Skip to content
DPDP
8 chapters·plain English

The DPDP Act 2023, in Plain English

No section-by-section recital. Just what the Act asks of you, in the order you will have to deal with it.

Top penalty
₹250 crTop penalty
Languages
22Languages
Age of majority
18Age of majority

Who it applies to

Anyone processing digital personal data of people in India, whether the data was collected digitally or later digitised. It also reaches processing outside India where goods or services are offered to people in India. If you hold customer records, you are almost certainly a Data Fiduciary.

Notice and consent

Before or at the time of collecting data, you must give an itemised notice describing what you collect and why, available in English and any of the 22 languages in the Eighth Schedule. Consent must be free, specific, informed, unconditional and unambiguous, and withdrawing it must be as easy as giving it.

Legitimate uses

A narrow set of situations allow processing without consent — a person voluntarily providing data for a stated purpose, employment purposes, medical emergencies, disaster response and certain State functions. These are exceptions to lean on carefully, not a general-purpose alternative to consent.

Your obligations as a Data Fiduciary

Keep data accurate, apply reasonable security safeguards, delete it once the purpose is served, notify breaches to the Data Protection Board and to affected people, publish the contact details of a Grievance Officer, and stay accountable for anything your processors do.

Rights of the Data Principal

Access to a summary of their data and who it was shared with, correction and completion, erasure, nomination of someone to exercise rights on their behalf, and a grievance redressal route that must be exhausted before approaching the Board.

Children's data

For anyone under eighteen, you need verifiable parental consent, and you may not run behavioural advertising or tracking directed at them, or process their data in a way likely to cause detrimental effect.

Significant Data Fiduciaries

The Government may designate you as significant based on data volume and sensitivity, risk to rights, and impact on sovereignty or public order. If designated, you must appoint an India-based Data Protection Officer, appoint an independent data auditor, and run periodic DPIAs and audits.

Penalties

Up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach, up to ₹200 crore for failures around breach notification or children's data obligations, and up to ₹50 crore for other breaches of Significant Data Fiduciary duties. The Board sets the amount by nature, gravity, duration and repetitiveness.

This guide is written for orientation and is not legal advice. The operative text is the Act itself, read with the Rules as notified.