What Is the DPDP Act? India’s Data Protection Law Explained
India’s DPDP Act, 2023 sets rules for consent, data principal rights, and breach notification, backed by penalties up to ₹250 crore. Here’s what it covers, who it applies to, and exactly where its phased 2025-2027 rollout stands today.
The Digital Personal Data Protection Act, 2023 (DPDP Act, or DPDPA) is India’s first comprehensive law governing how digital personal data gets processed. It sets rules for consent, data principal rights, and breach reporting, and backs them with penalties of up to ₹250 crore.[16] Full compliance isn’t legally required yet: the law is rolling out in three phases through May 2027, and the body meant to enforce it still has no appointed members.[20][23]
If you work in BFSI compliance, that gap between the law existing and the law being fully enforceable is the detail worth tracking. This piece covers what the Act says, who it applies to, and exactly where implementation stands as of today.
How the Act Became Law
The DPDP Bill moved through Parliament fast. It was introduced in the Lok Sabha on 3 August 2023, passed there four days later on 7 August, cleared the Rajya Sabha on 9 August, and received presidential assent on 11 August 2023, becoming the Digital Personal Data Protection Act, 2023.[2]
The Act runs 9 chapters and 44 sections, plus a penalty Schedule. It covers obligations on data fiduciaries (Chapter 2), rights and duties of data principals (Chapter 3), the Data Protection Board (Chapters 5-6), appeals (Chapter 7), and penalties (Chapter 8).[3]
“The Act’s Schedule sets a penalty of up to ₹250 crore for a data fiduciary that breaches its obligation to implement reasonable security safeguards against a personal data breach.[16]”
Who the Act Applies To
The DPDP Act applies to processing of digital personal data within India, including personal data that was originally collected offline and later digitised. Unlike GDPR, it carves out no exemption for small organisations; size doesn’t change whether the Act applies.[4]
The Act also reaches outside India. It applies to processing that happens abroad if that processing is connected to offering goods or services to individuals located in India.[5] A foreign fintech serving Indian customers is in scope even if it has no physical presence here.
A few categories sit outside the Act’s reach. Personal data an individual processes for their own personal or domestic purposes is generally exempt, and the government can exempt processing tied to legal proceedings, regulatory or law-enforcement functions, and matters of national security, sovereignty, or public order.[6]
The Act’s own definitions section sets the vocabulary everything else builds on:
| Term | Meaning Under Section 2 |
|---|---|
| Personal data | Any data about an individual who is identifiable by or in relation to that data |
| Data fiduciary | Any person who, alone or with others, determines the purpose and means of processing personal data |
| Data principal | The individual to whom the personal data relates |
| Data processor | Any person who processes personal data on behalf of a data fiduciary |
[7]
A data fiduciary is the entity that decides why and how data gets processed. A bank onboarding a customer, an NBFC underwriting a loan, or an insurer settling a claim would typically fit that description; these are illustrative examples, not part of the Act’s own text.
What Data Fiduciaries Have to Do
Consent is the foundation. Personal data can only be processed on the basis of consent that is free, specific, informed, unconditional, unambiguous, and given through clear affirmative action. Every consent request has to come with an itemised notice describing what data is being collected, why, how to withdraw consent, and how to complain to the Data Protection Board.[8]
Section 7 carves out “legitimate uses,” cases where a data fiduciary can process personal data without consent. This replaced the “deemed consent” language from the 2022 draft bill. Legitimate uses include specified employment purposes, responding to medical emergencies, fulfilling legal obligations on behalf of the state, and providing a service or benefit the data principal has themselves sought, subject in some cases to the data principal not objecting.[9]
Security and breach obligations apply regardless of scale. A data fiduciary must implement reasonable security safeguards, and on becoming aware of a breach, must notify both the Data Protection Board and every affected data principal, with a detailed report due to the Board within 72 hours (or longer if the Board permits). There’s no minimum-records threshold; the obligation applies even if only one record is affected.[12]
Organisations designated a “Significant Data Fiduciary,” based on factors like volume and sensitivity of data processed, risk to data principals, and potential impact on India’s sovereignty, electoral democracy, state security, or public order, carry extra obligations: appointing a Data Protection Officer, running an annual Data Protection Impact Assessment and audit, ensuring algorithmic transparency, and observing added restrictions on cross-border transfer of specified data categories.[13]
Children’s data gets specific treatment under Section 9. Anyone under 18 counts as a child, and data fiduciaries need verifiable parental or guardian consent before processing a child’s personal data. Tracking, behavioural monitoring, and targeted advertising directed at children are barred outright.[14]
Cross-border data transfer takes a “blacklist” approach rather than GDPR’s adequacy-and-mechanism model: personal data can go to any country or territory except those the central government specifically restricts by notification. There’s no requirement to justify each individual transfer or use tools like standard contractual clauses.[15]
What Data Principals Can Do
The Act gives data principals four core rights: to access information about how their personal data is being processed, to correction and erasure of that data, to grievance redressal, and to nominate someone else to exercise these rights on their behalf if they die or become incapacitated.[10] Under Rule 14 of the DPDP Rules, 2025, data fiduciaries and consent managers have to resolve a grievance within 90 days.[11]
Penalties and Who Enforces Them
The Act’s Schedule sets tiered financial penalties, adjudicated by the Data Protection Board of India:
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable security safeguards against a breach | ₹250 crore |
| Failure to notify the Board and affected data principals of a breach | ₹200 crore |
| Non-compliance with children's-data obligations | ₹200 crore |
| A data principal's breach of their own duties under the Act | ₹10,000 |
[16]
The Data Protection Board of India is the adjudicatory body the Act sets up. It investigates and determines non-compliance, imposes penalties, issues corrective orders such as data erasure or a stop to processing, and hears escalated grievances from data principals.[17] Its Chairperson and Members are meant to be selected through a Search-cum-Selection Committee. The Cabinet Secretary chairs the committee for the Chairperson role, alongside the Secretaries of the Department of Legal Affairs and MeitY plus two subject-matter experts; a similar structure, chaired by the MeitY Secretary, applies to Member selection. At least one Member must be a legal expert.[18]
Where Implementation Actually Stands
This is the part of the DPDP story that moves fastest, so treat what follows as current as of this piece’s publish date rather than a permanent status.
