India flag

India

India Data Privacy Laws: DPDP Act 2023 and DPDP Rules 2025 Complete Guide

Independently fact-checked against primary sources (last audited June 19, 2026). · 9 primary sources cited on this page. How we verify our legal content

India Data Privacy Laws: DPDP Act 2023 and DPDP Rules 2025 Complete Guide

Frequently Asked Questions

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) is India's first comprehensive statute governing the processing of digital personal data. Parliament enacted it on August 11, 2023. It establishes the roles of Data Fiduciary and Data Principal, sets out lawful bases for processing, creates individual rights, and constitutes the Data Protection Board of India as the regulatory enforcement body. The implementing DPDP Rules were notified by MeitY on November 13, 2025.

When does the DPDP Act take full effect?

The Act is being enforced through a three-phase rollout. Phase 1 took effect on November 13, 2025, establishing the Data Protection Board. Phase 2 activates the consent manager registration framework on November 13, 2026. Phase 3, requiring full compliance with all substantive obligations including consent notices, data principal rights, breach notification, and Significant Data Fiduciary requirements, takes effect on May 13, 2027.

What are the maximum penalties under the DPDP Act?

The highest penalty under Schedule 1 is INR 250 crore (approximately USD 30 million) for failure to implement reasonable security safeguards that leads to a personal data breach. Failure to notify the Board and affected individuals of a data breach, and breach of children's data obligations, each carry up to INR 200 crore. Significant Data Fiduciary violations carry up to INR 150 crore. All other Act or Rules violations carry up to INR 50 crore. Data Principal duty violations carry up to INR 10,000. The DPBI must conduct an inquiry before imposing any penalty.

Can Indian personal data be transferred outside India?

Yes. The DPDP Act uses a negative-list approach under Section 16: personal data may be transferred to any country unless the Central Government specifically restricts that jurisdiction. As of May 2026, the Central Government had not published any list of restricted jurisdictions, so transfers to all countries remain permissible. Restrictions can be imposed without a mandated transition period; organisations should monitor MeitY notifications.

Does the DPDP Act apply to foreign companies?

Yes. The Act applies to processing of digital personal data outside India when it is done in connection with providing goods or services to Data Principals located within India. Foreign companies that offer Indian-language apps, accept Indian Rupee payments, or otherwise target Indian consumers must assess their DPDP Act compliance obligations regardless of where they are incorporated.

How does the DPDP Act handle children's data?

The Act defines a child as anyone under 18 years of age. Before processing a child's personal data, a Data Fiduciary must obtain verifiable parental consent, including verification of the guardian's identity, age, and parent-child relationship. Behavioural monitoring, tracking, and targeted advertising directed at children are expressly prohibited. The Central Government may lower the threshold to 16 or 13 for specific Data Fiduciaries demonstrating verifiably safe data processing; no such designations had been made as of May 2026.

What is a consent manager under the DPDP Act?

A consent manager is an entity registered with the Data Protection Board that allows individuals to manage their data processing consents across multiple platforms through a single interoperable interface. Consent managers must be Indian-incorporated companies with a minimum net worth of INR 2 crore, deploy AES-256 encryption, and act in a fiduciary capacity toward Data Principals. The consent manager registration framework activates on November 13, 2026 under Phase 2 of the rollout.

What is a Significant Data Fiduciary?

A Significant Data Fiduciary (SDF) is a Data Fiduciary designated by the Central Government based on the volume and sensitivity of personal data it processes, the risk of harm to Data Principals, or the potential impact on India's sovereignty, security, or public order. SDFs must appoint an India-based Data Protection Officer, conduct annual Data Protection Impact Assessments, undergo independent annual audits, and appoint an algorithmic auditor. They may also face data localisation requirements. As of May 2026, MeitY had not published an initial SDF list.

What is the constitutional basis for the DPDP Act?

The DPDP Act rests on the Supreme Court's nine-judge ruling in K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, which unanimously held that privacy is a fundamental right traceable to Articles 14, 19, and 21 of the Constitution of India. The Puttaswamy judgment applied a proportionality standard to state interference with privacy and overruled two earlier decisions that had denied constitutional privacy protection. The DPDP Act's preamble explicitly invokes this constitutional mandate.

How does the DPDP Act differ from the GDPR?

Key differences: the DPDP Act covers only digital personal data while the GDPR covers all personal data; the DPDP Act has no broad legitimate-interests legal basis; it does not create separate sensitive-data categories; it omits rights to data portability and objection to automated decisions; it requires notification of all breaches rather than only those posing risk to individual rights; and it uses a negative-list model for cross-border transfers rather than adequacy decisions. The DPDP Act's consent manager framework has no GDPR equivalent. The Act's maximum penalty of INR 250 crore is lower than the GDPR's cap of EUR 20 million or 4% of global annual turnover.

What replaces the SPDI Rules under the IT Act 2000?

The DPDP Act will supersede Section 43A of the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, when Phase 3 provisions take full effect on May 13, 2027. Until then, organisations with potential SPDI exposure should treat both regimes as concurrently applicable and apply the higher standard.

Does the DPDP Act create a private right of action?

No. Enforcement under the DPDP Act is exclusively through the Data Protection Board of India. Individual Data Principals have no right to sue a Data Fiduciary directly for DPDP Act violations in a civil court. The right to file a complaint with the DPBI and escalate unresolved grievances to TDSAT is the primary individual remedy.

Updates

Independently fact-checked against the cited primary sources

Full refresh: expanded from 2,850 to 6,200 words. Added Puttaswamy constitutional foundation, DPDP Rules 2025 detailed coverage (notified November 13, 2025), startup and MSME simplified compliance, DPBI appointment status, expanded GDPR comparison table, UpdatesLog, and extended FAQ to 12 questions.

Initial publication covering DPDP Act 2023 and draft Rules.

Sources and References

  1. Digital Personal Data Protection Act, 2023 - Ministry of Electronics and Information Technology (MeitY)(meity.gov.in).gov
  2. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) - Official Gazette Text(meity.gov.in).gov
  3. India Code: Digital Personal Data Protection Act, 2023(indiacode.nic.in).gov
  4. India Code: Digital Personal Data Protection Act, 2023 - Full Text PDF(indiacode.nic.in).gov
  5. Government notifies DPDP Rules to empower citizens and protect privacy - PIB, November 2025(pib.gov.in).gov
  6. DPDP Rules 2025 - Press Information Bureau Full Document(static.pib.gov.in).gov
  7. Digital Personal Data Protection Rules, 2025 - MeitY Official Page(meity.gov.in).gov
  8. Simplified compliance framework for start-ups and certain data fiduciaries under DPDP Act and Rules - PIB(pib.gov.in).gov
  9. K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 - Supreme Court of India Digital SCR(digiscr.sci.gov.in).gov
  10. The Digital Personal Data Protection Bill, 2023 - PRS Legislative Research(prsindia.org)
  11. With rules finalized, India DPDPA takes force - IAPP(iapp.org)
  12. Top 10 operational impacts of India DPDPA: Cross-border data transfers - IAPP(iapp.org)
  13. Top 10 operational impacts of India DPDPA: Enforcement and the Data Protection Board - IAPP(iapp.org)
  14. Data Protection Laws and Regulations Report 2025-2026 India - ICLG(iclg.com)
Share: