The short answer: The Digital Personal Data Protection Act, 2023 is India's law governing how organisations process digital personal data. It applies to digital personal data processed within India, and to processing outside India where that processing relates to offering goods or services to individuals in India. Personal data made publicly available by the individual, and processing for purely personal or domestic purposes, fall outside it.

What the DPDP Act Covers

⚖️ Legal structure: Chapter I, ss. 1–4📅 In force from: 13 November 2025🔍 Source: DPDP Act 2023 · Rules 2025
On this page
  1. What is the DPDP Act, in one paragraph?
  2. What data does the Act govern?
  3. Who does the DPDP Act apply to?
  4. What does the Act leave alone?
  5. Who's who — the Act's own vocabulary
  6. When does the Act take effect?
  7. Where to go next
  8. Frequently asked questions

What is the DPDP Act, in one paragraph?

The Digital Personal Data Protection Act, 2023 — Act No. 22 of 2023 — received presidential assent on 11 August 2023. It runs to 44 sections across nine chapters, with a single Schedule setting out penalties. The Act's stated purpose is to provide for the processing of digital personal data in a way that recognises both the individual's right to protect their personal data and the need to process that data for lawful purposes.

Two features make it unusual among data protection statutes. It is written in deliberately plain language, and it uses worked illustrations inside the statutory text — small worked examples, given legal status, showing how a provision applies. When you're unsure what a section means, the illustration attached to it is often the fastest route to an answer.

What data does the Act govern?

Three qualifiers narrow the Act's subject matter, and all three have to be satisfied.

Personal data means data about an individual who is identifiable by or in relation to that data. There is no separate category of "sensitive" data. This is a significant departure from the earlier SPDI Rules, which singled out passwords, financial information, health condition, sexual orientation, medical records and biometrics for heightened treatment. The DPDP Act abandons that tiering entirely — every item of personal data attracts the same baseline obligations.

Digital means the Act reaches personal data in digital form, and personal data in non-digital form that is subsequently digitised. A paper form in a filing cabinet is outside; the same form once scanned is inside.

Processing is defined broadly, covering an automated operation or set of operations performed on digital personal data — collection, storage, use, sharing, disclosure and erasure all fall within it.

Who does the DPDP Act apply to?

Under s. 3, the Act applies to the processing of digital personal data within the territory of India.

It also applies to processing outside India, where that processing is in connection with any activity related to offering goods or services to Data Principals within India. A company with no Indian entity, no Indian servers and no Indian staff is still within scope if it offers goods or services to people in India.

Note what the extraterritorial limb does not cover: processing outside India that merely happens to involve Indian residents' data without any offering of goods or services to them.

What does the Act leave alone?

s. 3 excludes two situations, and both are narrower than they first appear.

Personal data made publicly available by the Data Principal themselves, or by another person under a legal obligation to make it public. The Act's own illustration involves a person blogging and posting their own details on social media. The key word is by — data that leaked, was scraped, or was published by someone else without obligation is not "made publicly available" in this sense.

Processing by an individual for any personal or domestic purpose. This exempts the individual, not the organisation. A person keeping a contact list is outside; a business keeping the same list is not.

Who's who — the Act's own vocabulary

Using these terms consistently matters, because the Act allocates obligations by role rather than by industry.

TermWho it is
Data PrincipalThe individual the personal data relates to. Where the individual is a child, it includes the parent or lawful guardian
Data FiduciaryThe person who, alone or with others, determines the purpose and means of processing. This is the accountable party
Data ProcessorA person who processes personal data on behalf of a Data Fiduciary
Consent ManagerA person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform
Significant Data FiduciaryA Data Fiduciary or class of them notified as such by the Central Government under section 10, attracting additional obligations

The word "fiduciary" is doing real work. It signals that the organisation holds the data in a position of trust and accountability, not as an owner.

When does the Act take effect?

The Act did not commence on assent. Different provisions were brought into force on different dates by notification, and the Rules follow a matching schedule.

DateWhat is in force
13 November 2025Definitions, the Data Protection Board and its powers, rule-making provisions
13 November 2026Consent Manager registration under Rule 4; s. 6(9); s. 27(1)(d)
13 May 2027Notice, consent, Data Fiduciary obligations, children's data, Significant Data Fiduciary duties, all Data Principal rights, and the penalty regime

So as at today, the Board exists and is operating, but it cannot yet adjudicate a breach of the notice, consent or rights provisions, because those provisions have not commenced.

Where to go next

Frequently asked questions

Is the DPDP Act the same as GDPR?

No. The DPDP Act has no legitimate-interest basis for processing, no separate category of sensitive personal data, a nomination right with no GDPR equivalent, and its own notice content requirements. Organisations that hold a GDPR programme still have mapping work to do; they do not have a head start on consent architecture.

Does the DPDP Act apply to paper records?

Only once digitised. The Act governs digital personal data, and non-digital personal data that is subsequently digitised. A paper form remains outside scope until it is scanned or keyed in.

Does the DPDP Act apply to business contact details?

Yes, where they identify an individual. The Act draws no distinction between personal and professional context — a named individual's work email is personal data about an identifiable individual.

Does the DPDP Act cover employee data?

Yes. Employers process digital personal data about identifiable individuals and are Data Fiduciaries in respect of it. Certain provisions are relaxed for employment-related processing under the legitimate uses in s. 7, but the Act applies.

Is there a sensitive personal data category under the DPDP Act?

No. Unlike the SPDI Rules it replaces, the DPDP Act applies one standard to all personal data. Health data, financial data and biometrics attract the same baseline obligations as a name and email address.

See how Consiva handles this automatically

Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.

Start Free — No Credit Card →

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); commencement notification G.S.R. 843(E) dated 13 November 2025. Reference material about the law, not legal advice — see /disclaimer.