Ask Veda

TaxClue AI · Active
Namaste! I'm Veda — TaxClue's AI assistant. 🙏

Before we begin, please share your name, phone & email below so our expert can guide you personally. Right after that, you can ask me anything.
Share your details — our expert will call you
Powered by TaxClue · India's Trusted Compliance Platform

DPDP Data Protection Act 2023: Key Obligations for Businesses in India

Guide to the Digital Personal Data Protection Act 2023. Covers consent requirements, data principal rights, data fiduciary obligations, cross-border transfers, and penalties up to ...

TaxClue Team Tax & Compliance Expert
2 min read 0 views Updated May 24, 2026
Expert Reviewed High Complexity
0:00

India's Digital Personal Data Protection Act 2023 (DPDP Act) is the first comprehensive data protection legislation in India. Applicable to the processing of digital personal data of individuals (data principals), the Act creates significant obligations for businesses (data fiduciaries) with penalties up to Rs. 250 crore per violation.

Key Definitions

  • Personal Data: Any data about an identifiable individual
  • Data Principal: The individual whose personal data is processed (the person)
  • Data Fiduciary: Entity that determines the purpose and means of processing data (the business)
  • Data Processor: Entity processing data on behalf of a data fiduciary

Consent Requirements

  • Processing of personal data requires freely given, specific, informed, unconditional, and unambiguous consent
  • Consent must be for a specific purpose — cannot be bundled into general terms
  • Consent requests must be in plain language and multilingual
  • Consent can be withdrawn at any time — as easily as it was given

Grounds for Processing Without Consent (Legitimate Use)

  • State and its instrumentalities for national security, law enforcement
  • Employment-related processing (employee data)
  • Medical emergency processing
  • Compliance with a judgment or court order

Rights of Data Principals

  • Right to information about processing
  • Right to correction and erasure
  • Right to grievance redressal
  • Right to nominate a person to exercise rights on death/incapacity

Obligations of Data Fiduciaries

  • Purpose limitation: collect only what is needed for stated purpose
  • Data minimisation: collect minimum necessary data
  • Storage limitation: retain only as long as necessary
  • Security safeguards: implement appropriate technical/organizational measures
  • Data breach notification: notify Data Protection Board and affected individuals
  • Significant Data Fiduciaries (large processors) must appoint: Data Protection Officer (DPO), conduct Data Protection Impact Assessment (DPIA), data audits

Cross-Border Data Transfers

Transfer of personal data outside India to countries approved by the Central Government. No data localisation requirement for most data (unlike some earlier drafts), but Government can restrict specific countries/sectors.

Penalties

ViolationPenalty
Breach of children's data obligationsUp to Rs. 200 crore
Failure to implement security safeguardsUp to Rs. 250 crore
Breach notification failureUp to Rs. 200 crore
Other violationsUp to Rs. 50 crore

Need Expert Help?

TaxClue's CA and legal team can assist you. Contact us or see our services.

Need Help with Compliance?

Our CA experts guide you through the entire process — registration to filing.

Frequently Asked Questions
What is the DPDP Act 2023?
India's Digital Personal Data Protection Act 2023 — first comprehensive data protection law governing how businesses (data fiduciaries) collect, process, and store personal data of individuals.
What consent is required under DPDP Act?
Freely given, specific, informed, unconditional, and unambiguous consent for each stated purpose. Bundled consent in general T&Cs is not sufficient.
What is a Significant Data Fiduciary?
Large data processors designated by the Government who face enhanced obligations: DPO appointment, Data Protection Impact Assessment (DPIA), and periodic data audits.
What are the penalties under DPDP Act?
Up to Rs. 250 crore for security safeguard failures, Rs. 200 crore for children's data violations, and up to Rs. 50 crore for other violations.
Does India require data localisation under DPDP Act?
No general data localisation requirement. Cross-border transfers to government-approved countries are permitted. Specific sectors/countries may be restricted by notification.
What rights do individuals have under DPDP Act?
Right to information, right to correction and erasure, right to grievance redressal, and right to nominate a representative.

Was this article helpful?

Thank you for your feedback!
Need help with Cyber & Data Protection?
  • Pvt Ltd Registration
  • ITR Filing
  • GST Registration
TT
TaxClue Team VERIFIED EXPERT
Tax & Compliance Expert
Experienced in company registration, GST, trademark, and FSSAI compliance.

Need Expert Help? We're Here.

Our CAs and CS professionals handle everything — from registration to compliance.