Who the Act applies to
Section 3 applies the Act to digital personal data processed within India, and to processing outside India where it is in connection with offering goods or services to Data Principals in India. Personal data made publicly available by the Data Principal themselves, and personal data processed for personal or domestic purposes, are outside its scope.
A Data Fiduciary is the person who alone or with others determines the purpose and means of processing (Section 2(i)). A Data Processor processes on behalf of a Data Fiduciary. A Data Principal is the individual the data relates to; for a child it includes the parent or lawful guardian.
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. Its provisions are brought into force, and its operational detail supplied, through Rules notified by the Central Government; a draft of those Rules was published for public consultation in January 2025. Confirm the commencement status of the specific section and the current text of the Rules before relying on any date or timeline.
Notice and consent
Under Section 5 the request for consent must be accompanied, or preceded, by a notice stating the personal data to be collected, the purpose of processing, how the Data Principal may exercise their rights, and how a complaint may be made to the Data Protection Board. The notice must be available in English or any language in the Eighth Schedule to the Constitution, at the Data Principal's option.
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose. Consent can be withdrawn at any time and withdrawal must be as easy as giving it. On withdrawal, the Data Fiduciary must stop processing within a reasonable time unless another law requires it to continue.
Section 7 sets out 'certain legitimate uses' where consent is not required — including where the Data Principal has voluntarily provided data for a specified purpose and has not indicated an objection, for State functions and subsidies, compliance with law or court orders, medical emergencies, epidemics, disasters and specified employment purposes.
Duties of a Data Fiduciary
- Remain responsible for compliance even where processing is done by a Data Processor under contract (Section 8(1) and 8(2)).
- Ensure completeness, accuracy and consistency of data used to make a decision affecting the Data Principal or disclosed to another Data Fiduciary (Section 8(3)).
- Implement reasonable security safeguards to prevent a personal data breach (Section 8(5)).
- Notify the Data Protection Board and each affected Data Principal of a personal data breach (Section 8(6)).
- Erase personal data on withdrawal of consent or when the purpose is no longer being served, unless retention is required by law (Section 8(7)).
- Publish the contact details of a Data Protection Officer or a person able to answer questions about processing (Section 8(9)).
- Establish an effective grievance redressal mechanism (Section 8(10)).
Children and persons with disability
Section 9 requires verifiable consent of a parent or lawful guardian before processing the personal data of a child — defined as a person under eighteen — and of a person with disability who has a lawful guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited, and no processing may be undertaken that is likely to cause a detrimental effect on a child's well-being. The Central Government may exempt specified classes of Data Fiduciaries or purposes from parts of this section.
Significant Data Fiduciaries
Section 10 allows the Central Government to notify a Data Fiduciary or class of Data Fiduciaries as 'Significant', based on factors including the volume and sensitivity of data processed, risk to the rights of Data Principals, potential effects on India's sovereignty and integrity, risk to electoral democracy, and public order. A Significant Data Fiduciary must appoint a Data Protection Officer based in India who reports to the board or governing body, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.
Rights of the Data Principal
- Right to a summary of personal data being processed and the processing activities, and the identities of other Data Fiduciaries with whom it has been shared (Section 11).
- Right to correction, completion, updating and erasure (Section 12).
- Right to a readily available means of grievance redressal, which must be exhausted before approaching the Data Protection Board (Section 13).
- Right to nominate another individual to exercise these rights in the event of death or incapacity (Section 14).
Section 15 also places duties on the Data Principal, including not raising false or frivolous grievances and not furnishing false particulars.
Cross-border transfer
Section 16 permits transfer of personal data outside India except to countries or territories restricted by notification of the Central Government. Where another law gives a higher degree of protection or restriction on transfer for a sector, that law prevails.
Penalties
Penalties are set out in the Schedule to the Act and are imposed by the Data Protection Board after an inquiry under Section 27. The Board determines the amount having regard to the factors in Section 33(2), including the nature, gravity and duration of the breach and any mitigating action taken.
| Failure | Penalty may extend to |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a personal data breach to the Board or affected Data Principals | ₹200 crore |
| Breach of the additional obligations relating to children | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of a Data Principal's duties | ₹10,000 |
| Breach of any other provision or Rule | ₹50 crore |
What this means in practice
- Maintain a record of the notice text and the consent event for each Data Principal, since the Data Fiduciary carries the burden of showing that valid consent was obtained.
- Give withdrawal of consent the same prominence as giving it.
- Map every purpose to the data it needs, and stop collecting fields no purpose relies on.
- Publish a working contact point for data questions and a grievance route, and staff both.
- Write breach detection and notification into the incident-response plan, not just the policy document.
