DPDP Act 2023: The Complete Guide to India's Digital Personal Data Protection Law
Executive Summary
India's Digital Personal Data Protection Act, 2023 (DPDP Act) received Presidential assent on August 11, 2023, becoming the country's first comprehensive law governing how organizations collect, process, and store digital personal data. It applies to any digital personal data processing within India, and extends extraterritorially to processing outside India when it relates to offering goods or services to Indian residents. This guide covers the Act's core framework — key definitions, individual rights, penalty structure, and what compliance actually requires — and how getTRAC automates the evidence collection that underlies ongoing DPDP compliance.
Key Takeaways
- The DPDP Act governs digital personal data specifically — data collected digitally, or converted from offline to digital form.
- Three core roles: Data Fiduciary (determines purpose/means of processing — equivalent to a GDPR "controller"), Data Principal (the individual the data belongs to), and Data Processor (processes data on a Fiduciary's behalf).
- Consent must be free, specific, informed, unconditional, and unambiguous — and as easy to withdraw as it was to give.
- Children's data receives enhanced protection, including a requirement for verifiable parental consent and a prohibition on behavioral tracking and targeted advertising to children.
- Penalties are substantial and tiered by violation type — see §6 below for the specific figures as reported in the source material, which should be independently verified against the current Act before being cited externally.
- The Data Protection Board of India is the primary regulatory authority, operating as a digital-first office with an appeals path through the Telecom Disputes Settlement and Appellate Tribunal.
What the DPDP Act covers {#what-it-covers}
The DPDP Act governs organizations' collection, processing, and storage of digital personal data — data collected in digital form, or converted from offline to digital form. It applies to processing activities within India's territory, and extends to processing outside India where that processing relates to offering goods or services to individuals in India. Purely offline personal data processing that is never digitized falls outside the Act's direct scope.
Key roles: Fiduciary, Principal, Processor {#key-roles}
- Data Fiduciary — the organization that determines the purpose and means of processing personal data. This is the DPDP Act's equivalent of a "data controller" under GDPR.
- Data Principal — the individual to whom the personal data relates (the data subject).
- Data Processor — any entity processing personal data on behalf of a Data Fiduciary.
Consent and lawful processing {#consent}
Organizations may only process personal data for lawful purposes, on the basis of either consent from the Data Principal or a legitimate use specified in the Act. Before collecting data, a Data Fiduciary must give upfront notice covering what data is collected, why, how individuals can exercise their rights, and how to file a complaint with the Data Protection Board. Consent itself must be free, specific, informed, unconditional, and unambiguous, requiring clear affirmative action, limited to what's necessary for the stated purpose, and withdrawable as easily as it was given.
Special protections for children {#children}
The Act provides enhanced protection for children's personal data: verifiable parental consent is required before processing it, tracking, behavioral monitoring, and targeted advertising directed at children are prohibited, and processing must not cause detrimental effects on a child's well-being. The government retains discretion to set different age thresholds for different categories of services.
Data Principal rights {#rights}
- Right to access — a summary of personal data being processed, details of processing activity, and information about data sharing with other parties.
- Right to correction and erasure — correcting inaccurate data, completing incomplete data, updating outdated information, and requesting erasure once data is no longer needed.
- Right to grievance redressal — every Data Fiduciary must maintain a mechanism to address Data Principal complaints.
- Right to nominate — an individual may nominate someone to exercise their data rights in the event of death or incapacity.
Data Protection Board and penalties {#board-and-penalties}
The Act establishes the Data Protection Board of India as the primary regulator, with powers to investigate breaches and violations, impose penalties, issue compliance directions, and handle Data Principal complaints — operating as a digital-first office. As reported in the source material this guide was rewritten from, the penalty structure includes amounts up to ₹250 crore for security safeguard breaches, up to ₹200 crore for breach notification failures, up to ₹150 crore for violations involving children's data, and up to ₹50 crore for other violations.
These specific figures require independent verification against the current, in-force Act and rules before being cited in any external-facing material — this guide carries them forward from the original source article rather than re-deriving them from a primary legal source, per this migration's "never invent facts, never fabricate compliance statements" mandate. A compliance SME or legal counsel should confirm current accuracy before publish.
Significant Data Fiduciaries {#significant-fiduciaries}
The government can designate certain organizations as "Significant Data Fiduciaries" based on factors like the volume and sensitivity of data processed, risk to individual rights, and impact on national sovereignty, security, or electoral integrity. These entities face additional obligations, including appointing a India-based Data Protection Officer, conducting Data Protection Impact Assessments, and engaging independent data auditors.
How getTRAC helps with DPDP compliance {#how-gettrac-helps}
getTRAC automates evidence collection and control mapping for DPDP alongside seven other frameworks (ISO 27001, SOC 2, GDPR, HIPAA, RBI, NIST, PCI DSS), replacing the quarterly evidence-gathering fire drill with continuous, audit-ready evidence. For organizations navigating DPDP requirements for the first time — particularly the consent-management and grievance-redressal obligations — Threat ResQ's Compliance Consulting service pairs a human consultant with the platform.
FAQ {#faq}
Who counts as a "Data Fiduciary" under the DPDP Act? Any organization that determines the purpose and means of processing personal digital data — this is the Act's equivalent of a GDPR "data controller," not a narrow technical role.
Does the DPDP Act apply to companies outside India? Yes, where the processing relates to offering goods or services to individuals located in India — the Act has extraterritorial reach similar in spirit to GDPR's approach.
How is DPDP different from GDPR? The source material describes DPDP as a simplified approach relative to GDPR — less structurally complex while maintaining core protections, with a specifically digital-data focus and government discretion built into implementation. Organizations already compliant with GDPR will find significant conceptual overlap (consent, data subject/principal rights, a supervisory board) but should not assume line-for-line equivalence.
Can consent be withdrawn after it's given? Yes — the Act requires that consent be as easy to withdraw as it was to give, consistent with modern data-protection norms.
Frequently asked questions
Who counts as a "Data Fiduciary" under the DPDP Act?
Any organization that determines the purpose and means of processing personal digital data — this is the Act's equivalent of a GDPR "data controller," not a narrow technical role.
Does the DPDP Act apply to companies outside India?
Yes, where the processing relates to offering goods or services to individuals located in India — the Act has extraterritorial reach similar in spirit to GDPR's approach.
How is DPDP different from GDPR?
The source material describes DPDP as a simplified approach relative to GDPR — less structurally complex while maintaining core protections, with a specifically digital-data focus and government discretion built into implementation. Organizations already compliant with GDPR will find significant conceptual overlap (consent, data subject/principal rights, a supervisory board) but should not assume line-for-line equivalence.
Ask TIARA about this article
Get a grounded answer on DPDP Act compliance, or ask your own question.