What the DPDP Act is — and why the clock is running
Scope, timeline, who it applies to, and what changed when the Rules were notified.
The one-paragraph version
The Digital Personal Data Protection Act, 2023 (DPDPA) is India's first comprehensive personal-data law. It received Presidential assent on 11 August 2023. The operative detail — notices, consent managers, breach reporting formats, retention periods, the Data Protection Board's procedure — lives in the DPDP Rules, 2025, notified by MeitY on 13 November 2025 with a phased implementation: institutional provisions (the Board, consent-manager registration) come first, and the substantive obligations on organisations apply after an 18-month window. Treat that window as your compliance runway, not a pause.
Who it applies to
- Digital personal data — data about an identifiable individual that is collected digitally, or collected offline and then digitised.
- Processing within India, and processing outside India if it is in connection with offering goods or services to individuals in India.
- It does not apply to personal data processed by an individual for personal/domestic purposes, or to data made publicly available by the individual themselves or under a legal obligation.
The three roles you must know
| Role | Who | Analogy |
|---|---|---|
| Data Principal | The individual the data is about (for children: their parent/lawful guardian; for persons with disability: lawful guardian) | GDPR "data subject" |
| Data Fiduciary | The person/organisation that decides the purpose and means of processing | GDPR "controller" |
| Data Processor | Processes on behalf of a Fiduciary | GDPR "processor" |
The Central Government can also notify certain organisations as Significant Data Fiduciaries (SDFs) based on volume/sensitivity of data, risk to sovereignty, electoral democracy, security of the state or public order. SDFs carry extra duties (Module 6).
Why decision makers care
- Penalties are per instance and reach ₹250 crore for a failure of reasonable security safeguards.
- The Data Protection Board of India is a digital-first adjudicator: complaints, inquiries and hearings are online.
- Regulators that already supervise you (RBI, SEBI, IRDAI, CERT-In) continue to apply — DPDPA sits on top, not instead.
What you should do after this module
- Confirm whether your organisation is a Fiduciary, Processor, or both (most are both).
- Put the 18-month Rules window on the board calendar with quarterly milestones.
- Nominate an owner — even if you are not an SDF, someone must be accountable for the programme.