Cornerstone guide

What is the DPDP Act, 2023? A plain-English guide

A plain-English guide to India's Digital Personal Data Protection Act, 2023 — what it is, who it covers, what it requires, and how to comply.

By DreamyHook Consultancy ServicesUpdated 9 min read

India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") is the country's first comprehensive law dedicated to protecting personal data. If your organization collects, stores, or uses the personal data of people in India — and almost every modern business does — this law now governs how you must do it.

This guide explains the Act in plain language: what it is, who it covers, what it asks of you, and where to start.

What the DPDP Act is, in one sentence

The DPDP Act sets the rules for how organizations may handle the digital personal data of individuals in India, gives individuals enforceable rights over their data, and creates a regulator — the Data Protection Board of India — to enforce it all.

It received Presidential assent on 11 August 2023. The detailed operational requirements come through the DPDP Rules, which are being rolled out on a phased timeline.

The key players (in the Act's language)

  • Data Principal — the individual the personal data is about (you, your customers, your users).
  • Data Fiduciary — the organization that decides why and how personal data is processed. This is probably you.
  • Data Processor — anyone who processes personal data on behalf of a Data Fiduciary (your vendors and tools).
  • Significant Data Fiduciary (SDF) — a higher-risk Data Fiduciary, notified by the government, with extra duties. Learn more about SDFs.
  • Consent Manager — a new, registered intermediary that lets people manage their consents in one place.

Who has to comply

Practically every organization that processes the digital personal data of people in India. The Act applies to processing within India, and also to processing outside India where it relates to offering goods or services to people in India.

It covers data collected digitally, and non-digital data that is later digitized. Purely personal or domestic use is excluded, and certain government processing has specific treatment.

What the Act requires of you

At its heart, the DPDP Act asks you to process personal data lawfully, for clear purposes, with consent (or another permitted ground), and no more than you need. In practice that means:

  • Notice & consent. Tell people clearly what you collect and why, and obtain consent that is free, specific, informed, unconditional, and unambiguous — with withdrawal as easy as giving it. (We build this in our Consent Management service.)
  • Purpose limitation & minimization. Collect only what you need, and only use it for the purpose you stated.
  • Accuracy & retention limits. Keep data accurate, and delete it when the purpose is served.
  • Security safeguards. Protect data with reasonable technical and organizational measures.
  • Honor Data Principal rights. Provide access, correction, erasure, grievance redressal, and nomination. (See Data Principal Rights Automation.)
  • Breach notification. Notify the Data Protection Board and affected individuals if a personal data breach occurs.
  • Children's data. Obtain verifiable parental consent for under-18s and avoid tracking or targeting them.

Rights of the Data Principal

The Act gives individuals the right to:

  1. Access a summary of their personal data and who it has been shared with.
  2. Correction, completion, updating, and erasure of their data.
  3. Grievance redressal through a readily available mechanism.
  4. Nomination of another person to exercise their rights in case of death or incapacity.

Penalties

The Data Protection Board can impose significant financial penalties — up to ₹250 crore for certain failures (for example, inadequate security safeguards leading to a breach). Penalties are decided after due process and are graded to the nature and gravity of the breach. See Penalties & Enforcement for the detail.

How to actually comply

Reading the law is the easy part. The hard part is making your systems match it. A sensible sequence:

  1. Find out where you stand with a readiness audit — map your data and your gaps.
  2. Fix the gaps through technical implementation — consent, rights, retention, security.
  3. Stay compliant with managed compliance and, where needed, a DPO.

The fastest way to see your own position is our free DPDP Quick Scan — five minutes for an instant readiness snapshot.

This guide is general information about the DPDP Act, 2023, not legal advice. Confirm specifics against the official notified text or with a qualified lawyer.

Frequently asked questions

The Digital Personal Data Protection Act was passed by Parliament and received Presidential assent on 11 August 2023. Its provisions are being brought into force in phases through the DPDP Rules.

Yes. The Act applies to almost any organization that processes the digital personal data of people in India, regardless of size. Some obligations are lighter for smaller players, but the core duties apply broadly.

Financial penalties can reach up to ₹250 crore for certain breaches, imposed by the Data Protection Board of India after due process.

See how this applies to you

The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.

Take the free Quick Scan

The deadline isn't moving. Start today.

Get your free DPDP Quick Scan — no obligation, instant results. See where you stand in five minutes.