A concise overview of the Digital Personal Data Protection Act, explaining applicability, key rights and duties, compliance needs, penalties and the path toward full enforcement.
View on Batoi SecureMinistry of Electronics and IT (MeitY)
Privacy & Personal Data Governance
Assented August 2023 · Enforcement January 2024
High · Penalties up to INR 250 crores
The Digital Personal Data Protection (DPDP) Act (version 2023), is India’s first comprehensive privacy law, establishing a framework for protecting digital personal data. Enacted in August 2023, the Act’s purpose is to balance “the rights of individuals to protect their personal data and the need to process such personal data for lawful purposes”. It introduces clear obligations for organizations (termed Data Fiduciaries) on how they collect, use, and store personal data, and grants enforceable rights to individuals (termed Data Principals) over their data. The law applies broadly – not only to businesses in India but also to foreign entities processing digital personal data in connection with...
The Digital Personal Data Protection (DPDP) Act (version 2023), is India’s first comprehensive privacy law, establishing a framework for protecting digital personal data. Enacted in August 2023, the Act’s purpose is to balance “the rights of individuals to protect their personal data and the need to process such personal data for lawful purposes”. It introduces clear obligations for organizations (termed Data Fiduciaries) on how they collect, use, and store personal data, and grants enforceable rights to individuals (termed Data Principals) over their data. The law applies broadly – not only to businesses in India but also to foreign entities processing digital personal data in connection with offering goods or services to people in India. It mandates principles such as consent-based processing, data minimization, purpose limitation, and the secure handling of personal data. A dedicated regulatory body, the Data Protection Board of India (DPB), will oversee compliance and address grievances, with powers to impose significant penalties for violations. In essence, the DPDP Act aims to build trust in the digital economy by safeguarding personal information, while allowing data to be used for innovation and legitimate purposes within a well-defined legal framework. (Notably, the Act focuses on digital data and does not cover purely offline personal data, which has drawn some criticism.)
The Digital Personal Data Protection Act, is poised to become fully operational. Organizations should use this interim period to shore up their data privacy practices by deploying the available tools and templates (such as those from Batoi Secure), training staff on the new obligations, auditing data flows, and monitoring the final Rules. The regulatory landscape is being built in real-time through Rules and guidance documents. By staying updated with these developments and proactively adjusting their compliance programs, enterprises and auditors can ensure that when the DPDP Act’s provisions take effect, they are ready to meet the standards of India’s new data protection era. Compliance not only avoids penalties but also fosters trust with customers and stakeholders in the long run.
Sources:
The DPDP Act governs all persons and entities that process digital personal data within India, whether in the private sector or the government. It defines a “Data Fiduciary” as any person (including companies, firms, or public authorities) that determines the purpose and means of processing personal data, and a “Data Processor” as one who processes data on a fiduciary’s behalf. There is no blanket exemption for small businesses or startups – any organization handling personal data must comply. However, the law empowers the government to notify specific relaxations or delayed requirements for certain classes of Data Fiduciaries (for example, startups or MSMEs) based on the volume...
The DPDP Act governs all persons and entities that process digital personal data within India, whether in the private sector or the government. It defines a “Data Fiduciary” as any person (including companies, firms, or public authorities) that determines the purpose and means of processing personal data, and a “Data Processor” as one who processes data on a fiduciary’s behalf. There is no blanket exemption for small businesses or startups – any organization handling personal data must comply. However, the law empowers the government to notify specific relaxations or delayed requirements for certain classes of Data Fiduciaries (for example, startups or MSMEs) based on the volume and nature of data they handle. The Act’s scope is digital-only: it covers personal data that is collected or processed digitally (including personal data initially collected offline but subsequently digitized), while data that remains in purely non-digital form is outside its scope.
Government bodies are considered Data Fiduciaries under the law. However, the Central Government can exempt certain processing by government agencies from specific provisions of the Act for reasons such as national security, public order, or law enforcement. The Act also has an important “outsourcing exception” – personal data of individuals not located in India, when processed in India pursuant to a contract with a foreign entity, can be exempted from many obligations (this spares Indian IT/BPO companies handling overseas data from some compliance burdens). Additionally, the law’s reach is extraterritorial: a company based outside India must comply with DPDP if it processes digital personal data in connection with any business offering goods/services to people in India. In summary, the Act’s applicability is broad, covering private companies (large or small), government departments, and their service providers, with only narrow carve-outs and potential temporary reliefs for specified entities.
For organizations seeking to comply with the DPDP Act, Batoi Secure provides a suite of resources to simplify and accelerate implementation:
For organizations seeking to comply with the DPDP Act, Batoi Secure provides a suite of resources to simplify and accelerate implementation:
By leveraging tools such as the DPDP Lite Checker and the Compliance Toolkit, enterprises and auditors can efficiently assess current gaps and obtain vetted materials to meet their DPDP obligations. These assets, curated by Batoi Secure, are designed to translate the legal mandates into practical steps and documents for Indian organizations.
Aug 01, 2023
Official timelines for the rollout of the DPDP Act have been phased and are evolving, as the government has opted for a graded implementation approach. Key milestones and deadlines are...
Read MoreSep 01, 2023
The Ministry of Electronics and IT (MeitY) initiated industry consultations on implementation. Officials indicated a “graded compliance timeline” whereby larger and more experienced companies (especially Big Tech firms) would be...
Read MoreJan 01, 2024
Although the Act itself did not set a fixed compliance date, the government indicated that rules and subordinate regulations would be implemented by the end of 2023 or early 2024....
Read MoreJan 01, 2025
On 3 January 2025, MeitY published the Draft Digital Personal Data Protection Rules, 2025, for public consultation. These draft Rules outline operational requirements, including how consent notices should be provided,...
Read MoreJun 01, 2025
As of mid-2025, the DPDP Act remains formally in force, although the government has not yet issued the notification bringing its provisions into effect. This waiting period ensures that the...
Read MoreNov 01, 2025
Once the Act is notified (anticipated in late 2025 or 2026), the government is likely to prescribe staggered compliance dates. For example, large fiduciaries may need to comply immediately on...
Read More
A: The DPDP Act 2023 became law in August 2023, but is not enforceable until the Central Government issues a commencement notification. The government is phasing in the law – key provisions will likely be notified by late 2025 after finalizing the Rules. Once notified, larger companies may be expected to comply immediately, whereas smaller startups might get a short additional grace period. In any case, compliance is expected soon, so companies should act now. (As of mid-2025, the Act remained dormant pending rules, but this status will change once regulations are finalized.)
A: It applies to all organizations (public or private) that process digital personal data, regardless of size. There is no blanket exemption for SMEs or startups. However, the government can grant exemptions or extend timelines for specific categories. In fact, officials have indicated that “entities like Startups, MSMEs & hospitals will get more time to comply” with some DPDP provisions. Such relief might include temporary exemption from specific obligations (like appointing a Data Protection Officer or conducting audits) or extra time to implement compliance measures. Any such concessions will be formally notified. Until then, even startups should prepare to comply...
A: It applies to all organizations (public or private) that process digital personal data, regardless of size. There is no blanket exemption for SMEs or startups. However, the government can grant exemptions or extend timelines for specific categories. In fact, officials have indicated that “entities like Startups, MSMEs & hospitals will get more time to comply” with some DPDP provisions. Such relief might include temporary exemption from specific obligations (like appointing a Data Protection Officer or conducting audits) or extra time to implement compliance measures. Any such concessions will be formally notified. Until then, even startups should prepare to comply with core requirements (such as consent, security, and user rights), albeit with the expectation of a practical enforcement approach that scales with an entity’s size and data risk.
A: Consent is the primary basis for lawful processing of personal data under DPDP. Organizations must obtain a person’s consent before collecting or using their personal data, unless a specific “Legitimate Use” exception in the Act applies. Consent has to be free, specific, informed, unconditional, and given through a clear affirmative action. In practice, this means consent requests should be in plain language (available in English or any scheduled Indian language) and clearly explain what data will be used and for what purpose. Importantly, consent can be withdrawn at any time, and the process to withdraw must be as easy...
A: Consent is the primary basis for lawful processing of personal data under DPDP. Organizations must obtain a person’s consent before collecting or using their personal data, unless a specific “Legitimate Use” exception in the Act applies. Consent has to be free, specific, informed, unconditional, and given through a clear affirmative action. In practice, this means consent requests should be in plain language (available in English or any scheduled Indian language) and clearly explain what data will be used and for what purpose. Importantly, consent can be withdrawn at any time, and the process to withdraw must be as easy as giving consent. Upon withdrawal, the data must be deleted unless retention is required by law.
To streamline consent handling, the Act provides for Consent Managers – specialized services that individuals can use to give, track, and revoke consent across multiple platforms. These Consent Managers will be registered with the Data Protection Board and must provide an interoperable platform for users to manage their consents centrally. In essence, organizations should implement consent management mechanisms that allow users to easily opt in, view what they have consented to, and opt out. Many may integrate with or become Consent Manager platforms once the government publishes regulations for their registration and technical standards. In preparation, MeitY has even released a technical framework (BRD) describing how a consent management system should function (e.g., dashboards for users, secure logs of consent, standardized APIs for consent withdrawal). Enterprises should review their consent collection forms and workflows now to ensure they meet the DPDP Act’s high standards for clarity and user control.
A: Yes. Unlike previous drafts, the DPDP Act 2023 imposes no blanket data localization requirement. Personal data can be transferred outside India by default, except if the Central Government designates certain countries or destinations as restricted. In other words, the Act adopts a “blacklist” approach: data flows to all foreign jurisdictions are permitted unless specifically disallowed. As of now, the government has not published any list of banned countries, so companies can continue to use global data storage or processing services. That said, organizations remain responsible for protecting the data even when it’s transferred abroad, and they must comply with...
A: Yes. Unlike previous drafts, the DPDP Act 2023 imposes no blanket data localization requirement. Personal data can be transferred outside India by default, except if the Central Government designates certain countries or destinations as restricted. In other words, the Act adopts a “blacklist” approach: data flows to all foreign jurisdictions are permitted unless specifically disallowed. As of now, the government has not published any list of banned countries, so companies can continue to use global data storage or processing services. That said, organizations remain responsible for protecting the data even when it’s transferred abroad, and they must comply with any future government rules on cross-border transfer (for example, the government could introduce contractual or adequacy requirements via rules). It’s also worth noting that sectoral regulators in India (like RBI for banking data or IRDAI for insurance) have their own data localization norms that remain in force. The DPDP Act explicitly does not override stricter sectoral rules. In summary, cross-border transfers are permitted under the DPDP Act, provided that the Act’s overall obligations and any future specific restrictions are met; companies should monitor MeitY notifications on this topic.
A: The Act grants Data Principals a set of rights to give them more control over their personal data. Key rights include: Right to Information (to know what personal data of theirs is being collected and how it’s being used), Right to Access (to get a summary of their data held by a fiduciary), Right to Correction and Erasure (to correct inaccurate data or request deletion of data that is no longer needed), and Right to Grievance Redressal (to seek resolution of complaints about data handling). Individuals can also withdraw their consent at any time, as noted above, and the...
A: The Act grants Data Principals a set of rights to give them more control over their personal data. Key rights include: Right to Information (to know what personal data of theirs is being collected and how it’s being used), Right to Access (to get a summary of their data held by a fiduciary), Right to Correction and Erasure (to correct inaccurate data or request deletion of data that is no longer needed), and Right to Grievance Redressal (to seek resolution of complaints about data handling). Individuals can also withdraw their consent at any time, as noted above, and the Act gives them the right to nominate a representative to exercise their rights in the event of death or incapacity. For minors, parents/guardians act as their data principals and have similar rights on the child’s behalf.
From a compliance perspective, organizations must be ready to fulfill these rights. This involves establishing procedures for providing privacy notices that cover all required information, verifying and responding to user requests (e.g., updating or deleting data) within prescribed timelines, and setting up a grievance mechanism (such as a helpdesk or portal) to handle complaints. Under DPDP, if an individual requests correction or erasure and it’s valid, the Data Fiduciary must comply and also notify any third parties with whom the data was shared (draft rules are expected to clarify process details). Companies should also maintain verification and record-keeping for requests to ensure they are genuine and to log compliance. Essentially, user rights under the DPDP Act are similar to those under GDPR, minus data portability, and companies need to treat them seriously by building the required workflows (access reports, rectification forms, deletion confirmation, etc.). Failing to honor data principal rights can attract penalties up to ₹50 crore per instance, so automation and clear policies here are critical.
A: The Act obligates Data Fiduciaries to notify the Data Protection Board of India and affected data principals in the event of a “personal data breach” (i.e., unauthorized access or disclosure of personal data). While the Act itself does not specify a timeframe, the draft DPDP Rules 2025 propose a strict timeline (likely within 72 hours) for reporting breaches once detected, which is akin to global standards (hoganlovells.com). In practice, this means organizations must implement a robust incident response plan: as soon as a data breach is identified, an assessment should be done, and a report containing details of the...
A: The Act obligates Data Fiduciaries to notify the Data Protection Board of India and affected data principals in the event of a “personal data breach” (i.e., unauthorized access or disclosure of personal data). While the Act itself does not specify a timeframe, the draft DPDP Rules 2025 propose a strict timeline (likely within 72 hours) for reporting breaches once detected, which is akin to global standards (hoganlovells.com). In practice, this means organizations must implement a robust incident response plan: as soon as a data breach is identified, an assessment should be done, and a report containing details of the breach, its impact, and mitigation steps should be prepared for the DPB. Additionally, impacted individuals may need to be informed with recommendations on what they can do (e.g. reset passwords, watch for scams).
The DPDP Act also emphasizes the importance of reasonable security safeguards to prevent breaches in the first place. Compliance entails not only reactive measures but also proactive ones, such as encryption, access controls, and regular security audits. Suppose a company fails to protect personal data or fails to notify of a breach. In that case, the penalties are severe – up to ₹250 crore for failing to implement reasonable security measures to prevent a breach, and up to ₹200 crore for failing to notify a breach properly. Enterprises should invest in security infrastructure and also formulate a clear breach reporting protocol. In summary, if a breach happens: contain it, inform the authorities and users quickly, and take steps to prevent future incidents. Documentation of all these actions will be essential to demonstrate compliance with the DPB during any investigation.
A: The DPDP Act introduces steep financial penalties to enforce compliance. The Data Protection Board (DPB) can impose fines ranging from ₹50 crore up to ₹250 crore per violation, depending on the provision breached. The highest penalties (up to ₹250 Cr) are reserved for critical failures like not implementing security safeguards (leading to a personal data breach). Penalties up to ₹200 Cr apply to serious violations such as failing to notify the DPB and users about a data breach, or mishandling children’s personal data. For “routine” violations of obligations (e.g., not obtaining valid consent, ignoring data principal rights, processing data...
A: The DPDP Act introduces steep financial penalties to enforce compliance. The Data Protection Board (DPB) can impose fines ranging from ₹50 crore up to ₹250 crore per violation, depending on the provision breached. The highest penalties (up to ₹250 Cr) are reserved for critical failures like not implementing security safeguards (leading to a personal data breach). Penalties up to ₹200 Cr apply to serious violations such as failing to notify the DPB and users about a data breach, or mishandling children’s personal data. For “routine” violations of obligations (e.g., not obtaining valid consent, ignoring data principal rights, processing data for unauthorized purposes), fines up to ₹50 crore per incident can be levied. Importantly, these fines are “per instance”, so a recurring or large-scale lapse can multiply liability.
The Act empowers the DPB to determine the exact penalty within the allowed range by evaluating factors such as the nature and gravity of the breach, whether it was repetitive, whether the company gained financially, and the mitigation steps taken. There is no fixed minimum fine of ₹50 crore; rather, ₹50 crore is the maximum for certain categories of violations, but the DPB could impose a lower amount after considering the circumstances. On the other end, ₹250 Cr is the absolute cap per violation in the law. There is also a provision to discourage misuse by individuals: a Data Principal who files frivolous complaints or knowingly provides false information can be fined up to ₹10,000. Enforcement is expected to be digital and swift – organizations will likely be allowed to be heard. Still, there is no long grace period once the law is in effect. In short, non-compliance can be extremely costly, so investing in a compliance program is far cheaper than facing even a single penalty order.
