DPDPA: The Complete Guide
The Digital Personal Data Protection Act, 2023, is India's first comprehensive data protection legislation and one of the most consequential privacy laws enacted globally in the 2020s. Signed into law in August 2023 by President Droupadi Murmu, the DPDPA applies to the processing of digital personal data within India and to processing outside India when it relates to offering goods or services to individuals in India. With 1.4 billion residents and one of the world's fastest-growing digital economies, India's privacy framework will shape data governance across the entire Asia-Pacific technology sector.
What the DPDPA Is and Who Enforces It
The DPDPA is administered by the Data Protection Board of India, an adjudicatory body established under the Act with powers to investigate complaints, hear appeals, and impose penalties. MeitY retains significant rule-making authority, and the Rules under the DPDPA — governing notice formats, consent manager registration, and Significant Data Fiduciary designation criteria — were under consultation as of mid-2026 with phased enforcement expected to begin once the Rules are finalized.
The Act introduced new terminology that differs deliberately from the GDPR. Organizations processing personal data are called Data Fiduciaries (analogous to controllers). Individuals whose data is processed are Data Principals. Third parties who process data on behalf of a Fiduciary are Data Processors.
Territorial and Material Scope
The DPDPA covers processing of digital personal data — personal data in digital form, or non-digital data that has been digitized. Unlike the GDPR, it does not extend to manual filing systems. Coverage is triggered by:
- Processing of digital personal data within India, whether online or offline data that has been digitized.
- Processing outside India in connection with the offering of goods or services to Data Principals within India.
Exemptions apply to personal data processed by individuals for personal or domestic purposes, and to data made publicly available by the Data Principal themselves or as required by law.
Consent-Based Processing and Notice
The DPDPA is built on a consent-driven model with limited deemed-consent exceptions. Data Fiduciaries must:
- Provide clear, itemized notice describing what personal data is being collected, the purpose, and how Data Principals can exercise their rights and file grievances.
- Obtain free, specific, informed, and unambiguous consent before processing. Consent must be sought through a clear affirmative action and may not be bundled with other consents.
- Allow Data Principals to withdraw consent at any time — withdrawal must be as easy as giving consent. Upon withdrawal, the Fiduciary and Processors must cease processing and delete data, unless retention is required by law.
Deemed consent applies in narrower circumstances including employment-related processing by an employer, functions of a public authority, and public interest processing — but the categories are more restricted than GDPR's legitimate interests basis.
Rights of Data Principals
Data Principals receive four categories of rights under Sections 11 through 14:
- Right to information — Confirmation of processing and a summary of personal data held.
- Right to correction and erasure — Accuracy corrections and deletion of data when processing purpose is fulfilled or consent is withdrawn.
- Right to grievance redressal — Every Data Fiduciary must establish a process for Data Principals to file grievances, with responses required within a prescribed timeframe.
- Right to nominate — A novel provision allowing Data Principals to nominate a person to exercise rights on their behalf in the event of death or incapacity.
The DPDPA also uniquely imposes duties on Data Principals: they must not file false or frivolous complaints and must not suppress material information when providing data for processing. This two-way accountability model distinguishes the DPDPA from other global privacy frameworks.
Significant Data Fiduciaries
The government may designate certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data processed, the risk to Data Principals, national security and sovereignty considerations, and the potential impact on children's rights. Significant Data Fiduciaries face heightened obligations:
- Appointment of a Data Protection Officer resident in India who reports directly to the board of directors.
- Appointment of an independent data auditor for periodic compliance audits.
- Conducting Data Protection Impact Assessments for specified processing activities.
- Additional obligations that the government may prescribe by rule.
Large global technology companies, financial institutions, and healthcare platforms serving India are the most likely candidates for designation, though the government has not yet published the criteria finalized in Rules.
Children's Data Protections
Section 9 of the DPDPA establishes strict protections for children's personal data (individuals under 18). Data Fiduciaries must:
- Obtain verifiable parental or guardian consent before processing any personal data of a child.
- Refrain from behavioral monitoring and targeted advertising directed at children.
- Not track or profile children in a manner harmful to their well-being.
The government may exempt classes of Data Fiduciaries from some of these obligations where processing is demonstrably safe and the verifiable consent requirement is disproportionate — for example, for certain educational platforms. Rules clarifying these exemptions were anticipated in late 2025.
Breach Notification
Data Fiduciaries must notify the Data Protection Board and each affected Data Principal of any personal data breach in the manner and within the timeframe prescribed by Rules. Unlike the GDPR's risk-based threshold (only notifying if likely to result in risk), the DPDPA appears to require notification for all breaches — a broader obligation that organizations must build notification pipelines to meet.
Cross-Border Transfer Rules
Rather than adopting an adequacy-based model, the DPDPA permits cross-border data transfers to all countries by default, except those specifically restricted by the Indian government on a negative list. This is a fundamentally different approach from the GDPR, which requires a positive adequacy finding or safeguard for each destination. The government's negative list had not been published as of mid-2026, creating uncertainty for organizations managing global data flows. Until the list is finalized, transfers appear to be permitted unless specifically restricted.
