1. Executive Context
India's data protection regime is now operational. The Digital Personal Data Protection Act, 2023 (the DPDP Act) received assent in August 2023, and the DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025. The Rules trigger an 18-month, three-phase implementation that concludes in May 2027 with full enforcement of Data Fiduciary obligations.
This matters well beyond Indian borders. The Act applies extraterritorially to processing of digital personal data outside India when it is connected with offering goods or services to individuals within India. Global companies — from the United States, the Gulf, Europe and Asia — that serve Indian customers must plan for the regime alongside GDPR, sector laws and customer contracts.
2. What the DPDP Act Is
The DPDP Act is India's national data protection law. It provides for the processing of digital personal data in a manner that recognizes both the right of individuals to protect their personal data and the need to process such data for lawful purposes. It is Act No. 22 of 2023, drafted in a deliberately simple, plain-language style ("SARAL" — Simple, Accessible, Rational and Actionable), with illustrations rather than dense legal prose.
A framework law
The Act is intentionally principles-based. It relies on delegated legislation — the DPDP Rules, 2025 — to define operational details such as notice formats, retention periods, breach reporting procedures and the functioning of the Data Protection Board of India (DPB). Teams that read only the Act will miss the enforceable detail, which now lives in the Rules.
What it replaced
The Act followed a long lineage: the 2017 Puttaswamy right-to-privacy judgment, the 2018 Srikrishna committee report, the Personal Data Protection Bill 2019 (withdrawn in 2022) and the draft DPDP Bill 2022. The final 2023 Act is leaner than earlier drafts and closer to a consent-and-accountability model than a broad rights-based code.
Who it covers
The Act applies to Data Fiduciaries (entities that determine the purpose and means of processing) and grants rights to Data Principals (the individuals whose data is processed). It establishes the Data Protection Board of India as an independent adjudicatory body and relies on financial penalties rather than criminal sanctions.
For a full treatment of the operational rules, see the DPDP Act timeline and compliance deadlines article.
3. Scope and Applicability
Territorial scope (Section 3)
The Act applies to the processing of digital personal data within the territory of India, whether the data was collected digitally, or collected offline and subsequently digitized.
Extraterritorial reach
The Act also applies to processing of digital personal data outside India if that processing is in connection with offering goods or services to individuals within India. This is the single most important clause for international companies: serving Indian residents — through apps, e-commerce, SaaS, fintech, gaming, insurance or B2B platforms — can place the processing in scope even when the company has no physical presence in India.
What is excluded
The Act does not apply to non-personal data, offline data that remains in physical formats and data processed by an individual for purely personal or domestic purposes. State instrumentalities can be exempted by the Central Government in the interest of sovereignty, national security, friendly relations with foreign states or public order (Section 17). Exemptions also cover research, archiving, statistical purposes, judicial duties and ascertainment of financial liabilities for loan defaults.
4. Key Definitions
| Term | Meaning |
|---|---|
| Personal data | Any data about an individual who is identifiable by or in relation to such data. |
| Data Principal | The individual to whom the personal data relates. |
| Data Fiduciary | Any person who, alone or with others, determines the purpose and means of processing personal data. |
| Significant Data Fiduciary (SDF) | A Data Fiduciary or class of fiduciaries designated by the Central Government based on volume and sensitivity of data, risk to electoral democracy, public order or sovereignty. |
| Consent Manager | A registered digital intermediary that provides a platform to enable a Data Principal to give, manage, review and withdraw consent across Data Fiduciaries. |
| Data Protection Board of India (DPB) | The independent body that directs investigations into breaches, inquires into complaints and imposes financial penalties. |
| Data Protection Officer (DPO) | An individual, based in India, that an SDF must appoint and register to represent the SDF under the Act. |
These definitions drive everything else. For example, a "Consent Manager" is a separate, registered category — it does not describe your own consent screen. Your product collects consent; a Consent Manager is an independent platform through which users can manage consent across multiple fiduciaries.
