What Is the DPDP Act? Scope, Obligations and Timelines, Explained
India's DPDP Act 2023 and its 2025 Rules: who counts as a Data Fiduciary, what you must actually do, the penalty caps and the phased commencement dates.
What Is the DPDP Act? Scope, Obligations and Timelines, Explained
The Digital Personal Data Protection Act 2023 is India's general data protection statute. It covers digital personal data processed in India, and processing abroad connected to offering goods or services in India. Its Rules were notified in November 2025 and commence in phases, with most substantive duties landing eighteen months later.
What the DPDP Act is
The Digital Personal Data Protection Act, 2023 is India's first cross-sector statute dedicated to personal data. It runs to 44 sections and pushes most operating detail into subordinate rules.
Two design choices shape everything else. It covers digital personal data only: collected in digital form, or on paper and later digitised. And it recognises two lawful bases, consent under section 6 or one of the "certain legitimate uses" in section 7. There is no legitimate-interests balancing test and no separate category of sensitive personal data.
The Act sat uncommenced for two years. On 13 November 2025 MeitY notified the Digital Personal Data Protection Rules, 2025 as G.S.R. 846(E), with a companion notification staging the Act into force.
Who it applies to
Section 3(a) covers processing within India. Section 3(b) reaches abroad, to "processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India". A company with no Indian entity that sells to Indian consumers is in scope. Excluded: purely personal or domestic processing, and data the Data Principal has herself made public.
There is no revenue threshold, no headcount threshold and no business-to-business carve-out. Determine the purpose and means of processing and you are a Data Fiduciary, with your customers' employee contact records in scope.
Five roles matter. The Data Principal is the individual. The Data Fiduciary determines purpose and means. The Data Processor acts on a Fiduciary's behalf. A Significant Data Fiduciary (SDF) is one notified under section 10(1), on volume and sensitivity of data, risk to Data Principals' rights, and risk to sovereignty, electoral democracy, security of the State and public order. A Consent Manager gives a Data Principal one interoperable place to give, review and withdraw consent.
[NEEDS SOURCE: whether any Data Fiduciary or class of Data Fiduciaries has yet been notified as a Significant Data Fiduciary, and the notification reference.]
What it requires
| Obligation | Source | In practice |
|---|---|---|
| Notice | s.5; Rule 3 | Itemised data and purposes, plain language, standalone, with links to withdraw consent and complain to the Board |
| Consent | s.6 | Free, specific, informed, unconditional, unambiguous; limited to necessary data; withdrawable with comparable ease |
| Erasure | s.8(7); Rule 8 | On withdrawal, or when the specified purpose is no longer served, whichever is earlier |
| Security | s.8(5); Rule 6 | Encryption, masking or tokenisation, access control, monitoring, backups; logs kept at least one year |
| Breach intimation | s.8(6); Rule 7 | Affected Data Principals without delay; particulars to the Board within seventy-two hours |
| Rights and grievances | ss.11 to 14; Rule 14 | Publish the means to exercise rights; respond within ninety days at the outside |
| Contact person | s.8(9); Rule 9 | Publish details of the DPO, or of someone who can answer processing questions |
| SDF additions | s.10; Rule 13 | India-based DPO, independent auditor, DPIA and audit every twelve months, algorithmic due diligence, Rule 13(4) localisation |
| Consent Manager | s.6(9); Rule 4 | Indian company, net worth at least two crore rupees, certified platform, records kept seven years |
Rule 1(2) sets the phasing. Rules 1, 2 and 17 to 21 came into force on publication in the Official Gazette; Rule 4 (Consent Manager registration) one year after; Rules 3, 5 to 16, 22 and 23 eighteen months after. The Act is staged the same way: definitions, the Board's establishment and the amendments to the Right to Information Act 2005 and the TRAI Act 1997 are live now, and everything in the table above lands at eighteen months.
The Rules are dated 13 November 2025 and were published the next day, so the milestones fall on 13 or 14 November 2026 and 13 or 14 May 2027. Plan to the earlier date. In early 2026 MeitY also circulated a proposal to shorten the SDF window to twelve months and advance Rules 13(4) and 15. [NEEDS SOURCE: date of publication in the Official Gazette, gazette number of the Act's commencement notification, and whether the 2026 amendment proposal has been notified.]
What happens if you do not comply
The Data Protection Board of India inquires into breaches and imposes penalties under section 33. The Schedule sets the caps:
| Breach | Cap |
|---|---|
| Failure to take reasonable security safeguards | 250 crore rupees |
| Failure to notify a breach to the Board or Data Principals | 200 crore rupees |
| Children's-data obligations | 200 crore rupees |
| SDF obligations | 150 crore rupees |
| A Data Principal's own duties | 10,000 rupees |
| Any other breach | 50 crore rupees |
The Board runs as a digital office under Rule 20; appeals go to the Appellate Tribunal under Rule 22.
One caveat. As of mid-2026 the Board existed in law but had no appointed Chairperson or Members, nominations having been sought in May and June 2026. A body with no members cannot impose a penalty, which is why the eighteen-month date matters more today than enforcement risk. [NEEDS SOURCE: current constitution of the Data Protection Board of India, names and dates of appointment.]
Related terms
- Consent Manager: Board-registered Indian company letting a Data Principal manage consent across many Fiduciaries; records kept at least seven years.
- Significant Data Fiduciary: Fiduciary notified under section 10, carrying an annual DPIA and audit plus algorithmic due diligence.
- Notice: the standalone, itemised, plain-language statement required at or before consent (s.5, Rule 3).
- Purpose limitation: consent covers only the specified purpose, and data must go once that purpose ends.
- Breach intimation: Rule 7 duty to tell affected individuals without delay and file particulars with the Board within seventy-two hours.
FAQ
Is the DPDP Act in force yet? Partly. Definitions, the Board's establishment and the consequential amendments took effect in November 2025. Consent Manager registration follows at twelve months. Notice, consent, security, breach reporting, rights and enforcement follow at eighteen months, in mid-May 2027.
Does it apply to employee data? Yes. Section 7 treats employment purposes, and safeguarding the employer from loss or liability, as legitimate uses, so consent is not always the basis. Notice, security, erasure and grievance duties still apply.
Does the Act block sending data abroad? Not by default. Rule 15 permits transfer subject to requirements the Central Government may specify, and Rule 13(4) lets it confine specified categories held by SDFs to India. [NEEDS SOURCE: whether any country, territory or data category has been notified under Rule 15 or Rule 13(4).]
Where a system helps
If you run AI agents over customer data, the duty with no natural owner is showing what an automated process collected, why, and where it wrote. CohortaOS records that on every agent run, so a notice, an erasure request or a breach timeline can be rebuilt from evidence.
Related reading: The DPDP Act and AI Systems: Consent Managers, Notices and Data Principal Rights (KB-006).
