DPDP Act 2023 Explained: Full Form and Who Must Comply
DPDP Act 2023 in plain English: full form, who must comply, Data Fiduciary vs Data Principal, consent, rights, penalties and the 13 May 2027 deadline.
By the GRC-Flow team · Published · 9 min read
Key takeaways
- DPDP Act stands for the Digital Personal Data Protection Act, 2023: India's first full law on how organisations collect, use, store and share digital personal data.
- It applies to every organisation processing digital personal data of people in India, including foreign companies that offer goods or services to people in India. Company size does not matter.
- Most duties apply from 13 May 2027, 18 months after the DPDP Rules, 2025 were notified on 14 November 2025.
- Penalties go up to ₹250 crore per breach of duty, imposed by the Data Protection Board of India.
- There is no government certificate for compliance: each organisation must be able to prove its own compliance with records and evidence.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's law on personal data. It sets out when an organisation may use a person's data, what it must tell them, how it must protect the data, and what happens when things go wrong. Once fully in force, it takes over from the older "reasonable security practices" regime under Section 43A of the IT Act.
The Act is short and principle-based. The practical detail, such as what a privacy notice must contain or how fast to report a breach, sits in the DPDP Rules, 2025.
Who does it apply to?
The Act applies to processing of digital personal data:
- within India, whether the data was collected online or collected on paper and digitised later;
- outside India, when it is connected to offering goods or services to people in India.
It does not apply to data used for purely personal or domestic purposes, or to data that the person has made publicly available themselves (or that someone is legally required to make public).
The key terms, in plain words
| Term | Meaning | Example |
|---|---|---|
| Data Principal | The person the data is about (for a child, also the parent) | A customer, employee or student |
| Data Fiduciary | The organisation that decides why and how the data is used | Your company |
| Data Processor | An organisation that processes data on the Fiduciary's behalf | A cloud, payroll or CRM provider |
| Significant Data Fiduciary | A Fiduciary the government names because of volume or risk; it has extra duties | Large platforms, finance, health |
| Consent Manager | A platform registered with the Board that lets people give and withdraw consent | A consent dashboard used across apps |
| Data Protection Board | The regulator that inquires and imposes penalties | Data Protection Board of India |
When can an organisation use personal data?
Only on one of two grounds:
- Consent that is free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and as easy to withdraw as to give. It must follow a notice that lists the data and the purpose.
- Certain legitimate uses listed in Section 7, such as data the person voluntarily provided for a specified purpose, employment purposes, legal obligations and medical emergencies.
What a Data Fiduciary must do
- Give an itemised notice and take valid consent for each purpose.
- Keep data accurate when it is used to make decisions or shared.
- Put in place reasonable security safeguards to prevent a personal data breach, including at its processors.
- Report every personal data breach to the Board and to the affected people.
- Erase data once the purpose is served or consent is withdrawn, unless a law requires keeping it.
- Publish a contact for questions and run a grievance process.
- For children (under 18): get verifiable parental consent, and do no tracking, behavioural monitoring or targeted advertising.
Significant Data Fiduciaries must also appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.
The rights of people (Data Principals)
- to a summary of their data and how it is processed, and who it was shared with;
- to correction, completion, updating and erasure;
- to grievance redressal, before going to the Board;
- to nominate someone to exercise their rights after death or incapacity.
The Rules give organisations up to 90 days to respond to these requests.
Penalties
The Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for not reporting a breach or breaking the duties for children's data. See the full schedule in our guide to DPDP Act penalties.
When do you need to comply?
| Date | What applies |
|---|---|
| 14 November 2025 | Rules notified; Data Protection Board provisions in force |
| 13 November 2026 | Consent Manager registration and duties |
| 13 May 2027 | Notice, consent, security safeguards, breach reporting, rights, retention and the rest of the business obligations |
How to get started
Start with a gap assessment against each obligation, then fix the gaps in order of risk and keep evidence of each fix. Our DPDP compliance checklist walks through the steps. GRC Flow runs that assessment for you: guided intake mapped to every obligation, AI-drafted findings that cite the exact section and are reviewed by a person, and the evidence to prove it.
Frequently asked questions
What is the full form of DPDP?
DPDP stands for Digital Personal Data Protection. The law is the Digital Personal Data Protection Act, 2023 (often shortened to DPDP Act), and its detailed rules are the Digital Personal Data Protection Rules, 2025.
Is the DPDP Act in force?
Partly. The Act received Presidential assent in August 2023. The Rules were notified on 14 November 2025 and apply in phases: the Data Protection Board provisions applied immediately, Consent Manager provisions from 13 November 2026, and most obligations for businesses (notice, consent, security, breach reporting, rights) from 13 May 2027.
Does the DPDP Act apply to small businesses?
Yes. There is no turnover or headcount threshold. Any organisation that processes digital personal data of people in India is a Data Fiduciary and must comply. Some duties apply only to Significant Data Fiduciaries named by the government.
Does the DPDP Act apply to paper records?
Only once they are digitised. The Act covers personal data collected in digital form, and personal data collected on paper that is later digitised.
Who enforces the DPDP Act?
The Data Protection Board of India. It inquires into breaches and complaints and can impose the penalties set out in the Schedule to the Act.
Sources
- PIB: Digital Personal Data Protection Rules, 2025 (November 2025)
- KPMG India: DPDP Rules 2025, guidance to DPDP Act implementation
- SCC Online: MeitY notifies the DPDP Rules 2025
This guide explains the law in general terms and is not legal advice. Check specific situations with a qualified lawyer.
Related guides
- DPDP Rules 2025 Explained: Timeline and Key Rules
DPDP Rules 2025, rule by rule: notice, security safeguards, 72-hour breach reports, 90-day rights requests, children's data and the dates to May 2027.
- DPDP Compliance Checklist: 12 Steps Before May 2027
A practical DPDP compliance checklist: data mapping, notices, consent, security, a 72-hour breach plan, rights requests, vendors, children's data and evidence.
- DPDP Act Penalties: Up to ₹250 Crore, Explained
DPDP Act penalties in one table: ₹250 crore for weak security, ₹200 crore for unreported breaches or children's data, ₹150 crore for SDFs, and how fines are set.