5. Section-by-Section Walkthrough
The Act is short enough to walk through section by section. This is the map most executives need before they dive into detailed controls.
| Section | Topic | Core obligation |
|---|---|---|
| S.3 | Application | Digital personal data in India; extraterritorial reach for goods/services to Indian residents. |
| S.4 | Lawful processing | Processing only for a lawful purpose, with consent or under specified grounds. |
| S.5 | Notice | Itemized notice before or at the time of collecting personal data or seeking consent. |
| S.6 | Consent | Free, specific, informed, unconditional and unambiguous consent with easy withdrawal. |
| S.7 | Consent request rules | Consent requests clear and accessible; no denial of goods/services if data is not necessary for the purpose. |
| S.8 | General obligations | Reasonable security safeguards, purpose limitation, retention limits and grievance mechanism. |
| S.9 | Children | Verifiable parental consent; no tracking, behavioral monitoring or targeted advertising directed at children. |
| S.10 | SDF designation | Additional obligations for Significant Data Fiduciaries. |
| S.11-14 | Data Principal rights | Access, correction, erasure, grievance redressal and nomination. |
| S.15 | Data Principal duties | No false or frivolous complaints, no impersonation, no suppression of material information. |
| S.16 | Cross-border transfer | Global transfers permitted unless the Central Government restricts a territory. |
| S.17 | Exemptions | State instrumentalities, research, archiving, statistics, judicial functions, loan-default ascertainment. |
| S.18 | DPB | Establishment of the Data Protection Board of India. |
| Schedule | Penalties | Financial penalties up to ₹250 crore and ₹200 crore for specified violations. |
Note that the Act's numbering changed in the version that was passed; always verify section numbers against the official gazette text, which is cited in Sources and Review.
6. The Consent Framework
Consent is the engine of the DPDP regime. Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action — and it must be as easy to withdraw as to give. Under Section 5, a request for consent must be preceded by a notice that is itemized and easy to understand.

Notice before consent
Data Fiduciaries must provide a notice that specifies, in plain and itemized language: what personal data is collected, the purpose of processing, how the Data Principal can exercise rights and submit complaints, and a way to contact the fiduciary. Under the 2025 Rules, notices must be made available in English and all 22 scheduled Indian languages.
Consent quality
Consent cannot be inferred from silence or inaction. Pre-ticked boxes do not satisfy the "clear affirmative action" requirement. The request for consent must be presented separately from other matters and in a manner that is easily accessible and understandable — avoiding "dark patterns" that make withdrawal difficult.
Consent Managers
From Phase 2 (November 2026), registered Consent Managers will let individuals give, review and withdraw consent across multiple Data Fiduciaries from a single dashboard. This changes consent architecture: your systems should be designed to recognize and honor consent records maintained through a Consent Manager, not only consent captured on your own properties.
Purpose limitation and necessity
Processing must be limited to the purpose for which data was collected, and personal data may not be retained beyond what is necessary for that purpose. Section 7 requires that consent requests must not be bundled such that refusing unnecessary data means losing access to goods or services.
For a deeper treatment, see DPDP Act consent requirements.
7. Data Principal Rights and Duties
Rights of the Data Principal (Sections 11-14)
- Right to access: obtain a summary of personal data being processed and the identities of third parties with whom it has been shared.
- Right to correction and erasure: correct inaccurate or misleading data and request erasure once the purpose is fulfilled.
- Right to grievance redressal: register complaints with the Data Fiduciary; where the fiduciary fails to resolve, appeal to the Data Protection Board.
- Right to withdraw consent: withdraw consent with the same ease as giving it; processing based on consent must stop after withdrawal.
- Right to nominate: nominate an individual who can exercise rights on the Data Principal's behalf in the event of death or incapacity.
Under the 2025 Rules, fiduciaries must build clear channels for exercising these rights and must redress grievances within a defined period (generally 90 days).
