Digital Personal Data Protection

Digital Personal Data Protection Act, 2023

Understand India's Digital Personal Data Protection framework, including the DPDP Act, DPDP Rules 2025, Data Principal rights, Data Fiduciary responsibilities, consent requirements and key data protection concepts.

Based on India's Digital Personal Data Protection framework

Overview

What Is the DPDP Act?

DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act, 2023 establishes India’s statutory framework for processing digital personal data. It balances the right of individuals to protect their personal data with the need to process such data for lawful purposes.

Personal data means any data about an individual who is identifiable by or in relation to such data. The Act focuses on digital personal data — including personal data collected in non-digital form and digitised subsequently — within the scope set out in Section 3. This hub orients you; dedicated pages and the glossary own full definitions.

Major participants include Data Principals, Data Fiduciaries, Data Processors, Consent Managers where registered under the Act, and the Data Protection Board of India. Use the glossary for one-sentence definitions and the topic guides below for deep dives.

Source: Digital Personal Data Protection Act, 2023

Scope

Who Does the DPDP Act Apply To?

Section 3 applies the Act to processing of digital personal data within India — including data collected in non-digital form and digitised later — and to certain processing outside India in connection with offering goods or services to Data Principals in India. Personal or domestic processing and certain publicly available personal data are outside scope.

Not every organization is automatically subject to every provision in the same way. Role (Data Fiduciary vs processor), processing facts, Significant Data Fiduciary designation and commencement dates all matter. Exact applicability depends on the statutory text and your facts — this page does not replace a legal assessment.

Framework

How the DPDP Framework Works

Consent is central where it applies — but it is not the only processing basis. Section 4 also allows certain legitimate uses under Section 7.

  1. 01

    Person

  2. 02

    Personal data

  3. 03

    Purpose

  4. 04

    Notice

  5. 05

    Consent / other applicable basis

  6. 06

    Processing

  7. 07

    Data Fiduciary responsibilities

  8. 08

    Data Principal rights

  9. 09

    Security / retention / governance

  10. 10

    Withdrawal / requests / enforcement

Sources of law

DPDP Act and DPDP Rules

DPDP Act, 2023

Statutory framework

Act No. 22 of 2023. Defines concepts, processing grounds, obligations, rights, the Board and penalties. Different provisions commence on different dates.

DPDP Rules, 2025

Rules under the Act

Notified as G.S.R. 846(E). Elaborate notices, Consent Managers, security, breach, retention, children’s data, SDFs, rights processes, transfers and Board matters — with phased commencement in Rule 1.

Notified

Published in the Official Gazette.

Effective / commenced

In force on the appointed date.

Upcoming

Notified but not yet commenced — prepare during the runway.

Commencement

DPDP Implementation Timeline

Based on official notifications dated 13 November 2025. Always verify against the Gazette.

Immediate

~13 Nov 2025

Act: Section 1(2), Section 2, Sections 18–26, 35, 38–43, 44(1)/(3). Rules: 1, 2, 17–21. Institutional architecture is live; core Fiduciary obligations are not all immediately enforceable solely because the Rules were notified.

One year

~13 Nov 2026

Act: Section 6(9) and Section 27(1)(d). Rules: Rule 4 (Consent Manager registration).

Eighteen months

~13 May 2027

Core operational Act provisions (including Sections 3–5, most of Section 6, 7–17 and related enforcement) and Rules 3, 5–16, 22–23 — the primary compliance runway for most organizations.

Operations

What DPDP Means in Practice

Translate legal requirements into operational processes. This lifecycle is for planning — not a substitute for the Act or Rules.

  1. 01

    Identify data

    What digital personal data is processed?

  2. 02

    Identify purpose

    Why is each category processed?

  3. 03

    Determine basis

    Consent under Sections 4/6, or a certain legitimate use under Section 7?

  4. 04

    Provide notice

    What must the Data Principal be told?

  5. 05

    Record decisions

    How is consent or another basis evidenced?

  6. 06

    Manage lifecycle

    Purposes, retention, erasure and changes.

  7. 07

    Support requests

    How are Sections 11–14 handled operationally?

  8. 08

    Security & breach

    Safeguards and intimation processes.

  9. 09

    Governance

    Ownership, processors and SDF duties if applicable.

Open the compliance checklist →

Pitfalls

Common DPDP Compliance Mistakes

Treating DPDP as only a cookie-consent problem

Website cookies may be part of a program, but the Act addresses digital personal data across purposes and channels.

Treating consent as a one-time checkbox

Where consent applies, it is purpose-linked, must meet Section 6 qualities, and may be withdrawn. A single generic checkbox rarely reflects that lifecycle.

Assuming every processing activity uses consent

Section 4 also allows certain legitimate uses under Section 7. Assess the applicable basis for each situation.

Treating a generic privacy notice as automatically satisfying every notice requirement

Section 5 and Rule 3 set specific expectations for notices with consent requests. A general policy may not meet them by itself.

Assuming GDPR compliance automatically means DPDP compliance

The frameworks differ in structure, terminology, rights and institutions. One does not automatically satisfy the other.

Calling a product a “Consent Manager” without Board registration

A Consent Manager under the Act is registered with the Board under Section 6(9) and Rule 4. Product marketing is not that status.

