Data Protection Atlas

Digital Personal Data Protection Act (India)

Tier 2 Partially in force

Short and deliberately principle-light: 44 sections across 8 chapters, covering digital personal data only. Consent-or-legitimate-uses as the grounds, duties on individuals as well as companies, and a negative-list approach to transfers. The 2025 Rules carry the operational detail.

Identity

Citation
Digital Personal Data Protection Act, 2023 (No. 22 of 2023), India; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))
Jurisdiction
India
Type
comprehensive

Assented 11 Aug 2023; phased — Rules notified 14 Nov 2025

Amended by: Operationalised by the DPDP Rules 2025 (≈18-month phase-in)

← India overview

Structure

What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.

Chapter I — Preliminary (ss. 1–3)

Definitions — data principal, data fiduciary — and the digital-only scope.

  • s. 3 Applies to digital personal data, including offline data later digitised.
Chapter II — Obligations of data fiduciaries (ss. 4–10)

Grounds, notice, consent, security, breach, children and the ‘significant’ tier.

  • s. 4 + s. 7 Consent or enumerated ‘legitimate uses’.
  • s. 8 Security safeguards and breach notification.
  • s. 9 Children — under-18s: verifiable parental consent, no tracking or targeted ads.
  • s. 10 Significant Data Fiduciaries — DPO in India, audits, DPIAs.
Chapter III — Rights and duties of data principals (ss. 11–15)

The rights list — and, unusually, statutory duties on individuals.

  • s. 11 Access.
  • s. 12 Correction and erasure.
  • s. 15 Duties of data principals — no false grievances, no impersonation.
Chapter IV — Special provisions (ss. 16–17)

Transfers and the broad state exemptions.

  • s. 16 Transfers allowed except to blacklisted countries (negative list).
  • s. 17 Exemptions — state security and public order, notably broad.
Chapters V–VI — The Board and appeals (ss. 18–31)

A digital-first Data Protection Board; appeals to TDSAT.

Chapters VII–VIII — Penalties and miscellaneous (ss. 32–44)

The penalty schedule and consequential amendments.

  • s. 33 + Schedule Penalties up to INR 2.5bn per category.
  • s. 44(3) Amends the RTI Act — a persistent controversy.

Regulatory enforcement

Interactions and conflicts

Replaces the old IT Act s. 43A compensation route; sectoral rules (RBI localisation, health) continue in parallel. The DPDP Rules 2025 supply consent-manager, breach and children’s-verification detail, phased over roughly 18 months. State exemptions under s. 17 remain the main adequacy hurdle in EU discussions.

Sources

Never independently verified — seeded from the prototype.