Email WhatsApp
DPDP Act 2023 — overview

What is the DPDP Act, 2023?

India's first comprehensive personal data protection law, in plain language — what it covers, who it applies to, and where it stands today.

What the Act actually does

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive law governing how organisations collect, use, store, and protect the personal data of individuals. It replaces a patchwork of older, weaker rules with a single, consent-centred framework: organisations may only process personal data with a lawful basis — usually consent — for a stated purpose, and individuals are conferred a set of rights over their own data, with the operational obligations scheduled to commence on 13 May 2027.

The Act received Presidential assent in August 2023, but a law of this kind needs operational detail before it can actually be enforced — how consent should be captured, how breaches should be reported, what "reasonable security safeguards" means in practice. That detail arrived as the DPDP Rules, 2025.

Where it stands today

The DPDP Rules were notified on 13 November 2025, and with that notification the Act moved from a legal framework on paper to an enforceable, time-bound regime. The rollout is phased over 18 months:

DateWhat happens
13 Nov 2025Data Protection Board of India legally established; appointments and digital-office arrangements being put in place.
13 Nov 2026Consent Manager registration opens.
13 May 2027Most operational obligations take effect across substantive provisions. Penalties may be imposed after Board inquiry and decision.

See the full compliance timeline for what each phase actually requires of your organisation.

Who it applies to

Once the substantive provisions commence on 13 May 2027, the Act will generally apply to organisations processing digital personal data within India, including personal data collected in non-digital form and subsequently digitised. It will also apply to processing outside India where that processing is connected with offering goods or services to Data Principals in India. The Act contains exclusions (for example, personal or domestic use, and specified personal data made publicly available) and Section 17 permits further exemptions to be notified for specified classes of Data Fiduciaries, including startups. No such class exemption has been notified to date. In practice, for the vast majority of organisations collecting customer or employee data in India — including small ones — DPDP will apply, and the practical obligations scale with the risk and scale of the processing involved.

The three roles you need to know

Almost everything in the Act is built around three roles:

  • Data Principal — the individual the data is about. Your customer, your employee, yourself.
  • Data Fiduciary — the organisation that decides why and how the data is processed. In almost every employment context, this is your employer.
  • Data Processor — a vendor that processes data on the Data Fiduciary's behalf, under its instructions.

If your organisation collects customer or employee data and decides what to do with it, you're a Data Fiduciary — and the Act's obligations sit with you, not with any vendor you use.

What to do next

Two things matter most in the near term: understanding what's actually required of your organisation (start with the compliance timeline), and making sure every employee who touches personal data understands the basics — because most data incidents start with one person, one everyday decision, not a sophisticated attack.