DPDPA 2023 — From Awareness to Compliance
Module 1 of 9 · 6 min read

What the DPDP Act is — and why the clock is running

Scope, timeline, who it applies to, and what changed when the Rules were notified.

The one-paragraph version

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's first comprehensive personal-data law. It received Presidential assent on 11 August 2023. The operative detail — notices, consent managers, breach reporting formats, retention periods, the Data Protection Board's procedure — lives in the DPDP Rules, 2025, notified by MeitY on 13 November 2025 with a phased implementation: institutional provisions (the Board, consent-manager registration) come first, and the substantive obligations on organisations apply after an 18-month window. Treat that window as your compliance runway, not a pause.

Who it applies to

  • Digital personal data — data about an identifiable individual that is collected digitally, or collected offline and then digitised.
  • Processing within India, and processing outside India if it is in connection with offering goods or services to individuals in India.
  • It does not apply to personal data processed by an individual for personal/domestic purposes, or to data made publicly available by the individual themselves or under a legal obligation.

The three roles you must know

RoleWhoAnalogy
Data PrincipalThe individual the data is about (for children: their parent/lawful guardian; for persons with disability: lawful guardian)GDPR "data subject"
Data FiduciaryThe person/organisation that decides the purpose and means of processingGDPR "controller"
Data ProcessorProcesses on behalf of a FiduciaryGDPR "processor"

The Central Government can also notify certain organisations as Significant Data Fiduciaries (SDFs) based on volume/sensitivity of data, risk to sovereignty, electoral democracy, security of the state or public order. SDFs carry extra duties (Module 6).

Why decision makers care

  • Penalties are per instance and reach ₹250 crore for a failure of reasonable security safeguards.
  • The Data Protection Board of India is a digital-first adjudicator: complaints, inquiries and hearings are online.
  • Regulators that already supervise you (RBI, SEBI, IRDAI, CERT-In) continue to apply — DPDPA sits on top, not instead.

What you should do after this module

  1. Confirm whether your organisation is a Fiduciary, Processor, or both (most are both).
  2. Put the 18-month Rules window on the board calendar with quarterly milestones.
  3. Nominate an owner — even if you are not an SDF, someone must be accountable for the programme.