DPDP Act, 2023
Statutory framework
Act No. 22 of 2023. Defines concepts, processing grounds, obligations, rights, the Board and penalties. Different provisions commence on different dates.
Digital Personal Data Protection
Understand India's Digital Personal Data Protection framework, including the DPDP Act, DPDP Rules 2025, Data Principal rights, Data Fiduciary responsibilities, consent requirements and key data protection concepts.
Based on India's Digital Personal Data Protection framework
Overview
DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act, 2023 establishes India’s statutory framework for processing digital personal data. It balances the right of individuals to protect their personal data with the need to process such data for lawful purposes.
Personal data means any data about an individual who is identifiable by or in relation to such data. The Act focuses on digital personal data — including personal data collected in non-digital form and digitised subsequently — within the scope set out in Section 3. This hub orients you; dedicated pages and the glossary own full definitions.
Major participants include Data Principals, Data Fiduciaries, Data Processors, Consent Managers where registered under the Act, and the Data Protection Board of India. Use the glossary for one-sentence definitions and the topic guides below for deep dives.
Scope
Section 3 applies the Act to processing of digital personal data within India — including data collected in non-digital form and digitised later — and to certain processing outside India in connection with offering goods or services to Data Principals in India. Personal or domestic processing and certain publicly available personal data are outside scope.
Not every organization is automatically subject to every provision in the same way. Role (Data Fiduciary vs processor), processing facts, Significant Data Fiduciary designation and commencement dates all matter. Exact applicability depends on the statutory text and your facts — this page does not replace a legal assessment.
Framework
Consent is central where it applies — but it is not the only processing basis. Section 4 also allows certain legitimate uses under Section 7.
Person
Personal data
Purpose
Notice
Consent / other applicable basis
Processing
Data Fiduciary responsibilities
Data Principal rights
Security / retention / governance
Withdrawal / requests / enforcement
Sources of law
Statutory framework
Act No. 22 of 2023. Defines concepts, processing grounds, obligations, rights, the Board and penalties. Different provisions commence on different dates.
Rules under the Act
Notified as G.S.R. 846(E). Elaborate notices, Consent Managers, security, breach, retention, children’s data, SDFs, rights processes, transfers and Board matters — with phased commencement in Rule 1.
Notified
Published in the Official Gazette.
Effective / commenced
In force on the appointed date.
Upcoming
Notified but not yet commenced — prepare during the runway.
Commencement
Based on official notifications dated 13 November 2025. Always verify against the Gazette.
~13 Nov 2025
Act: Section 1(2), Section 2, Sections 18–26, 35, 38–43, 44(1)/(3). Rules: 1, 2, 17–21. Institutional architecture is live; core Fiduciary obligations are not all immediately enforceable solely because the Rules were notified.
~13 Nov 2026
Act: Section 6(9) and Section 27(1)(d). Rules: Rule 4 (Consent Manager registration).
~13 May 2027
Core operational Act provisions (including Sections 3–5, most of Section 6, 7–17 and related enforcement) and Rules 3, 5–16, 22–23 — the primary compliance runway for most organizations.
Operations
Translate legal requirements into operational processes. This lifecycle is for planning — not a substitute for the Act or Rules.
What digital personal data is processed?
Why is each category processed?
Consent under Sections 4/6, or a certain legitimate use under Section 7?
What must the Data Principal be told?
How is consent or another basis evidenced?
Purposes, retention, erasure and changes.
How are Sections 11–14 handled operationally?
Safeguards and intimation processes.
Ownership, processors and SDF duties if applicable.
Pitfalls
Website cookies may be part of a program, but the Act addresses digital personal data across purposes and channels.
Where consent applies, it is purpose-linked, must meet Section 6 qualities, and may be withdrawn. A single generic checkbox rarely reflects that lifecycle.
Section 4 also allows certain legitimate uses under Section 7. Assess the applicable basis for each situation.
Section 5 and Rule 3 set specific expectations for notices with consent requests. A general policy may not meet them by itself.
The frameworks differ in structure, terminology, rights and institutions. One does not automatically satisfy the other.
A Consent Manager under the Act is registered with the Board under Section 6(9) and Rule 4. Product marketing is not that status.
Topic guides
Every key entity, section and rule has its own canonical page. The hub routes you there — it does not duplicate the deep dive.
Where consent is the processing basis, the Act connects notice, purpose, the consent decision, withdrawal and accountability. Consent is not the only ground for processing.
The individual to whom personal data relates. Sections 11–14 provide rights of access, correction and erasure, grievance redressal and nomination.
Any person who alone or with others determines the purpose and means of processing personal data. Section 8 sets general obligations spanning purpose, notice, security, breach intimation and retention.
Designation is by Central Government notification based on statutory factors — not self-declared thresholds — with additional governance obligations under Section 10 and Rule 13.
Section 9 and Rules 10–12 address verifiable consent of a parent or lawful guardian and related processing restrictions for individuals under eighteen.
Rule 10 sets due-diligence expectations for obtaining verifiable parental consent before processing personal data of a child.
Chapter V establishes the Board — the institutional body that inquires into breaches and performs related enforcement functions.
The notice that must accompany or precede a consent request under Section 5, elaborated in Rule 3.
A person registered with the Board who enables Data Principals to give, manage, review and withdraw consent — registration opens under Rule 4.
Personal data may be processed only for a lawful purpose — via consent or certain legitimate uses under Section 7.
A parent or lawful guardian engaged for verifiable consent relating to a child or certain persons with disability.
Section 8(5) and Rule 6 require reasonable security safeguards to protect personal data and help prevent personal data breach.
Section 8(6) and Rule 7 address intimation to affected Data Principals and the Board, including timing for detailed Board updates.
Retention is purpose-linked. Section 8 and Rule 8 address when personal data must be erased and related operational expectations.
Rule 15 does not ban transfers or require all Indian personal data to stay in India. It sets a mechanism for government-specified restrictions.
Section 33 and the Schedule set maximum monetary penalties the Board may impose after inquiry. Penalties are enforcement tools, not a marketing message.
A starting-point planning checklist covering discovery, notice and consent, rights, security, retention, children and governance.
Any data about an individual who is identifiable by or in relation to such data.
Automated operations on digital personal data, including collection, storage, use and sharing.
An operational term for the structured record of a consent decision — not a defined term in the Act or Rules.
Authority
ConsentifyAI’s explanations are educational. Government of India / MeitY documents are authoritative.
FAQ
The Digital Personal Data Protection Act, 2023 is India’s primary statute for processing of digital personal data. It recognises both the right of individuals to protect their personal data and the need to process such data for lawful purposes.
DPDP stands for Digital Personal Data Protection — India’s framework centred on the DPDP Act, 2023, the DPDP Rules, 2025 and related institutions such as the Data Protection Board of India.
Section 3 applies the Act to processing of digital personal data within India (including later digitisation of non-digital collections) and to certain processing outside India connected with offering goods or services to Data Principals in India. Exact applicability depends on the facts and the statutory text.
Rules made under Section 40 that elaborate notices, Consent Managers, security, breach intimation, retention, children’s data, SDFs, rights processes, transfers and Board matters — with phased commencement under Rule 1.
Aligning an organization’s personal data processing with applicable Act and Rules provisions — purpose, notice, consent or other basis, rights, security, retention, children’s data where relevant, and governance — assessed against actual processing and commencement dates.
Use the DPDP Glossary for one-sentence definitions and dedicated /dpdp/ pages for deep dives on consent, rights, children’s data, Fiduciary duties, Rules and enforcement.
No. This hub is educational and implementation-oriented. Organizations should obtain legal advice for fact-specific obligations and decisions.
Use /features/ for capability-level explanations and /products/ for platform-level evaluation. This DPDP hub focuses on legal-framework context.
Learn
Understand the Act, Rules and terminology.
Plan
Translate applicable requirements into an organizational approach.
Implement
Use ConsentifyAI products where consent and cookie management technology is relevant.
Information on this page is provided for general educational and implementation-planning purposes and is based on the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and related official notifications. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.
Use the DPDP knowledge hub to understand the framework, then open dedicated topic pages and the glossary for depth.