DPDP Data Protection Act 2023: Key Obligations for Businesses in India

Guide to the Digital Personal Data Protection Act 2023. Covers consent requirements, data principal rights, data fiduciary obligations, cross-border transfers, and penalties up to...

Published
Updated
Reading time
3 min
Views
12
Questions
6 answered
  • Expert Reviewed
  • High Complexity
Topic
Cyber & Data Protection
Published
May 13, 2026
Last updated
Sep 23, 2026
Reading time
3 min
0:00
Last updated: September 2026Verified against: Government sources

India's Digital Personal Data Protection Act 2023 (DPDP Act) is the first comprehensive data protection legislation in India. Applicable to the processing of digital personal data of individuals (data principals), the Act creates significant obligations for businesses (data fiduciaries) with penalties up to Rs. 250 crore per violation.

Key Definitions

  • Personal Data: Any data about an identifiable individual
  • Data Principal: The individual whose personal data is processed (the person)
  • Data Fiduciary: Entity that determines the purpose and means of processing data (the business)
  • Data Processor: Entity processing data on behalf of a data fiduciary

Consent Requirements

  • Processing of personal data requires freely given, specific, informed, unconditional, and unambiguous consent
  • Consent must be for a specific purpose — cannot be bundled into general terms
  • Consent requests must be in plain language and multilingual
  • Consent can be withdrawn at any time — as easily as it was given

Grounds for Processing Without Consent (Legitimate Use)

  • State and its instrumentalities for national security, law enforcement
  • Employment-related processing (employee data)
  • Medical emergency processing
  • Compliance with a judgment or court order

Rights of Data Principals

  • Right to information about processing
  • Right to correction and erasure
  • Right to grievance redressal
  • Right to nominate a person to exercise rights on death/incapacity

Obligations of Data Fiduciaries

  • Purpose limitation: collect only what is needed for stated purpose
  • Data minimisation: collect minimum necessary data
  • Storage limitation: retain only as long as necessary
  • Security safeguards: implement appropriate technical/organizational measures
  • Data breach notification: notify Data Protection Board and affected individuals
  • Significant Data Fiduciaries (large processors) must appoint: Data Protection Officer (DPO), conduct Data Protection Impact Assessment (DPIA), data audits

Cross-Border Data Transfers

Transfer of personal data outside India to countries approved by the Central Government. No data localisation requirement for most data (unlike some earlier drafts), but Government can restrict specific countries/sectors.

Penalties

ViolationPenalty
Breach of children's data obligationsUp to Rs. 200 crore
Failure to implement security safeguardsUp to Rs. 250 crore
Breach notification failureUp to Rs. 200 crore
Other violationsUp to Rs. 50 crore

Need Expert Help?

TaxClue's CA and legal team can assist you. Contact us or see our services.

Quick recapKey facts & short answers

Key Facts About DPDP Data Protection Act

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes DPDP Data Protection Act end to end for you.

What is the DPDP Act 2023?

India's Digital Personal Data Protection Act 2023 — first comprehensive data protection law governing how businesses (data fiduciaries) collect, process, and store personal data of individuals.

What consent is required under DPDP Act?

Freely given, specific, informed, unconditional, and unambiguous consent for each stated purpose. Bundled consent in general T&Cs is not sufficient.

DPDP Data Protection Act: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
MS
About the author
846 articles
Monika Sharma Verified expert Director

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

India's Digital Personal Data Protection Act 2023 — first comprehensive data protection law governing how businesses (data fiduciaries) collect, process, and store personal data of individuals.

Freely given, specific, informed, unconditional, and unambiguous consent for each stated purpose. Bundled consent in general T&Cs is not sufficient.

Large data processors designated by the Government who face enhanced obligations: DPO appointment, Data Protection Impact Assessment (DPIA), and periodic data audits.

Up to Rs. 250 crore for security safeguard failures, Rs. 200 crore for children's data violations, and up to Rs. 50 crore for other violations.

No general data localisation requirement. Cross-border transfers to government-approved countries are permitted. Specific sectors/countries may be restricted by notification.

Right to information, right to correction and erasure, right to grievance redressal, and right to nominate a representative.