Complete Guide

The Complete Guide to DPDP Act 2023

Everything Indian businesses need to know about the Digital Personal Data Protection Act 2023, key definitions, obligations, penalties, compliance requirements, and how to achieve compliance.

Start Reading

DPDP Act 2023

Digital Personal Data Protection Act

45+
Sections
₹250 Cr
Max Penalty
2025
Enforcement

Overview of the DPDP Act 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection legislation. Passed by the Indian Parliament on August 11, 2023, it establishes a legal framework for the processing of digital personal data in India.

The Act applies to the processing of digital personal data within India, and also to processing outside India if it relates to offering goods or services to individuals in India.

Key Takeaway: The DPDP Act affects every business that collects, stores, or processes personal data of Indian citizens, from startups to multinational corporations.

Key Definitions

Understanding the DPDP Act starts with its core terminology:

Data Principal

The individual whose personal data is being processed. In case of a child, the parent or lawful guardian.

Data Fiduciary

The entity (individual, company, or government) that determines the purpose and means of processing personal data. This is likely your business.

Data Processor

Any entity that processes personal data on behalf of a Data Fiduciary (e.g., cloud providers, analytics services).

Significant Data Fiduciary

Data Fiduciaries designated by the government based on volume/sensitivity of data processed. Subject to additional obligations.

Personal Data

Any data about an individual who is identifiable by or in relation to such data. Includes name, email, phone, Aadhaar, PAN, health data, financial data, etc.

Consent Manager

An entity registered with the Data Protection Board that enables Data Principals to manage their consent through an accessible platform.

Who Must Comply?

The DPDP Act applies to:

  • All businesses operating in India that collect or process personal data digitally
  • Foreign companies that process personal data of Indian individuals (e.g., offering goods/services to India)
  • Government agencies that process citizen data
  • Startups and SMBs, there is no exemption based on company size

Important: If your website collects any personal data (contact forms, user accounts, cookies, analytics), you likely need to comply with the DPDP Act.

Key Obligations for Data Fiduciaries

1. Lawful Purpose

Personal data can only be processed for a lawful purpose. Processing must be either consent-based or for certain legitimate uses defined in the Act.

2. Purpose Limitation

Data can only be collected for a specific, clear purpose and cannot be used for unrelated purposes without fresh consent.

3. Data Minimization

Only collect personal data that is necessary for the stated purpose. Avoid collecting excessive or irrelevant data.

4. Accuracy

Ensure personal data is accurate and up-to-date, especially when decisions are being made based on it.

5. Storage Limitation

Personal data must be deleted when the purpose is fulfilled or consent is withdrawn, unless retention is required by law.

6. Security Safeguards

Implement reasonable security measures to protect personal data from breaches, unauthorized access, and misuse.

7. Breach Notification

In case of a data breach, notify the Data Protection Board and affected individuals within the prescribed timeframe.

Rights of Data Principals

The DPDP Act grants individuals the following rights:

Right to Access

Request a summary of personal data being processed and the processing activities

Right to Correction

Request correction of inaccurate or misleading personal data

Right to Erasure

Request deletion of personal data that is no longer necessary

Right to Grievance Redressal

File complaints with the Data Fiduciary and the Data Protection Board

Right to Nominate

Nominate another individual to exercise rights in case of death or incapacity

Right to Withdraw Consent

Withdraw consent at any time, with the same ease as giving it

Penalties for Non-Compliance

The DPDP Act prescribes significant financial penalties for violations:

ViolationMaximum Penalty
Failure to take reasonable security safeguards resulting in a data breach₹250 Crores
Failure to notify the Board and affected individuals of a data breach₹200 Crores
Non-compliance with obligations regarding children's data₹200 Crores
Non-compliance with additional obligations of Significant Data Fiduciaries₹150 Crores
Any other non-compliance with the Act₹50 Crores

DPDP Compliance Checklist

Use this checklist to assess your business's compliance status:

Privacy Policy. Do you have a DPDP-compliant privacy policy on your website?
Consent Collection. Are you collecting explicit, purpose-specific consent?
Consent Records. Do you maintain an audit trail of all consents?
DSR Process. Can users access, correct, and delete their data?
Data Inventory. Do you know what personal data you hold and where?
Security Measures. Are reasonable security safeguards in place?
Breach Response. Do you have a breach notification process?
Children's Data. Do you have special safeguards for minors' data?

How dcomply Helps You Comply

dcomply automates every aspect of the DPDP compliance checklist above:

Website Scanner

Automatically detect compliance gaps on your website

Consent Management

Collect and track DPDP-compliant consent with audit trails

DSR Portal

Automated handling of data subject rights requests

PII Discovery

Find and protect personal data across your organization

Don't Wait for Enforcement

Start your DPDP compliance today. Free forever plan, 74 AI modules, 46+ features, everything you need.

Talk to Sales