressal and nomination, subject to the applicable statutory conditions.
9. What is the maximum penalty under the DPDP Act?
The Schedule specifies a maximum penalty of ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach.
10. Does the DPDP Act apply to foreign companies?
The Act can apply to processing outside India where the processing is connected with offering goods or services to Data Principals within India.
11. What is the Data Protection Board of India?
The Data Protection Board of India is the statutory body established under the Act to perform specified functions relating to breaches, complaints, directions, penalties and other matters under the DPDP framework.
Many of our users also read
This compliance advisory was vetted by our Senior Consultant (Enforcement & Vigilance), a former BIS Director (Enforcement). He specializes in post-certification compliance, helping companies navigate surveillance audits and legal adherence to BIS mandates.
Dhruv Aggarwal
Head of Operations at Sun Certifications India
Experience: 10+ years & Handled 1000+ projects
Awarded by many Indian and International organisations

PT Quty Karunia, BIS Licensee in Vietnam
“Sun Certifications India provided excellent BIS Certification services. Their unparalleled service and sincerity gained our trust. One of the best BIS consultants in India!”

Thantawan Industries Ltd, BIS Licensee in Thailand
“Sun Certifications India supported us throughout the BIS certification process. Their responsive customer service and punctuality are exceptional. Highly recommend for hassle-free BIS certification.”

Leaderart Industries, BIS Licensee in Malaysia
“Sun Certifications India helped us acquire BIS Certification, doubling our engagement in India. Their services are fast, genuine, and up-to-date with latest BIS norms.”

Aluminium Bahrain (ALBA), BIS Licensee in Bahrain
“Excellent BIS certification support, highly reliable consultants.”

Bahrain Aluminium Manufacturing Company, BIS Licensee in Bahrain
“Smooth BIS registration process with expert consultants.”

Daiki Aluminium Japan, BIS Licensee in Japan
“Efficient BIS license assistance, great consultants.”

Trimble Navigation, BIS Licensee in USA
“Seamless BIS certification and registration support.”

Remsa Italia, BIS Licensee in Italy
“Helpful BIS consultants, simplified license process.”

Aquazzura, BIS Licensee in Italy
“We got our BIS certificate well within the timelines and at affordable prices, great work team Sun!”

PT Quty, BIS Licensee in Indonesia
“Excellent BIS registration service, highly recommended.”

Danu Vina, BIS Licensee in Vietnam
“Reliable BIS license consultants, fast process.”

Hanh My Production Company, BIS Licensee in Vietnam
“Expert BIS consultants, certification made easy.”

Sedo Vina, BIS Licensee in Vietnam
“Smooth BIS certificate registration, great support.”

Misumi Japan, BIS Licensee in Japan
“Trusted BIS consultants, quick certification process.”

Thantawan Public Industry Company, BIS Licensee in Thailand
“Professional BIS certification service, very efficient.”

Cortizo Aluminios, BIS Licensee in Spain
“Excellent BIS registration and license guidance.”

Midal Cables, BIS Licensee in Bahrain
“Expert BIS consultants, smooth certification process.”
Years Exp.
Our Clients
Success Rate
Countries Served
Our team brings 10e4+ years of experience in CDSCO and BIS compliance.
We reduce approval time by up to 40% with streamlined processes.
100% success rate with 1500+ successful registrations.
Dedicated account manager ensuring personalized service.
Leave your details below and our experts will call you back within 24 hours to discuss your regulatory compliance needs.
By submitting this form, you agree to our Privacy Policy and consent to being contacted.


















