The Digital Personal Data Protection Act, 2023 — Act No. 22 of 2023 — received presidential assent on 11 August 2023. It runs to 44 sections across nine chapters, with a single Schedule setting out penalties. The Act's stated purpose is to provide for the processing of digital personal data in a way that recognises both the individual's right to protect their personal data and the need to process that data for lawful purposes.
Two features make it unusual among data protection statutes. It is written in deliberately plain language, and it uses worked illustrations inside the statutory text — small worked examples, given legal status, showing how a provision applies. When you're unsure what a section means, the illustration attached to it is often the fastest route to an answer.
Three qualifiers narrow the Act's subject matter, and all three have to be satisfied.
Personal data means data about an individual who is identifiable by or in relation to that data. There is no separate category of "sensitive" data. This is a significant departure from the earlier SPDI Rules, which singled out passwords, financial information, health condition, sexual orientation, medical records and biometrics for heightened treatment. The DPDP Act abandons that tiering entirely — every item of personal data attracts the same baseline obligations.
Digital means the Act reaches personal data in digital form, and personal data in non-digital form that is subsequently digitised. A paper form in a filing cabinet is outside; the same form once scanned is inside.
Processing is defined broadly, covering an automated operation or set of operations performed on digital personal data — collection, storage, use, sharing, disclosure and erasure all fall within it.
Under s. 3, the Act applies to the processing of digital personal data within the territory of India.
It also applies to processing outside India, where that processing is in connection with any activity related to offering goods or services to Data Principals within India. A company with no Indian entity, no Indian servers and no Indian staff is still within scope if it offers goods or services to people in India.
Note what the extraterritorial limb does not cover: processing outside India that merely happens to involve Indian residents' data without any offering of goods or services to them.
s. 3 excludes two situations, and both are narrower than they first appear.
Personal data made publicly available by the Data Principal themselves, or by another person under a legal obligation to make it public. The Act's own illustration involves a person blogging and posting their own details on social media. The key word is by — data that leaked, was scraped, or was published by someone else without obligation is not "made publicly available" in this sense.
Processing by an individual for any personal or domestic purpose. This exempts the individual, not the organisation. A person keeping a contact list is outside; a business keeping the same list is not.
Using these terms consistently matters, because the Act allocates obligations by role rather than by industry.
| Term | Who it is |
|---|---|
| Data Principal | The individual the personal data relates to. Where the individual is a child, it includes the parent or lawful guardian |
| Data Fiduciary | The person who, alone or with others, determines the purpose and means of processing. This is the accountable party |
| Data Processor | A person who processes personal data on behalf of a Data Fiduciary |
| Consent Manager | A person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform |
| Significant Data Fiduciary | A Data Fiduciary or class of them notified as such by the Central Government under section 10, attracting additional obligations |
The word "fiduciary" is doing real work. It signals that the organisation holds the data in a position of trust and accountability, not as an owner.
The Act did not commence on assent. Different provisions were brought into force on different dates by notification, and the Rules follow a matching schedule.
| Date | What is in force |
|---|---|
| 13 November 2025 | Definitions, the Data Protection Board and its powers, rule-making provisions |
| 13 November 2026 | Consent Manager registration under Rule 4; s. 6(9); s. 27(1)(d) |
| 13 May 2027 | Notice, consent, Data Fiduciary obligations, children's data, Significant Data Fiduciary duties, all Data Principal rights, and the penalty regime |
So as at today, the Board exists and is operating, but it cannot yet adjudicate a breach of the notice, consent or rights provisions, because those provisions have not commenced.
No. The DPDP Act has no legitimate-interest basis for processing, no separate category of sensitive personal data, a nomination right with no GDPR equivalent, and its own notice content requirements. Organisations that hold a GDPR programme still have mapping work to do; they do not have a head start on consent architecture.
Only once digitised. The Act governs digital personal data, and non-digital personal data that is subsequently digitised. A paper form remains outside scope until it is scanned or keyed in.
Yes, where they identify an individual. The Act draws no distinction between personal and professional context — a named individual's work email is personal data about an identifiable individual.
Yes. Employers process digital personal data about identifiable individuals and are Data Fiduciaries in respect of it. Certain provisions are relaxed for employment-related processing under the legitimate uses in s. 7, but the Act applies.
No. Unlike the SPDI Rules it replaces, the DPDP Act applies one standard to all personal data. Health data, financial data and biometrics attract the same baseline obligations as a name and email address.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); commencement notification G.S.R. 843(E) dated 13 November 2025. Reference material about the law, not legal advice — see /disclaimer.