27 May 2026  ·  DPDPA & IT Compliance

Understanding the Digital Personal Data Protection Act, 2023

Back to Blog

India's Digital Personal Data Protection Act, 2023 marks a watershed moment in the country's approach to data governance. For individuals, businesses, and legal practitioners alike, understanding its provisions is no longer optional — it is a fundamental compliance imperative.

What is the DPDPA 2023?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's first comprehensive legislation dedicated to the protection of digital personal data. Enacted by Parliament and receiving Presidential assent on 11 August 2023, the Act establishes a framework governing how organisations — referred to as "Data Fiduciaries" — collect, store, process, and share the personal data of individuals, termed "Data Principals." The DPDPA applies to the processing of digital personal data within India, as well as to processing outside India if it involves offering goods or services to individuals in India.

Key Definitions Under the Act

The DPDPA introduces several important definitions. "Personal Data" means any data about an individual who is identifiable by or in relation to such data. A "Data Fiduciary" is any person who alone or in conjunction with others determines the purpose and means of processing personal data. A "Data Processor" is any person who processes personal data on behalf of a Data Fiduciary. "Consent" under the Act must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. These definitions form the bedrock of compliance obligations under the legislation.

Rights of Data Principals

The DPDPA confers several rights upon individuals whose data is being processed. These include the right to access information about personal data being processed, the right to correction and erasure of inaccurate or incomplete data, the right to grievance redressal, and the right to nominate another individual to exercise rights on their behalf in the event of death or incapacity. These rights represent a significant shift towards individual empowerment in India's digital economy and must be honoured by all Data Fiduciaries within prescribed timelines.

Obligations of Data Fiduciaries

Organisations processing personal data bear substantial obligations under the DPDPA. They must obtain valid consent before processing, provide clear and accessible privacy notices, implement reasonable security safeguards, notify the Data Protection Board and affected individuals in the event of a data breach, and ensure that personal data is erased once the purpose for which it was collected is fulfilled. Significant Data Fiduciaries — those processing large volumes of sensitive data — face additional obligations including data protection impact assessments and the appointment of a Data Protection Officer.

Penalties for Non-Compliance

The DPDPA prescribes substantial financial penalties for violations. A failure to implement adequate security safeguards resulting in a data breach may attract a penalty of up to ₹250 crore. Failure to notify the Data Protection Board of a breach may result in a penalty of up to ₹200 crore. Non-fulfilment of obligations relating to children's data may attract penalties of up to ₹200 crore. The Act also establishes the Data Protection Board of India as the adjudicatory authority for complaints and enforcement. These penalties underscore the importance of proactive compliance for all organisations operating in India's digital space.

Compliance with the DPDPA is not merely a legal obligation — it is an opportunity to build trust with clients, partners, and stakeholders. If your organisation requires guidance on DPDPA compliance, data protection policies, or responding to a data breach, our advocates are here to assist.

Consult Our Advocates

Advocacy A Law Firm  ·  DPDPA & IT Compliance

Advocacy A Law Firm

Your trusted advocates for corporate, civil, and compliance matters across India.

Legal Compliance

Udyam Registration

UDYAM-UP-09-0043193

GST No.

09CHFPK34641ZK

Office Hours

Mon – Sat  ·  10:00 AM – 6:00 PM IST

Data Privacy & Compliance Notice

Advocacy A Law Firm is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Digital Personal Data Protection Act, 2023 (DPDPA) (India). Any personal information you provide through this website — including your name, email address, and contact details — is collected solely for the purpose of responding to your legal enquiries and will not be shared with third parties without your explicit consent. You have the right to access, rectify, or request deletion of your personal data at any time by contacting us at [email protected]. By submitting the contact form on this website, you consent to the processing of your personal data for the stated purpose.

Copyright © 2026 Advocacy A Law Firm — All Rights Reserved.