Enforcement and Penalties
The Data Protection Board of India adjudicates complaints filed by Data Principals or referred by MeitY. Maximum penalties under the Schedule to the Act:
- Up to 250 crore rupees (approximately $30 million) for failure to implement reasonable security safeguards resulting in a breach.
- Up to 200 crore rupees for failure to notify a breach.
- Up to 200 crore rupees for violations of children's data obligations.
- Up to 50 crore rupees for failure to meet Data Principal rights obligations.
The Board may also direct remedial action and issue cease-and-desist orders. There is no private right of action; enforcement runs exclusively through the Board.
DPDPA vs. GDPR and Related Laws
The DPDPA shares approximately 55% conceptual overlap with the GDPR — both are consent-centric, recognize individual rights, and impose security obligations. Key differences:
- Scope: DPDPA covers only digital personal data; GDPR covers both automated and manual processing.
- Legal bases: DPDPA primarily relies on consent plus deemed consent; GDPR provides six bases including legitimate interests.
- Transfers: DPDPA uses a negative-list model; GDPR uses adequacy decisions and positive safeguards.
- Penalties: DPDPA imposes per-incident caps; GDPR calculates fines as a percentage of global turnover.
- Data Principal duties: Unique to the DPDPA; no equivalent in GDPR.
Compared to Singapore's PDPA (50% overlap), the DPDPA shares a consent-first orientation but goes further on children's protections and introduces the unique grievance redressal and nomination rights. The PIPL in China is stricter on cross-border transfers through mandatory security assessments, whereas India's approach is more permissive unless countries are added to the negative list.
Compliance Steps and Timeline
| Phase | Activities | Typical Duration |
|---|---|---|
| Assessment | Data mapping, legal basis review, children's data audit | 4-8 weeks |
| Design | Notice and consent architecture, grievance process | 4-8 weeks |
| Implementation | Technical controls, DPO appointment (if SDF), processor contracts | 6-12 weeks |
| Ongoing | Breach monitoring, rights fulfillment, Rules monitoring | Continuous |
Key compliance steps:
- Notice and consent — Implement clear, itemized notice and consent mechanisms for all personal data collection meeting DPDPA requirements.
- Grievance redressal — Establish and publish a process for Data Principals to file and track grievances, with timely responses.
- Children's data — Implement age verification and verifiable parental consent mechanisms for any service accessed by individuals under 18.
- Cross-border assessment — Monitor the government's negative list and verify that transfer destinations are not restricted.
- Breach notification pipeline — Build automated alerting and notification workflows for the Board and affected Data Principals.
- Significant Data Fiduciary evaluation — Assess whether your organization may be designated and begin building DPO and audit infrastructure proactively.
- Rules monitoring — Track MeitY rulemaking and DPDPA Rules publication for enforcement timelines and additional obligations.
How Privacy Automation Helps
The DPDPA's consent mechanics, grievance workflows, and breach notification requirements create operational infrastructure needs that are well-suited to automation. TruePrivacy covers the DPDPA among its 12-plus supported frameworks alongside GDPR, CCPA, and LGPD. Its AI-powered data discovery across 128-plus sources helps build the data inventory needed to support notice accuracy and breach scope assessment. DSR automation handles Principal rights requests and grievance routing.
At $5,000 per year with 24-hour onboarding, TruePrivacy is a cost-effective starting point for organizations building DPDPA compliance programs while Rules are still being finalized. AuditXYZ rates it 88/100. For organizations managing India compliance alongside 300-plus global jurisdictions or requiring deep customization, compare options at best privacy management tools.
Frequently Asked Questions
When does DPDPA enforcement actually begin? The Act was signed in August 2023, but enforcement is tied to the finalization and notification of the Rules under the Act. As of mid-2026, the Rules remain under consultation by MeitY. Enforcement is expected to begin in phases after the Rules are published, with larger Data Fiduciaries facing earlier deadlines. Organizations should prepare now rather than waiting for the final Rules.
What counts as a Significant Data Fiduciary? The government will designate Significant Data Fiduciaries by notification, based on criteria including volume and sensitivity of data, national security risk, and impact on children's rights. The Rules are expected to specify quantitative thresholds. Organizations processing large volumes of health, financial, or children's data in India should assume they may be designated and begin building the required DPO and audit infrastructure.
Does the DPDPA apply to B2B companies processing only employee data? The DPDPA covers processing of personal data of individuals in India. Employee data falls within scope. Deemed consent provisions apply to employers processing employee data for employment purposes, but the full set of obligations — including security safeguards, breach notification, and grievance redressal — still apply.
How does the DPDPA's negative-list transfer model work in practice? Until the government publishes the negative list, transfers appear to be permitted to all countries. Once the list is published, transfers to listed countries will require either government authorization or one of the safeguards prescribed in the Rules. Organizations with data flows to potentially restricted jurisdictions — particularly China, Pakistan, or countries with whom India has geopolitical tensions — should build transfer mapping into their compliance programs now.
What are Data Principal duties and do they create liability for individuals? Data Principals have a duty not to impersonate another person when providing personal data, not to suppress material information, and not to file false or frivolous complaints or grievances. The Act provides for penalties on Data Principals for these duties. This is a globally unusual provision, designed to create accountability on both sides of the data processing relationship.