Data Protection

Compliance with the DPDP Act, 2023 & DPDP Rules 2025

A comprehensive guide to India's Digital Personal Data Protection Act — scope, consent, data principal rights, penalties, and compliance strategy

The Digital Personal Data Protection Act 2023 — biometric shield data security concept

The Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) marks a significant step towards regulating the processing and handling of personal data in India. By focusing on the management of digital personal data without distinguishing between tiers of data sensitivity, the Act aims to provide a comprehensive framework that safeguards individuals' data privacy while accommodating the needs of businesses and organisations.

For organisations operating in India — or offering goods and services to Indian data principals — adapting to these changes demands a rigorous approach to data protection, requiring a blend of legal, technical, and operational strategies.

Overview of the DPDP Act, 2023

The DPDP Act, 2023 redefines how personal data is handled in India, mandating stringent compliance measures for organisations. It is an evolution in the realm of personal data regulation, replacing the patchwork of data protection provisions previously scattered across the Information Technology Act, 2000 and its rules.

Scope of the Act

  • Applies to the processing of personal data in digital form.
  • Covers processing activities within India and extraterritorial processing related to offering goods or services to Indian data principals.
  • Excludes personal data made publicly available under legal obligation.

Key Definitions

Personal Data

Data about an identifiable individual.

Data Fiduciary

Entity determining the purpose and means of personal data processing.

Data Principal

The individual to whom the personal data belongs.

Data Processor

Entity processing personal data on behalf of a Data Fiduciary.

Data Protection Officer (DPO)

Individual appointed for compliance oversight.

Consent and Notification Obligations

  • Strict consent standards: free, specific, informed, unconditional, and unambiguous.
  • Notice required with each consent request.
  • Continued processing permissible until withdrawal of consent.
Legitimate Uses: The Act also permits data processing without explicit consent for specific "legitimate uses" — including employment-related processing and compliance with legal obligations — subject to defined conditions.

Responsibilities of Data Fiduciaries

Compliance Assurance

Responsibility for any processing activity carried out by or on behalf of the Data Fiduciary.

Specific Erasure Requirements

Obligation to erase personal data once the purpose of processing is fulfilled or consent is withdrawn.

Personal Data Breach Reporting

Mandatory reporting of data breaches to the Data Protection Board and affected Data Principals.

Children's Data

Verifiable parental or guardian consent required. Prohibitions on behaviour tracking and targeted advertising towards children.

Significant Data Fiduciaries (SDFs)

Periodic audits, impact assessments, and appointment of a DPO domiciled in India, responsible for grievance resolution.

Rights of a Data Principal

  • 1Right to access personal data held by a Data Fiduciary
  • 2Right to correction and erasure of personal data
  • 3Right to grievance redressal through the Data Fiduciary
  • 4Right to nominate another individual to exercise rights in case of death or incapacity

Data Protection Board & Penalties

Data Protection Board

The Act establishes a Data Protection Board of India as the investigatory and enforcement authority for personal data violations. Appeals lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Consent Managers

Platforms for managing data principal consent must be registered with the Data Protection Board and must operate as independent, interoperable systems.

Penalties

The Act introduces a civil liability regime with penalties up to INR 250 crore for violations. Organisations may also opt for voluntary rectification undertakings before the Board. The Central Government retains authority to issue blocking orders and regulatory notifications.

International Data Transfers

The Central Government may restrict data transfer to certain territories by notification. Existing laws with stricter data transfer regulations continue to prevail. Organisations must define clear protocols for cross-border transfers and ensure recipient countries provide adequate data protection.

Compliance Strategies

  • Appointment of a Data Protection Officer (DPO)
  • Regular risk assessments and data handling audits
  • Transparent data policies communicated to all stakeholders
  • Regular employee training on data protection obligations
IT Act Alignment: The Information Technology Act, 2000 (amended 2008) continues to apply alongside the DPDP Act. Organisations must ensure their data protection, privacy, and reasonable security practices comply with both frameworks.

Advisory Services

We offer a suite of services to assist businesses in navigating the complex requirements of the DPDP Act, 2023, ensuring compliance and safeguarding the privacy of data principals:

01

DPDP Readiness Assessment

Assess current data handling and processing practices against the requirements of the DPDP Act, 2023 to identify compliance gaps and areas needing improvement.

02

DPDP Training and Awareness

Conduct detailed training sessions for all employees to deepen their understanding of the DPDP Act, 2023, emphasising the critical nature of compliance in everyday operations.

03

Contract Review and Revision

Ensure existing contracts with stakeholders are revised to incorporate necessary clauses for compliance with the DPDP Act, aligning all agreements with the latest personal data standards.

04

DPDP Policies and Procedures

Develop and implement robust policies and procedures covering data processing, security, retention, and breach response.

05

Data Principal Rights Procedures

Create efficient processes allowing data principals to exercise their rights under the DPDP Act effectively, including rights to access, correct, and delete personal data.

06

Privacy by Default

Integrate privacy at the design stage of all systems and processes handling personal data, ensuring data protection is an inherent aspect of all operations.

07

Data Protection Impact Assessment (DPIA)

Implement DPIAs for new and ongoing projects that handle personal data to identify potential risks and implement measures to mitigate them.

08

Cross-Border Transfer Procedures

Define clear protocols for the international transfer of personal data in compliance with the DPDP Act, ensuring recipient countries provide adequate data protection.

09

Incident Response Plan

Develop a thorough incident response plan to address data breaches or security incidents swiftly, minimising impact and complying with reporting obligations under the DPDP Act.

10

DPDP Audit

Perform regular audits to verify the effectiveness of data protection measures and ongoing compliance with the DPDP Act, pinpointing areas for ongoing improvement.

The Digital Personal Data Protection Act, 2023 introduces comprehensive measures for personal data protection, emphasising consent, data principal rights, and the responsibilities of data fiduciaries and processors. For organisations, adapting to these changes demands a rigorous approach to data protection — requiring a blend of legal, technical, and operational strategies.

AEQUITAS LEGIS ASSOCIATES | Advocates & Solicitors | Pune | Mumbai | Delhi
This article is prepared for general informational purposes only and does not constitute legal advice or a legal opinion on any specific matter. Readers should seek independent advice from qualified counsel before acting on any of the matters discussed.

Consult Our Advocates

Office

Aequitas Legis Associates

Mahavir Chambers, Fort
Mumbai, Maharashtra, India

Bar Council of India Disclaimer

As per the rules of the Bar Council of India, advocates are not permitted to solicit work or advertise. By accessing this website, the user acknowledges that the information provided herein is solely for informational purposes and should not be interpreted as soliciting or advertisement. The information provided on this website is not intended to constitute legal advice, and no attorney-client relationship is created by use of this website. Aequitas Legis Associates is not responsible for any consequence of any action taken by the user relying on material/information provided under this website. In cases where the user has any legal issues, he/she in all cases must seek independent legal advice.

Copyright © 2026 Aequitas Legis Associates Website - All Rights Reserved.