IN · DPDP Lite Checker

Digital Personal Data Protection Act

Privacy
Summary

A concise overview of the Digital Personal Data Protection Act, explaining applicability, key rights and duties, compliance needs, penalties and the path toward full enforcement.

View on Batoi Secure
Regulator

Ministry of Electronics and IT (MeitY)

Focus area

Privacy & Personal Data Governance

Status

Assented August 2023 · Enforcement January 2024

Enforcement Risk

High · Penalties up to INR 250 crores

Provisions

Privacy

Establishes key definitions – Personal Data refers to any information about an identifiable individual, and only digital personal data is covered (i.e., data collected or digitized electronically). Individuals are “Data...

Read More

Privacy

Grants individuals robust rights over their data. These include the right to access information about what data a fiduciary has about them, right to correction of inaccurate or misleading data,...

Read More

Privacy

Imposes several duties on organizations that handle personal data. Every Data Fiduciary must ensure processing is based on a valid legal basis – primarily, this means obtaining explicit consent from...

Read More

Privacy

The Act requires every Data Fiduciary to have a procedure for addressing grievances of Data Principals. Typically, this means designating a grievance officer and publishing their contact details. When an...

Read More

Privacy

The Act prescribes hefty financial penalties to drive compliance. There are six categories of violations, each with a maximum fine capped by the law. For most general obligations (such as...

Read More

Privacy

The DPDP Act carves out certain exemptions, under which some or all provisions of the law will not apply. These are generally in contexts where imposing consent or other requirements...

Read More