A: Maybe – it depends on the scale of your data processing. The Act introduces the concept of Significant Data Fiduciaries (SDF), which are companies that handle large volumes of personal data or carry a high risk (criteria to be defined in the Rules, likely based on the number of users or the nature of sensitive activities). If your organization is designated as an SDF by the government, then yes, you will have extra obligations: you must appoint a Data Protection Officer (DPO) to oversee compliance, conduct periodic data protection impact assessments (DPIAs) for high-risk processing, undergo independent data audits,...
A: Maybe – it depends on the scale of your data processing. The Act introduces the concept of Significant Data Fiduciaries (SDF), which are companies that handle large volumes of personal data or carry a high risk (criteria to be defined in the Rules, likely based on the number of users or the nature of sensitive activities). If your organization is designated as an SDF by the government, then yes, you will have extra obligations: you must appoint a Data Protection Officer (DPO) to oversee compliance, conduct periodic data protection impact assessments (DPIAs) for high-risk processing, undergo independent data audits, and possibly register with the DPB. The DPO would have to be a senior official (or independent person) acting as a point of contact for the Board and data principals. These additional requirements aim to ensure stronger accountability for bigger players, similar to how GDPR treats large data controllers.
If you are not an SDF, the law does not mandate a formal DPO or audits – but you still need to implement appropriate internal controls and a grievance officer. Many organizations may voluntarily assign a privacy officer or conduct self-assessments as best practice. We are awaiting clear thresholds in the upcoming Rules to know who exactly falls into the “Significant” category. In the meantime, a good rule of thumb is: if you’re a sizable company or processing very sensitive personal data, prepare to meet these higher compliance standards. Regulators have indicated that they will consider factors such as the volume of data processed, turnover, and risk profile when classifying SDFs. Therefore, while small companies may avoid these specific obligations, large enterprises should be prepared to incorporate DPIAs, appoint a capable DPO, and engage certified auditors once the regime takes effect.
Privacy
Establishes key definitions – Personal Data refers to any information about an identifiable individual, and only digital personal data is covered (i.e., data collected or digitized electronically). Individuals are “Data...
Read MorePrivacy
Grants individuals robust rights over their data. These include the right to access information about what data a fiduciary has about them, right to correction of inaccurate or misleading data,...
Read MorePrivacy
Imposes several duties on organizations that handle personal data. Every Data Fiduciary must ensure processing is based on a valid legal basis – primarily, this means obtaining explicit consent from...
Read MorePrivacy
The Act requires every Data Fiduciary to have a procedure for addressing grievances of Data Principals. Typically, this means designating a grievance officer and publishing their contact details. When an...
Read MorePrivacy
Since the passage of the DPDP Act in 2023, there have been ongoing efforts to clarify and operationalize the law, as well as scrutiny from various stakeholders. Here are the...
Read MorePrivacy
In June 2025, MeitY published a Business Requirement Document (BRD) for Consent Management under the DPDP Act. This is a technical guideline (not legally binding, but highly informative) that describes...
Read MorePrivacy
The government has been in the process of setting up the Data Protection Board of India (DPB), a regulatory authority established by the Act. In late 2023, the IT Ministry...
Read MorePrivacy
Recognizing that the DPDP Act marks a significant change, MeitY engaged in continuous dialogue with industry and other stakeholders. In September 2023, it hosted the Digital India Dialogue with tech...
Read MorePrivacy
As of November 2025, there have been no official amendments to the DPDP Act; the law remains unchanged since its passage in 2023. However, public discourse and expert commentary continue...
Read MorePrivacy
The DPDP Act’s rollout comes at a time when data privacy laws worldwide are becoming increasingly stringent. India’s law has been compared to the EU’s GDPR, and in many ways,...
Read More