Regulatory Guide8 min readSeptember 2026

What is DPDPA? Complete Guide to India's Digital Personal Data Protection Act

What is DPDPA? Learn everything about India's DPDP Act 2023, who it applies to, key obligations, compliance deadlines, and penalties up to ₹250 crore.

Adv. Rajesh Sharma

Adv. Rajesh Sharma

Lead Privacy Counsel & CIPP/E • PrivacyOS Global Research Desk

What is DPDPA? Complete Guide to India's Digital Personal Data Protection Act

What is DPDPA?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive national data privacy law enacted by Parliament. It establishes a legally binding framework governing the processing of digital personal data within India, replacing Section 43A of the Information Technology Act, 2000.

DPDPA balances an individual's fundamental right to protect their personal data (recognized in the landmark Puttaswamy judgment) with the legitimate processing needs of businesses and public entities.

---

Who Does the DPDPA Apply To?

The DPDP Act applies to: 1. Processing within India: Any processing of digital personal data collected online, or collected offline and digitized subsequently. 2. Extraterritorial Scope: Processing outside India if it involves offering goods or services to Data Principals located in India.

Every entity deciding the purpose and means of processing is defined as a Data Fiduciary, while individuals whose data is processed are termed Data Principals. Unlike Western frameworks, DPDPA provides no exemption based on business size or turnover—a 5-person startup and a conglomerate share identical statutory obligations.

---

Core Obligations Under the DPDP Act

  • Notice & Consent (Section 5 & 6): Prior to or at the time of request, Data Fiduciaries must present an itemised notice in English or any of the 22 scheduled Indian languages specifying the exact personal data to be processed and its purpose.
  • Data Principal Rights (Section 11–14): Citizens have statutory rights to access summaries of personal data, correct inaccuracies, erase obsolete records, and nominate representatives.
  • Mandatory Breach Notification (Section 8(6)): Fiduciaries must notify both the Data Protection Board of India (DPBI) and affected individuals in the event of a personal data breach.
  • Protection of Children's Data (Section 9): Absolute prohibition on behavioural tracking, targeted advertising, or profiling of individuals under 18 years, accompanied by verifiable parental consent.
  • Reasonable Security Safeguards (Section 8(5)): Technical and organisational measures, including tokenization, encryption, and role-based access control.
  • ---

    Compliance Timelines & Next Steps

    With the DPDP Rules notified, Indian enterprises must achieve full readiness before 13 May 2027. Beginning with automated data discovery, notice refactoring, and DSR workflow deployment ensures your organization avoids severe statutory penalties.
    Tags:#DPDPA#Data Protection Act#Indian Privacy Law#Compliance Guide
    STAY AHEAD OF DPDPA RULES

    Prepare Your Systems For The 2027 DPBI Enforcement

    Evaluate consent banners, DSR portals, vendor DPAs, and data discovery with an interactive PrivacyOS platform walkthrough.