DPDP Act 2023 explained: a practical guide for Indian businesses

Updated 19 Sep 2026 · 7min read · Reviewed by ConsentLo's DPDP audit team

The Digital Personal Data Protection Act, 2023 (the DPDP Act) is India's first comprehensive law on personal data. It decides when an organisation may use personal data, what it must tell people, what rights those people have, and what happens when things go wrong. This guide explains it in plain language.

Who the DPDP Act applies to

The Act applies to digital personal data: data collected online, and data collected offline that is later digitised. It covers processing in India, and processing outside India when it is connected to offering goods or services to people in India.

It uses four roles. A Data Fiduciary decides why and how personal data is processed (usually your company). A Data Processor processes data on its behalf (your cloud, courier or marketing vendor). A Data Principal is the individual the data is about. A Consent Manager is a registered platform that helps people give, manage and withdraw consent.

When you are allowed to use personal data

There are two lawful grounds. The main one is consent. The other is a short list of "legitimate uses", such as data a person voluntarily gives for a specific purpose, employment, compliance with law, medical emergencies and certain State functions.

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Pre-ticked boxes and consent buried in terms of service do not qualify. Every request for consent must come with a notice, available in English or any of the 22 languages in the Eighth Schedule of the Constitution.

Rights of Data Principals

Individuals get a practical set of rights that your team must be able to honour on time:

  • Access a summary of their personal data and who it has been shared with.
  • Correct, complete, update or erase their personal data.
  • Withdraw consent as easily as they gave it.
  • Have a grievance redressed by you, and then complain to the Data Protection Board of India.
  • Nominate someone to exercise these rights on their behalf in case of death or incapacity.

Obligations of a Data Fiduciary

You must keep personal data accurate where it is used for decisions, protect it with reasonable security safeguards, erase it once the purpose is served (unless a law requires retention), publish the contact of a person who answers questions on data, and run a grievance process.

Processors may only act under a valid contract. When a person withdraws consent or asks for erasure, your processors must stop and erase too.

Children and persons with disability

For anyone under 18, and for persons with disability who have a lawful guardian, you need verifiable consent from the parent or guardian. Tracking, behavioural monitoring and targeted advertising directed at children are not allowed.

Personal data breaches

If there is a personal data breach, you must inform the Data Protection Board and every affected Data Principal. The DPDP Rules, 2025 set the detail, including a full report to the Board within 72 hours.

Significant Data Fiduciaries

The Government can notify some organisations as Significant Data Fiduciaries based on the volume and sensitivity of data and risk to people. They must appoint a Data Protection Officer based in India, engage an independent data auditor and carry out periodic Data Protection Impact Assessments and audits.

Penalties and the Data Protection Board

The Data Protection Board of India investigates complaints and breaches and can impose penalties of up to ₹250 crore per instance, depending on the obligation breached. Appeals go to the Appellate Tribunal (TDSAT).

How to get compliant

Start by mapping what personal data you hold and why, then fix your notices and consent capture, set up processes for rights and grievances, prepare your breach response, and keep evidence of everything. ConsentLo runs each of these as a workflow, with the deadlines built in.

Frequently asked questions

Is the DPDP Act in force?

The Act was passed in August 2023. The DPDP Rules, 2025 were notified in November 2025 and bring the Act into force in phases over about 18 months, so most business obligations apply from 2027. Preparation takes time, so organisations are starting now.

Does the DPDP Act apply to small businesses?

Yes. It applies to any organisation that processes digital personal data, whatever its size. The Government may exempt some classes, such as certain startups, from specific obligations by notification.

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach. Other obligations carry penalties of up to ₹200 crore, ₹150 crore or ₹50 crore.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.