The Digital Personal Data Protection Rules, 2025, the operational rules under the 2023 Act, were notified by MeitY via gazette notification on 13 November 2025. There is no separate “DPDP Act 2025.” The statute is still the 2023 Act; “2025” refers to the Rules made under it.[19]
Those Rules come into force in three phases:
| Phase | Date | What Takes Effect |
|---|---|---|
| Phase 1 | 13 November 2025 | Rules 1, 2, and 17-21: definitions, procedural framework, and constitution of the Data Protection Board (complaints can begin to be filed) |
| Phase 2 | 13 November 2026 | Rule 4: Consent Manager registration opens; enforcement and penalty machinery switches on |
| Phase 3 | 13 May 2027 | Rules 3, 5-16, 22, 23: full compliance obligations for notice/consent standards, data principal rights, security safeguards, breach reporting, retention/erasure, children's data, and cross-border transfer conditions |
[20]
A Consent Manager, introduced by the Rules, is a distinct registrable entity: an Indian-incorporated company with a minimum net worth of ₹2 crore, that gives a data principal one interface to grant, manage, review, and withdraw consent across multiple data fiduciaries. Registration for these entities opens at the Phase 2 mark.[21]
Because of this phasing, full organisational compliance isn’t legally required until 13 May 2027. Coverage has described this as an 18-month compliance runway from the November 2025 notification, with no indication of a further grace period after that.[22]
“As of an August 2026-dated legal-affairs report, the Data Protection Board was constituted in law on 13 November 2025, but no Chairperson or Members had actually been appointed to it. Search committees solicited nominations through May and June 2026, without a finalised recommendation as of that report.[23]”
One consequence of that gap: courts have directed litigants to the Board for remedies it currently has no appointed members to adjudicate.[23]
What This Means for BFSI Compliance Teams
Read together, the phased compliance timeline and the unstaffed Board are running on two separate schedules. The Act’s substantive obligations (consent standards, breach notification, children’s-data restrictions, cross-border rules) become legally required on 13 May 2027 regardless of when the Board gets its members.[20][22] The Board’s staffing delay changes who can currently adjudicate a complaint; it does not move the 13 May 2027 deadline itself.[23] For a BFSI institution’s own compliance planning, the practical takeaway is to treat the 18-month runway from the November 2025 notification as the working deadline, independent of when the Board becomes fully staffed.[22][23]
The practical implication is that KYC and onboarding fit the Act’s own definition of data-fiduciary activity: an institution that decides why and how a customer’s data gets processed would generally be considered a data fiduciary,[7] bound by the Act’s consent and notice requirements[8] and its breach-notification obligations.[12] The 18-month runway from the November 2025 notification is the window to build that infrastructure before Phase 3 makes it a legal requirement.[22]
Read against that fiduciary categorization, the penalty Schedule’s own structure suggests where the compliance stakes actually sit. Fiduciary penalties run as high as ₹250 crore, while a data principal’s own breach of duties caps out at ₹10,000,[16]a gap wide enough to indicate that the Act’s enforcement weight, and the compliance burden it creates, falls on institutions like BFSI fiduciaries rather than on individual customers.
Frequently Asked Questions
This piece is KYCKART’s informational interpretation of publicly available regulatory sources on the DPDP Act and Rules. It is not legal advice. Organisations should verify specific compliance obligations against the primary statutory text and consult qualified counsel before acting on any interpretation here.
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published August 14, 2026
KYCKART Intelligence
Questions About Where Your DPDP Compliance Stands?
KYCKART’s compliance team tracks the DPDP Act’s phased rollout as it lands across BFSI onboarding and data-handling workflows. Talk to us about what the 13 May 2027 deadline means for your institution.
Talk to Our Teamarrow_forward