Digital Personal Data Protection Act (India)
Tier 2 Partially in forceShort and deliberately principle-light: 44 sections across 8 chapters, covering digital personal data only. Consent-or-legitimate-uses as the grounds, duties on individuals as well as companies, and a negative-list approach to transfers. The 2025 Rules carry the operational detail.
Identity
- Citation
- Digital Personal Data Protection Act, 2023 (No. 22 of 2023), India; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))
- Jurisdiction
- India
- Type
- comprehensive
Assented 11 Aug 2023; phased — Rules notified 14 Nov 2025
Amended by: Operationalised by the DPDP Rules 2025 (≈18-month phase-in)
Structure
What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.
Chapter I — Preliminary (ss. 1–3)
Definitions — data principal, data fiduciary — and the digital-only scope.
- s. 3 Applies to digital personal data, including offline data later digitised.
Chapter II — Obligations of data fiduciaries (ss. 4–10)
Grounds, notice, consent, security, breach, children and the ‘significant’ tier.
- s. 4 + s. 7 Consent or enumerated ‘legitimate uses’.
- s. 8 Security safeguards and breach notification.
- s. 9 Children — under-18s: verifiable parental consent, no tracking or targeted ads.
- s. 10 Significant Data Fiduciaries — DPO in India, audits, DPIAs.
Chapter III — Rights and duties of data principals (ss. 11–15)
The rights list — and, unusually, statutory duties on individuals.
- s. 11 Access.
- s. 12 Correction and erasure.
- s. 15 Duties of data principals — no false grievances, no impersonation.
Chapter IV — Special provisions (ss. 16–17)
Transfers and the broad state exemptions.
- s. 16 Transfers allowed except to blacklisted countries (negative list).
- s. 17 Exemptions — state security and public order, notably broad.
Chapters V–VI — The Board and appeals (ss. 18–31)
A digital-first Data Protection Board; appeals to TDSAT.
Chapters VII–VIII — Penalties and miscellaneous (ss. 32–44)
The penalty schedule and consequential amendments.
- s. 33 + Schedule Penalties up to INR 2.5bn per category.
- s. 44(3) Amends the RTI Act — a persistent controversy.
Regulatory enforcement
Interactions and conflicts
Replaces the old IT Act s. 43A compensation route; sectoral rules (RBI localisation, health) continue in parallel. The DPDP Rules 2025 supply consent-manager, breach and children’s-verification detail, phased over roughly 18 months. State exemptions under s. 17 remain the main adequacy hurdle in EU discussions.
Sources
- Primary Official text — MeitY
- Regulator Data Protection Board of India — regulator
Never independently verified — seeded from the prototype.