The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data-protection law. It governs the processing of digital personal data of individuals (called Data Principals) by organisations (called Data Fiduciaries). The Act is built around consent, lawful processing, purpose limitation, and accountability, and it applies to processing within India as well as to processing outside India that targets Indian Data Principals.
Core obligations include obtaining clear, informed consent (with an easy way to withdraw it), serving a plain-language notice describing the purpose of collection, processing data only for the stated purpose, implementing reasonable security safeguards, and reporting personal data breaches to the Data Protection Board of India. Significant Data Fiduciaries face additional duties such as appointing a Data Protection Officer and conducting periodic Data Protection Impact Assessments.
The Act also creates strong rights for Data Principals — the right to access information, the right to correction and erasure, the right to grievance redressal, and the right to nominate. Non-compliance can attract substantial financial penalties imposed by the Board, making operational evidence and demonstrable controls essential.
Comply automates this — see the DPDP framework page.