Topic guides

Explore DPDP Topics

Every key entity, section and rule has its own canonical page. The hub routes you there — it does not duplicate the deep dive.

Consent

Where consent is the processing basis, the Act connects notice, purpose, the consent decision, withdrawal and accountability. Consent is not the only ground for processing.

Explore Consent →

Data Principal

The individual to whom personal data relates. Sections 11–14 provide rights of access, correction and erasure, grievance redressal and nomination.

Explore Data Principal rights →

Data Fiduciary

Any person who alone or with others determines the purpose and means of processing personal data. Section 8 sets general obligations spanning purpose, notice, security, breach intimation and retention.

Explore Data Fiduciary duties →

Significant Data Fiduciary

Designation is by Central Government notification based on statutory factors — not self-declared thresholds — with additional governance obligations under Section 10 and Rule 13.

Explore Significant Data Fiduciary →

Children's data

Section 9 and Rules 10–12 address verifiable consent of a parent or lawful guardian and related processing restrictions for individuals under eighteen.

Explore children's data →

Verifiable consent (Rule 10)

Rule 10 sets due-diligence expectations for obtaining verifiable parental consent before processing personal data of a child.

Explore Rule 10 →

Data Protection Board

Chapter V establishes the Board — the institutional body that inquires into breaches and performs related enforcement functions.

Explore the Board →

Consent Notice

The notice that must accompany or precede a consent request under Section 5, elaborated in Rule 3.

Explore Consent Notice →

Consent Manager

A person registered with the Board who enables Data Principals to give, manage, review and withdraw consent — registration opens under Rule 4.

Explore Consent Manager →

Purpose

Personal data may be processed only for a lawful purpose — via consent or certain legitimate uses under Section 7.

Explore Purpose →

Lawful Guardian

A parent or lawful guardian engaged for verifiable consent relating to a child or certain persons with disability.

Explore Lawful Guardian →

Security safeguards

Section 8(5) and Rule 6 require reasonable security safeguards to protect personal data and help prevent personal data breach.

Explore Rule 6 →

Personal data breach

Section 8(6) and Rule 7 address intimation to affected Data Principals and the Board, including timing for detailed Board updates.

Explore Rule 7 →

Retention and erasure

Retention is purpose-linked. Section 8 and Rule 8 address when personal data must be erased and related operational expectations.

Explore Rule 8 →

Cross-border transfers

Rule 15 does not ban transfers or require all Indian personal data to stay in India. It sets a mechanism for government-specified restrictions.

Explore Rule 15 →

Penalties

Section 33 and the Schedule set maximum monetary penalties the Board may impose after inquiry. Penalties are enforcement tools, not a marketing message.

Explore penalties →

Compliance checklist

A starting-point planning checklist covering discovery, notice and consent, rights, security, retention, children and governance.

Explore checklist →

Processing

Automated operations on digital personal data, including collection, storage, use and sharing.

Explore Processing →

Consent Artefact

An operational term for the structured record of a consent decision — not a defined term in the Act or Rules.

Explore Consent Artefact →

Open the full DPDP Glossary →

Authority

Official DPDP Sources

ConsentifyAI’s explanations are educational. Government of India / MeitY documents are authoritative.

FAQ

DPDP FAQs

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 is India’s primary statute for processing of digital personal data. It recognises both the right of individuals to protect their personal data and the need to process such data for lawful purposes.

What does DPDP mean?

DPDP stands for Digital Personal Data Protection — India’s framework centred on the DPDP Act, 2023, the DPDP Rules, 2025 and related institutions such as the Data Protection Board of India.

Who does DPDP apply to?

Section 3 applies the Act to processing of digital personal data within India (including later digitisation of non-digital collections) and to certain processing outside India connected with offering goods or services to Data Principals in India. Exact applicability depends on the facts and the statutory text.

What are the DPDP Rules 2025?

Rules made under Section 40 that elaborate notices, Consent Managers, security, breach intimation, retention, children’s data, SDFs, rights processes, transfers and Board matters — with phased commencement under Rule 1.

What is DPDP compliance?

Aligning an organization’s personal data processing with applicable Act and Rules provisions — purpose, notice, consent or other basis, rights, security, retention, children’s data where relevant, and governance — assessed against actual processing and commencement dates.

Where should I go for detailed definitions?

Use the DPDP Glossary for one-sentence definitions and dedicated /dpdp/ pages for deep dives on consent, rights, children’s data, Fiduciary duties, Rules and enforcement.

Does this DPDP hub provide legal advice?

No. This hub is educational and implementation-oriented. Organizations should obtain legal advice for fact-specific obligations and decisions.

Where should product capability questions go?

Use /features/ for capability-level explanations and /products/ for platform-level evaluation. This DPDP hub focuses on legal-framework context.

From Understanding DPDP to Implementation

Implement

Use ConsentifyAI products where consent and cookie management technology is relevant.

Explore Products →

Information on this page is provided for general educational and implementation-planning purposes and is based on the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and related official notifications. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.

Understand DPDP. Plan Your Approach. Implement With Confidence.

Use the DPDP knowledge hub to understand the framework, then open dedicated topic pages and the glossary for depth.