Duties of the Data Principal (Section 15)
Unlike the GDPR, the DPDP Act imposes statutory duties on individuals. A Data Principal must not register false or frivolous grievances, impersonate another person or suppress material information while providing personal data. Violations can incur a financial penalty of up to ₹10,000.
8. Children's Data and Verifiable Parental Consent
Section 9 and the 2025 Rules place strict conditions on processing the personal data of children (individuals under 18).
- Verifiable parental consent: Data Fiduciaries must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data.
- Age verification: the Rules require mechanisms to verify the identity and age of the parent or guardian.
- Prohibited uses: fiduciaries may not process children's data for tracking, behavioral monitoring or targeted advertising directed at children.
- Exemptions: certain categories — such as healthcare professionals, educational institutions and child-transport providers — are exempt from parts of the parental-consent requirement because of the nature of their services.
Failure to comply with children's-data obligations can attract penalties up to ₹200 crore, the same tier as breach-notification failure. Product teams building edtech, gaming, social or health services that touch minors must treat this as a first-class design requirement, not a policy footnote. See verifiable parental consent explained.
9. Significant Data Fiduciaries
The Central Government may designate a Data Fiduciary or a class of fiduciaries as a Significant Data Fiduciary (SDF) based on factors such as the volume and sensitivity of personal data processed, the risk of harm to Data Principals, the risk to electoral democracy, and potential impact on public order and sovereignty.
SDF obligations
Once designated, an SDF faces heightened duties under Section 10 and the Rules:
- Data Protection Officer: appoint a DPO based in India and register the DPO with the Board, representing the SDF under the Act.
- Data Protection Impact Assessment (DPIA): conduct a DPIA before processing that poses a high risk to Data Principals, and review it periodically (annual DPIA per the Rules).
- Independent data audit: undergo an annual independent data audit by a registered auditor and publish the audit report.
- Algorithmic transparency: undertake algorithmic transparency and fairness assessments where decisions materially affect Data Principals.
- Enhanced due diligence: apply stricter technical due diligence for data processing systems and any new technologies used.
Most organizations will not be designated SDFs, but the SDF regime signals where the regulator expects the strongest evidence. Non-SDF fiduciaries should still adopt proportionate versions of these controls — see SDF obligations, DPO and DPIA.
10. Cross-Border Data Transfer
Section 16 takes a "blacklist" approach, which is a deliberate contrast to the GDPR's "whitelist" of adequacy-approved countries.
| Model | How it works |
|---|---|
| DPDP (blacklist) | Transfers of personal data outside India are permitted to any country unless the Central Government notifies a restriction for a specific territory. |
| GDPR (whitelist) | Transfers outside the EEA are permitted only to countries with an adequacy decision or with appropriate safeguards such as SCCs. |
For international companies, this means Indian personal data can generally flow to your existing infrastructure in the US, Europe, the Gulf or Asia without country-level blocking — until and unless a restriction is notified. Practical planning still matters: contracts with Indian counterparties, customer expectations and sector rules may impose their own transfer conditions, and future notifications could change the picture. Keep an eye on MeitY notifications and review transfer architecture whenever new restrictions are published.
11. Breach Response and the Data Protection Board
Breach notification (Section 8(6) and the Rules)
When a Data Fiduciary becomes aware of a personal data breach, it must notify the Data Protection Board and each affected Data Principal "without delay." The initial notification must be followed by a detailed report to the Board within 72 hours, covering the nature of the breach, the number of affected users and the mitigation steps taken.
Why response design matters
A 72-hour detailed report cannot be assembled from scratch. Teams need pre-built playbooks, a breach register, contacts at the Board, templates for affected-user communication and evidence trails that show when a breach was detected, assessed and reported. Breach-response readiness is one of the highest-leverage investments an organization can make before May 2027.
