A plain-English primer. What the DPDP Act says, who it covers, what happens if you ignore it — and how ProtectComply implements each section.
The Digital Personal Data Protection Act, 2023 is India's primary data-protection law. It governs how any business — Indian or foreign — collects, stores, uses, and shares the personal data of individuals located in India. The Act creates two key roles: the Data Fiduciary (you decide why and how data is processed) and the Data Processor (you process on someone else's behalf). It is enforced by the Data Protection Board of India.
Aug 2023
DPDP Act enacted by Parliament
Jan 2025
Draft Rules notified by MeitY
2025-2026
Phased enforcement rolling out
Any business processing the personal data of individuals in India. This includes start-ups, banks, hospitals, ed-tech, e-commerce, SaaS, and non-Indian companies that offer goods or services here. There is no size or revenue floor.
Up to ₹250 crore per failure to safeguard personal data. ₹200 crore for failing to notify the Board of a breach. Smaller bands for other categories under the Schedule.
§4
You can process personal data only with consent or for certain legitimate uses. No bundled consent.
§5
Every Notice must be itemised, in plain language, in any of the 22 official Indian languages — and available before or at the time of consent.
§6
Consent must be free, specific, informed, unconditional, unambiguous, with the right to withdraw — and as easy to withdraw as to grant.
§7
Certain processing — voluntary disclosure, employment, medical emergencies, court order — doesn't need consent. Document the basis.
§8
You must ensure accuracy, implement reasonable security safeguards, notify the Board of breaches, and erase data when its purpose is exhausted.
§9
Verifiable parental consent before processing. No behavioural monitoring or targeted advertising to minors.
§10
If the Board designates you as Significant, you owe a DPO, periodic DPIAs, and periodic audits.
§11
A principal can ask what personal data you process, how, and with whom you have shared it.
§12
A principal can have their personal data corrected, completed, updated, or erased when it is no longer needed.
§13
You must publish a grievance officer and resolve complaints within a defined period (90 days by Rule 13).
§14
A principal can nominate someone to exercise their rights on death or incapacity.
Each linked page covers the legal text, plain-English meaning, penalty exposure, and the module that solves it.
Once you know what the Act asks for, the next question is what to run it on. We compare the best DPDP compliance platform in India against the alternatives, and rank the wider market of DPDP platforms and DPDP compliance software on evidence you can verify.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →