Skip to content

DPDP Act 2023 Explained: Full Form and Who Must Comply

DPDP Act 2023 in plain English: full form, who must comply, Data Fiduciary vs Data Principal, consent, rights, penalties and the 13 May 2027 deadline.

By the GRC-Flow team · Published · 9 min read

Key takeaways

  • DPDP Act stands for the Digital Personal Data Protection Act, 2023: India's first full law on how organisations collect, use, store and share digital personal data.
  • It applies to every organisation processing digital personal data of people in India, including foreign companies that offer goods or services to people in India. Company size does not matter.
  • Most duties apply from 13 May 2027, 18 months after the DPDP Rules, 2025 were notified on 14 November 2025.
  • Penalties go up to ₹250 crore per breach of duty, imposed by the Data Protection Board of India.
  • There is no government certificate for compliance: each organisation must be able to prove its own compliance with records and evidence.

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's law on personal data. It sets out when an organisation may use a person's data, what it must tell them, how it must protect the data, and what happens when things go wrong. Once fully in force, it takes over from the older "reasonable security practices" regime under Section 43A of the IT Act.

The Act is short and principle-based. The practical detail, such as what a privacy notice must contain or how fast to report a breach, sits in the DPDP Rules, 2025.

Who does it apply to?

The Act applies to processing of digital personal data:

  • within India, whether the data was collected online or collected on paper and digitised later;
  • outside India, when it is connected to offering goods or services to people in India.

It does not apply to data used for purely personal or domestic purposes, or to data that the person has made publicly available themselves (or that someone is legally required to make public).

The key terms, in plain words

TermMeaningExample
Data PrincipalThe person the data is about (for a child, also the parent)A customer, employee or student
Data FiduciaryThe organisation that decides why and how the data is usedYour company
Data ProcessorAn organisation that processes data on the Fiduciary's behalfA cloud, payroll or CRM provider
Significant Data FiduciaryA Fiduciary the government names because of volume or risk; it has extra dutiesLarge platforms, finance, health
Consent ManagerA platform registered with the Board that lets people give and withdraw consentA consent dashboard used across apps
Data Protection BoardThe regulator that inquires and imposes penaltiesData Protection Board of India

When can an organisation use personal data?

Only on one of two grounds:

  1. Consent that is free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and as easy to withdraw as to give. It must follow a notice that lists the data and the purpose.
  2. Certain legitimate uses listed in Section 7, such as data the person voluntarily provided for a specified purpose, employment purposes, legal obligations and medical emergencies.

What a Data Fiduciary must do

  • Give an itemised notice and take valid consent for each purpose.
  • Keep data accurate when it is used to make decisions or shared.
  • Put in place reasonable security safeguards to prevent a personal data breach, including at its processors.
  • Report every personal data breach to the Board and to the affected people.
  • Erase data once the purpose is served or consent is withdrawn, unless a law requires keeping it.
  • Publish a contact for questions and run a grievance process.
  • For children (under 18): get verifiable parental consent, and do no tracking, behavioural monitoring or targeted advertising.

Significant Data Fiduciaries must also appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.

The rights of people (Data Principals)

  • to a summary of their data and how it is processed, and who it was shared with;
  • to correction, completion, updating and erasure;
  • to grievance redressal, before going to the Board;
  • to nominate someone to exercise their rights after death or incapacity.

The Rules give organisations up to 90 days to respond to these requests.

Penalties

The Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for not reporting a breach or breaking the duties for children's data. See the full schedule in our guide to DPDP Act penalties.

When do you need to comply?

DateWhat applies
14 November 2025Rules notified; Data Protection Board provisions in force
13 November 2026Consent Manager registration and duties
13 May 2027Notice, consent, security safeguards, breach reporting, rights, retention and the rest of the business obligations

How to get started

Start with a gap assessment against each obligation, then fix the gaps in order of risk and keep evidence of each fix. Our DPDP compliance checklist walks through the steps. GRC Flow runs that assessment for you: guided intake mapped to every obligation, AI-drafted findings that cite the exact section and are reviewed by a person, and the evidence to prove it.

Frequently asked questions

What is the full form of DPDP?

DPDP stands for Digital Personal Data Protection. The law is the Digital Personal Data Protection Act, 2023 (often shortened to DPDP Act), and its detailed rules are the Digital Personal Data Protection Rules, 2025.

Is the DPDP Act in force?

Partly. The Act received Presidential assent in August 2023. The Rules were notified on 14 November 2025 and apply in phases: the Data Protection Board provisions applied immediately, Consent Manager provisions from 13 November 2026, and most obligations for businesses (notice, consent, security, breach reporting, rights) from 13 May 2027.

Does the DPDP Act apply to small businesses?

Yes. There is no turnover or headcount threshold. Any organisation that processes digital personal data of people in India is a Data Fiduciary and must comply. Some duties apply only to Significant Data Fiduciaries named by the government.

Does the DPDP Act apply to paper records?

Only once they are digitised. The Act covers personal data collected in digital form, and personal data collected on paper that is later digitised.

Who enforces the DPDP Act?

The Data Protection Board of India. It inquires into breaches and complaints and can impose the penalties set out in the Schedule to the Act.

Sources

This guide explains the law in general terms and is not legal advice. Check specific situations with a qualified lawyer.