DPDP Primer

India's Digital Personal Data Protection Act

A plain-English primer. What the DPDP Act says, who it covers, what happens if you ignore it — and how ProtectComply implements each section.

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 is India's primary data-protection law. It governs how any business — Indian or foreign — collects, stores, uses, and shares the personal data of individuals located in India. The Act creates two key roles: the Data Fiduciary (you decide why and how data is processed) and the Data Processor (you process on someone else's behalf). It is enforced by the Data Protection Board of India.

Timeline

Aug 2023

DPDP Act enacted by Parliament

Jan 2025

Draft Rules notified by MeitY

2025-2026

Phased enforcement rolling out

Who is affected?

Any business processing the personal data of individuals in India. This includes start-ups, banks, hospitals, ed-tech, e-commerce, SaaS, and non-Indian companies that offer goods or services here. There is no size or revenue floor.

Penalty band

Up to ₹250 crore per failure to safeguard personal data. ₹200 crore for failing to notify the Board of a breach. Smaller bands for other categories under the Schedule.

Section-by-section primer

§4

Lawful basis for processing

You can process personal data only with consent or for certain legitimate uses. No bundled consent.

Solved by Consent Management →

§5

Notice & free consent

Every Notice must be itemised, in plain language, in any of the 22 official Indian languages — and available before or at the time of consent.

Solved by AI Policy Generator →

§6

Conditions of valid consent

Consent must be free, specific, informed, unconditional, unambiguous, with the right to withdraw — and as easy to withdraw as to grant.

Solved by Consent Management →

§7

Legitimate uses (no-consent paths)

Certain processing — voluntary disclosure, employment, medical emergencies, court order — doesn't need consent. Document the basis.

Solved by Readiness Assessment →

§8

Fiduciary obligations

You must ensure accuracy, implement reasonable security safeguards, notify the Board of breaches, and erase data when its purpose is exhausted.

Solved by Breach Management →

§9

Children's data

Verifiable parental consent before processing. No behavioural monitoring or targeted advertising to minors.

Solved by Children's consent flow →

§10

Significant Data Fiduciary duties

If the Board designates you as Significant, you owe a DPO, periodic DPIAs, and periodic audits.

Solved by SDF Readiness →

§11

Right to access information

A principal can ask what personal data you process, how, and with whom you have shared it.

Solved by Rights Manager →

§12

Correction and erasure

A principal can have their personal data corrected, completed, updated, or erased when it is no longer needed.

Solved by Rights Manager →

§13

Grievance redressal

You must publish a grievance officer and resolve complaints within a defined period (90 days by Rule 13).

Solved by Grievance Management →

§14

Nomination by data principal

A principal can nominate someone to exercise their rights on death or incapacity.

Solved by Rights Manager →

Deep dives per section

Each linked page covers the legal text, plain-English meaning, penalty exposure, and the module that solves it.

Section 5Section 6Section 8Section 9Section 11Section 13Rule 9Rule 12Rule 13

Choosing a platform to comply with

Once you know what the Act asks for, the next question is what to run it on. We compare the best DPDP compliance platform in India against the alternatives, and rank the wider market of DPDP platforms and DPDP compliance software on evidence you can verify.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →