Author: Mayank, Fairfield Institute of Management and Technology
Why This Law Matters
India spent the better part of a decade without a real rulebook for personal data — that gap finally closed in August 2023, when Parliament cleared the Digital Personal Data Protection Act (I’ll call it the DPDP Act or simply “the Act” from here on).
Getting here wasn’t quick. The idea first surfaced around 2018, went through several rewrites and rounds of public feedback, and survived more than one false start before landing in its current form. What India had until then was a set of privacy-adjacent rules tucked inside the old Information Technology Act of 2000 — workable in 2000, but never built for a country now running on smartphones, UPI payments, and cloud-hosted everything. Pressure to fix that only grew after the Supreme Court’s landmark 2017 ruling that treated privacy itself as a fundamental right. The DPDP Act is essentially Parliament answering that call: it hands individuals — termed “Data Principals” — real say over their own information, and puts firm, checkable duties on whoever is handling that information (the “Data Fiduciaries”).
Getting the Vocabulary Straight
A few terms recur constantly through the Act, so it helps to get comfortable with them early:
● Data Principal: put simply, whoever the data belongs to. A child’s or a disabled person’s parent or guardian steps in to act for them.
● Data Fiduciary: the organisation deciding why data gets collected and how it gets used. It’s on them, legally, to get compliance right.
● Data Processor: a third party doing the actual handling of data, but on someone else’s instructions rather than making the calls itself.
● Consent Manager: a brand-new type of registered intermediary meant to give people one place — rather than a dozen separate settings pages — to grant, check, or revoke consent.
● Significant Data Fiduciary: a label the government can pin on an organisation once its data footprint gets large or sensitive enough, or once its work touches things like elections or national security. That label comes with extra baggage — a locally based Data Protection Officer, an outside auditor, and ongoing impact assessments.
What the Act Asks of Businesses
Strip away the legal phrasing and the underlying rule is fairly intuitive: don’t touch someone’s personal data unless they’ve actually said yes, or unless the situation is one of a handful the law already blesses — a medical emergency, rolling out a government scheme, following a court’s order, or ordinary HR processes tied to someone’s job. Before that “yes” is even asked for, people need to be told, in plain terms, what’s being collected and for what purpose. And walking that consent back later should take no more effort than giving it did.
Beyond consent, Data Fiduciaries are on the hook for a handful of other things:
● Putting reasonable technical and organisational safeguards in place so breaches don’t happen in the first place.
● Telling both the regulator and every affected person quickly if a breach does happen.
● Deleting data once it’s no longer needed for the purpose it was collected for, unless some other law says otherwise.
● Running a grievance process that people can actually use and get answers from.
What People Actually Get to Do
On the individual’s side, the law hands out a fairly practical set of powers: ask a company for a rundown of what data it holds on you and who it’s been passed along to; get wrong or outdated entries fixed, filled in, or removed entirely; name someone to step into your shoes and exercise these rights if you die or become incapacitated; and raise a complaint with the company itself before ever needing to escalate to the regulator.
Kids Get Extra Guardrails
Anyone under eighteen counts as a child under this law, and processing their data needs a parent’s or guardian’s consent that can actually be checked, not just clicked through. Companies also can’t track children’s behaviour or run targeted ads at them at all — a flat ban that goes further than what many other countries require.
Who Actually Enforces This
A newly created regulator, the Data Protection Board of India, carries the enforcement load. It’s built to run almost entirely online — complaints, hearings, and penalty orders all handled digitally rather than through paper filings. The Board can order fixes after a breach, investigate suspected violations, and hand down fines. Anyone unhappy with its decision can appeal to the Telecom Disputes Settlement and Appellate Tribunal.
The Cost of Getting It Wrong
The fines here aren’t symbolic. Skimping on security safeguards can cost an organisation up to ₹250 crore, and staying quiet about a breach instead of reporting it can run up to ₹200 crore on its own. Mishandling the extra rules around children’s data, or around Significant Data Fiduciary duties, tops out at ₹200 crore and ₹150 crore respectively. On the flip side, if an individual misuses the system — say, by filing a bogus complaint — they’re looking at a much smaller penalty, capped at ₹10,000. None of these are automatic maximums; the Board weighs things like how serious and how long-running the violation was, whether the company profited from it, and whether it moved quickly to contain the damage.
Sending Data Abroad, and Who’s Exempt
Earlier drafts of this law flirted with forcing companies to keep Indian data inside India. The version that actually passed drops that requirement — cross-border transfers are allowed by default, though the government keeps a standing power to block transfers to specific countries if it chooses to. There’s also a fairly long list of situations the Act simply steps aside for: law-enforcement and judicial work, mergers and corporate restructuring, and research or statistical work, to name a few.
Where This Leaves Things
None of this switches on overnight. Different parts of the Act will be activated in phases as the government notifies them, and a fair amount of the fine print — how exactly breach notices should look, how Consent Managers get registered — is still waiting on rules that haven’t been finalised yet. That said, the direction is obvious enough that companies shouldn’t wait around: consent flows, breach-response playbooks, data-retention policies, and grievance handling are all worth building out now, ahead of whatever deadlines eventually land.
Frequently Asked Questions
1. Who exactly does this law cover?
Anyone processing digital personal data inside India, plus foreign entities if their processing is tied to offering goods or services to people in India. It carves out purely personal or household use, and data that individuals have chosen to put out publicly themselves.
2. Has the Act actually taken effect?
Presidential assent came in August 2023, but the law switches on section by section through separate government notifications rather than all at once. A lot of the supporting rules hadn’t been finalised at the time of passage, so the real compliance clock depends on notifications still to come.
3. How broadly is “personal data” defined?
Very broadly — anything about a person that can be tied back to them counts, whether that’s a name, a phone number, an ID number, or some other detail that identifies who they are.
4. Are startups and smaller companies treated differently?
The government can carve out exemptions for particular categories of Data Fiduciaries, startups included, from things like notice obligations or Significant Data Fiduciary-style duties, based on how much data they handle and what kind.
5. What’s the drill if a company gets breached?
It has to alert both the regulator and everyone affected, following a process the rules will spell out. Skipping that step is its own violation, punishable separately from the breach itself — up to ₹200 crore.
6. Can someone just take a company to court over this?
Not directly. Regular civil courts are shut out of anything that falls under the Board’s jurisdiction. The route is: complain to the company first, then the Board, then appeal to the Tribunal if needed.
7. How does this stack up against the GDPR?
There’s real overlap — consent requirements, breach notices, access and correction rights all show up in both. But the DPDP Act leaves more to future rulemaking rather than spelling everything out upfront, skips the GDPR’s separate “sensitive data” category, and gives the government wider latitude to exempt its own departments and agencies.
Footnotes
1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), assented to on 11 August 2023, published in the Gazette of India, Extraordinary, Part II — Section 1.
2. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, in which a nine-judge bench of the Supreme Court of India recognised privacy as a fundamental right under Article 21 of the Constitution.
3. Section 2(j), DPDP Act, 2023.
4. Section 2(g), DPDP Act, 2023.
5. Section 10, DPDP Act, 2023.
6. Sections 4 to 7, DPDP Act, 2023.
7. Section 8(6), DPDP Act, 2023.
8. Sections 11 to 14, DPDP Act, 2023.
9. Section 9, DPDP Act, 2023.
10. Sections 18–33, DPDP Act, 2023; Schedule (See section 33(1)).


