The Digital Personal Data Protection Act, 2023

India’s journey toward a comprehensive data protection framework was long and winding — from Justice K.S. Puttaswamy judgment recognizing privacy as a fundamental right, through multiple draft bills and a Joint Parliamentary Committee report, to the eventual passage of the Digital Personal Data Protection Act, 2023 (DPDP Act). For law students, this Act is essential reading: it is India’s first standalone data protection legislation and is expected to significantly shape how privacy, technology, and commercial law intersect in the years ahead. 1This post walks through the Act’s structure, key concepts, and current implementation status — everything you need for a solid foundational understanding.

Background and Legislative Journey

The DPDP Act was passed by the Lok Sabha on 7 August 2023 and by the Rajya Sabha on 9 August 2023, receiving presidential assent on 11 August 2023 as Act No. 22 of 2023. It replaced the earlier, more elaborate Personal Data Protection Bill drafts (2018–2022),opting instead for a comparatively leaner and principles-based framework. 2

Unlike many pieces of legislation that come into force on enactment, the DPDP Act was designed for phased commencement — different provisions activate at different times, giving both the government and regulated entities time to build the necessary institutional and compliance infrastructure.

Core Objective

The Act’s long title captures its dual purpose: to provide for the processing of digital personal data in a manner that recognises both an individual’s right to protect their personal data and the need to process such data for lawful purposes. This “balancing” framing — privacy versus legitimate processing needs — runs through the entire statute and is a useful lens for essay and exam answers.

Key Definitions Every Student Should Know

  • Data Principal: The individual to whom the personal data relates (equivalent to the “data subject” under the GDPR).

  • Data Fiduciary: Any person or entity that, alone or with others, determines the purpose and means of processing personal data (equivalent to a “data controller”).
  • Data Processor: An entity that processes personal data on behalf of a Data Fiduciary.

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data.

  • Consent Manager: A novel Indian concept — a registered entity that acts as a single point through which a Data Principal can give, manage, review, and withdraw consent across multiple fiduciaries.

Note that, unlike the GDPR, the DPDP Act does not create a separate category of “sensitive personal data” with heightened obligations — all personal data is treated under a single, unified standard, though children’s data receives special protection (discussed below).

Consent and Grounds for Processing

Processing of personal data is lawful only where the Data Principal has given consent, or where processing falls under the specified ‘legitimate uses’ recognised by the Act, such as certain State functions, compliance with legal obligations, medical emergencies, employment-related purposes in specified circumstances, and other situations expressly provided by the legislation.3 Consent must be free, specific, informed, unconditional, and unambiguous, accompanied by a clear affirmative action, and it can be withdrawn as easily as it was given.

A notice requirement accompanies every request for consent — Data Fiduciaries must inform Data Principals of the personal data being collected and the purpose of processing, in clear and plain language.

Rights of Data Principals

Students should be familiar with the core rights granted under the Act:

  • Right to access information about personal data being processed.

  • Right to correction and erasure of personal data.

  • Right to grievance redressal through the Data Fiduciary.

  • Right to nominate another individual to exercise these rights in the event of death or incapacity a distinctly Indian addition not commonly found in comparable foreign statutes.

Obligations of Data Fiduciaries

Data Fiduciaries carry significant compliance burdens, including implementing reasonable security safeguards, notifying the Data Protection Board and affected Data Principals in the event of a personal data breach, and ensuring reasonable accuracy and completeness of personal data where it is likely to be used for making decisions affecting the Data Principal or disclosed to another Data Fiduciary. “Significant Data Fiduciaries,” a category the government may notify based on factors like data volume or risk, face enhanced obligations such as appointing a Data Protection Officer and conducting periodic Data Protection Impact Assessments.

Children’s Data — A Notably Strict Regime

The Act adopts a uniform threshold of 18 years for defining a “child,” which is stricter than many other jurisdictions. Processing a child’s personal data requires verifiable parental consent, and the Act prohibits tracking, behavioural monitoring, or targeted advertising directed at children. This is one of the more debated provisions, since it may affect ed-tech and gaming platforms significantly.

The Data Protection Board of India

Rather than creating an independent regulator akin to a Data Protection Authority (as earlier drafts proposed), the DPDP Act establishes the Data Protection Board of India (DPB) — a body with more limited, adjudicatory functions. The Board’s core mandate is to inquire into breaches, impose penalties, and direct remedial measures, functioning as a digital-first tribunal rather than a full-fledged regulatory authority with rule-making powers of its own.

Penalties

The Act’s penalty structure is designed to be a strong deterrent: certain contraventions may attract financial penalties of up to ₹250 crore, depending on the nature of the violation, as provided under the Act5 for failure to implement reasonable security safeguards, with other specified violations such as processing without valid consent or breaching obligations concerning children’s data — attracting separate, substantial penalties. Because penalties can stack across multiple violations arising from a single breach, the cumulative exposure for a non-compliant organisation can be significantly higher than any single cap suggests.

Cross-Border Data Transfer

Departing from the more restrictive data-localisation approach of earlier drafts, the DPDP Act permits cross-border transfer of personal data by default, subject to the government’s power to restrict transfers to specific countries or territories through notification — effectively a “blacklist” model rather than a “whitelist” one.

Where Implementation Stands Today (as of August 2026)

This is where the Act’s story gets interesting for current students, because the law’s practical life has only just begun:

  • The Act received assent in August 2023, but sat un-notified for over two years while the government finalised subordinate rules.

  • The Digital Personal Data Protection Rules, 2025 were finally notified on 13 November 2025, along with a phased commencement schedule for the Act itself, formally operationalising India’s data protection framework and constituting the Data Protection Board.

Phase 1 (effective immediately from 13 November 2025): definitions, provisions establishing the Data Protection Board and its administrative machinery, and the government’s rule-making powers.

Phase 2 (effective 13 November 2026): provisions relating to the registration and operation of Consent Managers, along with certain Board-related conditions.

Phase 3 (effective 13 May 2027): the remaining substantive provisions of the Act, including full consent, notice, and breach-related compliance obligations along with enforcement powers — this is when the Act’s penalty regime becomes fully operative.

For law students, this phased rollout is itself a good case study in regulatory sequencing — building the adjudicatory body first, giving intermediaries like Consent Managers time to register, and only then switching on full enforcement.

DPDP Act vs. GDPR — A Quick Comparative Note

Comparative questions are common in exams, so a few key distinctions are worth memorising:

FeatureDPDP Act, 2023GDPR

Sensitive data

category

None — unified standard

Special category data with extra safeguards

Children’s age

threshold

Uniform 18 yearsVaries by member state (13–16)
RegulatorData Protection Board (adjudicatory)

Independent Data Protection Authorities (regulatory + adjudicatory)

Cross-border transfer

Permitted by default; government can restrict specific countries

Restricted by default; adequacy decisions or safeguards required

Consent intermediary

Consent Manager (unique to India)

No direct equivalent

Why This Matters for Your Legal Career

Whether you’re heading into technology law, corporate compliance, constitutional litigation, or policy work, the DPDP Act will likely intersect with your practice. It sits at the crossroads of the fundamental right to privacy recognised in Puttaswamy, evolving digital commerce, and India’s ambitions as a global tech and AI hub. Understanding its structure now — while the Rules are still bedding in and case law is yet to develop — provides a strong foundation for understanding one of India’s fastest-evolving areas of law.

Leave a Reply

Your email address will not be published. Required fields are marked *