What Is the DPDP Act 2023? A Plain-Language Introduction
India's Digital Personal Data Protection Act, 2023 introduces new obligations for any business that handles personal data. Here's what it actually says, without the legalese.
If your business collects a customer's name, phone number, email address, or almost any other piece of information that identifies a person, the Digital Personal Data Protection Act, 2023 (DPDP Act) probably applies to you. It's India's first comprehensive law dedicated specifically to personal data protection, and it changes how organisations are expected to collect, use, and safeguard that data.
This post walks through the basics: what the law covers, who it applies to, and the handful of ideas you need to understand before diving into the details.
Why India needed a dedicated law
Before the DPDP Act, personal data protection in India was addressed indirectly through the Information Technology Act, 2000 and its associated rules. Those rules were narrower in scope and predated the explosion of mobile apps, cloud services, and digital-first businesses that now routinely collect personal data at scale.
The DPDP Act was written specifically for this environment. It draws on ideas familiar from data protection laws elsewhere in the world, but it is its own law, with its own definitions, its own obligations, and its own enforcement body — the Data Protection Board of India.
Who does the Act apply to?
The Act applies to the processing of digital personal data within India, and also to processing outside India if it relates to offering goods or services to individuals in India. In short: if you have Indian users or customers and you process their personal data digitally, the Act is relevant to you, regardless of where your company is headquartered.
Two roles matter most:
- Data Fiduciary — the organisation that decides why and how personal data is processed. This is usually the business itself.
- Data Principal — the individual the data is about. Your customers, users, employees, and website visitors are all Data Principals.
The central idea: consent as a lawful basis
At the heart of the Act is a simple principle — personal data should generally only be processed with the informed, freely given consent of the Data Principal, for a clearly stated purpose. The Act calls out a limited set of "legitimate uses" where consent isn't required (for example, specified government functions or medical emergencies), but for most commercial processing, consent is the expected foundation.
This means notices need to be clear, consent needs to be specific rather than bundled, and individuals need a straightforward way to withdraw consent later.
What businesses are expected to do
At a practical level, the Act expects Data Fiduciaries to:
- Give clear notice about what data is collected and why, before or at the time of collection.
- Collect only the data that's actually necessary for the stated purpose.
- Put in place reasonable security safeguards to prevent breaches.
- Let individuals access, correct, and request erasure of their data.
- Notify the Data Protection Board and affected individuals if a data breach occurs.
None of this is exotic — most of it reflects practices that thoughtful product and engineering teams already try to follow. The difference is that under the DPDP Act, these become legal obligations with real financial penalties attached for serious non-compliance.
Where the law stands now
The Act received Presidential assent in August 2023, but its obligations arrive in phases. The DPDP Rules, 2025 — notified on 13 November 2025 — set out how the Act works in practice. Provisions establishing the Data Protection Board of India took effect immediately; provisions governing Consent Managers apply from 13 November 2026; and the remaining substantive obligations — notice, consent, Data Principal rights, and breach reporting — apply from 13 May 2027.
That phased timeline is preparation time, not a reason to wait. Consent flows, data mapping, and record-keeping take time to build well, and retrofitting them under deadline pressure is far harder than building them in early.
What this means in practice
For most growing businesses, the DPDP Act doesn't mean starting from zero. It means:
- Auditing what personal data you currently collect and why.
- Making sure your consent notices are specific and easy to understand.
- Building a way for people to see, correct, or delete their data.
- Keeping a record of consent that you could produce if asked.
That last point is where a dedicated consent management platform tends to save the most time — manually tracking consent across spreadsheets and code comments doesn't scale, and it definitely doesn't hold up well under audit.
In our next post, we'll go deeper into what "good" consent management actually looks like in practice.