The Complete Guide to DPDP Act 2023
Everything Indian businesses need to know about the Digital Personal Data Protection Act 2023, key definitions, obligations, penalties, compliance requirements, and how to achieve compliance.
DPDP Act 2023
Digital Personal Data Protection Act
Overview of the DPDP Act 2023
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection legislation. Passed by the Indian Parliament on August 11, 2023, it establishes a legal framework for the processing of digital personal data in India.
The Act applies to the processing of digital personal data within India, and also to processing outside India if it relates to offering goods or services to individuals in India.
Key Takeaway: The DPDP Act affects every business that collects, stores, or processes personal data of Indian citizens, from startups to multinational corporations.
Key Definitions
Understanding the DPDP Act starts with its core terminology:
Data Principal
The individual whose personal data is being processed. In case of a child, the parent or lawful guardian.
Data Fiduciary
The entity (individual, company, or government) that determines the purpose and means of processing personal data. This is likely your business.
Data Processor
Any entity that processes personal data on behalf of a Data Fiduciary (e.g., cloud providers, analytics services).
Significant Data Fiduciary
Data Fiduciaries designated by the government based on volume/sensitivity of data processed. Subject to additional obligations.
Personal Data
Any data about an individual who is identifiable by or in relation to such data. Includes name, email, phone, Aadhaar, PAN, health data, financial data, etc.
Consent Manager
An entity registered with the Data Protection Board that enables Data Principals to manage their consent through an accessible platform.
Who Must Comply?
The DPDP Act applies to:
- All businesses operating in India that collect or process personal data digitally
- Foreign companies that process personal data of Indian individuals (e.g., offering goods/services to India)
- Government agencies that process citizen data
- Startups and SMBs, there is no exemption based on company size
Important: If your website collects any personal data (contact forms, user accounts, cookies, analytics), you likely need to comply with the DPDP Act.
Key Obligations for Data Fiduciaries
1. Lawful Purpose
Personal data can only be processed for a lawful purpose. Processing must be either consent-based or for certain legitimate uses defined in the Act.
2. Purpose Limitation
Data can only be collected for a specific, clear purpose and cannot be used for unrelated purposes without fresh consent.
3. Data Minimization
Only collect personal data that is necessary for the stated purpose. Avoid collecting excessive or irrelevant data.
4. Accuracy
Ensure personal data is accurate and up-to-date, especially when decisions are being made based on it.
5. Storage Limitation
Personal data must be deleted when the purpose is fulfilled or consent is withdrawn, unless retention is required by law.
6. Security Safeguards
Implement reasonable security measures to protect personal data from breaches, unauthorized access, and misuse.
7. Breach Notification
In case of a data breach, notify the Data Protection Board and affected individuals within the prescribed timeframe.
Consent Requirements
Consent under the DPDP Act must be:
- Free, given voluntarily, not coerced or bundled with unrelated services
- Specific, for each distinct purpose of processing
- Informed, the Data Principal must understand what they're consenting to
- Unconditional, not conditional on provision of a service
- Unambiguous, through a clear affirmative action (not pre-ticked boxes)
Warning: Pre-ticked checkboxes, bundled consent, and vague "I agree to everything" approaches are non-compliant under the DPDP Act.
Consent for Children
Processing personal data of children (under 18) requires verifiable consent from a parent or lawful guardian. Behavioral tracking and targeted advertising directed at children is prohibited.
Rights of Data Principals
The DPDP Act grants individuals the following rights:
Right to Access
Request a summary of personal data being processed and the processing activities
Right to Correction
Request correction of inaccurate or misleading personal data
Right to Erasure
Request deletion of personal data that is no longer necessary
Right to Grievance Redressal
File complaints with the Data Fiduciary and the Data Protection Board
Right to Nominate
Nominate another individual to exercise rights in case of death or incapacity
Right to Withdraw Consent
Withdraw consent at any time, with the same ease as giving it
Penalties for Non-Compliance
The DPDP Act prescribes significant financial penalties for violations:
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards resulting in a data breach | ₹250 Crores |
| Failure to notify the Board and affected individuals of a data breach | ₹200 Crores |
| Non-compliance with obligations regarding children's data | ₹200 Crores |
| Non-compliance with additional obligations of Significant Data Fiduciaries | ₹150 Crores |
| Any other non-compliance with the Act | ₹50 Crores |
DPDP Compliance Checklist
Use this checklist to assess your business's compliance status:
How dcomply Helps You Comply
dcomply automates every aspect of the DPDP compliance checklist above:
Website Scanner
Automatically detect compliance gaps on your website
Consent Management
Collect and track DPDP-compliant consent with audit trails
DSR Portal
Automated handling of data subject rights requests
PII Discovery
Find and protect personal data across your organization
Don't Wait for Enforcement
Start your DPDP compliance today. Free forever plan, 74 AI modules, 46+ features, everything you need.