The Data Protection Board of India
The DPB is an adjudicatory body, not a proactive regulator. It directs investigations into breaches, inquires into complaints and imposes penalties. Under the 2025 Rules, its proceedings are "digital-first": electronic filings, virtual hearings and digital evidence submissions. Practical consequence: expect written, evidence-driven interactions with the Board rather than in-person hearings.
12. Penalties
The DPDP Act relies on financial deterrence. There are no criminal penalties — no jail terms — which is a major difference from older drafts and from some other jurisdictions.
| Violation | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards leading to a personal data breach | ₹250 crore |
| Failure to notify the Board and affected users of a breach | ₹200 crore |
| Violation of children's data obligations (S.9) | ₹200 crore |
| Other specified violations | ₹50 crore per the Schedule (verify current Schedule) |
| Data Principal duty violations (S.15) | Up to ₹10,000 |
Penalties are per-violation, and the Board may direct remediation or compounding in addition to monetary penalties. The absolute numbers matter less for planning than the pattern: the regime prices negligence in security and transparency far above administrative friction. See DPDP Act penalties explained.
13. DPDP vs GDPR: What Changes for Global Teams
Global companies often assume a GDPR-style compliance program is enough for India. Much carries over, but the differences are consequential.
| Dimension | GDPR | DPDP Act |
|---|---|---|
| Data categories | Special categories (sensitive data) get heightened rules | No special-category concept; consent-based model applies broadly |
| Legal bases | Multiple (consent, contract, legitimate interest, legal obligation...) | Consent is central; other lawful-purpose grounds exist but the regime is consent-led |
| Cross-border | Whitelist + safeguards | Blacklist — transfers permitted unless a territory is restricted |
| Individual duties | None | Data Principal duties with penalties up to ₹10,000 |
| Criminal penalties | Administrative fines | Financial penalties only; no jail terms |
| DPO | Required in defined cases | Required for SDFs, India-based |
| Consent Managers | No equivalent platform concept | Registered Consent Managers from Phase 2 (Nov 2026) |
| Notices | Privacy notices in accessible language | Itemized notices in English + 22 scheduled Indian languages |
| Breach reporting | 72 hours to supervisory authority | Notify Board and affected individuals "without delay" + detailed report within 72 hours |
The practical takeaway: reuse the muscle you built for GDPR — data mapping, ROPA-style records, incident response, vendor review — and then adapt the Indian-specific parts: consent-led flows, 22-language notices, Consent Manager integration, India DPO planning for SDFs and blacklist-aware transfer architecture. See DPDP vs GDPR.
14. Timeline and the 18-Month Readiness Roadmap
The three phases
| Phase | Date | What applies |
|---|---|---|
| Phase 1 | November 2025 | Data Protection Board of India establishment, composition and procedural functioning. |
| Phase 2 | November 2026 | Consent Manager framework, cross-border transfer mechanisms and SDF obligations. |
| Phase 3 | May 2027 | Full enforcement of all substantive Data Fiduciary obligations: notices, security safeguards, rights management, retention and breach penalties. |
A practical 18-month roadmap
- Months 0-6 — Assessment: data discovery and mapping, ROPA-style records, processing activity documentation, gap analysis against the Rules, scope decisions (Indian residents? children? SDF?).
- Months 6-12 — Core controls: update privacy notices (English + 22 languages where required), rebuild consent flows for withdrawal ease, strengthen security safeguards (encryption, access controls, log retention), build breach response, define retention schedules and erasure workflows.
- Months 12-18 — Advanced and sustained: DPIAs and independent audits for SDFs, vendor contract review, Consent Manager integration readiness, privacy-enhancing technologies, monitoring and management reporting.
If your program starts today, the Phase 2 date (November 2026) for Consent Manager readiness is closer than it looks, and Phase 3 (May 2027) is the hard deadline for the substantive program. See the full DPDP timeline article.
15. Sector Notes
Fintech and banking
Fintech firms already operate under RBI digital-lending and KYC rules; the DPDP Act adds a consent-and-notice overlay and 72-hour breach reporting. Credit information and CIBIL-style reporting connect to the loan-default ascertainment exemption. See DPDP for fintech and banking.
Healthcare
Healthcare providers that serve minors are among the exempt categories for parts of the parental-consent requirement, but all providers still need consent architecture, security safeguards and breach response. Health data has no special-category tier in the Act, so the discipline comes from the fiduciary's own risk assessment and sector regulators.
Government and public sector
Section 17 exemptions can remove state instrumentalities from the Act for sovereignty, security and public-order reasons — but exemptions are not automatic, and government digital platforms serving citizens should still plan for rights, notices and security best practice. KryptoMindz has delivered trust and identity work with Indian government organizations, including Smart City Ranchi, the Income Tax Department, DRDO and COAL India.
AI and data-driven products
AI systems that process personal data of Indian residents sit inside the DPDP regime like any other processing. Consent-led data minimization, purpose limitation and DPIAs for high-risk processing map naturally onto AI governance programs. This guide's approach to compliance by design is the bridge between the two disciplines.
16. Compliance by Design and Evidence Architecture
Compliance by design means embedding DPDP obligations and control checks into delivery workflows rather than layering them on at audit time. Evidence should be captured when work happens, linked to the governed version of a system or product and protected from unauthorized change.
One traceability chain
Map requirement to policy, control, owner, implementation, test, result, exception, approval and monitoring. Use identifiers and versioning so an auditor or the Board can establish which evidence supported which decision — for example, which notice text was live when consent was captured, or which breach report was submitted and when.
Consent as state, not event
Record consent lifecycle state: notice version, consent timestamp, affirmative action evidence, withdrawal timestamp and downstream stop-processing confirmation. If a Consent Manager revokes consent on behalf of a user, your systems must honor that state change.
Protect evidence
Apply access control, integrity, retention, confidentiality and legal hold. Avoid collecting sensitive or unnecessary personal data merely because storage is cheap — retention limits are a legal requirement, not just a hygiene preference.
17. DPDP Implementation Roadmap
- Establish mandate: executive sponsor, scope, risk appetite and budget for the May 2027 deadline.
- Map the data estate: inventory personal data, sources, processors, storage locations and Indian-resident exposure.
- Determine designation risk: assess SDF designation factors and plan DPO, DPIA and audit readiness if relevant.
- Redesign consent and notices: itemized notices, affirmative consent, easy withdrawal, 22-language coverage and Consent Manager readiness.
- Build rights workflows: access, correction, erasure, grievance (90-day) and nomination channels.
- Establish security and retention: safeguards, retention schedules, erasure automation and vendor obligations.
- Build breach response: playbooks, 72-hour detailed report templates, Board and user notification paths.
- Measure and improve: report readiness, incidents, rights-response times and audit evidence quarterly.
- Scope decisions are documented, including extraterritorial exposure.
- Every processing purpose has a notice version and a lawful basis.
- Consent withdrawal is tested end-to-end, including Consent Manager paths.
- Rights requests have owners, SLAs and escalation.
- Retention schedules are enforced, not just published.
- Breach detection triggers a tested 72-hour response.
- SDF obligations (DPO, DPIA, audit) are planned if designation is plausible.
- Evidence is versioned and traceable.
Related capabilities include DPDP Compliance Consulting, AI Governance Consulting, Digital Identity Consulting and the DPDP Act topic hub.
18. DPDP Compliance Anti-Patterns
Consent checkbox theater
Pre-ticked boxes and buried consent do not meet the "clear affirmative action" standard and invite scrutiny. Remedy: design consent as an explicit, itemized, withdrawable state.
Notice after collection
Collecting data first and posting a privacy policy later inverts the statutory sequence. Remedy: notice must precede or accompany collection and consent requests.
GDPR copy-paste
Reusing GDPR lawful-basis architecture ignores the consent-led structure and 22-language notice requirement. Remedy: adapt, do not copy; map each obligation to its DPDP equivalent.
No retention enforcement
Publishing a retention policy while data accumulates forever is a legal exposure. Remedy: enforce schedules with automation and deletion workflows.
72-hour breach fiction
Expecting a team to assemble a detailed breach report in 72 hours without a playbook is unrealistic. Remedy: build and rehearse response before an incident.
India as an afterthought
Treating India as a small market while routing Indian-user data through uncontrolled flows ignores extraterritorial scope. Remedy: include Indian-resident processing in global data maps and vendor reviews.
Evidence after the fact
Rebuilding history for audits and Board inquiries is unreliable. Remedy: capture versioned evidence continuously through delivery workflows.
19. Frequently Asked Questions
What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 is India's national data protection law. It regulates how organizations process digital personal data, grants individuals rights over their data and establishes the Data Protection Board of India.
When do the DPDP Rules 2025 apply?
The DPDP Rules 2025 were notified in November 2025 with an 18-month phased rollout: Board provisions from November 2025, Consent Manager and cross-border mechanisms from November 2026, and full Data Fiduciary enforcement from May 2027.
Who is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data, alone or with others. Fiduciaries must issue notices, obtain consent, secure data, honor rights and respond to breaches.
Who is a Data Principal under the DPDP Act?
A Data Principal is the individual to whom personal data relates. Data Principals have rights to access, correct, erase, obtain grievance redressal, withdraw consent and nominate a representative.
What is a Significant Data Fiduciary?
An SDF is a Data Fiduciary designated by the Central Government based on factors such as data volume and sensitivity and risk to electoral democracy or public order. SDFs must appoint an India-based DPO, conduct annual DPIAs and undergo annual independent data audits.
What are the penalties under the DPDP Act?
Penalties are financial, up to ₹250 crore for failure to take reasonable security safeguards leading to a breach and up to ₹200 crore for breach-notification failures or violations of children's data obligations. The Act does not impose criminal penalties.
Does the DPDP Act apply to companies outside India?
Yes. The Act applies to processing of digital personal data outside India when that processing is in connection with offering goods or services to individuals within India.
What consent is required under the DPDP Act?
Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and it must be easy to withdraw. A request for consent must be preceded by an itemized notice.
Is a Data Protection Officer mandatory for all companies?
No. Only Significant Data Fiduciaries are required to appoint an India-based Data Protection Officer. Other fiduciaries still need accountable ownership for consent, rights, security and breach response.
Does the DPDP Act allow cross-border data transfer?
Yes, with a blacklist approach. Transfers to other countries are generally permitted unless the Central Government restricts transfers to a specific country or territory.
Does DPDP compliance replace GDPR compliance?
No. Both regimes apply in their own territories. Global programs should share data mapping, incident response and vendor management muscle, then adapt the consent-led, 22-language, Consent Manager and blacklist-transfer specifics of the DPDP regime.
Is this guide legal advice?
No. This guide provides architecture, governance and engineering guidance. Applicability and conformity decisions require qualified legal counsel and relevant specialists.
Sources, Author and Technical Review
This guide prioritizes primary regulation, government sources and authoritative technical resources. Requirements and rules evolve; verify current editions and obtain qualified legal, privacy and security advice.
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India
- Digital Personal Data Protection Rules, 2025 (official text, MeitY)
- MeitY, Data Protection Framework
- Press Information Bureau, DPDP Rules 2025 notified
- EY India, Transforming data privacy: DPDP Act 2023 and DPDP Rules 2025
- Latham & Watkins, DPDP Act vs GDPR comparison
- Data Protection Board of India (official site)
- The Hindu, What are the DPDP Rules and when do they apply?
- Reuters, India strengthens privacy law with new data collection rules
Turn DPDP into an Operating Capability
KryptoMindz can translate the DPDP Act and Rules into a readiness assessment, consent and notice architecture, rights workflows, breach response and evidence design for global and India-facing organizations.
Discuss Your DPDP Program